CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6498
4.8 MEDIUM

The Chatbot for WordPress by Collect.chat ⚡️ WordPress plugin before 2.4.4 does not sanitise and escape some of its settings, which could allow high privilege …

Aug 5, 2024
CVE-2024-6270
4.8 MEDIUM

The Community Events WordPress plugin before 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Aug 5, 2024
CVE-2024-5081
6.1 MEDIUM

The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Aug 5, 2024
CVE-2024-3636
5.4 MEDIUM

The Pinpoint Booking System WordPress plugin before 2.9.9.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Aug 5, 2024
CVE-2024-2232
8.1 HIGH

The lacks CSRF checks allowing a user to invite any user to any group (including private groups)

Aug 5, 2024
CVE-2024-6118
9.1 CRITICAL

A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials …

Aug 5, 2024
CVE-2024-6117
8.8 HIGH

A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to perform …

Aug 5, 2024
CVE-2024-41889
9.8 CRITICAL

Multiple Pimax products accept WebSocket connections from unintended endpoints. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker.

Aug 5, 2024
CVE-2024-41720
8.0 HIGH

Incorrect permission assignment for critical resource issue exists in ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15, which may allow a network-adjacent authenticated attacker to alter the …

Aug 5, 2024
CVE-2024-39838
8.8 HIGH

ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15 uses hard-coded credentials, which may allow a network-adjacent attacker with an administrative privilege to alter the configuration of the …

Aug 5, 2024
CVE-2024-39713
8.6 HIGH

A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.

Aug 5, 2024
CVE-2024-7470
6.3 MEDIUM

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been rated as critical. This issue affects the function sslvpn_config_mod of …

Aug 5, 2024
CVE-2024-7469
6.3 MEDIUM

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been declared as critical. This vulnerability affects the function sslvpn_config_mod of …

Aug 5, 2024
CVE-2024-7468
6.3 MEDIUM

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been classified as critical. This affects the function sslvpn_config_mod of the …

Aug 5, 2024
CVE-2024-7467
6.3 MEDIUM

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90 and classified as critical. Affected by this issue is the function sslvpn_config_mod of …

Aug 5, 2024
CVE-2024-7466
2.4 LOW

A vulnerability has been found in PMWeb 7.2.00 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Web Application …

Aug 5, 2024
CVE-2024-7465
8.8 HIGH

A vulnerability, which was classified as critical, was found in TOTOLINK CP450 4.1.0cu.747_B20191224. Affected is the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Aug 5, 2024
CVE-2024-7464
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in TOTOLINK CP900 6.3c.566. This issue affects the function setTelnetCfg of the component Telnet Service. …

Aug 5, 2024
CVE-2024-7463
8.8 HIGH

A vulnerability classified as critical was found in TOTOLINK CP900 6.3c.566. This vulnerability affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Aug 5, 2024
CVE-2024-7462
8.8 HIGH

A vulnerability classified as critical has been found in TOTOLINK N350RT 9.3.5u.6139_B20201216. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Aug 5, 2024
CVE-2024-7461
7.3 HIGH

A vulnerability was found in ForIP Tecnologia Administração PABX 1.x. It has been rated as critical. Affected by this issue is some unknown functionality of …

Aug 5, 2024
CVE-2024-7460
4.3 MEDIUM

A vulnerability was found in OSWAPP Warehouse Inventory System 1.0/2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Aug 4, 2024
CVE-2024-7459
4.3 MEDIUM

A vulnerability was found in OSWAPP Warehouse Inventory System 1.0/2.0. It has been classified as problematic. Affected is an unknown function of the file /edit_account.php. …

Aug 4, 2024
CVE-2024-7458
5.5 MEDIUM

A vulnerability was found in elunez eladmin up to 2.7 and classified as critical. This issue affects some unknown processing of the file /api/deploy/upload /api/database/upload …

Aug 4, 2024
CVE-2024-35143
6.7 MEDIUM

IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it …

Aug 4, 2024
CVE-2024-7455
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System 1.0. This affects an unknown part of the file partedit.php. The …

Aug 4, 2024
CVE-2024-7454
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Clinics Patient Management System 1.0. Affected by this issue is the function patient_name …

