CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8605
4.3 MEDIUM

A vulnerability classified as problematic was found in code-projects Inventory Management 1.0. This vulnerability affects unknown code of the file /view/registration.php of the component Registration …

Sep 9, 2024
CVE-2024-8604
4.3 MEDIUM

A vulnerability classified as problematic has been found in SourceCodester Online Food Ordering System 2.0. This affects an unknown part of the file index.php of …

Sep 9, 2024
CVE-2024-44721
9.8 CRITICAL

SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.

Sep 9, 2024
CVE-2024-44720
7.5 HIGH

SeaCMS v13.1 was discovered to an arbitrary file read vulnerability via the component admin_safe.php.

Sep 9, 2024
CVE-2024-8373
4.8 MEDIUM

Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can …

Sep 9, 2024
CVE-2024-8372
4.8 MEDIUM

Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a …

Sep 9, 2024
CVE-2024-8042
2.4 LOW

Rapid7 Insight Platform versions between November 2019 and August 14, 2024 suffer from missing authorization issues whereby an attacker can intercept local requests to set …

Sep 9, 2024
CVE-2024-45041
8.3 HIGH

External Secrets Operator is a Kubernetes operator that integrates external secret management systems. The external-secrets has a deployment called default-external-secrets-cert-controller, which is bound with a …

Sep 9, 2024
CVE-2024-40643
9.6 CRITICAL

Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by a non letter character …

Sep 9, 2024
CVE-2024-7015
9.8 CRITICAL

Missing Authentication for Critical Function vulnerability in Profelis Informatics and Consulting PassBox allows Authentication Abuse.This issue affects PassBox: before v1.2.

Sep 9, 2024
CVE-2024-44375
7.5 HIGH

D-Link DI-8100 v16.07.26A1 has a stack overflow vulnerability in the dbsrv_asp function.

Sep 9, 2024
CVE-2024-8601
6.5 MEDIUM

This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on certain API endpoints. An authenticated remote attacker …

Sep 9, 2024
CVE-2024-6572
7.4 HIGH

Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem' in Checkmk before Checkmk 2.3.0p15, 2.2.0p33, 2.1.0p48 and …

Sep 9, 2024
CVE-2024-37288
9.9 CRITICAL

A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. This issue …

Sep 9, 2024
CVE-2024-45203
4.3 MEDIUM

Improper authorization in handler for custom URL scheme issue in "@cosme" App for Android versions prior 5.69.0 and "@cosme" App for iOS versions prior to …

Sep 9, 2024
CVE-2024-7918
4.8 MEDIUM

The Pocket Widget WordPress plugin through 0.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Sep 9, 2024
CVE-2024-7689
4.3 MEDIUM

The Snapshot Backup WordPress plugin through 2.1.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Sep 9, 2024
CVE-2024-7688
6.5 MEDIUM

The AZIndex WordPress plugin through 0.8.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin delete arbitrary …

Sep 9, 2024
CVE-2024-7687
4.3 MEDIUM

The AZIndex WordPress plugin through 0.8.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Sep 9, 2024
CVE-2024-6910
4.8 MEDIUM

The EventON WordPress plugin before 2.2.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Sep 9, 2024
CVE-2024-5561
4.8 MEDIUM

The Popup Maker WordPress plugin before 1.19.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Sep 9, 2024
CVE-2024-45625
6.1 MEDIUM

Cross-site scripting vulnerability exists in Forminator versions prior to 1.34.1. If this vulnerability is exploited, an arbitrary script may be executed on the web browser …

Sep 9, 2024
CVE-2024-8586
6.1 MEDIUM

WebITR from Uniong has an Open Redirect vulnerability, which allows unauthorized remote attackers to exploit this vulnerability to forge URLs. Users, believing they are accessing …

Sep 9, 2024
CVE-2024-8585
6.5 MEDIUM

Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowing a remote attacker with regular privileges to …

Sep 9, 2024
CVE-2024-8584
9.8 CRITICAL

Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege …

Sep 9, 2024
CVE-2024-8583
3.5 LOW

A vulnerability was found in SourceCodester Online Bank Management System and Online Bank Management System - 1.0. It has been classified as problematic. This affects …

