CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10733
7.3 HIGH

A vulnerability was found in code-projects Restaurant Order System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Nov 3, 2024
CVE-2024-10732
6.3 MEDIUM

A vulnerability has been found in Tongda OA 2017 up to 11.10 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Nov 3, 2024
CVE-2024-10731
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Tongda OA up to 11.10. Affected is an unknown function of the file /pda/appcenter/check_seal.php. The …

Nov 3, 2024
CVE-2024-10730
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Tongda OA up to 11.6. This issue affects some unknown processing of the file …

Nov 3, 2024
CVE-2024-10702
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Simple Car Rental System 1.0. Affected is an unknown function of the file /signup.php. The …

Nov 2, 2024
CVE-2024-10701
3.5 LOW

A vulnerability was found in PHPGurukul Car Rental Portal 1.0. It has been rated as problematic. This issue affects some unknown processing of the file …

Nov 2, 2024
CVE-2024-10700
6.3 MEDIUM

A vulnerability was found in code-projects University Event Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Nov 2, 2024
CVE-2024-10699
7.3 HIGH

A vulnerability was found in code-projects Wazifa System 1.0. It has been classified as critical. This affects an unknown part of the file /controllers/logincontrol.php. The …

Nov 2, 2024
CVE-2024-10698
8.8 HIGH

A vulnerability was found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this issue is the function formSetDeviceName of the file /goform/SetOnlineDevName. The …

Nov 2, 2024
CVE-2024-10697
6.3 MEDIUM

A vulnerability has been found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac …

Nov 2, 2024
CVE-2024-9896
6.1 MEDIUM

The BBP Core – Expand bbPress powered forums with useful features plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of …

Nov 2, 2024
CVE-2024-51774
8.1 HIGH

qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors.

Nov 2, 2024
CVE-2024-9868
5.4 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Nov 2, 2024
CVE-2024-8739
6.1 MEDIUM

The ReCaptcha Integration for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …

Nov 2, 2024
CVE-2024-10540
5.3 MEDIUM

The Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress plugin for WordPress is vulnerable to SQL Injection via the 'service' parameter of the bookingpress_form …

Nov 2, 2024
CVE-2024-10310
6.4 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Nov 2, 2024
CVE-2024-9191
7.1 HIGH

The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables attackers in a compromised device …

Nov 1, 2024
CVE-2024-44234
5.5 MEDIUM

The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia …

Nov 1, 2024
CVE-2024-44233
5.5 MEDIUM

The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia …

Nov 1, 2024
CVE-2024-44232
5.5 MEDIUM

The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia …

Nov 1, 2024
CVE-2024-51252
9.8 CRITICAL

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore function.

Nov 1, 2024
CVE-2024-48353
7.5 HIGH

Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the …

Nov 1, 2024
CVE-2024-51492
8.8 HIGH

Zusam is a free and open-source way to self-host private forums. Prior to version 0.5.6, specially crafted SVG files uploaded to the service as images …

Nov 1, 2024
CVE-2024-51483

changedetection.io is free, open source web page change detection software. Prior to version 0.47.5, when a WebDriver is used to fetch files, `source:file:///etc/passwd` can be …

Nov 1, 2024
CVE-2024-51431
9.8 CRITICAL

LB-LINK BL-WR 1300H v.1.0.4 contains hardcoded credentials stored in /etc/shadow which are easily guessable.

Nov 1, 2024
CVE-2024-51248
8.8 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the modifyrow function.

Nov 1, 2024
CVE-2024-51247
8.8 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPPo function.

Nov 1, 2024
CVE-2024-51245
8.8 HIGH

In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the rename_table function.

Nov 1, 2024
CVE-2024-51244
8.8 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doIPSec function.

Nov 1, 2024
CVE-2024-49770

`oak` is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. By default `oak` does not …

Nov 1, 2024
CVE-2024-48410
6.1 MEDIUM

Cross Site Scripting vulnerability in Camtrace v.9.16.2.1 allows a remote attacker to execute arbitrary code via the login.php.

Nov 1, 2024
CVE-2024-48352
7.5 HIGH

Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTTP request with enterprise ID.

Nov 1, 2024
CVE-2024-48217
8.8 HIGH

An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-privilege escalation.

Nov 1, 2024
CVE-2024-41745
6.1 MEDIUM

IBM CICS TX Standard is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus …

Nov 1, 2024
CVE-2024-41744
6.5 MEDIUM

IBM CICS TX Standard 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a …

Nov 1, 2024
CVE-2024-41741
5.3 MEDIUM

IBM TXSeries for Multiplatforms 10.1 could allow an attacker to determine valid usernames due to an observable timing discrepancy which could be used in further …

Nov 1, 2024
CVE-2024-41738
5.9 MEDIUM

IBM TXSeries for Multiplatforms 10.1 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a …

Nov 1, 2024
CVE-2024-51432
4.8 MEDIUM

Cross Site Scripting vulnerability in FiberHome HG6544C RP2743 allows an attacker to execute arbitrary code via the SSID field in the WIFI Clients List not …

Nov 1, 2024
CVE-2024-51399
5.7 MEDIUM

Altai Technologies Ltd Altai IX500 Indoor 22 802.11ac Wave 2 AP After login, there are file reads in the background, and attackers can obtain sensitive …

Nov 1, 2024
CVE-2024-51398
6.5 MEDIUM

Altai Technologies Ltd Altai X500 Indoor 22 802.11ac Wave 2 AP web Management Weak password leakage in the background may lead to unauthorized access, data …

Nov 1, 2024
CVE-2024-51377
5.4 MEDIUM

An issue in Ladybird Web Solution Faveo Helpdesk & Servicedesk (On-Premise and Cloud) 9.2.0 allows a remote attacker to execute arbitrary code via the Subject …

Nov 1, 2024
CVE-2024-40490
7.5 HIGH

An issue in Sourcebans++ before v.1.8.0 allows a remote attacker to obtain sensitive information via a crafted XAJAX call to the Forgot Password function.

Nov 1, 2024
CVE-2024-28265
9.1 CRITICAL

IBOS v4.5.5 has an arbitrary file deletion vulnerability via \system\modules\dashboard\controllers\LoginController.php.

Nov 1, 2024
CVE-2024-22733
7.5 HIGH

TP Link MR200 V4 Firmware version 210201 was discovered to contain a null-pointer-dereference in the web administration panel on /cgi/login via the sign, Action or …

Nov 1, 2024
CVE-2024-10662
8.8 HIGH

A vulnerability was found in Tenda AC15 15.03.05.19 and classified as critical. This issue affects the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of …

Nov 1, 2024
CVE-2024-10661
8.8 HIGH

A vulnerability has been found in Tenda AC15 15.03.05.19 and classified as critical. This vulnerability affects the function SetDlnaCfg of the file /goform/SetDlnaCfg. The manipulation …

Nov 1, 2024
CVE-2024-10660
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in ESAFENET CDG 5. This affects the function deleteHook of the file /com/esafenet/servlet/policy/HookService.java. The manipulation of …

Nov 1, 2024
CVE-2024-10659
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5. Affected by this issue is the function delSystemEncryptPolicy of the file …

Nov 1, 2024
CVE-2024-49256
5.4 MEDIUM

Incorrect Authorization vulnerability in WP Chill Htaccess File Editor htaccess-file-editor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Htaccess File Editor: from n/a …

Nov 1, 2024
CVE-2024-48289
6.5 MEDIUM

An issue in the Bluetooth Low Energy implementation of Cypress Bluetooth SDK v3.66 allows attackers to cause a Denial of Service (DoS) via supplying a …

Nov 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.