CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-31203
3.3 LOW

A “CWE-121: Stack-based Buffer Overflow” in the wd210std.dll dynamic library packaged with the ThermoscanIP installer allows a local attacker to possibly trigger a Denial-of-Service (DoS) …

Jul 31, 2024
CVE-2024-31202
7.8 HIGH

A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perform a Local Privilege Escalation.

Jul 31, 2024
CVE-2024-31201
6.5 MEDIUM

A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service. Such misconfiguration could be abused in scenarios where incorrect permissions were assigned to the …

Jul 31, 2024
CVE-2024-31200
4.2 MEDIUM

A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative account allows an attacker with physical access to the machine to retrieve the …

Jul 31, 2024
CVE-2024-31199
8.8 HIGH

A “CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')” allows malicious users to permanently inject arbitrary Javascript code.

Jul 31, 2024
CVE-2024-6208
6.4 MEDIUM

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packages' shortcode in all versions up to, and including, 3.2.97 …

Jul 31, 2024
CVE-2024-39379
5.5 MEDIUM

Acrobat for Edge versions 126.0.2592.81 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Jul 31, 2024
CVE-2024-7321
4.3 MEDIUM

A vulnerability classified as problematic was found in itsourcecode Online Blood Bank Management System 1.0. This vulnerability affects unknown code of the file signup.php of …

Jul 31, 2024
CVE-2024-7320
7.3 HIGH

A vulnerability classified as critical has been found in itsourcecode Online Blood Bank Management System 1.0. This affects an unknown part of the file /admin/index.php …

Jul 31, 2024
CVE-2024-7311
7.3 HIGH

A vulnerability was found in code-projects Online Bus Reservation Site 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Jul 31, 2024
CVE-2024-7135
6.5 MEDIUM

The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_file' function in all versions …

Jul 31, 2024
CVE-2024-6725
4.9 MEDIUM

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Jul 31, 2024
CVE-2024-7310
3.5 LOW

A vulnerability was found in SourceCodester Record Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file sort_user.php. …

Jul 31, 2024
CVE-2024-7309
3.5 LOW

A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as problematic. This affects an unknown part of the file entry.php. …

Jul 31, 2024
CVE-2024-7308
6.3 MEDIUM

A vulnerability was found in SourceCodester Establishment Billing Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Jul 31, 2024
CVE-2024-7307
6.3 MEDIUM

A vulnerability has been found in SourceCodester Establishment Billing Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Jul 31, 2024
CVE-2024-37142
7.3 HIGH

Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL …

Jul 31, 2024
CVE-2024-37129
6.7 MEDIUM

Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability. A local authenticated malicious user could potentially exploit this vulnerability, leading to arbitrary …

Jul 31, 2024
CVE-2024-37127
7.8 HIGH

Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL …

Jul 31, 2024
CVE-2024-32857
7.3 HIGH

Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL …

Jul 31, 2024
CVE-2024-2508
5.3 MEDIUM

The WP Mobile Menu plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_menu_item_icon function in …

Jul 31, 2024
CVE-2024-7306
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Establishment Billing Management System 1.0. Affected is an unknown function of the file /manage_block.php. …

Jul 31, 2024
CVE-2024-7303
3.5 LOW

A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of …

Jul 31, 2024
CVE-2024-7264
6.5 MEDIUM

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might …

Jul 31, 2024
CVE-2023-28074
6.2 MEDIUM

Dell BSAFE Crypto-C Micro Edition, version 4.1.5, and Dell BSAFE Micro Edition Suite, versions 4.0 through 4.6.1 and version 5.0, contains an Out-of-bounds Read vulnerability. …

Jul 31, 2024
CVE-2024-7300
3.5 LOW

A vulnerability classified as problematic has been found in Bolt CMS 3.7.1. Affected is an unknown function of the file /bolt/editcontent/showcases of the component Showcase …

Jul 31, 2024
CVE-2024-7299
3.5 LOW

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Bolt CMS 3.7.1. It has been rated as problematic. This issue affects some unknown processing …

Jul 31, 2024
CVE-2024-6980
9.8 CRITICAL

A verbose error handling issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This …

Jul 31, 2024
CVE-2024-7290
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Establishment Billing Management System 1.0. This affects an unknown part of the file /manage_tenant.php. The …

Jul 31, 2024
CVE-2024-7289
6.3 MEDIUM

A vulnerability was found in SourceCodester Establishment Billing Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Jul 31, 2024
CVE-2024-7205

When the device is shared, the homepage module are before 2.19.0 in eWeLink Cloud Service allows Secondary user to take over devices as primary user …

Jul 31, 2024
CVE-2024-6770
7.2 HIGH

The Lifetime free Drag & Drop Contact Form Builder for WordPress VForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up …

Jul 31, 2024
CVE-2024-6695
9.8 CRITICAL

it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is …

Jul 31, 2024
CVE-2024-6412
6.5 MEDIUM

The HTML Forms WordPress plugin before 1.3.34 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

Jul 31, 2024
CVE-2024-6408
5.4 MEDIUM

The Slider by 10Web WordPress plugin before 1.2.57 does not sanitise and escape its Slider Title, which could allow high privilege users such as editors …

Jul 31, 2024
CVE-2024-6272
6.1 MEDIUM

The SpiderContacts WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jul 31, 2024
CVE-2024-6165
4.8 MEDIUM

The WANotifier WordPress plugin before 2.6.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jul 31, 2024
CVE-2024-42381
8.3 HIGH

os/linux/elf.rb in Homebrew brew before 4.2.20 uses ldd to load ELF files obtained from untrusted sources, which allows attackers to achieve code execution via an …

Jul 31, 2024
CVE-2024-7288
6.3 MEDIUM

A vulnerability was found in SourceCodester Establishment Billing Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Jul 31, 2024
CVE-2024-7287
6.3 MEDIUM

A vulnerability was found in SourceCodester Establishment Billing Management System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Jul 31, 2024
CVE-2024-7286
7.3 HIGH

A vulnerability was found in SourceCodester Establishment Billing Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/ajax.php?action=login …

Jul 31, 2024
CVE-2024-7285
3.5 LOW

A vulnerability has been found in SourceCodester Establishment Billing Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/ajax.php?action=save_settings. …

Jul 31, 2024
CVE-2024-39950
8.6 HIGH

A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities to initiate device initialization.

Jul 31, 2024
CVE-2024-39949
7.5 HIGH

A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.

Jul 31, 2024
CVE-2024-39948
7.5 HIGH

A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.

Jul 31, 2024
CVE-2024-39947
6.5 MEDIUM

A vulnerability has been found in Dahua products.After obtaining the ordinary user's username and password, the attacker can send a carefully crafted data packet to …

Jul 31, 2024
CVE-2024-39946
6.0 MEDIUM

A vulnerability has been found in Dahua products.After obtaining the administrator's username and password, the attacker can send a carefully crafted data packet to the …

Jul 31, 2024
CVE-2024-39945
4.9 MEDIUM

A vulnerability has been found in Dahua products. After obtaining the administrator's username and password, the attacker can send a carefully crafted data packet to …

Jul 31, 2024
CVE-2024-39944
7.5 HIGH

A vulnerability has been found in Dahua products.Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.

Jul 31, 2024
CVE-2024-7284
3.5 LOW

A vulnerability, which was classified as problematic, was found in SourceCodester Lot Reservation Management System 1.0. This affects an unknown part of the file /admin/ajax.php?action=save_settings. …

Jul 31, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.