CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-50450
7.3 HIGH

Improper Control of Generation of Code ('Code Injection') vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Code Injection.This issue affects MDTF: from n/a through <= 1.3.3.4.

Oct 28, 2024
CVE-2024-50442
6.5 MEDIUM

Improper Restriction of XML External Entity Reference vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows XML Injection.This issue affects Royal Elementor Addons: from n/a …

Oct 28, 2024
CVE-2024-50416
8.8 HIGH

Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce wpc-shop-as-customer allows Object Injection.This issue affects WPC Shop as a Customer …

Oct 28, 2024
CVE-2024-50408
8.8 HIGH

Deserialization of Untrusted Data vulnerability in Bob Namaste! LMS namaste-lms allows Object Injection.This issue affects Namaste! LMS: from n/a through <= 2.6.3.

Oct 28, 2024
CVE-2024-48074
8.0 HIGH

An authorized RCE vulnerability exists in the DrayTek Vigor2960 router version 1.4.4, where an attacker can place a malicious command into the table parameter of …

Oct 28, 2024
CVE-2024-10446
6.3 MEDIUM

A vulnerability classified as critical has been found in Project Worlds Online Time Table Generator 1.0. Affected is an unknown function of the file /timetable/admin/admindashboard.php?info=add_course. …

Oct 28, 2024
CVE-2024-38821
9.1 CRITICAL

Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances. For this to impact an application, all …

Oct 28, 2024
CVE-2024-9162
7.2 HIGH

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing file type validation during the export …

Oct 28, 2024
CVE-2024-50307
5.5 MEDIUM

Use of potentially dangerous function issue exists in Chatwork Desktop Application (Windows) versions prior to 2.9.2. If a user clicks a specially crafted link in …

Oct 28, 2024
CVE-2024-48936
5.0 MEDIUM

SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. …

Oct 28, 2024
CVE-2024-10440
9.8 CRITICAL

The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL command to read, modify, and delete database …

Oct 28, 2024
CVE-2024-10439
5.3 MEDIUM

The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to access arbitrary …

Oct 28, 2024
CVE-2024-10438
7.5 HIGH

The eHRD CTMS from Sunnet has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to bypass authentication by satisfying specific conditions in order to access …

Oct 28, 2024
CVE-2024-23843
2.2 LOW

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Genians Genian NAC V5.0, Genians Genian NAC LTS V5.0.This issue affects …

Oct 28, 2024
CVE-2024-50067
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: uprobe: avoid out-of-bounds memory access of fetching args Uprobe needs to fetch args into a …

Oct 28, 2024
CVE-2024-10435
6.3 MEDIUM

A vulnerability was found in didi Super-Jacoco 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /cov/triggerEnvCov. The manipulation …

Oct 28, 2024
CVE-2024-10434
8.8 HIGH

A vulnerability was found in Tenda AC1206 up to 20241027. It has been classified as critical. This affects the function ate_Tenda_mfg_check_usb/ate_Tenda_mfg_check_usb3 of the file /goform/ate. …

Oct 28, 2024
CVE-2024-50624
5.9 MEDIUM

ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled mail server because cleartext HTTP is used for a URL …

Oct 28, 2024
CVE-2024-50623
9.8 CRITICAL KEV

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote …

Oct 28, 2024
CVE-2024-10433
3.5 LOW

A vulnerability was found in Project Worlds Simple Web-Based Chat Application 1.0 and classified as problematic. Affected by this issue is some unknown functionality of …

Oct 28, 2024
CVE-2024-10432
7.3 HIGH

A vulnerability has been found in Project Worlds Simple Web-Based Chat Application 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality …

Oct 28, 2024
CVE-2024-10431
7.3 HIGH

A vulnerability, which was classified as critical, was found in Codezips Pet Shop Management System 1.0. Affected is an unknown function of the file /deletebird.php. …

Oct 27, 2024
CVE-2024-10430
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Codezips Pet Shop Management System 1.0. This issue affects some unknown processing of the …

Oct 27, 2024
CVE-2024-50616
8.8 HIGH

Ironman PowerShell Universal 5.x before 5.0.12 allows an authenticated attacker to elevate their privileges and view job information.

