CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-44820
6.1 MEDIUM

A sensitive information disclosure vulnerability exists in ZZCMS v.2023 and before within the eginfo.php file located at /3/E_bak5.1/upload/. When accessed with the query parameter phome=ShowPHPInfo, …

Sep 4, 2024
CVE-2024-44819
6.1 MEDIUM

Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via a crafted script to the pagename parameter …

Sep 4, 2024
CVE-2024-8408
6.3 MEDIUM

A vulnerability was found in Linksys WRT54G 4.21.5. It has been rated as critical. Affected by this issue is the function validate_services_port of the file …

Sep 4, 2024
CVE-2024-8407
3.5 LOW

A vulnerability was found in alwindoss akademy up to 35caccea888ed63d5489e211c99edff1f62efdba. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Sep 4, 2024
CVE-2024-7923
9.8 CRITICAL

An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore configuration. This issue arises …

Sep 4, 2024
CVE-2024-7012
9.8 CRITICAL

An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configuration. This issue arises from Apache's mod_proxy …

Sep 4, 2024
CVE-2024-7834
7.8 HIGH

A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-writeable folder in SYSTEM context on launch. …

Sep 4, 2024
CVE-2024-44400
9.8 CRITICAL

A vulnerability was discovered in DI_8400-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the …

Sep 4, 2024
CVE-2024-44383
6.8 MEDIUM

WAYOS FBM-291W v19.09.11 is vulnerable to Command Execution via msp_info_htm.

Sep 4, 2024
CVE-2024-8413
5.4 MEDIUM

Cross Site Scripting (XSS) vulnerability through the action parameter in index.php. Affected product codebase https://github.com/Bioshox/Raspcontrol and forks such as https://github.com/harmon25/raspcontrol . An attacker could exploit …

Sep 4, 2024
CVE-2024-7821

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 4, 2024
CVE-2024-8289
9.8 CRITICAL

The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to privilege escalation/de-escalation and account takeover due to an insufficient capability …

Sep 4, 2024
CVE-2024-7870
6.5 MEDIUM

The PixelYourSite – Your smart PIXEL (TAG) & API Manager and the PixelYourSite PRO plugins for WordPress are vulnerable to Sensitive Information Exposure in all …

Sep 4, 2024
CVE-2024-45507
9.8 CRITICAL

Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are …

Sep 4, 2024
CVE-2024-45195
7.5 HIGH KEV

Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes …

Sep 4, 2024
CVE-2024-8318
6.4 MEDIUM

The Attributes for Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributesForBlocks’ parameter in all versions up to, and including, 1.0.6 …

Sep 4, 2024
CVE-2024-8123
5.4 MEDIUM

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Sep 4, 2024
CVE-2024-8121
5.4 MEDIUM

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of user names due to a missing capability check …

Sep 4, 2024
CVE-2024-8119
6.1 MEDIUM

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up …

Sep 4, 2024
CVE-2024-8117
6.1 MEDIUM

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘selected_option’ parameter in all versions up …

Sep 4, 2024
CVE-2024-8106
6.5 MEDIUM

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.8 …

Sep 4, 2024
CVE-2024-8104
8.8 HIGH

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0.8 via …

Sep 4, 2024
CVE-2024-8102
8.8 HIGH

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due …

Sep 4, 2024
CVE-2024-8325
6.4 MEDIUM

The Blockspare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Counters, Page Builder & Starter Site Imports, No Coding …

Sep 4, 2024
CVE-2024-7786
5.3 MEDIUM

The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.

Sep 4, 2024
CVE-2024-6926
9.8 CRITICAL

The Viral Signup WordPress plugin through 2.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX …

Sep 4, 2024
CVE-2024-6889
4.8 MEDIUM

The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high …

Sep 4, 2024
CVE-2024-6888
4.8 MEDIUM

The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high …

Sep 4, 2024
CVE-2024-6722
4.8 MEDIUM

The Chatbot Support AI: Free ChatGPT Chatbot, Woocommerce Chatbot WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow …

Sep 4, 2024
CVE-2024-6020
6.1 MEDIUM

The Sign-up Sheets WordPress plugin before 2.2.13 does not escape some generated URLs, as well as the $_SERVER['REQUEST_URI'] parameter before outputting them back in attributes, …

Sep 4, 2024
CVE-2024-34661
4.3 MEDIUM

Improper handling of insufficient permissions in Samsung Assistant prior to version 9.1.00.7 allows remote attackers to access location data. User interaction is required for triggering …

Sep 4, 2024
CVE-2024-34660
7.3 HIGH

Heap-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.

Sep 4, 2024
CVE-2024-34659
7.5 HIGH

Exposure of sensitive information in GroupSharing prior to version 13.6.13.3 allows remote attackers can force the victim to join the group.

Sep 4, 2024
CVE-2024-34658
4.0 MEDIUM

Out-of-bounds read in Samsung Notes allows local attackers to bypass ASLR.

Sep 4, 2024
CVE-2024-34657
8.6 HIGH

Stack-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows remote attackers to execute arbitrary code.

Sep 4, 2024
CVE-2024-34656
7.3 HIGH

Path traversal in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.

Sep 4, 2024
CVE-2024-34655
6.2 MEDIUM

Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows local attackers to access privileged API related to UniversalCredentialManager.

Sep 4, 2024
CVE-2024-34654
6.2 MEDIUM

Improper Export of android application component in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access files with My Files' privilege.

Sep 4, 2024
CVE-2024-34653
4.6 MEDIUM

Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access directories with My Files' privilege.

Sep 4, 2024
CVE-2024-34652
4.0 MEDIUM

Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.

Sep 4, 2024
CVE-2024-34651
6.2 MEDIUM

Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files.

Sep 4, 2024
CVE-2024-34650
4.0 MEDIUM

Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.

Sep 4, 2024
CVE-2024-34649
2.4 LOW

Improper access control in new Dex Mode in multitasking framework prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access an unlocked screen.

Sep 4, 2024
CVE-2024-34648
5.1 MEDIUM

Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1 allows local attackers to access sensitive data.

Sep 4, 2024
CVE-2024-34647
4.0 MEDIUM

Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper …

Sep 4, 2024
CVE-2024-34646
6.6 MEDIUM

Improper access control in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to cause local permanent denial of service.

Sep 4, 2024
CVE-2024-34645
6.1 MEDIUM

Improper input validation in ThemeCenter prior to SMR Sep-2024 Release 1 allows physical attackers to install privileged applications.

Sep 4, 2024
CVE-2024-34644
4.4 MEDIUM

Improper access control in item selection related in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is …

Sep 4, 2024
CVE-2024-34643
4.4 MEDIUM

Improper access control in key input related function in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction …

Sep 4, 2024
CVE-2024-34642
4.6 MEDIUM

Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information.

Sep 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.