CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-6743
8.8 HIGH

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, …

May 29, 2024
CVE-2024-0434
5.3 MEDIUM

The WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

May 29, 2024
CVE-2024-5204
8.8 HIGH

The Swiss Toolkit For WP plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.7. This is due to the …

May 29, 2024
CVE-2024-5150
9.8 CRITICAL

The Login with phone number plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.26. This is due to the …

May 29, 2024
CVE-2024-5437
3.5 LOW

A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as problematic. Affected is the function save_category of the file …

May 29, 2024
CVE-2024-36112
6.3 MEDIUM

Nautobot is a Network Source of Truth and Network Automation Platform. A user with permissions to view Dynamic Group records (`extras.view_dynamicgroup` permission) can use the …

May 28, 2024
CVE-2024-23580
6.5 MEDIUM

HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of One-Time Passwords (OTPs). This could allow an attacker with access to the database to …

May 28, 2024
CVE-2024-23579
6.5 MEDIUM

HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of security questions. This could allow an attacker with access to the database to recover …

May 28, 2024
CVE-2023-30314
6.5 MEDIUM

An issue discovered in 360 V6G, 360 T5G, 360 T6M, and 360 P1 routers allows attackers to hijack TCP sessions which could lead to a …

May 28, 2024
CVE-2023-30312
7.3 HIGH

An issue discovered in OpenWrt 18.06, 19.07, 21.02, 22.03, and beyond allows off-path attackers to hijack TCP sessions, which could lead to a denial of …

May 28, 2024
CVE-2024-35548
5.4 MEDIUM

A SQL injection vulnerability in Mybatis plus versions below 3.5.6 allows remote attackers to obtain database information via a Boolean blind injection. NOTE: the vendor's …

May 28, 2024
CVE-2024-35511
4.7 MEDIUM

phpgurukul Men Salon Management System v2.0 is vulnerable to SQL Injection via the "username" parameter of /msms/admin/index.php.

May 28, 2024
CVE-2024-35240
5.4 MEDIUM

Umbraco Commerce is an open source dotnet ecommerce solution. In affected versions there exists a stored Cross-site scripting (XSS) issue which would enable attackers to …

May 28, 2024
CVE-2024-35239
2.7 LOW

Umbraco Commerce is an open source dotnet web forms solution. In affected versions an authenticated user that has access to edit Forms may inject unsafe …

May 28, 2024
CVE-2024-35226
7.3 HIGH

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. In affected versions template authors could inject php code …

May 28, 2024
CVE-2024-22641
7.5 HIGH

TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file.

May 28, 2024
CVE-2024-35583
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected …

May 28, 2024
CVE-2024-35582
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected …

May 28, 2024
CVE-2024-35581
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected …

May 28, 2024
CVE-2024-35510
9.8 CRITICAL

An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute arbitrary code via uploading a crafted file.

May 28, 2024
CVE-2024-28061
6.3 MEDIUM

An issue was discovered in Apiris Kafeo 6.4.4. It permits a bypass, of the protection in place, to access to the data stored in the …

May 28, 2024
CVE-2024-28060
7.3 HIGH

An issue was discovered in Apiris Kafeo 6.4.4. It permits DLL hijacking, allowing a user to trigger the execution of arbitrary code every time the …

May 28, 2024
CVE-2023-46694
8.1 HIGH

Vtenext 21.02 allows an authenticated attacker to upload arbitrary files, potentially enabling them to execute remote commands. This flaw exists due to the application's failure …

May 28, 2024
CVE-2023-30313
7.5 HIGH

An issue discovered in Wavlink QUANTUM D2G routers allows attackers to hijack TCP sessions which could lead to a denial of service.

May 28, 2024
CVE-2023-30310
7.5 HIGH

An issue discovered in Comfast Comfast CF-616AC routers allows attackers to hijack TCP sessions which could lead to a denial of service.

May 28, 2024
CVE-2023-30309
5.7 MEDIUM

An issue discovered in D-Link DI-7003GV2 routers allows attackers to hijack TCP sessions which could lead to a denial of service.

