CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8568
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Mini-Tmall up to 20240901. Affected is the function rewardMapper.select of the file tmall/admin/order/1/1. The manipulation …

Sep 8, 2024
CVE-2024-8567
7.3 HIGH

A vulnerability, which was classified as critical, has been found in itsourcecode Payroll Management System 1.0. This issue affects some unknown processing of the file …

Sep 8, 2024
CVE-2024-8566
4.3 MEDIUM

A vulnerability classified as problematic was found in code-projects Online Shop Store 1.0. This vulnerability affects unknown code of the file /settings.php. The manipulation of …

Sep 8, 2024
CVE-2024-8565
7.3 HIGH

A vulnerability was found in SourceCodesters Clinics Patient Management System 2.0. It has been rated as critical. This issue affects some unknown processing of the …

Sep 7, 2024
CVE-2024-8564
6.3 MEDIUM

A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/update.php. The …

Sep 7, 2024
CVE-2024-8563
3.5 LOW

A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/update.php. The …

Sep 7, 2024
CVE-2024-8562
3.5 LOW

A vulnerability was found in SourceCodester PHP CRUD 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /endpoint/Add.php. …

Sep 7, 2024
CVE-2024-8561
6.3 MEDIUM

A vulnerability has been found in SourceCodester PHP CRUD 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file …

Sep 7, 2024
CVE-2024-8560
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Simple Invoice Generator System 1.0. Affected is an unknown function of the file /save_invoice.php. …

Sep 7, 2024
CVE-2024-8559
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Online Food Menu 1.0. This issue affects some unknown processing of the file …

Sep 7, 2024
CVE-2024-42024
8.8 HIGH

A vulnerability that allows an attacker in possession of the Veeam ONE Agent service account credentials to perform remote code execution on the machine where …

Sep 7, 2024
CVE-2024-42023
8.8 HIGH

An improper access control vulnerability allows low-privileged users to execute code with Administrator privileges remotely.

Sep 7, 2024
CVE-2024-42022
5.3 MEDIUM

An incorrect permission assignment vulnerability allows an attacker to modify product configuration files.

Sep 7, 2024
CVE-2024-42021
6.5 MEDIUM

An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.

Sep 7, 2024
CVE-2024-42020
5.4 MEDIUM

A Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection.

Sep 7, 2024
CVE-2024-42019
8.0 HIGH

A vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service service account. This attack requires user interaction and data …

Sep 7, 2024
CVE-2024-40718
8.8 HIGH

A server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through exploiting an SSRF vulnerability.

Sep 7, 2024
CVE-2024-40714
8.3 HIGH

An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations.

Sep 7, 2024
CVE-2024-40713
7.8 HIGH

A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and …

Sep 7, 2024
CVE-2024-40712
7.8 HIGH

A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation (LPE).

Sep 7, 2024
CVE-2024-40711
9.8 CRITICAL KEV

A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).

Sep 7, 2024
CVE-2024-40710
8.8 HIGH

A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive information (savedcredentials and …

Sep 7, 2024
CVE-2024-40709
7.8 HIGH

A missing authorization vulnerability allows a local low-privileged user on the machine to escalate their privileges to root level.

Sep 7, 2024
CVE-2024-39718
8.1 HIGH

An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service …

Sep 7, 2024
CVE-2024-39715
8.5 HIGH

A code injection vulnerability that allows a low-privileged user with REST API access granted to remotely upload arbitrary files to the VSPC server using REST …

Sep 7, 2024
CVE-2024-39714
9.9 CRITICAL

A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to remote code execution on VSPC server.

Sep 7, 2024
CVE-2024-38651
8.5 HIGH

A code injection vulnerability can allow a low-privileged user to overwrite files on that VSPC server, which can lead to remote code execution on VSPC …

Sep 7, 2024
CVE-2024-38650
9.9 CRITICAL

An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on the VSPC server.

Sep 7, 2024
CVE-2024-8558
4.3 MEDIUM

A vulnerability classified as problematic was found in SourceCodester Food Ordering Management System 1.0. This vulnerability affects unknown code of the file /foms/routers/place-order.php of the …

Sep 7, 2024
CVE-2024-36138
8.1 HIGH

Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious …

Sep 7, 2024
CVE-2024-36137
3.3 LOW

A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not …

Sep 7, 2024
CVE-2023-46809
7.4 HIGH

Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the …

Sep 7, 2024
CVE-2023-39333
5.3 MEDIUM

Maliciously crafted export names in an imported WebAssembly module can inject JavaScript code. The injected code may be able to access data and functions that …

Sep 7, 2024
CVE-2023-30587
7.5 HIGH

A vulnerability in Node.js version 20 allows for bypassing restrictions set by the --experimental-permission flag using the built-in inspector module (node:inspector). By exploiting the Worker …

Sep 7, 2024
CVE-2023-30584
7.7 HIGH

A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw relates to improper handling of path traversal bypass …

Sep 7, 2024
CVE-2023-30583
7.5 HIGH

fs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the `--allow-fs-read` flag in Node.js 20. This flaw arises from …

Sep 7, 2024
CVE-2023-30582
5.3 MEDIUM

A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flag is used with a non-* …

Sep 7, 2024
CVE-2024-8557
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Food Ordering Management System 1.0. This affects an unknown part of the file /foms/routers/cancel-order.php. The …

Sep 7, 2024
CVE-2024-8555
4.3 MEDIUM

A vulnerability was found in SourceCodester Clinics Patient Management System 2.0. It has been classified as problematic. Affected is an unknown function of the file …

Sep 7, 2024
CVE-2024-40681
7.5 HIGH

IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user in a specifically defined role, …

Sep 7, 2024
CVE-2024-8554
3.5 LOW

A vulnerability was found in SourceCodester Clinics Patient Management System 2.0 and classified as problematic. This issue affects some unknown processing of the file /users.php. …

Sep 7, 2024
CVE-2024-40680
5.5 MEDIUM

IBM MQ 9.3 CD and 9.4 LTS/CD could allow a local user to cause a denial of service due to improper memory allocation causing a …

Sep 7, 2024
CVE-2024-37068
5.9 MEDIUM

IBM Maximo Application Suite - Manage Component 8.10, 8.11, and 9.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly …

Sep 7, 2024
CVE-2024-7620
6.6 MEDIUM

The Customizer Export/Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '_import' function in all versions …

Sep 7, 2024
CVE-2024-7112
8.8 HIGH

The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘schedule’ parameter in all versions up …

Sep 7, 2024
CVE-2024-6010
5.3 MEDIUM

The Cost Calculator Builder PRO plugin for WordPress is vulnerable to price manipulation in all versions up to, and including, 3.2.1. This is due to …

Sep 7, 2024
CVE-2024-1596
7.2 HIGH

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. RTX file) in all versions …

Sep 7, 2024
CVE-2024-8538
4.3 MEDIUM

The Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and …

Sep 7, 2024
CVE-2024-8523
4.7 MEDIUM

A vulnerability was found in lmxcms up to 1.4 and classified as critical. Affected by this issue is the function formatData of the file /admin.php?m=Acquisi&a=testcj&lid=1 …

Sep 7, 2024
CVE-2024-6849
6.4 MEDIUM

The Preloader Plus – WordPress Loading Screen Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up …

Sep 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.