CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-3770
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Student Record System 3.20 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Apr 15, 2024
CVE-2024-2858
4.8 MEDIUM

The Simple Buttons Creator WordPress plugin through 1.04 does not have CSRF checks in some places, which could allow attackers to make logged in users …

Apr 15, 2024
CVE-2024-2857
6.1 MEDIUM

The Simple Buttons Creator WordPress plugin through 1.04 does not have any authorisation as well as CSRF in its add button function, allowing unauthenticated users …

Apr 15, 2024
CVE-2024-2836
4.8 MEDIUM

The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.64 does not sanitise and escape some of its settings, which could allow …

Apr 15, 2024
CVE-2024-2739
8.7 HIGH

The Advanced Search WordPress plugin through 1.1.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

Apr 15, 2024
CVE-2024-1849
5.4 MEDIUM

The WP Customer Reviews WordPress plugin before 3.7.1 does not validate a parameter allowing contributor and above users to redirect a page to a malicious …

Apr 15, 2024
CVE-2024-1846
5.4 MEDIUM

The Responsive Tabs WordPress plugin before 4.0.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Apr 15, 2024
CVE-2024-1755
8.8 HIGH

The NPS computy WordPress plugin through 2.7.5 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

Apr 15, 2024
CVE-2024-1754
4.7 MEDIUM

The NPS computy WordPress plugin through 2.7.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Apr 15, 2024
CVE-2024-1746
5.4 MEDIUM

The Testimonial Slider WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Apr 15, 2024
CVE-2024-1712
4.7 MEDIUM

The Carousel Slider WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Apr 15, 2024
CVE-2024-1660
4.8 MEDIUM

The Top Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Apr 15, 2024
CVE-2024-1310
4.9 MEDIUM

The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. …

Apr 15, 2024
CVE-2024-1307
6.5 MEDIUM

The Smart Forms WordPress plugin before 2.6.94 does not have proper authorization in some actions, which could allow users with a role as low as …

Apr 15, 2024
CVE-2024-1306
5.4 MEDIUM

The Smart Forms WordPress plugin before 2.6.94 does not have CSRF checks in some places, which could allow attackers to make logged-in users perform unwanted …

Apr 15, 2024
CVE-2024-1204
4.3 MEDIUM

The Meta Box WordPress plugin before 5.9.4 does not prevent users with at least the contributor role from access arbitrary custom fields assigned to other …

Apr 15, 2024
CVE-2024-0902
4.8 MEDIUM

The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Apr 15, 2024
CVE-2024-0399
8.1 HIGH

The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to …

Apr 15, 2024
CVE-2023-7201
6.5 MEDIUM

The Everest Backup WordPress plugin before 2.2.5 does not properly validate backup files to be uploaded, allowing high privilege users such as admin to upload …

Apr 15, 2024
CVE-2023-6067
5.4 MEDIUM

The WP User Profile Avatar WordPress plugin through 1.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a …

Apr 15, 2024
CVE-2024-3778
7.2 HIGH

The file upload functionality of Ai3 QbiBot does not properly restrict types of uploaded files, allowing remote attackers with administrator privilege to upload files with …

Apr 15, 2024
CVE-2024-3777
9.8 CRITICAL

The password reset feature of Ai3 QbiBot lacks proper access control, allowing unauthenticated remote attackers to reset any user's password.

Apr 15, 2024
CVE-2024-3776
6.1 MEDIUM

The parameter used in the login page of Netvision airPASS is not properly filtered for user input. An unauthenticated remote attacker can insert JavaScript code …

Apr 15, 2024
CVE-2024-3775
5.3 MEDIUM

aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not properly restrict user input. This allows attackers to pass arbitrary arguments to youtube-dl.exe, leading …

Apr 15, 2024
CVE-2024-3769
7.3 HIGH

A vulnerability, which was classified as critical, was found in PHPGurukul Student Record System 3.20. Affected is an unknown function of the file /login.php. The …

Apr 15, 2024
CVE-2024-3768
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul/itsourcecode News Portal 4.1. This issue affects some unknown processing of the file search.php. …

Apr 15, 2024
CVE-2024-3767
6.3 MEDIUM

A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. This vulnerability affects unknown code of the file /admin/edit-post.php. The manipulation of the …

Apr 15, 2024
CVE-2024-1655
8.8 HIGH

Certain ASUS WiFi routers models has an OS Command Injection vulnerability, allowing an authenticated remote attacker to execute arbitrary system commands by sending a specially …

Apr 15, 2024
CVE-2024-3774
5.3 MEDIUM

aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restrictions on a specific parameter, allowing attackers to modify this parameter to …

Apr 15, 2024
CVE-2024-3772
5.9 MEDIUM

Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string.

