CVE Database

38893+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-47977
7.1 HIGH

Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in …

Dec 10, 2024
CVE-2024-47484
8.2 HIGH

Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in …

Dec 10, 2024
CVE-2024-10959
7.3 HIGH

The The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to arbitrary shortcode execution via woot_get_smth AJAX action …

Dec 10, 2024
CVE-2024-47946
7.2 HIGH

If the attacker has access to a valid Poweruser session, remote code execution is possible because specially crafted valid PNG files with injected PHP content …

Dec 10, 2024
CVE-2024-28138
7.3 HIGH

An unauthenticated attacker with network access to the affected device's web interface can execute any system command via the "msg_events.php" script as the www-data user. …

Dec 10, 2024
CVE-2023-6947
7.7 HIGH

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.26. This makes …

Dec 10, 2024
CVE-2024-21542
8.6 HIGH

Versions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due to improper destination file path validation …

Dec 10, 2024
CVE-2024-11205
8.5 HIGH

The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpforms_is_admin_page' function in versions starting …

Dec 10, 2024
CVE-2024-37144
8.2 HIGH

Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior …

Dec 10, 2024
CVE-2024-53919
7.6 HIGH

An injection vulnerability in Barco ClickShare CX-30/20, C-5/10, and ClickShare Bar Pro and Core models, running firmware before 2.21.1, allows physically proximate attackers or local …

Dec 10, 2024
CVE-2024-54198
8.5 HIGH

In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can …

Dec 10, 2024
CVE-2024-54197
7.2 HIGH

SAP NetWeaver Administrator(System Overview) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation …

Dec 10, 2024
CVE-2024-55634
8.1 HIGH

A vulnerability in Drupal Core allows Privilege Escalation.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.

Dec 10, 2024
CVE-2024-50628
8.8 HIGH

An issue was discovered in the web services of Digi ConnectPort LTS before 1.4.12. It allows an attacker on the local area network to achieve …

Dec 9, 2024
CVE-2024-50627
8.8 HIGH

An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Privilege Escalation vulnerability exists in the file upload feature. It allows an attacker on …

Dec 9, 2024
CVE-2024-50626
8.8 HIGH

An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Directory Traversal vulnerability exists in WebFS. This allows an attacker on the local area …

Dec 9, 2024
CVE-2024-50625
8.0 HIGH

An issue was discovered in Digi ConnectPort LTS before 1.4.12. A vulnerability in the file upload handling of a web application allows manipulation of file …

Dec 9, 2024
CVE-2024-54151
7.5 HIGH

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 11.0.0 and prior to version 11.3.0, when setting `WEBSOCKETS_GRAPHQL_AUTH` …

Dec 9, 2024
CVE-2024-54149
8.4 HIGH

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Winter CMS prior to versions 1.2.7, 1.1.11, and 1.0.476 allow …

Dec 9, 2024
CVE-2024-54938
7.5 HIGH

A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/uploads.

Dec 9, 2024
CVE-2024-54928
7.2 HIGH

kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php,

Dec 9, 2024
CVE-2024-54927
7.2 HIGH

Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_users.php.

Dec 9, 2024
CVE-2024-46547
7.5 HIGH

A vulnerability was found in Romain Bourdon Wampserver all versions (discovered in v3.2.3 and v3.2.6) where unauthorized users could access sensitive information due to improper …

Dec 9, 2024
CVE-2024-54933
7.2 HIGH

Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php.

Dec 9, 2024
CVE-2024-54930
7.2 HIGH

Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php.

Dec 9, 2024
CVE-2024-54922
7.2 HIGH

A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized …

Dec 9, 2024
CVE-2024-11608
7.8 HIGH

A maliciously crafted SKP file, when linked or imported into Autodesk Revit, can be used to cause a Heap-based Overflow. A malicious actor can leverage …

Dec 9, 2024
CVE-2024-11454
7.8 HIGH

A maliciously crafted DLL file, when placed in the same directory as an RVT file could be loaded by Autodesk Revit, and execute arbitrary code …

Dec 9, 2024
CVE-2024-54926
8.8 HIGH

A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get …

Dec 9, 2024
CVE-2024-53450
7.5 HIGH

RAGFlow 0.13.0 suffers from improper access control in document-hooks.ts, allowing unauthorized access to user documents.

Dec 9, 2024
CVE-2024-40582
7.5 HIGH

Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.

Dec 9, 2024
CVE-2024-49600
7.8 HIGH

Dell Power Manager (DPM), versions prior to 3.17, contain an improper access control vulnerability. A low privileged attacker with local access could potentially exploit this …

Dec 9, 2024
CVE-2024-54929
7.2 HIGH

KASHIPARA E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_subject.php.

Dec 9, 2024
CVE-2024-54226
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in karlkiesinger Country Blocker country-blocker allows Stored XSS.This issue affects Country Blocker: from n/a through <= 3.2.

Dec 9, 2024
CVE-2024-54225
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in codegearthemes Designer designer allows PHP Local File Inclusion.This issue …

Dec 9, 2024
CVE-2024-54220
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in roninwp FAT Services Booking fat-services-booking allows Stored XSS.This issue affects FAT Services Booking: …

Dec 9, 2024
CVE-2024-54219
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thehp AIO Contact aio-contact.This issue affects AIO Contact: from n/a through <= 2.8.1.

Dec 9, 2024
CVE-2024-53790
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ogun Labs Lenxel Core for Lenxel(LNX) LMS lenxel-core allows PHP Local File …

Dec 9, 2024
CVE-2023-51355
8.2 HIGH

Missing Authorization vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MultiVendorX: from n/a through <= 4.0.23.

Dec 9, 2024
CVE-2023-49856
8.1 HIGH

Missing Authorization vulnerability in EDGARROJAS Smart Forms smart-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Forms: from n/a through <= 2.6.84.

Dec 9, 2024
CVE-2023-49831
7.5 HIGH

Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RegistrationMagic: from n/a through <= 5.2.3.0.

Dec 9, 2024
CVE-2023-49817
8.2 HIGH

Missing Authorization vulnerability in heoLixfy Flexible Woocommerce Checkout Field Editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flexible Woocommerce Checkout Field Editor: …

Dec 9, 2024
CVE-2023-49158
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Binh Nguyen LadiApp ladipage allows Stored XSS.This issue affects LadiApp: from n/a through …

Dec 9, 2024
CVE-2023-48286
8.2 HIGH

Missing Authorization vulnerability in mra13 Stripe Payments stripe-payments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stripe Payments: from n/a through <= 2.0.79.

Dec 9, 2024
CVE-2023-47698
8.6 HIGH

Missing Authorization vulnerability in shohei.tanaka Japanized For WooCommerce woocommerce-for-japan allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Japanized For WooCommerce: from n/a through …

Dec 9, 2024
CVE-2023-25714
7.5 HIGH

Missing Authorization vulnerability in Fullworks Quick Paypal Payments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Paypal Payments: from n/a through 5.7.25.

Dec 9, 2024
CVE-2023-22701
7.5 HIGH

Missing Authorization vulnerability in Shopfiles Ltd Ebook Store allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ebook Store: from n/a through 5.775.

Dec 9, 2024
CVE-2024-55580
7.5 HIGH

An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. Unprivileged users with network access may be able to execute remote …

Dec 9, 2024
CVE-2024-55579
8.8 HIGH

An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. An unprivileged user with network access may be able to create …

Dec 9, 2024
CVE-2024-53473
7.5 HIGH

WeGIA 3.2.0 before 3998672 does not verify permission to change a password.

Dec 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.