CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5881
6.4 MEDIUM

The Webico Slider Flatsome Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wbc_image shortcode in all versions up to, and …

Jul 9, 2024
CVE-2024-37923
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in cliengo Cliengo – Chatbot cliengo allows Cross Site Request Forgery.This issue affects Cliengo – Chatbot: from n/a through <= …

Jul 9, 2024
CVE-2024-37555
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in ZealousWeb Generate PDF using Contact Form 7 generate-pdf-using-contact-form-7.This issue affects Generate PDF using Contact Form 7: …

Jul 9, 2024
CVE-2024-28751
9.1 CRITICAL

An high privileged remote attacker can enable telnet access that accepts hardcoded credentials.

Jul 9, 2024
CVE-2024-28750
7.2 HIGH

A remote attacker with high privileges may use a deleting file function to inject OS commands.

Jul 9, 2024
CVE-2024-28749
7.2 HIGH

A remote attacker with high privileges may use a writing file function to inject OS commands.

Jul 9, 2024
CVE-2024-28748
7.2 HIGH

A remote attacker with high privileges may use a reading file function to inject OS commands.

Jul 9, 2024
CVE-2024-28747
9.8 CRITICAL

An unauthenticated remote attacker can use the hard-coded credentials to access the SmartSPS devices with high privileges.

Jul 9, 2024
CVE-2024-22062
6.3 MEDIUM

There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permissions to administrator permissions by modifying the configuration.

Jul 9, 2024
CVE-2024-6334
6.1 MEDIUM

The Easy Table of Contents WordPress plugin before 2.0.67.1 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jul 9, 2024
CVE-2024-5802
4.8 MEDIUM

The URL Shortener by Myhop WordPress plugin through 1.0.17 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jul 9, 2024
CVE-2024-5488
9.8 CRITICAL

The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow …

Jul 9, 2024
CVE-2024-5441
8.8 HIGH

The Modern Events Calendar plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_featured_image function in all …

Jul 9, 2024
CVE-2024-3410
4.3 MEDIUM

The DN Footer Contacts WordPress plugin before 1.6.3 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jul 9, 2024
CVE-2024-6171
5.3 MEDIUM

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, …

Jul 9, 2024
CVE-2024-6170
6.4 MEDIUM

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘email’ parameter in all versions …

Jul 9, 2024
CVE-2024-6169
6.4 MEDIUM

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ parameter in all versions …

Jul 9, 2024
CVE-2024-6166
8.8 HIGH

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘addons_order’ parameter in all versions …

Jul 9, 2024
CVE-2024-4667
6.4 MEDIUM

The Blog, Posts and Category Filter for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post and Category Filter widget in …

Jul 9, 2024
CVE-2024-39600
5.0 MEDIUM

Under certain conditions, the memory of SAP GUI for Windows contains the password used to log on to an SAP system, which might allow an …

Jul 9, 2024
CVE-2024-39599
4.7 MEDIUM

Due to a Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP Platform, a developer can bypass the configured malware scanner API …

Jul 9, 2024
CVE-2024-39596
4.3 MEDIUM

Due to missing authorization checks, SAP Enable Now allows an author to escalate privileges to access information which should otherwise be restricted. On successful exploitation, …

Jul 9, 2024
CVE-2024-39595
5.4 MEDIUM

SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user-controlled inputs, resulting in Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability allows …

Jul 9, 2024
CVE-2024-39594
6.1 MEDIUM

SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user controlled inputs, resulting in Reflected Cross-Site Scripting (XSS) vulnerability. After successful …

Jul 9, 2024
CVE-2024-37180
4.1 MEDIUM

Under certain conditions SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to access remote-enabled function module with no further authorization which …

Jul 9, 2024
CVE-2024-37175
4.3 MEDIUM

SAP CRM WebClient does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to access …

Jul 9, 2024
CVE-2024-37172
5.4 MEDIUM

SAP S/4HANA Finance (Advanced Payment Management) does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. As a result, it …