Apr 15, 2024
CVE-2024-3766
2.4 LOW

A vulnerability, which was classified as problematic, has been found in slowlyo OwlAdmin up to 3.5.7. Affected by this issue is some unknown functionality of …

Apr 15, 2024
CVE-2024-29844
9.8 CRITICAL

Default credentials on the Web Interface of Evolution Controller 2.x allows anyone to log in to the server directly to perform administrative functions. Upon installation …

Apr 15, 2024
CVE-2024-29843
7.5 HIGH

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on MOBILE_GET_USERS_LIST, allowing for an unauthenticated attacker to enumerate all …

Apr 15, 2024
CVE-2024-29842
7.5 HIGH

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_ABACARD_FIELDS, allowing for an unauthenticated attacker to return the …

Apr 15, 2024
CVE-2024-29841
7.5 HIGH

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_KEYS_FIELDS, allowing for an unauthenticated attacker to return the …

Apr 15, 2024
CVE-2024-29840
7.5 HIGH

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_PIN_FIELDS, allowing for an unauthenticated attacker to return the …

Apr 15, 2024
CVE-2024-29839
7.5 HIGH

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_CARD, allowing for an unauthenticated attacker to return the …

Apr 15, 2024
CVE-2024-29838
7.5 HIGH

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below does not proper sanitize user input, allowing for an unauthenticated attacker to crash the controller …

Apr 15, 2024
CVE-2024-29837
8.8 HIGH

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing for an unauthenticated attacker to access administrator functionality if any …

Apr 15, 2024
CVE-2024-29836
9.8 CRITICAL

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control, allowing for an unauthenticated attacker to update and add user …

Apr 15, 2024
CVE-2024-3765
9.8 CRITICAL

A vulnerability classified as critical was found in Xiongmai AHB7804R-MH-V2, AHB8004T-GL, AHB8008T-GL, AHB7004T-GS-V3, AHB7004T-MHV2, AHB8032F-LME and XM530_R80X30-PQ_8M. Affected by this vulnerability is an unknown functionality …

Apr 14, 2024
CVE-2024-3764
2.7 LOW

** DISPUTED ** A vulnerability classified as problematic has been found in Tuya SDK up to 5.0.x. Affected is an unknown function of the component …

Apr 14, 2024
CVE-2024-3763
2.4 LOW

A vulnerability was found in Emlog Pro 2.2.10. It has been rated as problematic. This issue affects some unknown processing of the file /admin/tag.php of …

Apr 14, 2024
CVE-2024-27462

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Apr 14, 2024
CVE-2024-3762
2.4 LOW

A vulnerability was found in Emlog Pro 2.2.10. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/twitter.php of the …

Apr 14, 2024
CVE-2024-24863

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. CVE-2024-24863 has been replaced by CVE-2024-36014.

Apr 14, 2024
CVE-2024-24862

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Apr 14, 2024
CVE-2024-3740
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in cym1102 nginxWebUI up to 3.9.9. This issue affects the function exec of the file …

Apr 13, 2024
CVE-2024-3739
6.3 MEDIUM

A vulnerability classified as critical was found in cym1102 nginxWebUI up to 3.9.9. This vulnerability affects unknown code of the file /adminPage/main/upload. The manipulation of …

Apr 13, 2024
CVE-2024-3738
7.3 HIGH

A vulnerability classified as critical has been found in cym1102 nginxWebUI up to 3.9.9. This affects the function handlePath of the file /adminPage/conf/saveCmd. The manipulation …

Apr 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.