CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-28991
9.0 CRITICAL

SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow an authenticated user …

Sep 12, 2024
CVE-2024-28990
6.3 MEDIUM

SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability would allow access to the RabbitMQ …

Sep 12, 2024
CVE-2024-45857
7.8 HIGH

Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl file to run arbitrary code …

Sep 12, 2024
CVE-2024-45856
9.0 CRITICAL

A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an …

Sep 12, 2024
CVE-2024-45855
7.1 HIGH

Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code …

Sep 12, 2024
CVE-2024-45854
7.1 HIGH

Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code …

Sep 12, 2024
CVE-2024-45853
7.1 HIGH

Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code …

Sep 12, 2024
CVE-2024-45852
8.8 HIGH

Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on …

Sep 12, 2024
CVE-2024-45851
8.8 HIGH

An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the …

Sep 12, 2024
CVE-2024-45850
8.8 HIGH

An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the …

Sep 12, 2024
CVE-2024-45849
8.8 HIGH

An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the …

Sep 12, 2024
CVE-2024-45848
8.8 HIGH

An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the ChromaDB integration is installed on the server. …

Sep 12, 2024
CVE-2024-45847
8.8 HIGH

An arbitrary code execution vulnerability exists in versions 23.11.4.2 up to 24.7.4.1 of the MindsDB platform, when one of several integrations is installed on the …

Sep 12, 2024
CVE-2024-45846
8.8 HIGH

An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the Weaviate integration is installed on the server. …

Sep 12, 2024
CVE-2024-3306
7.5 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in Utarit Information SoliClub allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SoliClub: before 4.4.0 for iOS, …

Sep 12, 2024
CVE-2024-3305
7.5 HIGH

Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Utarit Information SoliClub allows Retrieve Embedded Sensitive Data. This issue affects SoliClub: before 4.4.0 for iOS, …

Sep 12, 2024
CVE-2024-27321
7.8 HIGH

An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its multilabel classification tasks handle …

Sep 12, 2024
CVE-2024-27320
7.8 HIGH

An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its classification tasks handle provided …

Sep 12, 2024
CVE-2022-26322
4.9 MEDIUM

Possible Insertion of Sensitive Information into Log File Vulnerability in Identity Manager has been discovered in OpenText™ Identity Manager REST Driver. This impact version before …

Sep 12, 2024
CVE-2021-38133
7.4 HIGH

Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.

Sep 12, 2024
CVE-2021-38132
5.3 MEDIUM

Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.

Sep 12, 2024
CVE-2021-38131
5.4 MEDIUM

Possible Cross-Site Scripting (XSS) Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.5.0000.

Sep 12, 2024
CVE-2021-22533
6.5 MEDIUM

Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.4.0000.

Sep 12, 2024
CVE-2021-22532
7.6 HIGH

Possible NLDAP Denial of Service attack Vulnerability in eDirectory has been discovered in OpenText™ eDirectory before 9.2.4.0000.

Sep 12, 2024
CVE-2021-22518
5.8 MEDIUM

A vulnerability identified in OpenText™ Identity Manager AzureAD Driver that allows logging of sensitive information into log file. This impacts all versions before 5.1.4.0

Sep 12, 2024
CVE-2021-22503
5.4 MEDIUM

Possible Improper Neutralization of Input During Web Page Generation Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.3.0000.

Sep 12, 2024
CVE-2024-8750
5.4 MEDIUM

Cross-site Scripting (XSS) vulnerability in idoit pro version 28. This vulnerability allows an attacker to retrieve session details of an authenticated user due to lack …

Sep 12, 2024
CVE-2024-8749
8.8 HIGH

SQL injection vulnerability in idoit pro version 28. This vulnerability could allow an attacker to send a specially crafted query to the ID parameter in …

Sep 12, 2024
CVE-2024-8622
6.1 MEDIUM

The amCharts: Charts and Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'amcharts_javascript' parameter in all versions up to, and including, …

Sep 12, 2024
CVE-2024-8529
10.0 CRITICAL

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter of the /wp-json/lp/v1/courses/archive-course REST API endpoint in …

Sep 12, 2024
CVE-2024-8522
10.0 CRITICAL

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress/v1/courses REST API endpoint in …

Sep 12, 2024
CVE-2024-2010
6.1 MEDIUM

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in TE Informatics V5 allows Reflected XSS.This issue affects V5: before 6.2.

Sep 12, 2024
CVE-2024-8056
6.1 MEDIUM

The MM-Breaking News WordPress plugin through 0.7.9 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected …

Sep 12, 2024
CVE-2024-8054
6.1 MEDIUM

The MM-Breaking News WordPress plugin through 0.7.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Sep 12, 2024
CVE-2024-7862
6.5 MEDIUM

The blogintroduction-wordpress-plugin WordPress plugin through 0.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged …

Sep 12, 2024
CVE-2024-7861
6.1 MEDIUM

The Misiek Paypal WordPress plugin through 1.1.20090324 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Sep 12, 2024
CVE-2024-7860
6.1 MEDIUM

The Simple Headline Rotator WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which …

Sep 12, 2024
CVE-2024-7859
6.5 MEDIUM

The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Sep 12, 2024
CVE-2024-7822
6.1 MEDIUM

The Quick Code WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Sep 12, 2024
CVE-2024-7820
6.5 MEDIUM

The ILC Thickbox WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Sep 12, 2024
CVE-2024-7818
6.1 MEDIUM

The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which …

Sep 12, 2024
CVE-2024-7817
6.5 MEDIUM

The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF checks in some places, which could allow attackers to make logged in users …

Sep 12, 2024
CVE-2024-7816
6.1 MEDIUM

The Gixaw Chat WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Sep 12, 2024
CVE-2024-7766
7.2 HIGH

The Adicon Server WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform …

Sep 12, 2024
CVE-2024-6887
4.8 MEDIUM

The Giveaways and Contests by RafflePress WordPress plugin before 1.12.16 does not sanitise and escape some of its Giveaways settings, which could allow high privilege …

Sep 12, 2024
CVE-2024-6019
6.1 MEDIUM

The Music Request Manager WordPress plugin through 1.3 does not sanitise and escape incoming music requests, which could allow unauthenticated users to perform Cross-Site Scripting …

Sep 12, 2024
CVE-2024-6018
6.1 MEDIUM

The Music Request Manager WordPress plugin through 1.3 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to …

Sep 12, 2024
CVE-2024-6017
6.1 MEDIUM

The Music Request Manager WordPress plugin through 1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which …

Sep 12, 2024
CVE-2024-5799
4.8 MEDIUM

The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which could allow high privilege users …

Sep 12, 2024
CVE-2024-3163
4.3 MEDIUM

The Easy Property Listings WordPress plugin before 3.5.4 does not have CSRF check when deleting contacts in bulk, which could allow attackers to make a …

Sep 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.