CVE Database

10843+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-45168
9.1 CRITICAL

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is transferred over a raw socket without any authentication mechanism. …

Aug 22, 2024
CVE-2024-45167
9.8 CRITICAL

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper restriction of …

Aug 22, 2024
CVE-2024-45166
9.8 CRITICAL

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper restriction of …

Aug 22, 2024
CVE-2024-45163
9.1 CRITICAL

The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server. Unauthenticated sessions remain open, causing resource consumption. For example, …

Aug 22, 2024
CVE-2024-28987
9.1 CRITICAL KEV

The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.

Aug 21, 2024
CVE-2024-7971
9.6 CRITICAL KEV

Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security …

Aug 21, 2024
CVE-2024-6386
9.9 CRITICAL

The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Template Injection. This …

Aug 21, 2024
CVE-2024-42784
9.8 CRITICAL

A SQL injection vulnerability in "/music/controller.php?page=view_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.

Aug 21, 2024
CVE-2024-42783
9.8 CRITICAL

Kashipara Music Management System v1.0 is vulnerable to SQL Injection via /music/manage_playlist_items.php. An attacker can execute arbitrary SQL commands via the "pid" parameter.

Aug 21, 2024
CVE-2024-42782
9.8 CRITICAL

A SQL injection vulnerability in "/music/ajax.php?action=find_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "search" parameter.

Aug 21, 2024
CVE-2024-42781
9.8 CRITICAL

A SQL injection vulnerability in "/music/ajax.php?action=login" of Kashipara Music Management System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the …

Aug 21, 2024
CVE-2024-42777
9.8 CRITICAL

An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management System v1.0, which allows attackers to execute arbitrary code via uploading a …

Aug 21, 2024
CVE-2024-40453
9.8 CRITICAL

squirrellyjs squirrelly v9.0.0 and fixed in v.9.0.1 was discovered to contain a code injection vulnerability via the component options.varName.

Aug 21, 2024
CVE-2024-28000
9.8 CRITICAL

Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1.

Aug 21, 2024
CVE-2024-5335
9.8 CRITICAL

The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin is vulnerable to PHP Object …

Aug 21, 2024
CVE-2024-7854
10.0 CRITICAL

The Woo Inquiry plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 0.1 due to insufficient escaping on the …

Aug 21, 2024
CVE-2024-6800
9.8 CRITICAL

An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity providers utilizing publicly exposed signed federation …

Aug 20, 2024
CVE-2024-38175
9.6 CRITICAL

An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network.

Aug 20, 2024
CVE-2024-42919
9.8 CRITICAL

eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.

Aug 20, 2024
CVE-2024-27185
9.1 CRITICAL

The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors.

Aug 20, 2024
CVE-2024-43404
9.8 CRITICAL

MEGABOT is a fully customized Discord bot for learning and fun. The `/math` command and functionality of MEGABOT versions < 1.5.0 contains a remote code …

Aug 20, 2024
CVE-2024-35540
9.0 CRITICAL

A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Aug 20, 2024
CVE-2024-30949
9.8 CRITICAL

An issue in newlib v.4.3.0 allows an attacker to execute arbitrary code via the time unit scaling in the _gettimeofday function.

Aug 20, 2024
CVE-2024-33872
9.8 CRITICAL

Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code execution and escalation of privileges.

Aug 20, 2024
CVE-2024-42575
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at substaff.php.

Aug 20, 2024
CVE-2024-42574
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at attendance.php.

Aug 20, 2024
CVE-2024-42573
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at dtmarks.php.

Aug 20, 2024
CVE-2024-42572
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at unitmarks.php.

Aug 20, 2024
CVE-2024-42571
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at insertattendance.php.

Aug 20, 2024
CVE-2024-42570
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at admininsert.php.

Aug 20, 2024
CVE-2024-42569
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at paidclass.php.

Aug 20, 2024
CVE-2024-42568
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the transport parameter at vehicle.php.

Aug 20, 2024
CVE-2024-42567
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the sid parameter at /search.php?action=2.

Aug 20, 2024
CVE-2024-42566
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the password parameter at login.php

Aug 20, 2024
CVE-2024-42565
9.8 CRITICAL

ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/contact/delete?action=delete.

Aug 20, 2024
CVE-2024-42563
9.8 CRITICAL

An arbitrary file upload vulnerability in ERP commit 44bd04 allows attackers to execute arbitrary code via uploading a crafted HTML file.

Aug 20, 2024
CVE-2024-42562
9.8 CRITICAL

Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at preview.php.

Aug 20, 2024
CVE-2024-42559
9.8 CRITICAL

An issue in the login component (process_login.php) of Hotel Management System commit 79d688 allows attackers to authenticate without providing a valid password.

Aug 20, 2024
CVE-2024-42558
9.8 CRITICAL

Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_modify_room.php.

Aug 20, 2024
CVE-2024-42556
9.8 CRITICAL

Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_removed.php.

Aug 20, 2024
CVE-2024-43202
9.8 CRITICAL

Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgrade Apache DolphinScheduler to version 3.2.2, …

Aug 20, 2024
CVE-2024-6847
9.8 CRITICAL

The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to …

Aug 20, 2024
CVE-2024-7777
9.0 CRITICAL

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable …

Aug 20, 2024
CVE-2024-5932
10.0 CRITICAL

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 …

Aug 20, 2024
CVE-2024-43354
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2.

Aug 19, 2024
CVE-2024-43311
9.8 CRITICAL

Improper Privilege Management vulnerability in Geek Code Lab Login As Users allows Privilege Escalation.This issue affects Login As Users: from n/a through 1.4.2.

Aug 19, 2024
CVE-2024-42815
9.8 CRITICAL

In the TP-Link RE365 V1_180213, there is a buffer overflow vulnerability due to the lack of length verification for the USER_AGENT field in /usr/bin/httpd. Attackers …

Aug 19, 2024
CVE-2024-42813
9.8 CRITICAL

In TRENDnet TEW-752DRU FW1.03B01, there is a buffer overflow vulnerability due to the lack of length verification for the service field in gena.cgi. Attackers who …

Aug 19, 2024
CVE-2024-42812
9.8 CRITICAL

In D-Link DIR-860L v2.03, there is a buffer overflow vulnerability due to the lack of length verification for the SID field in gena.cgi. Attackers who …

Aug 19, 2024
CVE-2024-43261
9.6 CRITICAL

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hamed Naderfar Compute Links allows PHP Remote File Inclusion.This …

Aug 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.