CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7008
5.4 MEDIUM

Unsanitized user-input in Calibre <= 7.15.0 allow attackers to perform reflected cross-site scripting.

Aug 6, 2024
CVE-2024-6886

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects …

Aug 6, 2024
CVE-2024-6782
9.8 CRITICAL

Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution.

Aug 6, 2024
CVE-2024-6781
7.5 HIGH

Path traversal in Calibre <= 7.14.0 allow unauthenticated attackers to achieve arbitrary file read.

Aug 6, 2024
CVE-2024-28962
6.5 MEDIUM

Dell Command | Update, Dell Update, and Alienware Update UWP, versions prior to 5.4, contain an Exposed Dangerous Method or Function vulnerability. An unauthenticated attacker …

Aug 6, 2024
CVE-2024-7499
6.3 MEDIUM

A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Aug 6, 2024
CVE-2024-7498
7.3 HIGH

A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been classified as critical. Affected is the function login/login2 of the file /admin/login.php …

Aug 6, 2024
CVE-2024-5963
6.7 MEDIUM

Unquoted Executable Path vulnerability in Hitachi Device Manager on Windows (Device Manager Server component).This issue affects Hitachi Device Manager: before 8.8.7-00.

Aug 6, 2024
CVE-2024-5828
8.6 HIGH

Expression Language Injection vulnerability in Hitachi Tuning Manager on Windows, Linux, Solaris allows Code Injection.This issue affects Hitachi Tuning Manager: before 8.8.7-00.

Aug 6, 2024
CVE-2024-7497
6.3 MEDIUM

A vulnerability was found in itsourcecode Airline Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/index.php. The …

Aug 6, 2024
CVE-2024-7496
6.3 MEDIUM

A vulnerability has been found in itsourcecode Airline Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file /index.php. The …

Aug 6, 2024
CVE-2024-7485
7.2 HIGH

The Traffic Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page' parameter in the 'UserWebStat' AJAX function in all versions up …

Aug 6, 2024
CVE-2024-7484
7.2 HIGH

The CRM Perks Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'handle_uploaded_files' function in versions up …

Aug 6, 2024
CVE-2024-6315
8.8 HIGH

The Blox Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handleUploadFile' function in all …

Aug 6, 2024
CVE-2023-5000
8.8 HIGH

The Horizontal scrolling announcements plugin for WordPress is vulnerable to SQL Injection via the plugin's 'hsas-shortcode' shortcode in versions up to, and including, 2.4 due …

Aug 6, 2024
CVE-2024-7495
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Laravel Accounting System 1.0. This affects an unknown part of the file app/Http/Controllers/HomeController.php. The …

Aug 6, 2024
CVE-2024-7547
7.8 HIGH

oFono SMS Decoder Stack-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker …

Aug 6, 2024
CVE-2024-7546
7.8 HIGH

oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must …

Aug 6, 2024
CVE-2024-7545
7.8 HIGH

oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must …

Aug 6, 2024
CVE-2024-7544
7.8 HIGH

oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must …

Aug 6, 2024
CVE-2024-7543
7.8 HIGH

oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must …

Aug 6, 2024
CVE-2024-7542
3.3 LOW

oFono AT CMGR Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. An attacker …

Aug 6, 2024
CVE-2024-7541
3.3 LOW

oFono AT CMT Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. An attacker …

Aug 6, 2024
CVE-2024-7540
3.3 LOW

oFono AT CMGL Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. An attacker …

Aug 6, 2024
CVE-2024-7539
7.8 HIGH

oFono CUSD Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must …

Aug 6, 2024
CVE-2024-7538
7.8 HIGH

oFono CUSD AT Command Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An …

Aug 6, 2024
CVE-2024-7537
5.5 MEDIUM

oFono QMI SMS Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. Authentication is …

Aug 6, 2024
CVE-2024-7494
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Clinics Patient Management System 1.0. Affected by this issue is some unknown functionality …

Aug 5, 2024
CVE-2024-42352
8.6 HIGH

Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. `nuxt/icon` provides an API to allow client side icon …

Aug 5, 2024
CVE-2024-41811
3.9 LOW

ipl/web is a set of common web components for php projects. Some of the recent development by Icinga is, under certain circumstances, susceptible to cross …

Aug 5, 2024
CVE-2024-34344
8.8 HIGH

Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Due to the insufficient validation of the `path` parameter …

Aug 5, 2024
CVE-2024-34343
6.3 MEDIUM

Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. The `navigateTo` function attempts to blockthe `javascript:` protocol, but …

Aug 5, 2024
CVE-2024-23657
8.8 HIGH

Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Nuxt Devtools is missing authentication on the `getTextAssetContent` RPC …

Aug 5, 2024
CVE-2024-6915
9.3 CRITICAL

JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to Improper Input Validation that could potentially lead to cache poisoning.

Aug 5, 2024
CVE-2024-42350
3.0 LOW

Biscuit is an authorization token with decentralized verification, offline attenuation and strong security policy enforcement based on a logic language. Third-party blocks can be generated …

Aug 5, 2024
CVE-2024-41960
3.8 LOW

mailcow: dockerized is an open source groupware/email suite based on docker. An authenticated admin user can inject a JavaScript payload into the Relay Hosts configuration. …

Aug 5, 2024
CVE-2024-41959
7.6 HIGH

mailcow: dockerized is an open source groupware/email suite based on docker. An unauthenticated attacker can inject a JavaScript payload into the API logs. This payload …

Aug 5, 2024
CVE-2024-41958
6.6 MEDIUM

mailcow: dockerized is an open source groupware/email suite based on docker. A vulnerability has been discovered in the two-factor authentication (2FA) mechanism. This flaw allows …

Aug 5, 2024
CVE-2024-41820
6.0 MEDIUM

Kubean is a cluster lifecycle management toolchain based on kubespray and other cluster LCM engine. The ClusterRole has `*` verbs of `*` resources. If a …

Aug 5, 2024
CVE-2024-41816
5.4 MEDIUM

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the ‘[cooked-timer]’ shortcode in versions …

Aug 5, 2024
CVE-2024-6361
5.4 MEDIUM

Improper Neutralization vulnerability (XSS) has been discovered in OpenText™ ALM Octane. The vulnerability affects all version prior to version 23.4. The vulnerability could cause remote …

Aug 5, 2024
CVE-2024-42010
7.5 HIGH

mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-mail messages, allowing a remote attacker …

Aug 5, 2024
CVE-2024-42009
9.3 CRITICAL KEV

A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via …

Aug 5, 2024
CVE-2024-42008
9.3 CRITICAL

A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a …

Aug 5, 2024
CVE-2024-41381
6.1 MEDIUM

microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php.

Aug 5, 2024
CVE-2024-41380
6.1 MEDIUM

microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_tagging_tagged.php.

Aug 5, 2024
CVE-2024-41376
8.8 HIGH

dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.

Aug 5, 2024
CVE-2024-41200
5.5 MEDIUM

A segmentation fault in KMPlayer v4.2.2.65 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file.

Aug 5, 2024
CVE-2024-40498
9.8 CRITICAL

SQL Injection vulnerability in PuneethReddyHC Online Shopping sysstem advanced v.1.0 allows an attacker to execute arbitrary code via the register.php

Aug 5, 2024
CVE-2024-40531
8.8 HIGH

A mass assignment vulnerability exists in Pantera CRM versions 401.152 and 402.072. This flaw allows authenticated users to modify any user attribute, including roles, by …

Aug 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.