CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7512
4.8 MEDIUM

Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in Board instances. A rogue administrator could inject malicious code. The Concrete …

Aug 12, 2024
CVE-2024-7503
9.8 CRITICAL

The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.5. This is due to the …

Aug 12, 2024
CVE-2024-7416
5.3 MEDIUM

The Reveal Template plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.7. This is due to the …

Aug 12, 2024
CVE-2024-7414
5.3 MEDIUM

The PDF Builder for WPForms plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.116. This is due …

Aug 12, 2024
CVE-2024-7413
5.3 MEDIUM

The Obfuscate Email plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.8.1. This is due to the …

Aug 12, 2024
CVE-2024-7412
5.3 MEDIUM

The No Update Nag plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.12. This is due to …

Aug 12, 2024
CVE-2024-7410
5.3 MEDIUM

The My Custom CSS PHP & ADS plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.3. This …

Aug 12, 2024
CVE-2024-7408
6.5 MEDIUM

This vulnerability exists in Airveda Air Quality Monitor PM2.5 PM10 due to transmission of sensitive information in plain text during AP pairing mode. An attacker …

Aug 12, 2024
CVE-2024-7399
8.8 HIGH KEV

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as …

Aug 12, 2024
CVE-2024-7382
5.3 MEDIUM

The Linkify Text plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.9.1. This is due to the …

Aug 12, 2024
CVE-2024-7272
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in FFmpeg up to 5.1.5. This affects the function fill_audiodata of the file /libswresample/swresample.c. The manipulation …

Aug 12, 2024
CVE-2024-7006
7.5 HIGH

A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, …

Aug 12, 2024
CVE-2024-6760
7.5 HIGH

A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it should have, allowing unprivileged …

Aug 12, 2024
CVE-2024-6759
5.3 MEDIUM

When mounting a remote filesystem using NFS, the kernel did not sanitize remotely provided filenames for the path separator character, "/". This allows readdir(3) and …

Aug 12, 2024
CVE-2024-6758
6.5 MEDIUM

Improper Privilege Management in Sprecher Automation SPRECON-E below version 8.71j allows a remote attacker with low privileges to save unauthorized protection assignments.

Aug 12, 2024
CVE-2024-6692
3.3 LOW

The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Aug 12, 2024
CVE-2024-6691
4.4 MEDIUM

The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Aug 12, 2024
CVE-2024-6684

Authentication Bypass Using an Alternate Path or Channel vulnerability in GST Electronics inohom Nova Panel N7 allows Authentication Bypass.This issue affects inohom Nova Panel N7: …

Aug 12, 2024
CVE-2024-6640
6.3 MEDIUM

In ICMPv6 Neighbor Discovery (ND), the ID is always 0. When pf is configured to allow ND and block incoming Echo Requests, a crafted Echo …

Aug 12, 2024
CVE-2024-6562
5.3 MEDIUM

The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.5.5. This is …

Aug 12, 2024
CVE-2024-6158
4.8 MEDIUM

The Category Posts Widget WordPress plugin before 4.9.17, term-and-category-based-posts-widget WordPress plugin before 4.9.13 does not validate and escape some of its "Category Posts" widget settings …

Aug 12, 2024
CVE-2024-6136
5.4 MEDIUM

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted …

Aug 12, 2024
CVE-2024-6134
5.4 MEDIUM

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Aug 12, 2024
CVE-2024-6133
6.5 MEDIUM

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Aug 12, 2024
CVE-2024-5801

Enabled IP Forwarding feature in B&R Automation Runtime versions before 6.0.2 may allow remote attack-ers to compromise network security by routing IP-based packets through the …

Aug 12, 2024
CVE-2024-5800
7.5 HIGH

Diffie-Hellman groups with insufficient strength are used in the SSL/TLS stack of B&R Automation Runtime versions before 6.0.2, allowing a network attacker to decrypt the …

Aug 12, 2024
CVE-2024-5651
8.8 HIGH

A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) primitive by supplying an arbitrary command …

Aug 12, 2024
CVE-2024-5527
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in file auditing configuration.

Aug 12, 2024
CVE-2024-5487
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's export option.

Aug 12, 2024
CVE-2024-5445
3.8 LOW

Ecosystem Agent version 4 < 4.1.5.2597 and Ecosystem Agent version 5 < 5.1.4.2473 did not properly validate SSL/TLS certificates, which could allow a malicious actor …

Aug 12, 2024
CVE-2024-4360
6.4 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Aug 12, 2024
CVE-2024-4359
6.5 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to arbitrary file reads in …

Aug 12, 2024
CVE-2024-4350
4.8 MEDIUM

Concrete CMS versions 9.0.0 to 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in RSS Displayer when user input is stored and later embedded …

Aug 12, 2024
CVE-2024-43168
4.8 MEDIUM

DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet Labs) falls within the …

Aug 12, 2024
CVE-2024-43167
2.8 LOW

DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet Labs) falls within the …

Aug 12, 2024
CVE-2024-42473
7.5 HIGH

OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses `but not` …

Aug 12, 2024
CVE-2024-42470
6.5 MEDIUM

openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. Several endpoints in versions prior to 4.2.1 of the CometVisu …

Aug 12, 2024
CVE-2024-42469
9.8 CRITICAL

openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. Prior to version 4.2.1, CometVisu's file system endpoints don't require …

Aug 12, 2024
CVE-2024-42468
5.3 MEDIUM

openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. CometVisuServlet in versions prior to 4.2.1 is susceptible to an …

Aug 12, 2024
CVE-2024-42467
10.0 CRITICAL

openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. Prior to version 4.2.1, the proxy endpoint of openHAB's CometVisu …

Aug 12, 2024
CVE-2024-42370
8.3 HIGH

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions 2.10.0 and prior, Litestar's `docs-preview.yml` workflow is vulnerable to Environment Variable injection which may …

Aug 12, 2024
CVE-2024-42367
4.8 MEDIUM

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions on the 3.10 branch prior to version 3.10.2, static routes which contain …

Aug 12, 2024
CVE-2024-42167
9.1 CRITICAL

The function "generate_app_certificates" in controllers/saml2/saml2.js of FIWARE Keyrock <= 8.4 does not neutralize special elements used in an OS Command properly. This allows an authenticated …

Aug 12, 2024
CVE-2024-42166
9.1 CRITICAL

The function "generate_app_certificates" in lib/app_certificates.js of FIWARE Keyrock <= 8.4 does not neutralize special elements used in an OS Command properly. This allows an authenticated …

Aug 12, 2024
CVE-2024-42165
6.3 MEDIUM

Insufficiently random values for generating activation token in FIWARE Keyrock <= 8.4 allow attackers to activate accounts of any user by predicting the token for …

Aug 12, 2024
CVE-2024-42164
4.3 MEDIUM

Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to disable two factor authorization of any user by predicting …

Aug 12, 2024
CVE-2024-42163
8.3 HIGH

Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to take over the account of any user by predicting …

Aug 12, 2024
CVE-2024-42001
8.6 HIGH

An improper authentication vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior enables an unauthenticated remote attacker to …

Aug 12, 2024
CVE-2024-41936
7.5 HIGH

A directory traversal vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enables an unauthenticated remote attacker to …

Aug 12, 2024
CVE-2024-41890
5.3 MEDIUM

Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. User sends multiple password reset emails, each …

Aug 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.