Jul 9, 2024
CVE-2024-37171
5.0 MEDIUM

SAP Transportation Management (Collaboration Portal) allows an attacker with non-administrative privileges to send a crafted request from a vulnerable web application. This will trigger the …

Jul 9, 2024
CVE-2024-34692
3.3 LOW

Due to missing verification of file type or content, SAP Enable Now allows an authenticated attacker to upload arbitrary files. These files include executables which …

Jul 9, 2024
CVE-2024-34689
5.0 MEDIUM

WebFlow Services of SAP Business Workflow allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On …

Jul 9, 2024
CVE-2024-6365
9.8 CRITICAL

The Product Table by WBW plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.1 via the 'saveCustomTitle' …

Jul 9, 2024
CVE-2024-39598
5.0 MEDIUM

SAP CRM (WebClient UI Framework) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful …

Jul 9, 2024
CVE-2024-39597
7.2 HIGH

In SAP Commerce, a user can misuse the forgotten password functionality to gain access to a Composable Storefront B2B site for which early login and …

Jul 9, 2024
CVE-2024-39593
6.9 MEDIUM

SAP Landscape Management allows an authenticated user to read confidential data disclosed by the REST Provider Definition response. Successful exploitation can cause high impact on …

Jul 9, 2024
CVE-2024-39592
7.7 HIGH

Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This allows an attacker to read sensitive …

Jul 9, 2024
CVE-2024-37174
6.1 MEDIUM

Custom CSS support option in SAP CRM WebClient UI does not sufficiently encode user-controlled inputs resulting in Cross-Site Scripting vulnerability. On successful exploitation an attacker …

Jul 9, 2024
CVE-2024-37173
6.1 MEDIUM

Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script. When a …

Jul 9, 2024
CVE-2024-34685
6.1 MEDIUM

Due to weak encoding of user-controlled input in SAP NetWeaver Knowledge Management XMLEditor which allows malicious scripts can be executed in the application, potentially leading …

Jul 9, 2024
CVE-2024-5974
7.2 HIGH

A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges …

Jul 9, 2024
CVE-2024-4944
7.8 HIGH

A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated …

Jul 9, 2024
CVE-2024-5855
4.3 MEDIUM

The Media Hygiene: Remove or Delete Unused Images and More! plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability …

Jul 9, 2024
CVE-2024-5793
8.8 HIGH

The Houzez Theme - Functionality plugin for WordPress is vulnerable to SQL Injection via the ‘currency_code’ parameter in all versions up to, and including, 3.2.2 …

Jul 9, 2024
CVE-2024-34786
4.8 MEDIUM

UniFi iOS app 10.15.0 introduces a misconfiguration on 2nd Generation UniFi Access Points configured as standalone (not using UniFi Network Application) that could cause the …

Jul 9, 2024
CVE-2024-22020
6.5 MEDIUM

A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URLs, an attacker can execute arbitrary code, …

Jul 9, 2024
CVE-2024-5569
6.2 MEDIUM

A Denial of Service (DoS) vulnerability exists in the jaraco/zipp library, affecting all versions prior to 3.19.1. The vulnerability is triggered when processing a specially …

Jul 9, 2024
CVE-2024-5549
8.1 HIGH

A CORS misconfiguration in the stitionai/devika repository allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from …

Jul 9, 2024
CVE-2024-3653
5.3 MEDIUM

A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the maxAge …

Jul 8, 2024
CVE-2024-28882
4.3 MEDIUM

OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session

Jul 8, 2024
CVE-2024-5971
7.5 HIGH

A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the …

Jul 8, 2024
CVE-2024-38372
2.0 LOW

Undici is an HTTP/1.1 client, written from scratch for Node.js. Depending on network and process conditions of a `fetch()` request, `response.arrayBuffer()` might include portion of …

Jul 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.