Aug 4, 2024
CVE-2024-7453
2.4 LOW

A vulnerability was found in FastAdmin 1.5.0.20240328. It has been declared as problematic. This vulnerability affects unknown code of the file /[admins_url].php/general/attachment/edit/ids/4?dialog=1 of the component …

Aug 4, 2024
CVE-2024-7452
6.3 MEDIUM

A vulnerability was found in itsourcecode Placement Management System 1.0. It has been classified as critical. This affects an unknown part of the file view_company.php. …

Aug 4, 2024
CVE-2024-7451
6.3 MEDIUM

A vulnerability was found in itsourcecode Placement Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Aug 4, 2024
CVE-2024-7450
6.3 MEDIUM

A vulnerability has been found in itsourcecode Placement Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Aug 4, 2024
CVE-2024-7449
7.3 HIGH

A vulnerability, which was classified as critical, was found in itsourcecode Placement Management System 1.0. Affected is an unknown function of the file login.php. The …

Aug 4, 2024
CVE-2024-6331
7.5 HIGH

stitionai/devika main branch as of commit cdfb782b0e634b773b10963c8034dc9207ba1f9f is vulnerable to Local File Read (LFI) by Prompt Injection. The integration of Google Gimini 1.0 Pro with …

Aug 4, 2024
CVE-2024-7446
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Ticket Reservation System 1.0. This affects an unknown part of the file list_tickets.php. The …

Aug 3, 2024
CVE-2024-7445
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in itsourcecode Ticket Reservation System 1.0. Affected by this issue is some unknown functionality of …

Aug 3, 2024
CVE-2024-7444
7.3 HIGH

A vulnerability classified as critical was found in itsourcecode Ticket Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file login.php …

Aug 3, 2024
CVE-2024-7443
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Vivotek IB8367A VVTK-0100b. Affected is the function getenv of the file …

Aug 3, 2024
CVE-2024-7442
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek SD9364 VVTK-0103f. It has been rated as critical. This issue affects the function getenv …

Aug 3, 2024
CVE-2024-7441
8.8 HIGH

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek SD9364 VVTK-0103f. It has been declared as critical. This vulnerability affects the function read …

Aug 3, 2024
CVE-2024-7440
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek CC8160 VVTK-0100d. It has been classified as critical. This affects the function getenv of …

Aug 3, 2024
CVE-2024-7439
8.8 HIGH

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek CC8160 VVTK-0100d and classified as critical. Affected by this issue is the function read …

Aug 3, 2024
CVE-2024-7438
4.3 MEDIUM

A vulnerability has been found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php?action=profile;u=2;area=showalerts;do=read …

Aug 3, 2024
CVE-2024-37286
5.7 MEDIUM

APM server logs contain document body from a partially failed bulk index request. For example, in case of unavailable_shards_exception for a specific document, since the …

Aug 3, 2024
CVE-2024-7437
5.4 MEDIUM

A vulnerability, which was classified as critical, was found in SimpleMachines SMF 2.1.4. Affected is an unknown function of the file /index.php?action=profile;u=2;area=showalerts;do=remove of the component …

Aug 3, 2024
CVE-2024-7436
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in D-Link DI-8100 16.07. This issue affects the function msp_info_htm of the file msp_info.htm. The …

Aug 3, 2024
CVE-2024-38321
5.3 MEDIUM

IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2, and 24.0.0 stores potentially sensitive information in log files under certain situations that could be read by an …

Aug 3, 2024
CVE-2024-6872
4.3 MEDIUM

The Build Your Dream Website Fast with 400+ Starter Templates and Landing Pages, No Coding Needed, One-Click Import for Elementor & Gutenberg Blocks! – TemplateSpare …

Aug 3, 2024
CVE-2024-6709
4.3 MEDIUM

The Sync Post With Other Site plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sps_add_update_post' …

Aug 3, 2024
CVE-2024-7356
6.4 MEDIUM

The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘filename’ parameter in all versions up to, and including, 3.3.100 …

Aug 3, 2024
CVE-2024-7257
9.8 CRITICAL

The YayExtra – WooCommerce Extra Product Options plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_upload_file …

Aug 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.