CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-36514
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in file summary option.

Aug 23, 2024
CVE-2024-43883
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: usb: vhci-hcd: Do not drop references before new references are gained At a few places …

Aug 23, 2024
CVE-2024-7986
7.5 HIGH

A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat actor can exploit this vulnerability …

Aug 23, 2024
CVE-2024-5502
6.4 MEDIUM

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion, Dual Heading, and Vertical Timeline widgets …

Aug 23, 2024
CVE-2024-38807
6.3 MEDIUM

Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where …

Aug 23, 2024
CVE-2024-43105
4.3 MEDIUM

Mattermost Plugin Channel Export versions <=1.0.0 fail to restrict concurrent runs of the /export command which allows a user to consume excessive resource by running …

Aug 23, 2024
CVE-2024-40766
9.8 CRITICAL KEV

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing …

Aug 23, 2024
CVE-2024-6715
6.1 MEDIUM

The Ditty WordPress plugin before 3.1.46 re-introduced a previously fixed security issue (https://wpscan.com/vulnerability/80a9eb3a-2cb1-4844-9004-ba2554b2d46c/) in v3.1.39

Aug 23, 2024
CVE-2024-3282
4.8 MEDIUM

The WP Table Builder WordPress plugin through 1.5.0 does not sanitise and escape some of its Table data, which could allow high privilege users such …

Aug 23, 2024
CVE-2024-7258
8.8 HIGH

The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'wppfm_removeFeedFile' function …

Aug 23, 2024
CVE-2024-7559
8.8 HIGH

The File Manager Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in the mk_file_folder_manager …

Aug 23, 2024
CVE-2024-43477
7.5 HIGH

Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable ID's on another tenant.

Aug 23, 2024
CVE-2024-8089
6.3 MEDIUM

A vulnerability was found in SourceCodester E-Commerce System 1.0. It has been classified as critical. Affected is an unknown function of the file /ecommerce/admin/products/controller.php. The …

Aug 23, 2024
CVE-2024-8087
6.3 MEDIUM

A vulnerability was found in SourceCodester E-Commerce System 1.0 and classified as critical. This issue affects some unknown processing of the file /ecommerce/popup_Item.php. The manipulation …

Aug 22, 2024
CVE-2024-8086
7.3 HIGH

A vulnerability has been found in SourceCodester E-Commerce System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ecommerce/admin/login.php of the …

Aug 22, 2024
CVE-2024-38210
7.8 HIGH

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Aug 22, 2024
CVE-2024-38209
7.8 HIGH

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Aug 22, 2024
CVE-2024-38208
6.1 MEDIUM

Microsoft Edge for Android Spoofing Vulnerability

Aug 22, 2024
CVE-2024-8084
2.4 LOW

A vulnerability, which was classified as problematic, was found in SourceCodester Online Computer and Laptop Store 1.0. This affects an unknown part of the file …

Aug 22, 2024
CVE-2024-8083
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this issue is some unknown …

Aug 22, 2024
CVE-2024-8081
7.3 HIGH

A vulnerability classified as critical was found in itsourcecode Payroll Management System 1.0. Affected by this vulnerability is an unknown functionality of the file login.php. …

Aug 22, 2024
CVE-2024-43790
4.5 MEDIUM

Vim is an open source command line text editor. When performing a search and displaying the search-count message is disabled (:set shm+=S), the search pattern …

Aug 22, 2024
CVE-2024-8080
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Online Health Care System 1.0. Affected is an unknown function of the file search.php. The …

Aug 22, 2024
CVE-2024-8079
8.8 HIGH

A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been rated as critical. This issue affects the function exportOvpn. The manipulation leads to …

Aug 22, 2024
CVE-2024-8078
8.8 HIGH

A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been declared as critical. This vulnerability affects the function setTracerouteCfg. The manipulation leads to …

Aug 22, 2024
CVE-2024-42763
5.4 MEDIUM

A Reflected Cross Site Scripting (XSS) vulnerability was found in the "/schedule.php" page of the Kashipara Bus Ticket Reservation System v1.0, which allows remote attackers …

