CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-37220
5.3 MEDIUM

Missing Authorization vulnerability in OptinlyHQ Optinly allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Optinly: from n/a through 1.0.18.

Nov 1, 2024
CVE-2024-37218
4.3 MEDIUM

Missing Authorization vulnerability in WordPress Page Builder Sandwich Team Page Builder Sandwich – Front-End Page Builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue …

Nov 1, 2024
CVE-2024-37214
6.5 MEDIUM

Missing Authorization vulnerability in Dropshipping Guru Ali2Woo Lite Exploiting Incorrectly Configured Access Control Security Levels, Stored XSS.This issue affects Ali2Woo Lite: from n/a through 3.3.5.

Nov 1, 2024
CVE-2024-37209
6.5 MEDIUM

Access Control vulnerability in Prism IT Systems User Rights Access Manager allows . This issue affects User Rights Access Manager: from n/a through 1.1.2.

Nov 1, 2024
CVE-2024-37207
5.4 MEDIUM

Missing Authorization vulnerability in Theme4Press Demo Awesome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Demo Awesome: from n/a through 1.0.2.

Nov 1, 2024
CVE-2024-37204
4.3 MEDIUM

Missing Authorization vulnerability in PropertyHive PropertyHive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through 2.0.9.

Nov 1, 2024
CVE-2024-37203
4.3 MEDIUM

Missing Authorization vulnerability in Laybuy Laybuy Payment Extension for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Laybuy Payment Extension for WooCommerce: …

Nov 1, 2024
CVE-2024-37201
4.3 MEDIUM

Missing Authorization vulnerability in javmah Woocommerce Customers Order History allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Woocommerce Customers Order History: from n/a …

Nov 1, 2024
CVE-2024-37123
5.3 MEDIUM

Missing Authorization vulnerability in VowelWeb Ibtana allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ibtana: from n/a through 1.2.3.3.

Nov 1, 2024
CVE-2024-37119
5.3 MEDIUM

Missing Authorization vulnerability in Uncanny Owl Uncanny Automator Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uncanny Automator Pro: from n/a through …

Nov 1, 2024
CVE-2024-37108
7.7 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WishList Products WishList Member X allows Path Traversal.This issue affects WishList Member …

Nov 1, 2024
CVE-2024-37106
8.2 HIGH

Missing Authorization vulnerability in WishList Products WishList Member X allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WishList Member X: from n/a through …

Nov 1, 2024
CVE-2024-37096
4.3 MEDIUM

Missing Authorization vulnerability in Popup Box Team Popup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup box: from n/a through 4.5.1.

Nov 1, 2024
CVE-2024-37095
4.3 MEDIUM

Missing Authorization vulnerability in Envira Gallery Team Envira Photo Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Envira Photo Gallery: from n/a …

Nov 1, 2024
CVE-2024-27525
4.6 MEDIUM

Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the …

Nov 1, 2024
CVE-2024-27524
7.1 HIGH

Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the …

Nov 1, 2024
CVE-2024-10658
6.3 MEDIUM

A vulnerability classified as critical was found in Tongda OA up to 11.10. Affected by this vulnerability is an unknown functionality of the file /pda/approve_center/check_seal.php. …

Nov 1, 2024
CVE-2024-10657
6.3 MEDIUM

A vulnerability classified as critical has been found in Tongda OA up to 11.10. Affected is an unknown function of the file /pda/approve_center/prcs_info.php. The manipulation …

Nov 1, 2024
CVE-2024-10656
6.3 MEDIUM

A vulnerability was found in Tongda OA 2017 up to 11.9. It has been rated as critical. This issue affects some unknown processing of the …

Nov 1, 2024
CVE-2024-51407
6.2 MEDIUM

Floodlight SDN OpenFlow Controller v.1.2 has an issue that allows local hosts to construct false broadcast ports causing inter-host communication anomalies.

Nov 1, 2024
CVE-2024-51406
6.2 MEDIUM

Floodlight SDN Open Flow Controller v.1.2 has an issue that allows local hosts to build fake LLDP packets that allow specific clusters to be missed …

Nov 1, 2024
CVE-2024-48270
7.5 HIGH

An issue in the component /logins of oasys v1.1 allows attackers to access sensitive information via a burst attack.

Nov 1, 2024
CVE-2024-37094
8.2 HIGH

Missing Authorization vulnerability in StylemixThemes MasterStudy LMS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MasterStudy LMS: from n/a through 3.2.12.

