CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-42052
7.8 HIGH

The MSI installer for Splashtop Streamer for Windows before 3.5.8.0 uses a temporary folder with weak permissions during installation. A local user can exploit this …

Jul 28, 2024
CVE-2024-42051
7.8 HIGH

The MSI installer for Splashtop Streamer for Windows before 3.6.2.0 uses a temporary folder with weak permissions during installation. A local user can exploit this …

Jul 28, 2024
CVE-2024-42050
7.0 HIGH

The MSI installer for Splashtop Streamer for Windows before 3.7.0.0 uses a temporary folder with weak permissions during installation. A local user can exploit this …

Jul 28, 2024
CVE-2024-42049
9.1 CRITICAL

TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection.

Jul 28, 2024
CVE-2024-7153
5.3 MEDIUM

A vulnerability classified as problematic has been found in Netgear WN604 up to 20240719. Affected is an unknown function of the file siteSurvey.php. The manipulation …

Jul 27, 2024
CVE-2024-7152
8.8 HIGH

A vulnerability was found in Tenda O3 1.0.0.10(2478). It has been rated as critical. This issue affects the function fromSafeSetMacFilter of the file /goform/setMacFilterList. The …

Jul 27, 2024
CVE-2024-7151
8.8 HIGH

A vulnerability was found in Tenda O3 1.0.0.10(2478). It has been declared as critical. This vulnerability affects the function fromMacFilterSet of the file /goform/setMacFilter. The …

Jul 27, 2024
CVE-2024-6703
4.9 MEDIUM

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site …

Jul 27, 2024
CVE-2024-6897
6.4 MEDIUM

The aThemes Starter Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.53 …

Jul 27, 2024
CVE-2024-6627
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's PDF View widget in all versions up to, …

Jul 27, 2024
CVE-2024-6521
4.4 MEDIUM

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site …

Jul 27, 2024
CVE-2024-6520
4.4 MEDIUM

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site …

Jul 27, 2024
CVE-2024-6518
4.4 MEDIUM

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site …

Jul 27, 2024
CVE-2024-5614
5.3 MEDIUM

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.29 via the 'pafe_posts_list' …

Jul 27, 2024
CVE-2024-6569
5.3 MEDIUM

The Campaign Monitor for WordPress plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.8.15. This is due …

Jul 27, 2024
CVE-2024-6458
6.4 MEDIUM

The WooCommerce Product Table Lite plugin for WordPress is vulnerable to unauthorized post title modification due to a missing capability check on the wcpt_presets__duplicate_preset_to_table function …

Jul 27, 2024
CVE-2024-5969
5.8 MEDIUM

The AIomatic - Automatic AI Content Writer for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 2.0.5. This is …

Jul 27, 2024
CVE-2024-42029
6.3 MEDIUM

xdg-desktop-portal-hyprland (aka an XDG Desktop Portal backend for Hyprland) before 1.3.3 allows OS command execution, e.g., because single quotes are not used when sending a …

Jul 27, 2024
CVE-2024-6661
4.4 MEDIUM

The ParityPress – Parity Pricing with Discount Rules plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Discount Text' in all versions up to, …

Jul 27, 2024
CVE-2024-6634
6.4 MEDIUM

The Master Currency WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's currencyconverterform shortcode in all versions up to, and including, …

Jul 27, 2024
CVE-2024-6591
5.8 MEDIUM

The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized email creation and sending due to a missing capability check on the 'send_auction_email_callback' …

Jul 27, 2024
CVE-2024-6573
5.3 MEDIUM

The Intelligence plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.0. This is due the plugin not …

Jul 27, 2024
CVE-2024-6566
5.3 MEDIUM

The Aramex Shipping WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.1.21. This is due the …

Jul 27, 2024
CVE-2024-6549
5.3 MEDIUM

The Admin Post Navigation plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.1. This is due to …

Jul 27, 2024
CVE-2024-6548
5.3 MEDIUM

The Add Admin JavaScript plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0. This is due to …

