CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8445
5.7 MEDIUM

The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while …

Sep 5, 2024
CVE-2024-45178
7.1 HIGH

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to download arbitrary files from the …

Sep 5, 2024
CVE-2024-45173
8.8 HIGH

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper privilege management concerning sudo privileges, C-MOR is vulnerable to a privilege escalation …

Sep 5, 2024
CVE-2024-44587
8.8 HIGH

itsourcecode Alton Management System 1.0 is vulnerable to SQL Injection in /noncombo_save.php via the "menu" parameter.

Sep 5, 2024
CVE-2024-8473
6.3 MEDIUM

Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of …

Sep 5, 2024
CVE-2024-8472
6.3 MEDIUM

Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of …

Sep 5, 2024
CVE-2024-8471
6.3 MEDIUM

Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of …

Sep 5, 2024
CVE-2024-8470
9.8 CRITICAL

SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/vacancy/controller.php, and retrieve all the information stored in …

Sep 5, 2024
CVE-2024-8469
9.8 CRITICAL

SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/employee/index.php, and retrieve all the information stored in …

Sep 5, 2024
CVE-2024-8468
9.8 CRITICAL

SQL injection vulnerability, by which an attacker could send a specially designed query through search parameter in /jobportal/index.php, and retrieve all the information stored in …

Sep 5, 2024
CVE-2024-8467
9.8 CRITICAL

SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/category/index.php, and retrieve all the information stored in …

Sep 5, 2024
CVE-2024-8466
9.8 CRITICAL

SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/category/controller.php, and retrieve all the information stored in …

Sep 5, 2024
CVE-2024-8465
9.8 CRITICAL

SQL injection vulnerability, by which an attacker could send a specially designed query through user_id parameter in /jobportal/admin/user/controller.php, and retrieve all the information stored in …

Sep 5, 2024
CVE-2024-8464
9.8 CRITICAL

SQL injection vulnerability, by which an attacker could send a specially designed query through JOBREGID parameter in /jobportal/admin/applicants/controller.php, and retrieve all the information stored in …

Sep 5, 2024
CVE-2024-8463
9.9 CRITICAL

File upload restriction bypass vulnerability in PHPGurukul Job Portal 1.0, the exploitation of which could allow an authenticated user to execute an RCE via webshell.

Sep 5, 2024
CVE-2024-8462
3.7 LOW

A vulnerability was found in Windmill 1.380.0. It has been classified as problematic. Affected is an unknown function of the file backend/windmill-api/src/users.rs of the component …

Sep 5, 2024
CVE-2024-8461
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in D-Link DNS-320 2.02b01. This affects an unknown part of the file /cgi-bin/discovery.cgi of the component …

Sep 5, 2024
CVE-2024-7884
7.5 HIGH

When a canister method is called via ic_cdk::call* , a new Future CallFuture is created and can be awaited by the caller to get the …

Sep 5, 2024
CVE-2024-8460
3.7 LOW

A vulnerability, which was classified as problematic, has been found in D-Link DNS-320 2.02b01. Affected by this issue is some unknown functionality of the file …

Sep 5, 2024
CVE-2024-7605
4.3 MEDIUM

The HelloAsso plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ha_ajax' function in all versions …

Sep 5, 2024
CVE-2024-7381
5.3 MEDIUM

The Geo Controller plugin for WordPress is vulnerable to unauthorized shortcode execution due to missing authorization and capability checks on the ajax__shortcode_cache function in all …

Sep 5, 2024
CVE-2024-7380
4.3 MEDIUM

The Geo Controller plugin for WordPress is vulnerable to unauthorized menu creation/deletion due to missing capability checks on the ajax__geolocate_menu and ajax__geolocate_remove_menu functions in all …

Sep 5, 2024
CVE-2024-5957
6.3 MEDIUM

This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.

