CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-33987
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL …

Aug 6, 2024
CVE-2024-33986
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL …

Aug 6, 2024
CVE-2024-33985
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL …

Aug 6, 2024
CVE-2024-33984
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL …

Aug 6, 2024
CVE-2024-33983
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL …

Aug 6, 2024
CVE-2024-33982
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL …

Aug 6, 2024
CVE-2024-33974
9.8 CRITICAL

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted …

Aug 6, 2024
CVE-2024-33973
9.8 CRITICAL

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted …

Aug 6, 2024
CVE-2024-33972
9.8 CRITICAL

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted …

Aug 6, 2024
CVE-2024-33971
9.8 CRITICAL

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted …

Aug 6, 2024
CVE-2024-33970
9.8 CRITICAL

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted …

Aug 6, 2024
CVE-2024-33969
9.8 CRITICAL

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted …

Aug 6, 2024
CVE-2024-33968
9.8 CRITICAL

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted …

Aug 6, 2024
CVE-2024-33967
9.8 CRITICAL

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted …

Aug 6, 2024
CVE-2024-33966
9.8 CRITICAL

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted …

Aug 6, 2024
CVE-2024-33965
9.8 CRITICAL

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted …

Aug 6, 2024
CVE-2024-33964
9.8 CRITICAL

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted …

Aug 6, 2024
CVE-2024-33963
9.8 CRITICAL

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted …

Aug 6, 2024
CVE-2024-33962
9.8 CRITICAL

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted …

Aug 6, 2024
CVE-2024-33961
9.8 CRITICAL

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted …

Aug 6, 2024
CVE-2024-33960
9.8 CRITICAL

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted …

Aug 6, 2024
CVE-2024-7317
6.4 MEDIUM

The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG …

Aug 6, 2024
CVE-2024-7246
5.3 MEDIUM

It's possible for a gRPC client communicating with a HTTP/2 proxy to poison the HPACK table between the proxy and the backend such that other …

Aug 6, 2024
CVE-2024-33981
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send …

Aug 6, 2024
CVE-2024-33980
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send …

Aug 6, 2024
CVE-2024-33979
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send …

Aug 6, 2024
CVE-2024-33978
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to …

Aug 6, 2024
CVE-2024-33977
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to …

Aug 6, 2024
CVE-2024-33976
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an …

Aug 6, 2024
CVE-2024-33975
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an …

Aug 6, 2024
CVE-2024-33959
9.8 CRITICAL

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted …

Aug 6, 2024
CVE-2024-33958
9.8 CRITICAL

SQL injection vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and …

Aug 6, 2024
CVE-2024-33957
9.8 CRITICAL

SQL injection vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and …

Aug 6, 2024
CVE-2024-41995
7.5 HIGH

Initialization of a resource with an insecure default vulnerability exists in JavaTM Platform Ver.12.89 and earlier. If this vulnerability is exploited, the product may be …

Aug 6, 2024
CVE-2024-7084
4.8 MEDIUM

The Ajax Search Lite WordPress plugin before 4.12.1 does not sanitise and escape some parameters, which could allow users with a role as low as …

Aug 6, 2024
CVE-2024-7082
6.1 MEDIUM

The Easy Table of Contents WordPress plugin before 2.0.68 does not sanitise and escape some parameters, which could allow users with a role as low …

Aug 6, 2024
CVE-2024-7055
6.3 MEDIUM

A vulnerability was found in FFmpeg up to 7.0.1. It has been classified as critical. This affects the function pnm_decode_frame in the library /libavcodec/pnmdec.c. The …

Aug 6, 2024
CVE-2024-6766
5.4 MEDIUM

The shortcodes-ultimate-pro WordPress plugin before 7.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the …

Aug 6, 2024
CVE-2024-6651
6.1 MEDIUM

The WordPress File Upload WordPress plugin before 4.24.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Aug 6, 2024
CVE-2024-6203
8.3 HIGH

HaloITSM versions up to 2.146.1 are affected by a Password Reset Poisoning vulnerability. Poisoned password reset links can be sent to existing HaloITSM users (given …

Aug 6, 2024
CVE-2024-6202
9.8 CRITICAL

HaloITSM versions up to 2.146.1 are affected by a SAML XML Signature Wrapping (XSW) vulnerability. When having a SAML integration configured, anonymous actors could impersonate …

Aug 6, 2024
CVE-2024-6201
5.3 MEDIUM

HaloITSM versions up to 2.146.1 are affected by a Template Injection vulnerability within the engine used to generate emails. This can lead to the leakage …

Aug 6, 2024
CVE-2024-6200
8.0 HIGH

HaloITSM versions up to 2.146.1 are affected by a Stored Cross-Site Scripting (XSS) vulnerability. The injected JavaScript code can execute arbitrary action on behalf of …

Aug 6, 2024
CVE-2024-5709
8.8 HIGH

The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.7 via the 'layout_name' parameter. …

Aug 6, 2024
CVE-2024-5708
6.4 MEDIUM

The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in all versions up to, and including, 7.7 …

Aug 6, 2024
CVE-2024-7506
6.3 MEDIUM

A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Aug 6, 2024
CVE-2024-39817
6.5 MEDIUM

Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to the …

Aug 6, 2024
CVE-2024-7505
7.3 HIGH

A vulnerability, which was classified as critical, was found in itsourcecode Bike Delivery System 1.0. Affected is an unknown function of the file contact_us_action.php. The …

Aug 6, 2024
CVE-2024-7500
6.3 MEDIUM

A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been rated as critical. Affected by this issue is the function save_settings of …

Aug 6, 2024
CVE-2024-7009
4.2 MEDIUM

Unsanitized user-input in Calibre <= 7.15.0 allow users with permissions to perform full-text searches to achieve SQL injection on the SQLite database.

Aug 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.