CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-43408
6.3 MEDIUM

Discourse Placeholder Forms will let you build dynamic documentation. Unsanitized and stored user input was injected in the html of the post. The vulnerability is …

Aug 20, 2024
CVE-2024-42919
9.8 CRITICAL

eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.

Aug 20, 2024
CVE-2024-42598
6.7 MEDIUM

SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still …

Aug 20, 2024
CVE-2024-40743
6.1 MEDIUM

The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.

Aug 20, 2024
CVE-2024-27187
7.5 HIGH

Improper Access Controls allows backend users to overwrite their username when disallowed.

Aug 20, 2024
CVE-2024-27186
6.1 MEDIUM

The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.

Aug 20, 2024
CVE-2024-27185
9.1 CRITICAL

The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors.

Aug 20, 2024
CVE-2024-27184
6.1 MEDIUM

Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..

Aug 20, 2024
CVE-2024-43409
6.5 MEDIUM

Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and …

Aug 20, 2024
CVE-2024-43406
8.8 HIGH

LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL …

Aug 20, 2024
CVE-2024-43404
9.8 CRITICAL

MEGABOT is a fully customized Discord bot for learning and fun. The `/math` command and functionality of MEGABOT versions < 1.5.0 contains a remote code …

Aug 20, 2024
CVE-2024-43397
4.3 MEDIUM

Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks. …

Aug 20, 2024
CVE-2024-43377
5.4 MEDIUM

Umbraco CMS is an ASP.NET CMS. An authenticated user can access a few unintended endpoints. This issue is fixed in 14.1.2.

Aug 20, 2024
CVE-2024-43376
4.3 MEDIUM

Umbraco is an ASP.NET CMS. Some endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode. This …

Aug 20, 2024
CVE-2024-42662
7.5 HIGH

An issue in apollocongif apollo v.2.2.0 allows a remote attacker to obtain sensitive information via a crafted request.

Aug 20, 2024
CVE-2024-42621
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_editor.php

Aug 20, 2024
CVE-2024-42618
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /module.php?module=karma

Aug 20, 2024
CVE-2024-42617
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_config.php?action=save&var_id=32

Aug 20, 2024
CVE-2024-42616
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.php?action=remove&widget=Statistics

Aug 20, 2024
CVE-2024-42613
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.php?action=install&widget=akismet

Aug 20, 2024
CVE-2024-42611
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/admin_page.php?link_id=1&mode=delete

Aug 20, 2024
CVE-2024-42610
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=files

Aug 20, 2024
CVE-2024-42609
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=avatars

Aug 20, 2024
CVE-2024-42607
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=database

Aug 20, 2024
CVE-2024-42606
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_log.php?clear=1

Aug 20, 2024
CVE-2024-42605
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/edit_page.php?link_id=1

Aug 20, 2024
CVE-2024-42604
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_group.php?mode=delete&group_id=3

Aug 20, 2024
CVE-2024-42603
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=clearall

Aug 20, 2024
CVE-2024-42369
4.1 MEDIUM

matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. A malicious homeserver can craft a room or room structure such that the predecessors form …

Aug 20, 2024
CVE-2024-39690
8.4 HIGH

Capsule is a multi-tenancy and policy-based framework for Kubernetes. In Capsule v0.7.0 and earlier, the tenant-owner can patch any arbitrary namespace that has not been …

Aug 20, 2024
CVE-2024-35540
9.0 CRITICAL

A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Aug 20, 2024
CVE-2024-30949
9.8 CRITICAL

An issue in newlib v.4.3.0 allows an attacker to execute arbitrary code via the time unit scaling in the _gettimeofday function.

Aug 20, 2024
CVE-2024-8005
7.3 HIGH

A vulnerability was found in demozx gf_cms 1.0/1.0.1. It has been classified as critical. This affects the function init of the file internal/logic/auth/auth.go of the …

Aug 20, 2024
CVE-2024-8003
3.5 LOW

A vulnerability was found in Go-Tribe gotribe-admin 1.0 and classified as problematic. Affected by this issue is the function InitRoutes of the file internal/app/routes/routes.go of …

Aug 20, 2024
CVE-2024-6379
7.7 HIGH

A reflected Cross-site Scripting (XSS) vulnerability affecting 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in …

Aug 20, 2024
CVE-2024-6378
8.7 HIGH

A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary …

Aug 20, 2024
CVE-2024-6377
8.1 HIGH

An URL redirection to untrusted site (open redirect) vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to …

Aug 20, 2024
CVE-2024-42608
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/submit_page.php.

Aug 20, 2024
CVE-2024-42006
7.5 HIGH

Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure.

Aug 20, 2024
CVE-2024-39094
5.4 MEDIUM

Friendica 2024.03 is vulnerable to Cross Site Scripting (XSS) in settings/profile via the homepage, xmpp, and matrix parameters.

Aug 20, 2024
CVE-2024-34458
7.5 HIGH

Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in information disclosure.

Aug 20, 2024
CVE-2024-33872
9.8 CRITICAL

Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code execution and escalation of privileges.

Aug 20, 2024
CVE-2024-6918
7.5 HIGH

CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause a crash of the Accutech Manager when receiving a …

Aug 20, 2024
CVE-2024-42586
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42585
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component delete_media.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42584
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component delete_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42583
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component delete_user.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42582
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component delete_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42581
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component delete_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42580
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component edit_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.