Sep 8, 2024
CVE-2024-8582
3.5 LOW

A vulnerability was found in SourceCodester Food Ordering Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the …

Sep 8, 2024
CVE-2024-8580
8.1 HIGH

A vulnerability classified as critical was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. This vulnerability affects unknown code of the file /etc/shadow.sample. The manipulation leads to …

Sep 8, 2024
CVE-2024-8579
8.8 HIGH

A vulnerability classified as critical has been found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. This affects the function setWiFiRepeaterCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Sep 8, 2024
CVE-2024-8578
8.8 HIGH

A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. It has been rated as critical. Affected by this issue is the function setWiFiMeshName of the …

Sep 8, 2024
CVE-2024-8577
8.8 HIGH

A vulnerability was found in TOTOLINK AC1200 T8 and AC1200 T10 4.1.5cu.861_B20230220/4.1.8cu.5207. It has been declared as critical. Affected by this vulnerability is the function …

Sep 8, 2024
CVE-2024-8576
8.8 HIGH

A vulnerability was found in TOTOLINK AC1200 T8 and AC1200 T10 4.1.5cu.861_B20230220/4.1.8cu.5207. It has been classified as critical. Affected is the function setIpPortFilterRules of the …

Sep 8, 2024
CVE-2024-8575
8.8 HIGH

A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220 and classified as critical. This issue affects the function setWiFiScheduleCfg of the file /cgi-bin/cstecgi.cgi. The manipulation …

Sep 8, 2024
CVE-2024-42343
5.3 MEDIUM

Loway - CWE-204: Observable Response Discrepancy

Sep 8, 2024
CVE-2024-42342
4.3 MEDIUM

Loway - CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

Sep 8, 2024
CVE-2024-42341
6.1 MEDIUM

Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

Sep 8, 2024
CVE-2024-8574
6.3 MEDIUM

A vulnerability has been found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220 and classified as critical. This vulnerability affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The …

Sep 8, 2024
CVE-2024-8573
8.8 HIGH

A vulnerability, which was classified as critical, was found in TOTOLINK AC1200 T8 and AC1200 T10 4.1.5cu.861_B20230220/4.1.8cu.5207. This affects the function setParentalRules of the file …

Sep 8, 2024
CVE-2024-8572
3.5 LOW

A vulnerability was found in Gouniverse GoLang CMS 1.4.0. It has been declared as problematic. This vulnerability affects the function PageRenderHtmlByAlias of the file FrontendHandler.go. …

Sep 8, 2024
CVE-2024-8571
3.5 LOW

A vulnerability was found in erjemin roll_cms up to 1484fe2c4e0805946a7bcf46218509fcb34883a9. It has been classified as problematic. This affects an unknown part of the file roll_cms/roll_cms/views.py. …

Sep 8, 2024
CVE-2024-8570
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Sep 8, 2024
CVE-2024-6928
9.8 CRITICAL

The Opti Marketing WordPress plugin through 2.0.9 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX …

Sep 8, 2024
CVE-2024-6925
4.3 MEDIUM

The TrueBooker WordPress plugin before 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged …

Sep 8, 2024
CVE-2024-6924
9.8 CRITICAL

The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action …

Sep 8, 2024
CVE-2024-6859
5.4 MEDIUM

The WP MultiTasking WordPress plugin through 0.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Sep 8, 2024
CVE-2024-6856
4.3 MEDIUM

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Sep 8, 2024
CVE-2024-6855
4.3 MEDIUM

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating exit popups, which could allow attackers to make logged admins perform …

Sep 8, 2024
CVE-2024-6853
4.3 MEDIUM

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating welcome popups, which could allow attackers to make logged admins perform …

Sep 8, 2024
CVE-2024-6852
4.3 MEDIUM

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Sep 8, 2024
CVE-2024-8569
7.3 HIGH

A vulnerability has been found in code-projects Hospital Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Sep 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.