May 28, 2024
CVE-2023-30308
6.5 MEDIUM

An issue discovered in Ruijie EG210G-P, Ruijie EG105G-V2, Ruijie NBR, and Ruijie EG105G routers allows attackers to hijack TCP sessions which could lead to a …

May 28, 2024
CVE-2023-30307
5.3 MEDIUM

An issue discovered in TP-LINK TL-R473GP-AC, TP-LINK XDR6020, TP-LINK TL-R479GP-AC, TP-LINK TL-R4239G, TP-LINK TL-WAR1200L, and TP-LINK TL-R476G routers allows attackers to hijack TCP sessions which …

May 28, 2024
CVE-2023-30306
4.3 MEDIUM

An issue discovered in Mercury x30g, Mercury YR1800XG routers allows attackers to hijack TCP sessions which could lead to a denial of service.

May 28, 2024
CVE-2022-45171
8.8 HIGH

An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Unrestricted Upload of a File with a Dangerous Type can occur under the vShare …

May 28, 2024
CVE-2024-5434

The Campbell Scientific CSI Web Server stores web authentication credentials in a file with a specific file name. Passwords within that file are stored in …

May 28, 2024
CVE-2024-5433

The Campbell Scientific CSI Web Server supports a command that will return the most recent file that matches a given expression. A specially crafted expression …

May 28, 2024
CVE-2024-36110
8.2 HIGH

ansibleguy-webui is an open source WebUI for using Ansible. Multiple forms in versions < 0.0.21 allowed injection of HTML elements. These are returned to the …

May 28, 2024
CVE-2024-36109
7.6 HIGH

CoCalc is web-based software that enables collaboration in research, teaching, and scientific publishing. In affected versions the markdown parser allows `<script>` tags to be included …

May 28, 2024
CVE-2024-36107
5.3 MEDIUM

MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. `If-Modified-Since` and `If-Unmodified-Since` headers when used with anonymous requests by …

May 28, 2024
CVE-2024-33450
7.5 HIGH

SQL Injection in Finereport v.8.0 allows a remote attacker to obtain sensitive information

May 28, 2024
CVE-2024-24919
8.6 HIGH KEV

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or …

May 28, 2024
CVE-2023-43850
6.5 MEDIUM

Improper input validation in the user management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to cause a partial …

May 28, 2024
CVE-2023-43849
6.5 MEDIUM

Incorrect access control in firmware upgrade function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to submit a firmware image …

May 28, 2024
CVE-2023-43848
8.0 HIGH

Incorrect access control in the firewall management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to alter local firewall …

May 28, 2024
CVE-2023-43847
5.3 MEDIUM

Incorrect access control in the outlet control function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to control all the …

May 28, 2024
CVE-2023-43846
5.3 MEDIUM

Incorrect access control in logs management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote attackers to get the device logs via …

May 28, 2024
CVE-2023-43845
9.8 CRITICAL

Aten PE6208 2.3.228 and 2.4.232 have default credentials for the privileged telnet account. The user is not asked to change the credentials after first login. …

May 28, 2024
CVE-2023-43844
8.0 HIGH

Aten PE6208 2.3.228 and 2.4.232 have default credentials for the privileged web interface account. The user is not asked to change the credentials after first …

May 28, 2024
CVE-2023-43843
7.3 HIGH

Incorrect access control in the account management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to read user and …

May 28, 2024
CVE-2023-43842
7.3 HIGH

Incorrect access control in the account management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to alter user and …

May 28, 2024
CVE-2023-30311
7.5 HIGH

An issue discovered in H3C Magic R365 and H3C Magic R100 routers allows attackers to hijack TCP sessions which could lead to a denial of …

May 28, 2024
CVE-2023-30305
7.5 HIGH

An issue discovered in Linksys E5600 routers allows attackers to hijack TCP sessions which could lead to a denial of service.

May 28, 2024
CVE-2024-33402
8.1 HIGH

A SQL injection vulnerability in /model/approve_petty_cash.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.

May 28, 2024
CVE-2024-35563
9.8 CRITICAL

CDG-Server-V5.6.2.126.139 and earlier was discovered to contain a SQL injection vulnerability via the permissionId parameter in CDGTempPermissions.

May 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.