Sep 5, 2024
CVE-2024-5956
6.5 MEDIUM

This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the vulnerable Trellix IPS Manager with garbage data in response …

Sep 5, 2024
CVE-2022-4529
5.3 MEDIUM

The Security, Antivirus, Firewall – S.A.F plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.3.5. This is due …

Sep 5, 2024
CVE-2022-3556
4.4 MEDIUM

The Cab fare calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vehicle title setting in versions up to, and including, 1.1.6 …

Sep 5, 2024
CVE-2024-6929
6.4 MEDIUM

The Dynamic Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘dfiFeatured’ parameter in all versions up to, and including, 3.7.0 …

Sep 5, 2024
CVE-2024-6894
6.4 MEDIUM

The RD Station plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.3.2 due to insufficient input sanitization …

Sep 5, 2024
CVE-2024-6332
6.5 MEDIUM

The Booking for Appointments and Events Calendar – Amelia Premium and Lite plugins for WordPress are vulnerable to unauthorized access of data due to a …

Sep 5, 2024
CVE-2024-8363
6.4 MEDIUM

The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's STI Buttons shortcode in all versions up to, and …

Sep 5, 2024
CVE-2024-5309
5.4 MEDIUM

The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a …

Sep 5, 2024
CVE-2024-45107
5.5 MEDIUM

Acrobat Reader versions 20.005.30636, 24.002.20964, 24.001.30123, 24.002.20991 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. …

Sep 5, 2024
CVE-2024-6835
5.3 MEDIUM

The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.5.6 via the …

Sep 5, 2024
CVE-2024-6846
5.3 MEDIUM

The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and …

Sep 5, 2024
CVE-2024-8178
8.8 HIGH

The ctl_write_buffer and ctl_read_buffer functions allocated memory to be returned to userspace, without initializing it. Malicious software running in a guest VM that exposes virtio_scsi …

Sep 5, 2024
CVE-2024-45063
8.8 HIGH

The function ctl_write_buffer incorrectly set a flag which resulted in a kernel Use-After-Free when a command finished processing. Malicious software running in a guest VM …

Sep 5, 2024
CVE-2024-43110
8.8 HIGH

The ctl_request_sense function could expose up to three bytes of the kernel heap to userspace. Malicious software running in a guest VM that exposes virtio_scsi …

Sep 5, 2024
CVE-2024-43102
10.0 CRITICAL

Concurrent removals of certain anonymous shared memory mappings by using the UMTX_SHM_DESTROY sub-request of UMTX_OP_SHM can lead to decreasing the reference count of the object …

Sep 5, 2024
CVE-2024-42416
8.8 HIGH

The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbitrary write to a limited amount of kernel help memory. Malicious …

Sep 5, 2024
CVE-2024-32668
8.2 HIGH

An insufficient boundary validation in the USB code could lead to an out-of-bounds write on the heap, with data controlled by the caller. A malicious, …

Sep 5, 2024
CVE-2024-45288
8.4 HIGH

A missing null-termination character in the last element of an nvlist array string can lead to writing outside the allocated buffer.

Sep 5, 2024
CVE-2024-45287
7.5 HIGH

A malicious value of size in a structure of packed libnv can cause an integer overflow, leading to the allocation of a smaller buffer than …

Sep 5, 2024
CVE-2024-41928
8.4 HIGH

Malicious software running in a guest VM can exploit the buffer overflow to achieve code execution on the host in the bhyve userspace process, which …

Sep 5, 2024
CVE-2024-7627
8.1 HIGH

The Bit File Manager plugin for WordPress is vulnerable to Remote Code Execution in versions 6.0 to 6.5.5 via the 'checkSyntax' function. This is due …

Sep 5, 2024
CVE-2024-45692
7.5 HIGH

Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000.

Sep 4, 2024
CVE-2024-45429
6.1 MEDIUM

Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5 and earlier. If an attacker with …

Sep 4, 2024
CVE-2024-2166
8.8 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email Security (Real Time Monitor modules) allows Reflected XSS.This issue affects Email …

Sep 4, 2024
CVE-2024-20506
6.1 MEDIUM

A vulnerability in the ClamD service module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions, all …

Sep 4, 2024
CVE-2024-20505
4.0 MEDIUM

A vulnerability in the PDF parsing module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions, all …

Sep 4, 2024
CVE-2024-45395
3.1 LOW

sigstore-go, a Go library for Sigstore signing and verification, is susceptible to a denial of service attack in versions prior to 0.6.1 when a verifier …

Sep 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.