CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-43005
4.7 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the component dl_liuyan_save.php of ZZCMS v2023 allows attackers to execute arbitrary code in the context of a user's …

Aug 16, 2024
CVE-2023-47728
6.5 MEDIUM

IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a remote attacker to obtain sensitive information …

Aug 16, 2024
CVE-2024-42850
9.8 CRITICAL

An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.

Aug 16, 2024
CVE-2024-42849
6.5 MEDIUM

An issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function.

Aug 16, 2024
CVE-2022-4405

Rejected reason: **REJECT** This is not considered a valid security vulnerability.

Aug 16, 2024
CVE-2022-33162
7.3 HIGH

IBM Security Directory Integrator 7.2.0 and Security Verify Directory Integrator 10.0.0 does not perform any authentication for functionality that requires a provable user identity or …

Aug 16, 2024
CVE-2024-7646
8.8 HIGH

A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `extensions` API group) can bypass …

Aug 16, 2024
CVE-2024-42758
5.4 MEDIUM

A Cross-site Scripting (XSS) vulnerability exists in version v2024-01-05 of the indexmenu plugin when is used and enabled in Dokuwiki (Open Source Wiki Engine). A …

Aug 16, 2024
CVE-2024-42639
9.8 CRITICAL

H3C GR1100-P v100R009 was discovered to use a hardcoded password in /etc/shadow, which allows attackers to log in as root.

Aug 16, 2024
CVE-2024-42638
9.8 CRITICAL

H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

Aug 16, 2024
CVE-2024-42637
9.8 CRITICAL

H3C R3010 v100R002L02 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

Aug 16, 2024
CVE-2024-25837
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in October CMS Bloghub Plugin v1.3.8 and lower allows attackers to execute arbitrary web scripts or HTML via a …

Aug 16, 2024
CVE-2024-42995
8.3 HIGH

VTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the "Migration" administrative module to disable arbitrary modules.

Aug 16, 2024
CVE-2024-42994
7.2 HIGH

VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the "CompanyDetails" …

Aug 16, 2024
CVE-2024-42634
9.8 CRITICAL

A Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03.06.42. As a result, attacker can execute OS commands with root …

Aug 16, 2024
CVE-2024-6098
5.3 MEDIUM

When performing an online tag generation to devices which communicate using the ControlLogix protocol, a machine-in-the-middle, or a device that is not configured correctly, could …

Aug 16, 2024
CVE-2024-6004
6.5 MEDIUM

A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to deny printer connections until the …

Aug 16, 2024
CVE-2024-5210
6.5 MEDIUM

A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to prevent printer services from being …

Aug 16, 2024
CVE-2024-5209
6.5 MEDIUM

A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to deny printing capabilities until the …

Aug 16, 2024
CVE-2024-4782
6.5 MEDIUM

A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to disrupt the printer's functionality until …

Aug 16, 2024
CVE-2024-4781
6.5 MEDIUM

A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to crash printer communications until the …

Aug 16, 2024
CVE-2024-4763
7.8 HIGH

An insecure driver vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM) that could allow a local attacker …

Aug 16, 2024
CVE-2024-43810
4.6 MEDIUM

In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin

Aug 16, 2024
CVE-2024-43809
3.5 LOW

In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page

Aug 16, 2024
CVE-2024-43808
3.7 LOW

In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin

Aug 16, 2024
CVE-2024-43807
4.6 MEDIUM

In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page

Aug 16, 2024
CVE-2024-43381
5.0 MEDIUM

reNgine is an automated reconnaissance framework for web applications. Versions 2.1.2 and prior are susceptible to Stored Cross-Site Scripting (XSS) attacks. This vulnerability occurs when …

Aug 16, 2024
CVE-2024-42486
5.4 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In versions on the 1.15.x branch prior to 1.15.8 and the 1.16.x branch …

Aug 16, 2024
CVE-2024-2175
7.8 HIGH

An insecure permissions vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM) that could allow a local attacker …

Aug 16, 2024
CVE-2024-7145
8.8 HIGH

The JetElements plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.6.20 via the 'progress_type' parameter. This makes …

Aug 16, 2024
CVE-2024-7144
6.4 MEDIUM

The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'slide_id' parameters in all versions up to, and including, 2.6.20 …

Aug 16, 2024
CVE-2024-42466
9.8 CRITICAL

Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Abuse.This issue affects upKeeper Manager: through 5.1.9.

Aug 16, 2024
CVE-2024-42465
9.8 CRITICAL

Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Abuse.This issue affects upKeeper Manager: through 5.1.9.

Aug 16, 2024
CVE-2024-42464
6.5 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Utilizing REST's Trust in the System Resource to Obtain Sensitive Data.This issue …

Aug 16, 2024
CVE-2024-42463
6.5 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Utilizing REST's Trust in the System Resource to Obtain Sensitive Data.This issue …

Aug 16, 2024
CVE-2024-42462
9.8 CRITICAL

Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This issue affects upKeeper Manager: through 5.1.9.

Aug 16, 2024
CVE-2024-7147
6.4 MEDIUM

The JetBlocks for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple placeholder parameters in all versions up to, and including, 1.3.12 …

Aug 16, 2024
CVE-2024-7146
8.8 HIGH

The JetTabs for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.3 via the 'switcher_preset' parameter. …

Aug 16, 2024
CVE-2024-7136
6.4 MEDIUM

The JetSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 3.5.2 due to …

Aug 16, 2024
CVE-2024-25008
6.8 MEDIUM

Ericsson RAN Compute and Site Controller 6610 contains a vulnerability in the Control System where Improper Input Validation can lead to arbitrary code execution, for …

Aug 16, 2024
CVE-2024-7501
4.2 MEDIUM

The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Aug 16, 2024
CVE-2024-6460
9.8 CRITICAL

The Grow by Tradedoubler WordPress plugin through 2.0.21 is vulnerable to Local File Inclusion via the component parameter. This makes it possible for attackers to …

Aug 16, 2024
CVE-2024-7301
7.2 HIGH

The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.24.8 …

Aug 16, 2024
CVE-2024-7422
4.3 MEDIUM

The Theme My Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.1.7. This is due to …

Aug 16, 2024
CVE-2024-7630
5.3 MEDIUM

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.22.2 (Free) and 2.25.1 …

Aug 16, 2024
CVE-2023-7049
4.3 MEDIUM

The Custom Field For WP Job Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2 …

Aug 16, 2024
CVE-2022-3399
4.4 MEDIUM

The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cookie_notice_options[refuse_code_head]' parameter in versions up …

Aug 16, 2024
CVE-2024-7853
6.3 MEDIUM

A vulnerability was found in SourceCodester Yoga Class Registration System up to 1.0. It has been classified as critical. Affected is an unknown function of …

Aug 16, 2024
CVE-2024-7852
3.5 LOW

A vulnerability was found in SourceCodester Yoga Class Registration System 1.0 and classified as problematic. This issue affects some unknown processing of the file /admin/inquiries/view_inquiry.php. …

Aug 16, 2024
CVE-2024-7851
6.3 MEDIUM

A vulnerability has been found in SourceCodester Yoga Class Registration System 1.0 and classified as critical. This vulnerability affects unknown code of the file /classes/Users.php?f=save …

Aug 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.