CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-41888
5.3 MEDIUM

Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. The password reset link remains valid within …

Aug 12, 2024
CVE-2024-41577
9.8 CRITICAL

An arbitrary file upload vulnerability in the Ueditor component of productinfoquick v1.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.

Aug 12, 2024
CVE-2024-41570
9.8 CRITICAL

An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send arbitrary network traffic originating from the team …

Aug 12, 2024
CVE-2024-41482
6.1 MEDIUM

Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the MathJax component.

Aug 12, 2024
CVE-2024-41481
6.1 MEDIUM

Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the Mermaid component.

Aug 12, 2024
CVE-2024-41476
9.8 CRITICAL

AMTT Hotel Broadband Operation System (HiBOS) V3.0.3.151204 and before is vulnerable to SQL Injection via /manager/card/card_detail.php.

Aug 12, 2024
CVE-2024-41332
6.5 MEDIUM

Incorrect access control in the delete_category function of Sourcecodester Computer Laboratory Management System v1.0 allows authenticated attackers with low-level privileges to arbitrarily delete categories.

Aug 12, 2024
CVE-2024-40488
8.8 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability was found in the Kashipara Live Membership System v1.0. This could lead to an attacker tricking the administrator into …

Aug 12, 2024
CVE-2024-40487
7.6 HIGH

A Stored Cross Site Scripting (XSS) vulnerability was found in "/view_type.php" of Kashipara Live Membership System v1.0, which allows remote attackers to execute arbitrary code …

Aug 12, 2024
CVE-2024-40486
9.8 CRITICAL

A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the …

Aug 12, 2024
CVE-2024-40484
6.1 MEDIUM

A Reflected Cross Site Scripting (XSS) vulnerability was found in "/oahms/search.php" in PHPGurukul Old Age Home Management System v1.0, which allows remote attackers to execute …

Aug 12, 2024
CVE-2024-40482
9.8 CRITICAL

An Unrestricted file upload vulnerability was found in "/Membership/edit_member.php" of Kashipara Live Membership System v1.0, which allows attackers to execute arbitrary code via uploading a …

Aug 12, 2024
CVE-2024-40481
5.4 MEDIUM

A Stored Cross Site Scripting (XSS) vulnerability was found in "/admin/view-enquiry.php" in PHPGurukul Old Age Home Management System v1.0, which allows remote attackers to execute …

Aug 12, 2024
CVE-2024-40480
9.8 CRITICAL

A Broken Access Control vulnerability was found in /admin/update.php and /admin/dashboard.php in Kashipara Online Exam System v1.0, which allows remote unauthenticated attackers to view administrator …

Aug 12, 2024
CVE-2024-40479
8.1 HIGH

A SQL injection vulnerability in "/admin/quizquestion.php" in Kashipara Online Exam System v1.0 allows remote attackers to execute arbitrary SQL commands via the "eid" parameter.

Aug 12, 2024
CVE-2024-40478
5.4 MEDIUM

A Stored Cross Site Scripting (XSS) vulnerability was found in "/admin/afeedback.php" in Kashipara Online Exam System v1.0, which allows remote attackers to execute arbitrary code …

Aug 12, 2024
CVE-2024-40477
9.8 CRITICAL

A SQL injection vulnerability in "/oahms/admin/forgot-password.php" in PHPGurukul Old Age Home Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "email" …

Aug 12, 2024
CVE-2024-40476
8.0 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability was found in SourceCodester Best House Rental Management System v1.0. This could lead to an attacker tricking the administrator …

Aug 12, 2024
CVE-2024-40475
8.8 HIGH

SourceCodester Best House Rental Management System v1.0 is vulnerable to Incorrect Access Control via /rental/payment_report.php, /rental/balance_report.php, /rental/invoices.php, /rental/tenants.php, and /rental/users.php.

Aug 12, 2024
CVE-2024-40474
5.4 MEDIUM

A Reflected Cross Site Scripting (XSS) vulnerability was found in "edit-cate.php" in SourceCodester House Rental Management System v1.0.