Jul 27, 2024
CVE-2024-6547
5.3 MEDIUM

The Add Admin CSS plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1. This is due to …

Jul 27, 2024
CVE-2024-6546
5.3 MEDIUM

The One Click Close Comments plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.7.1. This is due …

Jul 27, 2024
CVE-2024-6545
5.3 MEDIUM

The Admin Trim Interface plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.5.1. This is due to …

Jul 27, 2024
CVE-2024-6431
8.8 HIGH

The Media.net Ads Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and missing capability check in the …

Jul 27, 2024
CVE-2024-6152
8.8 HIGH

The Flipbox Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5 via deserialization of untrusted input …

Jul 27, 2024
CVE-2024-4410
5.4 MEDIUM

The IgnitionDeck Crowdfunding Platform plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.9.8. This is due to missing capability …

Jul 27, 2024
CVE-2024-1804
4.3 MEDIUM

The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tutor_import_from_xml …

Jul 27, 2024
CVE-2024-1798
5.3 MEDIUM

The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the tutor_lp_export_xml …

Jul 27, 2024
CVE-2024-40433
8.8 HIGH

Insecure Permissions vulnerability in Tencent wechat v.8.0.37 allows an attacker to escalate privileges via the web-view component.

Jul 26, 2024
CVE-2024-37034
5.9 MEDIUM

An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with the Key-Value (KV) …

Jul 26, 2024
CVE-2024-41815
7.4 HIGH

Starship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily …

Jul 26, 2024
CVE-2024-41628
7.5 HIGH

Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and 2.1.0 before 2.1.0-9780 allows a remote attacker to include and display …

Jul 26, 2024
CVE-2024-41120
9.8 CRITICAL

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `url` variable on line 63 of `pages/9_🔲_Vector_Data_Visualization.py` takes user input, which …

Jul 26, 2024
CVE-2024-41119
9.8 CRITICAL

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 80 in `8_🏜️_Raster_Data_Visualization.py` takes user input, which …

Jul 26, 2024
CVE-2024-41118
7.5 HIGH

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `url` variable on line 47 of `pages/7_📦_Web_Map_Service.py` takes user input, which …

Jul 26, 2024
CVE-2024-41117
9.8 CRITICAL

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 115 in `pages/10_🌍_Earth_Engine_Datasets.py` takes user input, which …

Jul 26, 2024
CVE-2024-41116
9.8 CRITICAL

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 1254 in `pages/1_📷_Timelapse.py` takes user input, which …

Jul 26, 2024
CVE-2024-41115
9.8 CRITICAL

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `palette` variable on line 488 in `pages/1_📷_Timelapse.py` takes user input, which …

Jul 26, 2024
CVE-2024-41114
9.8 CRITICAL

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `palette` variable on line 430 in `pages/1_📷_Timelapse.py` takes user input, which …

Jul 26, 2024
CVE-2024-4786
2.8 LOW

An improper validation vulnerability was reported in the Lenovo Tab K10 that could allow a specially crafted application to keep the device on.

Jul 26, 2024
CVE-2024-41113
9.8 CRITICAL

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 383 or line 390 in `pages/1_📷_Timelapse.py` takes …

Jul 26, 2024
CVE-2024-41112
9.8 CRITICAL

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the palette variable in `pages/1_📷_Timelapse.py` takes user input, which is later used …

Jul 26, 2024
CVE-2024-40117
9.8 CRITICAL

Incorrect access control in Solar-Log 1000 before v2.8.2 and build 52- 23.04.2013 allows attackers to obtain Administrative privileges via connecting to the web administration server. …

Jul 26, 2024
CVE-2024-40116
8.1 HIGH

An issue in Solar-Log 1000 before v2.8.2 and build 52-23.04.2013 was discovered to store plaintext passwords in the export.html, email.html, and sms.html files -- fixed …

Jul 26, 2024
CVE-2024-38512
7.2 HIGH

A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated privileges to perform command injection via specially crafted …

Jul 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.