Nov 1, 2024
CVE-2024-10655
6.3 MEDIUM

A vulnerability was found in Tongda OA 2017 up to 11.9. It has been declared as critical. This vulnerability affects unknown code of the file …

Nov 1, 2024
CVE-2024-7456
9.8 CRITICAL

A SQL injection vulnerability exists in the `/api/v1/external-users` route of lunary-ai/lunary version v1.4.2. The `order by` clause of the SQL query uses `sql.unsafe` without prior …

Nov 1, 2024
CVE-2024-10654
5.3 MEDIUM

A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Nov 1, 2024
CVE-2024-10367
6.4 MEDIUM

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API …

Nov 1, 2024
CVE-2024-10653
7.2 HIGH

IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrative privileges to inject and …

Nov 1, 2024
CVE-2024-10652
6.1 MEDIUM

IDExpert from CHANGING Information Technology does not properly validate a parameter for a specific functionality, allowing unauthenticated remote attackers to inject JavsScript code and perform …

Nov 1, 2024
CVE-2024-10651
4.9 MEDIUM

IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrator privileges to exploit this …

Nov 1, 2024
CVE-2024-10232
6.4 MEDIUM

The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's atomchat shortcode in all versions …

Nov 1, 2024
CVE-2024-9655
6.4 MEDIUM

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon …

Nov 1, 2024
CVE-2024-7424
5.4 MEDIUM

The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to unauthorized modification of and access to data due to a missing capability …

Nov 1, 2024
CVE-2024-0106
8.7 HIGH

NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit (DPU) contains a vulnerability where an attacker may cause an improper handling of insufficient privileges …

Nov 1, 2024
CVE-2024-0105
8.9 HIGH

NVIDIA ConnectX Firmware contains a vulnerability where an attacker may cause an improper handling of insufficient privileges issue. A successful exploit of this vulnerability may …

Nov 1, 2024
CVE-2024-49501
5.7 MEDIUM

Sysmac Studio provided by OMRON Corporation contains an incorrect authorization vulnerability. If this vulnerability is exploited, an attacker may access the program which is protected …

Nov 1, 2024
CVE-2024-47939
7.7 HIGH

Stack-based buffer overflow vulnerability exists in multiple laser printers and MFPs which implement Ricoh Web Image Monitor. If this vulnerability is exploited, receiving a specially …

Nov 1, 2024
CVE-2024-21510
5.4 MEDIUM

Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making …

Nov 1, 2024
CVE-2024-10620
5.3 MEDIUM

A vulnerability was found in knightliao Disconf 2.6.36. It has been classified as critical. This affects an unknown part of the file /api/config/list of the …

Nov 1, 2024
CVE-2024-10619
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.10. Affected is an unknown function of the file /pda/reportshop/next_detail.php. …

Nov 1, 2024
CVE-2024-10618
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Tongda OA 2017 up to 11.10. This issue affects some unknown processing of the …

Nov 1, 2024
CVE-2024-10617
6.3 MEDIUM

A vulnerability classified as critical was found in Tongda OA up to 11.10. This vulnerability affects unknown code of the file /pda/workflow/check_seal.php. The manipulation of …

Nov 1, 2024
CVE-2024-10616
6.3 MEDIUM

A vulnerability classified as critical has been found in Tongda OA up to 11.9. This affects an unknown part of the file /pda/workflow/webSignSubmit.php. The manipulation …

Nov 1, 2024
CVE-2024-10615
6.3 MEDIUM

A vulnerability was found in Tongda OA 2017 up to 11.10. It has been rated as critical. Affected by this issue is some unknown functionality …

Nov 1, 2024
CVE-2024-10613
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. Affected by this vulnerability is the function delSystemEncryptPolicy of the file …

Nov 1, 2024
CVE-2024-10612
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. Affected is the function removeHookInvalidCourse of the file /com/esafenet/servlet/system/HookInvalidCourseService.java. The manipulation …

Nov 1, 2024
CVE-2024-10611
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5 and classified as critical. This issue affects the function delProtocol of the file /com/esafenet/servlet/system/PrintScreenListService.java. The manipulation of …

Nov 1, 2024
CVE-2024-10610
6.3 MEDIUM

A vulnerability has been found in ESAFENET CDG 5 and classified as critical. This vulnerability affects the function delProtocol of the file /com/esafenet/servlet/system/ProtocolService.java. The manipulation …

Nov 1, 2024
CVE-2024-10609
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System Project 1.0. This affects an unknown part of the file typeadd.php. …

Nov 1, 2024
CVE-2024-10608
7.3 HIGH

A vulnerability was found in code-projects Courier Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Nov 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.