CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-43414
7.5 HIGH

Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them …

Aug 27, 2024
CVE-2024-42851
7.8 HIGH

Buffer Overflow vulnerability in open source exiftags v.1.01 allows a local attacker to execute arbitrary code via the paresetag function.

Aug 27, 2024
CVE-2024-36068
9.8 CRITICAL

An incorrect access control vulnerability in Rubrik CDM versions prior to 9.1.2-p1, 9.0.3-p6 and 8.1.3-p12, allows an attacker with network access to execute arbitrary code.

Aug 27, 2024
CVE-2022-39996
4.8 MEDIUM

Cross Site Scripting vulnerability in Teldats Router RS123, RS123w allows attacker to execute arbitrary code via the cmdcookie parameter to the upgrade/query.php page.

Aug 27, 2024
CVE-2024-43788
6.4 MEDIUM

Webpack is a module bundler. Its main purpose is to bundle JavaScript files for usage in a browser, yet it is also capable of transforming, …

Aug 27, 2024
CVE-2024-8200
4.3 MEDIUM

The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to Cross-Site Request Forgery …

Aug 27, 2024
CVE-2024-8199
4.3 MEDIUM

The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to unauthorized modification of …

Aug 27, 2024
CVE-2024-45264
8.8 HIGH

A cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to add a new administrator, leading to …

Aug 27, 2024
CVE-2024-44342
9.8 CRITICAL

D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the wl(0).(0)_ssid parameter. This vulnerability is exploited via a crafted …

Aug 27, 2024
CVE-2024-44341
9.8 CRITICAL

D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted …

Aug 27, 2024
CVE-2024-44340
8.8 HIGH

D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via keys smartqos_express_devices and smartqos_normal_devices in SetSmartQoSSettings.

Aug 27, 2024
CVE-2024-41622
9.8 CRITICAL

D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in /HNAP1/ interface.

Aug 27, 2024
CVE-2024-40395
6.5 MEDIUM

An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, including PII, regardless of access level.

Aug 27, 2024
CVE-2024-6633
9.8 CRITICAL

The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of these credentials could lead …

Aug 27, 2024
CVE-2024-6632
7.2 HIGH

A vulnerability exists in FileCatalyst Workflow whereby a field accessible to the super admin can be used to perform an SQL injection attack which can …

Aug 27, 2024
CVE-2024-7071
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hibernate vulnerability in Brain Information Technologies Inc. …

Aug 27, 2024
CVE-2024-8182
7.5 HIGH

An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of the instance running a vulnerable version due …

Aug 27, 2024
CVE-2024-8181
9.8 CRITICAL

An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints as an administrator and allow …

Aug 27, 2024
CVE-2024-7941
4.3 MEDIUM

An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the …

Aug 27, 2024
CVE-2024-7940
8.3 HIGH

The product exposes a service that is intended for local only to all network interfaces without any authentication.

Aug 27, 2024
CVE-2024-4872
9.9 CRITICAL

A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inject code towards …

Aug 27, 2024
CVE-2024-3982
8.2 HIGH

An attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging supporting the product and try to exploit …

Aug 27, 2024
CVE-2024-3980
9.9 CRITICAL

The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operations. If …

Aug 27, 2024
CVE-2024-8207
6.4 MEDIUM

In certain highly specific configurations of the host system and MongoDB server binary installation on Linux Operating Systems, it may be possible for a unintended …

Aug 27, 2024
CVE-2024-7791
6.4 MEDIUM

The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘arrow’ parameter within the …

Aug 27, 2024
CVE-2024-6789
6.5 MEDIUM

A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 23.8.12892.0 SR6 allows authenticated user to …

Aug 27, 2024
CVE-2024-8046
6.4 MEDIUM

The Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads …

Aug 27, 2024
CVE-2024-7608
5.9 MEDIUM

An authenticated user can access the restricted files from NX, EX, FX, AX, IVX and CMS using path traversal.

Aug 27, 2024
CVE-2024-41176
7.3 HIGH

The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local attacker to induce a Denial-of-Service (DoS) condition on the daemon and execute code in …

Aug 27, 2024
CVE-2024-41175
5.5 MEDIUM

The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local denial-of-service attack by a low privileged attacker.

Aug 27, 2024
CVE-2024-41174
7.3 HIGH

The IPC-Diagnostics package in TwinCAT/BSD is susceptible to improper input neutralization by a low-privileged local attacker.

Aug 27, 2024
CVE-2024-41173
7.8 HIGH

The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local authentication bypass by a low privileged attacker.

Aug 27, 2024
CVE-2024-7304
6.4 MEDIUM

The Ninja Tables – Easiest Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up …

Aug 27, 2024
CVE-2024-6804
6.4 MEDIUM

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.7 …

Aug 27, 2024
CVE-2024-7125
7.8 HIGH

Authentication Bypass vulnerability in Hitachi Ops Center Common Services.This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.2-01.

Aug 27, 2024
CVE-2024-6688
4.3 MEDIUM

The Oxygen Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the oxy_save_css_from_admin AJAX action in …

Aug 27, 2024
CVE-2024-45321
8.1 HIGH

The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.

Aug 27, 2024
CVE-2024-45036
4.3 MEDIUM

Tophat is a mobile applications testing harness. An Improper Access Control vulnerability can expose the `TOPHAT_APP_TOKEN` token stored in `~/.tophatrc` through use of a malicious …

Aug 26, 2024
CVE-2024-43798
8.6 HIGH

Chisel is a fast TCP/UDP tunnel, transported over HTTP, secured via SSH. The Chisel server doesn't ever read the documented `AUTH` environment variable used to …

Aug 26, 2024
CVE-2024-7989

Rejected reason: Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that the …

Aug 26, 2024
CVE-2024-43916
4.3 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.102.

Aug 26, 2024
CVE-2024-43915
5.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager allows Reflected XSS.This issue affects Zephyr …

Aug 26, 2024
CVE-2024-43356
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in bobbingwide.This issue affects oik: from n/a through 4.12.0.

Aug 26, 2024
CVE-2024-43340
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Nasirahmed Advanced Form Integration.This issue affects Advanced Form Integration: from n/a through 1.89.4.

Aug 26, 2024
CVE-2024-43339
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress allows Cross-Site Scripting (XSS).This issue affects WebinarPress: from n/a through 1.33.20.

Aug 26, 2024
CVE-2024-43337
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Brave Brave Popup Builder.This issue affects Brave Popup Builder: from n/a through 0.7.0.

Aug 26, 2024
CVE-2024-43336
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in WP User Manager WP User Manager wp-user-manager.This issue affects WP User Manager: from n/a through <= 2.9.10.

Aug 26, 2024
CVE-2024-43325
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Naiche Dark Mode for WP Dashboard.This issue affects Dark Mode for WP Dashboard: from n/a through 1.2.3.

Aug 26, 2024
CVE-2024-43316
5.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Checkout Plugins Stripe Payments For WooCommerce by Checkout.This issue affects Stripe Payments For WooCommerce by Checkout: from n/a through …

Aug 26, 2024
CVE-2024-43301
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Fonts Plugin Fonts allows Stored XSS.This issue affects Fonts: from n/a through 3.7.7.

Aug 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.