CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-39943
9.9 CRITICAL

rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have …

Jul 4, 2024
CVE-2024-39937
8.6 HIGH

supOS 5.0 allows api/image/download?fileName=../ directory traversal for reading files.

Jul 4, 2024
CVE-2024-39936
8.6 HIGH

An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code …

Jul 4, 2024
CVE-2024-39935
8.8 HIGH

jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated user (with certificate management privileges) via untrusted input to the DNS …

Jul 4, 2024
CVE-2024-6511
3.5 LOW

A vulnerability classified as problematic was found in y_project RuoYi up to 4.7.9. Affected by this vulnerability is the function isJsonRequest of the component Content-Type …

Jul 4, 2024
CVE-2024-39934
7.8 HIGH

Robotmk before 2.0.1 allows a local user to escalate privileges (e.g., to SYSTEM) if automated Python environment setup is enabled, because the "shared holotree usage" …

Jul 4, 2024
CVE-2024-37474
6.5 MEDIUM

Cross Site Scripting (XSS) vulnerability in Automattic Newspack Ads allows Stored XSS.This issue affects Newspack Ads: from n/a through 1.47.1.

Jul 4, 2024
CVE-2024-37472
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WofficeIO Woffice woffice.This issue affects Woffice: from n/a through <= 5.4.8.

Jul 4, 2024
CVE-2024-37471
7.1 HIGH

Cross Site Scripting (XSS) vulnerability in WofficeIO Woffice Core allows Reflected XSS.This issue affects Woffice Core: from n/a through 5.4.8.

Jul 4, 2024
CVE-2024-37476
6.5 MEDIUM

Cross Site Scripting (XSS) vulnerability in Automattic Newspack Campaigns allows Stored XSS.This issue affects Newspack Campaigns: from n/a through 2.31.1.

Jul 4, 2024
CVE-2024-6513

Rejected reason: CVE assigned by mistake as a duplicate.

Jul 4, 2024
CVE-2024-39933
7.7 HIGH

Gogs through 0.13.0 allows argument injection during the tagging of a new release.

Jul 4, 2024
CVE-2024-39932
9.9 CRITICAL

Gogs through 0.13.0 allows argument injection during the previewing of changes.

Jul 4, 2024
CVE-2024-39931
9.9 CRITICAL

Gogs through 0.13.0 allows deletion of internal files.

Jul 4, 2024
CVE-2024-39930
9.9 CRITICAL

The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attackers can exploit this by opening …

Jul 4, 2024
CVE-2024-39929
5.4 MEDIUM

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable …

Jul 4, 2024
CVE-2024-22277
6.4 MEDIUM

VMware Cloud Director Availability contains an HTML injection vulnerability. A malicious actor with network access to VMware Cloud Director Availability can craft malicious HTML tags …

Jul 4, 2024
CVE-2024-6506
8.2 HIGH

Information exposure vulnerability in the MRW plugin, in its 5.4.3 version, affecting the "mrw_log" functionality. This vulnerability could allow a remote attacker to obtain other …

Jul 4, 2024
CVE-2024-39211
5.3 MEDIUM

Kaiten 57.128.8 allows remote attackers to enumerate user accounts via a crafted POST request, because a login response contains a user_email field only if the …

Jul 4, 2024
CVE-2024-39165
9.8 CRITICAL

QR/demoapp/qr_image.php in Asial JpGraph Professional through 4.2.6-pro allows remote attackers to execute arbitrary code via a PHP payload in the data parameter in conjunction with …

Jul 4, 2024
CVE-2024-6507
8.1 HIGH

Command injection when ingesting a remote Kaggle dataset due to a lack of input sanitization in the ingest_kaggle() API

Jul 4, 2024
CVE-2024-5943
8.8 HIGH

The Nested Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.7. This is due to missing …

Jul 4, 2024
CVE-2024-32754
3.1 LOW

Under certain circumstances, when the controller is in factory reset mode waiting for initial setup, it will broadcast its MAC address, serial number, and firmware …

Jul 4, 2024
CVE-2024-6434
3.1 LOW

The Premium Addons for Elementor plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in all versions up to, and including, 4.10.35. …

