CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-42579
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component add_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42578
8.0 HIGH

A Cross-Site Request Forgery (CSRF) in the component edit_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42577
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component add_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42576
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component edit_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42575
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at substaff.php.

Aug 20, 2024
CVE-2024-42574
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at attendance.php.

Aug 20, 2024
CVE-2024-42573
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at dtmarks.php.

Aug 20, 2024
CVE-2024-42572
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at unitmarks.php.

Aug 20, 2024
CVE-2024-42571
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at insertattendance.php.

Aug 20, 2024
CVE-2024-42570
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at admininsert.php.

Aug 20, 2024
CVE-2024-42569
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at paidclass.php.

Aug 20, 2024
CVE-2024-42568
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the transport parameter at vehicle.php.

Aug 20, 2024
CVE-2024-42567
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the sid parameter at /search.php?action=2.

Aug 20, 2024
CVE-2024-42566
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the password parameter at login.php

Aug 20, 2024
CVE-2024-42565
9.8 CRITICAL

ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/contact/delete?action=delete.

Aug 20, 2024
CVE-2024-42564
7.6 HIGH

ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/inventory/delete?action=delete.

Aug 20, 2024
CVE-2024-42563
9.8 CRITICAL

An arbitrary file upload vulnerability in ERP commit 44bd04 allows attackers to execute arbitrary code via uploading a crafted HTML file.

Aug 20, 2024
CVE-2024-42562
9.8 CRITICAL

Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at preview.php.

Aug 20, 2024
CVE-2024-42561
8.8 HIGH

Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at sales_report.php.

Aug 20, 2024
CVE-2024-42560
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the component update_page_details.php of Blood Bank And Donation Management System commit dc9e039 allows attackers to execute arbitrary web scripts …

Aug 20, 2024
CVE-2024-42559
9.8 CRITICAL

An issue in the login component (process_login.php) of Hotel Management System commit 79d688 allows attackers to authenticate without providing a valid password.

Aug 20, 2024
CVE-2024-42558
9.8 CRITICAL

Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_modify_room.php.

Aug 20, 2024
CVE-2024-42557
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component admin_modify_room.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42556
9.8 CRITICAL

Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_removed.php.

Aug 20, 2024
CVE-2024-42555
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component admin_room_removed.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42554
8.8 HIGH

Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_added.php.

Aug 20, 2024
CVE-2024-42553
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component admin_room_added.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42552
8.6 HIGH

Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_room_history.php.

Aug 20, 2024
CVE-2024-42336
8.2 HIGH

Servision - CWE-287: Improper Authentication

Aug 20, 2024
CVE-2024-42335
5.4 MEDIUM

7Twenty - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Aug 20, 2024
CVE-2024-42334

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 20, 2024
CVE-2024-41700
7.5 HIGH

Barix – CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Aug 20, 2024
CVE-2024-41699
4.4 MEDIUM

Priority – CWE-552: Files or Directories Accessible to External Parties

Aug 20, 2024
CVE-2024-41698
4.3 MEDIUM

Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Aug 20, 2024
CVE-2024-41697
6.1 MEDIUM

Priority - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Aug 20, 2024
CVE-2024-25009
6.5 MEDIUM

Ericsson Packet Core Controller (PCC) contains a vulnerability in Access and Mobility Management Function (AMF) where improper input validation can lead to denial of service …

Aug 20, 2024
CVE-2024-7054
6.4 MEDIUM

The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Aug 20, 2024
CVE-2024-28829
7.8 HIGH

Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0p12, 2.2.0p32, 2.1.0p47 and 2.0.0 (EOL) allows local users …

Aug 20, 2024
CVE-2024-21689
8.0 HIGH

This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689 was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0 of Bamboo Data Center and …

Aug 20, 2024
CVE-2024-43202
9.8 CRITICAL

Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgrade Apache DolphinScheduler to version 3.2.2, …

Aug 20, 2024
CVE-2024-38808
4.3 MEDIUM

In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language …

Aug 20, 2024
CVE-2024-6847
9.8 CRITICAL

The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to …

Aug 20, 2024
CVE-2024-5576
6.4 MEDIUM

The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'course_carousel_skin' attribute within the plugin's Course Carousel widget in …

Aug 20, 2024
CVE-2024-43688
7.3 HIGH

cron/entry.c in vixie cron before 9cc8ab1, as used in OpenBSD 7.4 and 7.5, allows a heap-based buffer underflow and memory corruption. NOTE: this issue was …

Aug 20, 2024
CVE-2024-6864
6.4 MEDIUM

The WP Last Modified Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘template’ attribute of the lmt-post-modified-info shortcode in all versions …

Aug 20, 2024
CVE-2024-7782
8.7 HIGH

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable …

Aug 20, 2024
CVE-2024-7780
7.2 HIGH

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable …

Aug 20, 2024
CVE-2024-7777
9.0 CRITICAL

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable …

Aug 20, 2024
CVE-2024-7775
5.5 MEDIUM

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable …

Aug 20, 2024
CVE-2024-7702
7.2 HIGH

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable …

Aug 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.