Aug 22, 2024
CVE-2024-42762
5.4 MEDIUM

A Stored Cross Site Scripting (XSS) vulnerability was found in "/history.php" in Kashipara Bus Ticket Reservation System v1.0, which allows remote attackers to execute arbitrary …

Aug 22, 2024
CVE-2024-42761
6.1 MEDIUM

A Stored Cross Site Scripting (XSS) vulnerability was found in "/admin_schedule.php" in Kashipara Bus Ticket Reservation System v1.0, which allows remote attackers to execute arbitrary …

Aug 22, 2024
CVE-2023-7260
7.5 HIGH

Path Traversal vulnerability discovered in OpenText™ CX-E Voice, affecting all version through 22.4. The vulnerability could allow arbitrarily access files on the system.

Aug 22, 2024
CVE-2024-8077
6.3 MEDIUM

A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been classified as critical. This affects the function setTracerouteCfg. The manipulation leads to os …

Aug 22, 2024
CVE-2024-8076
8.8 HIGH

A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228 and classified as critical. Affected by this issue is the function setDiagnosisCfg. The manipulation leads to …

Aug 22, 2024
CVE-2024-8075
6.3 MEDIUM

A vulnerability has been found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228 and classified as critical. Affected by this vulnerability is the function setDiagnosisCfg. The manipulation leads …

Aug 22, 2024
CVE-2024-45201
8.8 HIGH

An issue was discovered in llama_index before 0.10.38. download/integration.py includes an exec call for import {cls_name}.

Aug 22, 2024
CVE-2024-42599
8.8 HIGH

SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_files.php imposes restrictions on edited files, attackers can still …

Aug 22, 2024
CVE-2024-42418
7.5 HIGH

Avtec Outpost uses a default cryptographic key that can be used to decrypt sensitive information.

Aug 22, 2024
CVE-2024-39776
7.5 HIGH

Avtec Outpost stores sensitive information in an insecure location without proper access controls in place.

Aug 22, 2024
CVE-2024-8088

There is a HIGH severity vulnerability affecting the CPython "zipfile" module affecting "zipfile.Path". Note that the more common API "zipfile.ZipFile" class is unaffected. When iterating …

Aug 22, 2024
CVE-2024-39717
7.2 HIGH KEV

The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user …

Aug 22, 2024
CVE-2024-7634
4.9 MEDIUM

NGINX Agent's "config_dirs" restriction feature allows a highly privileged attacker to gain the ability to write/overwrite files outside of the designated secure directory.

Aug 22, 2024
CVE-2024-42773
9.1 CRITICAL

An Incorrect Access Control vulnerability was found in /admin/edit_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to edit the valid hotel …

Aug 22, 2024
CVE-2024-42767
7.2 HIGH

Kashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php.

Aug 22, 2024
CVE-2024-42776
7.2 HIGH

Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php.

Aug 22, 2024
CVE-2024-42775
9.1 CRITICAL

An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to add the valid hotel …

Aug 22, 2024
CVE-2024-42774
7.5 HIGH

An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to delete valid hotel room …

Aug 22, 2024
CVE-2024-42772
7.5 HIGH

An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to view valid hotel room …

Aug 22, 2024
CVE-2024-42768
6.8 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Hotel Management System v1.0 via /admin/delete_room.php.

Aug 22, 2024
CVE-2024-8041
6.5 MEDIUM

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior …

Aug 22, 2024
CVE-2024-7110
6.4 MEDIUM

An issue was discovered in GitLab EE affecting all versions starting 17.0 to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1 allows an …

Aug 22, 2024
CVE-2024-6502
5.7 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.2 prior to 17.1.6 starting from 17.2 prior to 17.2.4, and starting from …

Aug 22, 2024
CVE-2024-45193
4.3 MEDIUM

An issue was discovered in Matrix libolm through 3.2.16. There is Ed25519 signature malleability due to lack of validation criteria (does not ensure that S …

Aug 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.