Aug 12, 2024
CVE-2024-40473
5.4 MEDIUM

A Stored Cross Site Scripting (XSS) vulnerability was found in "manage_houses.php" in SourceCodester Best House Rental Management System v1.0. It allows remote attackers to execute …

Aug 12, 2024
CVE-2024-40472
9.8 CRITICAL

Sourcecodester Daily Calories Monitoring Tool v1.0 is vulnerable to SQL Injection via "delete-calorie.php."

Aug 12, 2024
CVE-2024-3279
9.1 CRITICAL

An improper access control vulnerability exists in the mintplex-labs/anything-llm application, specifically within the import endpoint. This vulnerability allows an anonymous attacker, without an account in …

Aug 12, 2024
CVE-2024-39815
9.1 CRITICAL

Improper check or handling of exceptional conditions vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enable an …

Aug 12, 2024
CVE-2024-39791
10.0 CRITICAL

Stack-based buffer overflow vulnerabilities affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enable an unauthenticated remote attacker to …

Aug 12, 2024
CVE-2024-39338
7.5 HIGH

axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs.

Aug 12, 2024
CVE-2024-38989
9.8 CRITICAL

izatop bunt v0.29.19 was discovered to contain a prototype pollution via the component /esm/qs.js. This vulnerability allows attackers to execute arbitrary code or cause a …

Aug 12, 2024
CVE-2024-38219
6.5 MEDIUM

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Aug 12, 2024
CVE-2024-38218
8.4 HIGH

Microsoft Edge (HTML-based) Memory Corruption Vulnerability

Aug 12, 2024
CVE-2024-38200
6.5 MEDIUM

Microsoft Office Spoofing Vulnerability

Aug 12, 2024
CVE-2024-37826
7.5 HIGH

A NULL pointer dereference in vercot Serva v4.6.0 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

Aug 12, 2024
CVE-2024-37283
6.5 MEDIUM

An issue was discovered whereby Elastic Agent will leak secrets from the agent policy elastic-agent.yml only when the log level is configured to debug. By …

Aug 12, 2024
CVE-2024-37023
9.1 CRITICAL

Multiple OS command injection vulnerabilities affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enable an authenticated remote attacker …

Aug 12, 2024
CVE-2024-36518
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's dashboard.

Aug 12, 2024
CVE-2024-36462
7.5 HIGH

Uncontrolled resource consumption refers to a software vulnerability where a attacker or system uses excessive resources, such as CPU, memory, or network bandwidth, without proper …

Aug 12, 2024
CVE-2024-36461
9.1 CRITICAL

Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.

Aug 12, 2024
CVE-2024-36460
8.1 HIGH

The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.

Aug 12, 2024
CVE-2024-36035
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session recording.

Aug 12, 2024
CVE-2024-36034
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in aggregate reports' search option.

Aug 12, 2024
CVE-2024-32765
4.2 MEDIUM

A vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow local authenticated administrators to gain access to and …

Aug 12, 2024
CVE-2024-30188
8.1 HIGH

File read and write vulnerability in Apache DolphinScheduler , authenticated users can illegally access additional resource files. This issue affects Apache DolphinScheduler: from 3.1.0 before …

Aug 12, 2024
CVE-2024-29831
8.8 HIGH

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using …

Aug 12, 2024
CVE-2024-29082
8.6 HIGH

Improper access control vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enables an unauthenticated remote attacker to …

Aug 12, 2024
CVE-2024-22123
2.7 LOW

Setting SMS media allows to set GSM modem file. Later this file is used as Linux device. But due everything is a file for Linux, …

Aug 12, 2024
CVE-2024-22122
3.0 LOW

Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on …

Aug 12, 2024
CVE-2024-22121
6.1 MEDIUM

A non-admin user can change or remove important features within the Zabbix Agent application, thus impacting the integrity and availability of the application.

Aug 12, 2024
CVE-2024-22116
9.9 CRITICAL

An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default escaping for script parameters enabled …

Aug 12, 2024
CVE-2024-22114
4.3 MEDIUM

User with no permission to any of the Hosts can access and view host count & other statistics through System Information Widget in Global View …

Aug 12, 2024
CVE-2024-21881

Inadequate Encryption Strength vulnerability allow an authenticated attacker to execute arbitrary OS Commands via encrypted package upload.This issue affects Envoy: 4.x and 5.x

Aug 12, 2024
CVE-2024-21880
7.2 HIGH

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly …

Aug 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.