Oct 27, 2024
CVE-2024-50615
6.5 MEDIUM

TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/digit, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.

Oct 27, 2024
CVE-2024-50614
6.5 MEDIUM

TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/16, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.

Oct 27, 2024
CVE-2024-50613
6.5 MEDIUM

libsndfile through 1.2.2 has a reachable assertion, that may lead to application exit, in mpeg_l3_encode.c mpeg_l3_encoder_close.

Oct 27, 2024
CVE-2024-50612
5.5 MEDIUM

libsndfile through 1.2.2 has an ogg_vorbis.c vorbis_analysis_wrote out-of-bounds read.

Oct 27, 2024
CVE-2024-50611
7.2 HIGH

CycloneDX cdxgen through 10.10.7, when run against an untrusted codebase, may execute code contained within build-related files such as build.gradle.kts, a similar issue to CVE-2022-24441. …

Oct 27, 2024
CVE-2024-50610
3.6 LOW

GSL (GNU Scientific Library) through 2.8 has an integer signedness error in gsl_siman_solve_many in siman/siman.c. When params.n_tries is negative, incorrect memory allocation occurs.

Oct 27, 2024
CVE-2024-10429
7.2 HIGH

A vulnerability classified as critical has been found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. Affected is the function set_ipv6 of the file …

Oct 27, 2024
CVE-2024-10428
7.2 HIGH

A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. It has been rated as critical. This issue affects the function set_ipv6 …

Oct 27, 2024
CVE-2024-10427
6.3 MEDIUM

A vulnerability was found in Codezips Pet Shop Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Oct 27, 2024
CVE-2024-10426
6.3 MEDIUM

A vulnerability was found in Codezips Pet Shop Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Oct 27, 2024
CVE-2024-10425
6.3 MEDIUM

A vulnerability was found in Project Worlds Student Project Allocation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of …

Oct 27, 2024
CVE-2024-10424
6.3 MEDIUM

A vulnerability has been found in Project Worlds Student Project Allocation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality …

Oct 27, 2024
CVE-2024-10423
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Project Worlds Student Project Allocation System 1.0. Affected is an unknown function of the file …

Oct 27, 2024
CVE-2024-10422
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Attendance and Payroll System 1.0. This issue affects some unknown processing of the …

Oct 27, 2024
CVE-2024-10421
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Attendance and Payroll System 1.0. This vulnerability affects unknown code of the file /admin/overtime_row.php. The manipulation …

Oct 27, 2024
CVE-2024-10420
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Attendance and Payroll System 1.0. This affects the function upload of the file /marimar/guest/update.php. The …

Oct 27, 2024
CVE-2024-10419
3.5 LOW

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality …

Oct 27, 2024
CVE-2024-10418
6.3 MEDIUM

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Oct 27, 2024
CVE-2024-10417
6.3 MEDIUM

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Oct 27, 2024
CVE-2024-10416
6.3 MEDIUM

A vulnerability was found in code-projects Blood Bank Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /file/cancel.php. …

Oct 27, 2024
CVE-2024-10415
6.3 MEDIUM

A vulnerability has been found in code-projects Blood Bank Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /file/accept.php. …

Oct 27, 2024
CVE-2024-10414
2.4 LOW

A vulnerability, which was classified as problematic, was found in PHPGurukul Vehicle Record System 1.0. This affects an unknown part of the file /admin/edit-brand.php. The …

Oct 27, 2024
CVE-2024-10413
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Online Hotel Reservation System 1.0. Affected by this issue is the function upload …

Oct 27, 2024
CVE-2024-10412
3.5 LOW

A vulnerability was found in Poco-z Guns-Medical 1.0. It has been declared as problematic. Affected by this vulnerability is the function upload of the file …

Oct 27, 2024
CVE-2024-50602
5.9 MEDIUM

An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.

Oct 27, 2024
CVE-2024-10411
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Hotel Reservation System 1.0. It has been classified as critical. Affected is the function doCancelRoom/doCancel/doConfirm/doCancel/doCheckin/doCheckout of the file …

Oct 27, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.