Jul 4, 2024
CVE-2024-6319
8.8 HIGH

The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload' function in all versions up …

Jul 4, 2024
CVE-2024-6318
8.8 HIGH

The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_img_file' function in all versions up …

Jul 4, 2024
CVE-2024-3904
8.8 HIGH

Incorrect Default Permissions vulnerability in Smart Device Communication Gateway preinstalled on MELIPC Series MI5122-VW firmware versions "05" to "07" allows a local attacker to execute …

Jul 4, 2024
CVE-2024-39884
6.2 MEDIUM

A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, …

Jul 4, 2024
CVE-2024-1574
6.7 MEDIUM

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in the licensing feature of Mitsubishi Electric GENESIS64 versions 10.97.2 and prior, Mitsubishi …

Jul 4, 2024
CVE-2024-1573
5.9 MEDIUM

Missing Authentication for Critical Function vulnerability in the mobile monitoring feature of Mitsubishi Electric GENESIS64 versions 10.97.2 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.2 …

Jul 4, 2024
CVE-2024-1182
7.0 HIGH

Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian …

Jul 4, 2024
CVE-2024-5641
6.4 MEDIUM

The One Click Order Re-Order plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ced_ocor_save_general_setting' function …

Jul 4, 2024
CVE-2024-3639
6.4 MEDIUM

The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Posts Grid widget in all versions up to, …

Jul 4, 2024
CVE-2024-3638
6.4 MEDIUM

The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Marquee Text Widget, Testimonials Widget, and Testimonial Slider …

Jul 4, 2024
CVE-2024-2926
6.4 MEDIUM

The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, …

Jul 4, 2024
CVE-2024-2385
8.8 HIGH

The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.4 via several of …

Jul 4, 2024
CVE-2024-38471
6.8 MEDIUM

Multiple TP-LINK products allow a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by restoring a crafted backup file. The affected device, …

Jul 4, 2024
CVE-2024-38345
8.1 HIGH

A cross-site request forgery vulnerability exists in Sola Testimonials versions prior to 3.0.0. If this vulnerability is exploited, an attacker allows a user who logs …

Jul 4, 2024
CVE-2024-38344
5.4 MEDIUM

A cross-site request forgery vulnerability exists in WP Tweet Walls versions prior to 1.0.4. If this vulnerability is exploited, an attacker allows a user who …

Jul 4, 2024
CVE-2024-6284
7.3 HIGH

In https://github.com/google/nftables IP addresses were encoded in the wrong byte order, resulting in an nftables configuration which does not work as intended (might block or …

Jul 3, 2024
CVE-2024-6383
5.3 MEDIUM

The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow where the function might attempt to allocate too small of buffer …

Jul 3, 2024
CVE-2024-6464

Rejected reason: **REJECT** This is a duplicate CVE issued in error on a framework vulnerability. Please use CVE-2024-5324 instead.

Jul 3, 2024
CVE-2024-6463

Rejected reason: **REJECT** This is a duplicate CVE issued in error on a framework vulnerability. Please use CVE-2024-5324 instead.

Jul 3, 2024
CVE-2024-6461

Rejected reason: **REJECT** This is a duplicate CVE issued in error on a framework vulnerability. Please use CVE-2024-5324 instead.

Jul 3, 2024
CVE-2024-39683
5.7 MEDIUM

ZITADEL is an open-source identity infrastructure tool. ZITADEL provides users the ability to list all user sessions of the current user agent (browser). Starting in …

Jul 3, 2024
CVE-2024-37157
6.4 MEDIUM

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passed` branches, a malicious …

Jul 3, 2024
CVE-2024-36122
2.4 LOW

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passed` branches, moderators using …

Jul 3, 2024
CVE-2024-34750
7.5 HIGH

Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive …

Jul 3, 2024
CVE-2024-6488

Rejected reason: This is REJECTED.

Jul 3, 2024
CVE-2024-36113
4.9 MEDIUM

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch, version 3.3.0.beta3 on the `beta` branch, and version 3.3.0.beta4-dev on the …

Jul 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.