CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-20401
9.8 CRITICAL

A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to overwrite arbitrary files …

Jul 17, 2024
CVE-2024-20400
4.7 MEDIUM

A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote attacker to redirect a user to a malicious web …

Jul 17, 2024
CVE-2024-20396
5.3 MEDIUM

A vulnerability in the protocol handlers of Cisco Webex App could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability exists …

Jul 17, 2024
CVE-2024-20395
6.4 MEDIUM

A vulnerability in the media retrieval functionality of Cisco Webex App could allow an unauthenticated, adjacent attacker to gain access to sensitive session information. This …

Jul 17, 2024
CVE-2024-20323
7.5 HIGH

A vulnerability in Cisco Intelligent Node (iNode) Software could allow an unauthenticated, remote attacker to hijack the TLS connection between Cisco iNode Manager and associated …

Jul 17, 2024
CVE-2024-20296
4.7 MEDIUM

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to upload arbitrary files to an …

Jul 17, 2024
CVE-2024-6830
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Simple Inventory Management System 1.0. Affected is an unknown function of the file action.php …

Jul 17, 2024
CVE-2023-4976

A flaw exists in FlashBlade whereby a local account is permitted to authenticate to the management interface using an unintended method that allows an attacker …

Jul 17, 2024
CVE-2024-6834
9.0 CRITICAL

A vulnerability in APIML Spring Cloud Gateway which leverages user privileges by unexpected signing proxied request by Zowe's client certificate. This allows access to a …

Jul 17, 2024
CVE-2024-6833
5.9 MEDIUM

A vulnerability in Zowe CLI allows local, privileged actors to store previously entered secure credentials in a plaintext file as part of an auto-init operation.

Jul 17, 2024
CVE-2024-29120
5.9 MEDIUM

In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use …

Jul 17, 2024
CVE-2024-28993
7.6 HIGH

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file …

Jul 17, 2024
CVE-2024-28992
7.6 HIGH

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file …

Jul 17, 2024
CVE-2024-28074
9.6 CRITICAL

It was discovered that a previous vulnerability was not completely fixed with SolarWinds Access Rights Manager. While some controls were implemented the researcher was able …

Jul 17, 2024
CVE-2024-23475
9.6 CRITICAL

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file …

Jul 17, 2024
CVE-2024-23474
7.6 HIGH

The SolarWinds Access Rights Manager was found to be susceptible to an Arbitrary File Deletion and Information Disclosure vulnerability.

Jul 17, 2024
CVE-2024-23472
9.6 CRITICAL

SolarWinds Access Rights Manager (ARM) is susceptible to Directory Traversal vulnerability. This vulnerability allows an authenticated user to arbitrary read and delete files in ARM.

Jul 17, 2024
CVE-2024-23471
9.6 CRITICAL

The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to …

Jul 17, 2024
CVE-2024-23470
9.6 CRITICAL

The SolarWinds Access Rights Manager was found to be susceptible to a pre-authentication remote code execution vulnerability. If exploited, this vulnerability allows an unauthenticated user …

Jul 17, 2024
CVE-2024-23469
9.6 CRITICAL

SolarWinds Access Rights Manager (ARM) is susceptible to a Remote Code Execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to perform the actions …

Jul 17, 2024
CVE-2024-23468
7.6 HIGH

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file …

Jul 17, 2024
CVE-2024-23467
9.6 CRITICAL

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform remote code …

Jul 17, 2024
CVE-2024-23466
9.6 CRITICAL

SolarWinds Access Rights Manager (ARM) is susceptible to a Directory Traversal Remote Code Execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to perform …

Jul 17, 2024
CVE-2024-23465
8.3 HIGH

The SolarWinds Access Rights Manager was found to be susceptible to an authentication bypass vulnerability. This vulnerability allows an unauthenticated user to gain domain admin …

Jul 17, 2024
CVE-2023-7272
8.6 HIGH

In Eclipse Parsson before 1.0.4 and 1.1.3, a document with a large depth of nested objects can allow an attacker to cause a Java stack …

Jul 17, 2024
CVE-2024-6765

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 17, 2024
CVE-2024-5471
8.8 HIGH

Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to agent takeover vulnerability due to the hard-coded sensitive keys.

Jul 17, 2024
CVE-2024-27311
5.5 MEDIUM

Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to directory traversal vulnerability which allows the user to upload new files to the server …

Jul 17, 2024
CVE-2024-31411
8.8 HIGH

Unrestricted Upload of File with dangerous type vulnerability in Apache StreamPipes. Such a dangerous type might be an executable file that may lead to a …

Jul 17, 2024
CVE-2024-40617
6.5 MEDIUM

Path traversal vulnerability exists in FUJITSU Network Edgiot GW1500 (M2M-GW for FENICS). If a remote authenticated attacker with User Class privilege sends a specially crafted …

Jul 17, 2024
CVE-2024-36491
9.8 CRITICAL

FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allow an administrative user to execute an arbitrary OS command, obtain …

Jul 17, 2024
CVE-2024-36475
8.8 HIGH

FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. contain an active debug code vulnerability. If a user who knows …

Jul 17, 2024
CVE-2024-31979
4.3 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Apache StreamPipes during installation process of pipeline elements. Previously, StreamPipes allowed users to configure custom endpoints from which to …

Jul 17, 2024
CVE-2024-31070
9.1 CRITICAL

Initialization of a resource with an insecure default vulnerability in FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allows …

Jul 17, 2024
CVE-2024-30471
3.7 LOW

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache StreamPipes in user self-registration. This allows an attacker to potentially request the creation of multiple accounts with …

Jul 17, 2024
CVE-2024-29737
4.7 MEDIUM

In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, …

Jul 17, 2024
CVE-2023-52291
4.7 MEDIUM

In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, …

Jul 17, 2024
CVE-2024-6220
9.8 CRITICAL

The 简数采集器 (Keydatas) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the keydatas_downloadImages function in all versions …

Jul 17, 2024
CVE-2024-5703
4.3 MEDIUM

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized API access due …

Jul 17, 2024
CVE-2024-5582
6.4 MEDIUM

The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' attribute within the …

Jul 17, 2024
CVE-2024-39877
8.8 HIGH

Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that could …

Jul 17, 2024
CVE-2024-39863
5.4 MEDIUM

Apache Airflow versions before 2.9.3 have a vulnerability that allows an authenticated attacker to inject a malicious link when installing a provider. Users are recommended …

Jul 17, 2024
CVE-2024-6669
5.5 MEDIUM

The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and …

Jul 17, 2024
CVE-2024-6660
8.8 HIGH

The BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to …

Jul 17, 2024
CVE-2024-6467
8.8 HIGH

The BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin plugin for WordPress is vulnerable to Arbitrary File Read to Arbitrary File Creation in …

Jul 17, 2024
CVE-2024-6033
4.3 MEDIUM

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized data importation due to a missing capability check on …

Jul 17, 2024
CVE-2024-5255
6.4 MEDIUM

The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_dual_color shortcode in all versions up to, and …

Jul 17, 2024
CVE-2024-5254
6.4 MEDIUM

The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_info_banner shortcode in all versions up to, and …

Jul 17, 2024
CVE-2024-5253
6.4 MEDIUM

The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ult_team shortcode in all versions up to, and …

Jul 17, 2024
CVE-2024-5252
6.4 MEDIUM

The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_info_table shortcode in all versions up to, and …

Jul 17, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.