CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-37504
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team FileBird Document Library.This issue affects FileBird Document Library: from n/a through 2.0.6.

Jul 10, 2024
CVE-2024-37498
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pauple Table & Contact Form 7 Database – Tablesome.This issue affects Table & Contact Form …

Jul 10, 2024
CVE-2024-37270
5.3 MEDIUM

Insertion of Sensitive Information into Log File vulnerability in TrustedLogin TrustedLogin Vendor.This issue affects TrustedLogin Vendor: from n/a before 1.1.1.

Jul 10, 2024
CVE-2024-37205
5.3 MEDIUM

Insertion of Sensitive Information into Log File vulnerability in SERVIT Software Solutions.This issue affects affiliate-toolkit: from n/a through 3.4.4.

Jul 10, 2024
CVE-2024-37115
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Automattic Newspack Blocks.This issue affects Newspack Blocks: from n/a through 3.0.8.

Jul 10, 2024
CVE-2024-37113
9.8 CRITICAL

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7.

Jul 10, 2024
CVE-2024-37110
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7.

Jul 10, 2024
CVE-2024-32759

Under certain circumstances the Software House C●CURE 9000 installer will utilize weak credentials.

Jul 10, 2024
CVE-2024-6645
6.3 MEDIUM

A vulnerability was found in WuKongOpenSource Wukong_nocode up to 20230807. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jul 10, 2024
CVE-2024-6644
6.3 MEDIUM

A vulnerability was found in zmops ArgusDBM up to 0.1.0. It has been classified as critical. Affected is the function getDefaultClassLoader of the file CalculateAlarm.java …

Jul 10, 2024
CVE-2024-5217
9.8 CRITICAL KEV

ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an …

Jul 10, 2024
CVE-2024-5178
4.9 MEDIUM

ServiceNow has addressed a sensitive file read vulnerability that was identified in the Washington DC, Vancouver, and Utah Now Platform releases. This vulnerability could allow …

Jul 10, 2024
CVE-2024-4879
9.8 CRITICAL KEV

ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user …

Jul 10, 2024
CVE-2024-3325
7.2 HIGH

Vulnerability in Jaspersoft JasperReport Servers.This issue affects JasperReport Servers: from 8.0.4 through 9.0.0.

Jul 10, 2024
CVE-2024-40417
6.5 MEDIUM

A vulnerability was found in Tenda AX1806 1.0.0.1. Affected by this issue is the function formSetRebootTimer of the file /goform/SetIpMacBind. The manipulation of the argument …

Jul 10, 2024
CVE-2024-40412
6.8 MEDIUM

Tenda AX12 v1.0 v22.03.01.46 contains a stack overflow in the deviceList parameter of the sub_42E410 function.

Jul 10, 2024
CVE-2024-20456
6.7 MEDIUM

A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Cisco Secure …

Jul 10, 2024
CVE-2023-35006
5.4 MEDIUM

IBM Security QRadar EDR 3.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in …

Jul 10, 2024
CVE-2023-33860
5.3 MEDIUM

IBM Security QRadar EDR 3.12 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie …

Jul 10, 2024
CVE-2023-33859
5.3 MEDIUM

IBM Security QRadar EDR 3.12 could disclose sensitive information due to an observable login response discrepancy. IBM X-Force ID: 257697.

Jul 10, 2024
CVE-2024-40336
6.1 MEDIUM

idccms v1.35 is vulnerable to Cross Site Scripting (XSS) within the 'Image Advertising Management.'

Jul 10, 2024
CVE-2024-40332
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/moneyRecord_deal.php?mudi=delRecord

Jul 10, 2024
CVE-2024-40331
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/dbBakMySQL_deal.php?mudi=backup

Jul 10, 2024
CVE-2024-6642

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

Jul 10, 2024
CVE-2024-40334
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/serverFile_deal.php?mudi=upFileDel&dataID=3

Jul 10, 2024
CVE-2024-40333
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mudi=del&dataID=2

Jul 10, 2024
CVE-2024-40329
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mudi=backup

Jul 10, 2024
CVE-2024-40328
6.3 MEDIUM

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/memberOnline_deal.php?mudi=del&dataType=&dataID=6

Jul 10, 2024
CVE-2024-28828
8.8 HIGH

Cross-Site request forgery in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) could lead to 1-click compromize of the site.

Jul 10, 2024
CVE-2024-28827
8.8 HIGH

Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) allows a local attacker …

Jul 10, 2024
CVE-2024-3799

Insecure handling of POST header parameter body included in requests being sent to an instance of the open-source project Phoniebox allows an attacker to create …

Jul 10, 2024
CVE-2024-3798

Insecure handling of GET header parameter file included in requests being sent to an instance of the open-source project Phoniebox allows an attacker to create …

Jul 10, 2024
CVE-2024-6556
5.3 MEDIUM

The SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, …

Jul 10, 2024
CVE-2024-6422
9.8 CRITICAL

An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data.

Jul 10, 2024
CVE-2024-6421
7.5 HIGH

An unauthenticated remote attacker can read out sensitive device information through a incorrectly configured FTP service.

Jul 10, 2024
CVE-2024-5664
6.4 MEDIUM

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' …

Jul 10, 2024
CVE-2024-39493
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: qat - Fix ADF_DEV_RESET_SYNC memory leak Using completion_done to determine whether the caller has …

Jul 10, 2024
CVE-2024-39492
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: mailbox: mtk-cmdq: Fix pm_runtime_get_sync() warning in mbox shutdown The return value of pm_runtime_get_sync() in cmdq_mbox_shutdown() …

Jul 10, 2024
CVE-2024-39491
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: cs35l56: Fix lifetime of cs_dsp instance The cs_dsp instance is initialized in the …

Jul 10, 2024
CVE-2024-39490
6.2 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix missing sk_buff release in seg6_input_core The seg6_input() function is responsible for adding …

Jul 10, 2024
CVE-2024-39489
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix memleak in seg6_hmac_init_algo seg6_hmac_init_algo returns without cleaning up the previous allocations if …

Jul 10, 2024
CVE-2024-39488
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: arm64: asm-bug: Add .align 2 to the end of __BUG_ENTRY When CONFIG_DEBUG_BUGVERBOSE=n, we fail to …

Jul 10, 2024
CVE-2023-6813
6.1 MEDIUM

The Login by Auth0 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wle’ parameter in all versions up to, and including, 4.6.0 …

Jul 10, 2024
CVE-2024-39927
8.2 HIGH

Out-of-bounds write vulnerability exists in Ricoh MFPs and printers. If a remote attacker sends a specially crafted request to the affected products, the products may …

Jul 10, 2024
CVE-2024-39886
3.7 LOW

TONE store App version 3.4.2 and earlier contains an issue with unprotected primary channel. Since TONE store App communicates with TONE store website in cleartext, …

Jul 10, 2024
CVE-2024-36453
6.1 MEDIUM

Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions prior to 1.820. If this vulnerability is exploited, an arbitrary …

Jul 10, 2024
CVE-2024-36452
3.1 LOW

Cross-site request forgery vulnerability exists in ajaxterm module of Webmin versions prior to 2.003. If this vulnerability is exploited, unintended operations may be performed when …

Jul 10, 2024
CVE-2024-36451
8.8 HIGH

Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003. If this vulnerability is exploited, a console session …

Jul 10, 2024
CVE-2024-36450
5.4 MEDIUM

Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exploited, an arbitrary script may be executed on the …

Jul 10, 2024
CVE-2024-6411
8.8 HIGH

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.8.9. This …

Jul 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.