CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10161
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. This affects an unknown part of the file change-image.php of …

Oct 20, 2024
CVE-2024-10160
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Boat Booking System 1.0. Affected by this issue is some unknown functionality of …

Oct 20, 2024
CVE-2024-10159
7.3 HIGH

A vulnerability classified as critical was found in PHPGurukul Boat Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/profile.php …

Oct 20, 2024
CVE-2024-10158
4.3 MEDIUM

A vulnerability classified as problematic has been found in PHPGurukul Boat Booking System 1.0. Affected is the function session_start. The manipulation leads to session fixiation. …

Oct 19, 2024
CVE-2024-10157
7.3 HIGH

A vulnerability was found in PHPGurukul Boat Booking System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Oct 19, 2024
CVE-2024-10156
7.3 HIGH

A vulnerability was found in PHPGurukul Boat Booking System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php …

Oct 19, 2024
CVE-2024-10155
3.5 LOW

A vulnerability was found in PHPGurukul Boat Booking System 1.0. It has been classified as problematic. This affects an unknown part of the file book-boat.php?bid=1 …

Oct 19, 2024
CVE-2024-10154
6.3 MEDIUM

A vulnerability was found in PHPGurukul Boat Booking System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Oct 19, 2024
CVE-2024-10153
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Oct 19, 2024
CVE-2024-10142
3.5 LOW

A vulnerability has been found in code-projects Blood Bank System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /viewrequest.php. The …

Oct 19, 2024
CVE-2024-10141
3.7 LOW

A vulnerability, which was classified as problematic, was found in jsbroks COCO Annotator 0.11.1. This affects an unknown part of the component Session Handler. The …

Oct 19, 2024
CVE-2024-10140
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Pharmacy Management System 1.0. Affected by this issue is some unknown functionality of …

Oct 19, 2024
CVE-2024-10139
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Pharmacy Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add_new_supplier.php. …

Oct 19, 2024
CVE-2024-10138
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. Affected is an unknown function of the file /add_new_purchase.php?action=is_supplier. The manipulation …

Oct 19, 2024
CVE-2024-10137
6.3 MEDIUM

A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Oct 19, 2024
CVE-2024-10136
6.3 MEDIUM

A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /manage_invoice.php. …

Oct 19, 2024
CVE-2024-10135
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. This affects the function actionDelNetSecConfig of the file /com/esafenet/servlet/netSec/NetSecConfigService.java. The manipulation …

Oct 19, 2024
CVE-2024-9897
6.4 MEDIUM

The StreamWeasels Twitch Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw-twitch-embed shortcode in all versions up to, and including, …

Oct 19, 2024
CVE-2024-10134
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5 and classified as critical. Affected by this issue is the function connectLogout of the file /com/esafenet/servlet/ajax/MultiServerAjax.java. The …

Oct 19, 2024
CVE-2024-10133
6.3 MEDIUM

A vulnerability has been found in ESAFENET CDG 5 and classified as critical. Affected by this vulnerability is the function updateNetSecPolicyPriority of the file /com/esafenet/servlet/ajax/NetSecPolicyAjax.java. …

Oct 19, 2024
CVE-2024-9889
4.3 MEDIUM

The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.9 via the Page …

Oct 19, 2024
CVE-2023-6243
4.3 MEDIUM

The EventON PRO - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Oct 19, 2024
CVE-2024-21536
7.5 HIGH

Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown …

Oct 19, 2024
CVE-2024-9219
6.1 MEDIUM

The WordPress Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …

Oct 19, 2024
CVE-2024-10131
8.8 HIGH

The `add_llm` function in `llm_app.py` in infiniflow/ragflow version 0.11.0 contains a remote code execution (RCE) vulnerability. The function uses user-supplied input `req['llm_factory']` and `req['llm_name']` to …

Oct 19, 2024
CVE-2019-25218
4.9 MEDIUM

The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, …

Oct 19, 2024
CVE-2024-43577
4.3 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Oct 18, 2024
CVE-2024-37404
8.8 HIGH

Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated …

Oct 18, 2024
CVE-2024-29821
7.8 HIGH

Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack …

Oct 18, 2024
CVE-2024-29213
7.8 HIGH

Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack …

Oct 18, 2024
CVE-2024-10130
8.8 HIGH

A vulnerability classified as critical was found in Tenda AC8 16.03.34.06. This vulnerability affects the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg. The manipulation of the …

Oct 18, 2024
CVE-2024-10129
6.3 MEDIUM

A vulnerability classified as critical has been found in HFO4 shudong-share up to 2.4.7. This affects an unknown part of the file /includes/create_share.php of the …

Oct 18, 2024
CVE-2024-10128
2.7 LOW

A vulnerability was found in Topdata Inner Rep Plus WebServer 2.01. It has been rated as problematic. Affected by this issue is some unknown functionality …

Oct 18, 2024
CVE-2024-10123
8.8 HIGH

A vulnerability was found in Tenda AC8 16.03.34.06. It has been declared as critical. Affected by this vulnerability is the function compare_parentcontrol_time of the file …

Oct 18, 2024
CVE-2024-49361

ACON is a widely-used library of tools for machine learning that focuses on adaptive correlation optimization. A potential vulnerability has been identified in the input …

Oct 18, 2024
CVE-2024-45944
9.8 CRITICAL

In J2eeFAST <=2.7, the backend function has unsafe filtering, which allows an attacker to trigger certain sensitive functions resulting in arbitrary code execution.

Oct 18, 2024
CVE-2024-10122
2.7 LOW

A vulnerability was found in Topdata Inner Rep Plus WebServer 2.01. It has been classified as problematic. Affected is an unknown function of the file …

Oct 18, 2024
CVE-2024-10121
7.3 HIGH

A vulnerability was found in wfh45678 Radar up to 1.0.8 and classified as critical. This issue affects some unknown processing of the component Interface Handler. …

Oct 18, 2024
CVE-2024-9593
8.3 HIGH

The Time Clock plugin and Time Clock Pro plugin for WordPress are vulnerable to Remote Code Execution in versions up to, and including, 1.2.2 (for …

Oct 18, 2024
CVE-2024-48016
4.6 MEDIUM

Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.24, contains a Use of a Broken or Risky Cryptographic Algorithm vulnerability. A low privileged …

Oct 18, 2024
CVE-2024-47241
5.5 MEDIUM

Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.24, contains an Improper Certificate Validation vulnerability. A low privileged attacker with remote access could …

Oct 18, 2024
CVE-2024-10120
7.3 HIGH

A vulnerability has been found in wfh45678 Radar up to 1.0.8 and classified as critical. This vulnerability affects unknown code of the file /services/v1/common/upload. The …

Oct 18, 2024
CVE-2023-6080
7.8 HIGH

Lakeside Software’s SysTrack LsiAgent Installer version 10.7.8 for Windows contains a local privilege escalation vulnerability which allows attackers SYSTEM level access.

Oct 18, 2024
CVE-2024-42508
5.5 MEDIUM

This vulnerability could be exploited, leading to unauthorized disclosure of information to authenticated users.

Oct 18, 2024
CVE-2024-9537
9.8 CRITICAL KEV

ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vulnerability is addressed in SL1 versions …

Oct 18, 2024
CVE-2024-47240
5.5 MEDIUM

Dell Secure Connect Gateway (SCG) 5.24 contains an Incorrect Default Permissions vulnerability. A local attacker with low privileges can access the file system and could …

Oct 18, 2024
CVE-2024-9674
6.4 MEDIUM

The Debrandify · Remove or Replace WordPress Branding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up …

Oct 18, 2024
CVE-2024-43300
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bert Movie Database movie-database allows Stored XSS.This issue affects Movie Database: from n/a …

Oct 18, 2024
CVE-2024-9425
6.4 MEDIUM

The Advanced Category and Custom Taxonomy Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ad_tax_image shortcode in all versions up …

Oct 18, 2024
CVE-2024-49243
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ramjon27 Dynamic Elementor Addons dynamic-elementor-addons allows PHP Local File …

Oct 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.