CVE Database

38893+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-50544
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MicahBlu RSVP ME rsvp-me allows SQL Injection.This issue affects RSVP ME: …

Nov 9, 2024
CVE-2024-50539
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in lodgix Lodgix.com Vacation Rental Website Builder lodgixcom-vacation-rental-listing-management-booking-plugin allows SQL Injection.This issue …

Nov 9, 2024
CVE-2024-50524
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Quý Lê 91 Administrator Z administrator-z allows Blind SQL Injection.This issue …

Nov 9, 2024
CVE-2024-10676
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wojciechborowicz Conversion Helper conversion-helper allows Reflected XSS.This issue affects Conversion Helper: from n/a …

Nov 9, 2024
CVE-2024-51784
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VietFriend team FriendStore for WooCommerce friendstore-for-woocommerce allows Reflected XSS.This issue affects FriendStore for …

Nov 9, 2024
CVE-2024-51783
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zaus Forms: 3rd-Party Post Again forms-3rdparty-post-again allows Reflected XSS.This issue affects Forms: 3rd-Party …

Nov 9, 2024
CVE-2024-51782
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sanjay Prasad Loginplus loginplus allows Stored XSS.This issue affects Loginplus: from n/a through …

Nov 9, 2024
CVE-2024-51625
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in edckwt Quran Shortcode quran-shortcode allows Blind SQL Injection.This issue affects Quran …

Nov 9, 2024
CVE-2024-51621
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in reza19 Download-Mirror-Counter wp-download-mirror-counter allows SQL Injection.This issue affects Download-Mirror-Counter: from n/a …

Nov 9, 2024
CVE-2024-51620
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in porsline Porsline porsline allows Blind SQL Injection.This issue affects Porsline: from …

Nov 9, 2024
CVE-2024-51619
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in market360 Market 360 Viewer market-360-viewer allows Blind SQL Injection.This issue affects …

Nov 9, 2024
CVE-2024-51607
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in percent20 Golf Tracker golf-tracker allows SQL Injection.This issue affects Golf Tracker: …

Nov 9, 2024
CVE-2024-51602
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in oleksandr87 Simple Job Manager simple-job-manager allows SQL Injection.This issue affects Simple …

Nov 9, 2024
CVE-2024-51601
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Maksym Marko Website price calculator price-calculator-to-your-website allows SQL Injection.This issue affects …

Nov 9, 2024
CVE-2024-51579
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder Team: Tobias 5 Stars Rating Funnel 5-stars-rating-funnel.This issue affects 5 …

Nov 9, 2024
CVE-2024-51570
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in odihost Easy Gallery simple-gallery-odihost allows SQL Injection.This issue affects Easy Gallery: …

Nov 9, 2024
CVE-2024-10674
8.8 HIGH

The Th Shop Mania theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the th_shop_mania_install_and_activate_callback() function in …

Nov 9, 2024
CVE-2024-10673
8.8 HIGH

The Top Store theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the top_store_install_and_activate_callback() function in all …

Nov 9, 2024
CVE-2024-10626
8.8 HIGH

The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_uploaded_file() function in …

Nov 9, 2024
CVE-2024-52007
8.6 HIGH

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. XSLT parsing performed by various components are vulnerable to …

Nov 8, 2024
CVE-2024-52002
8.8 HIGH

Combodo iTop is a simple, web based IT Service Management tool. Several url endpoints are subject to a Cross-Site Request Forgery (CSRF) vulnerability. Please refer …

Nov 8, 2024
CVE-2024-35423
7.8 HIGH

vmir e8117 was discovered to contain a heap buffer overflow via the wasm_parse_section_functions function at /src/vmir_wasm_parser.c.

Nov 8, 2024
CVE-2024-35422
7.8 HIGH

vmir e8117 was discovered to contain a heap buffer overflow via the wasm_call function at /src/vmir_wasm_parser.c.

Nov 8, 2024
CVE-2024-27532
7.5 HIGH

wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function `block_type_get_result_types.

Nov 8, 2024
CVE-2024-27530
8.4 HIGH

wasm3 139076a contains a Use-After-Free in ForEachModule.

Nov 8, 2024
CVE-2024-27529
8.4 HIGH

wasm3 139076a contains memory leaks in Read_utf8.

Nov 8, 2024
CVE-2024-27528
8.4 HIGH

wasm3 139076a suffers from Invalid Memory Read, leading to DoS and potential Code Execution.

Nov 8, 2024
CVE-2024-27527
7.5 HIGH

wasm3 139076a is vulnerable to Denial of Service (DoS).

Nov 8, 2024
CVE-2024-50809
8.8 HIGH

The theme.php file in SDCMS 2.8 has a command execution vulnerability that allows for the execution of system commands

Nov 8, 2024
CVE-2024-50808
8.8 HIGH

SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the backend user module, due to unsafe …

Nov 8, 2024
CVE-2024-51997
8.1 HIGH

Trustee is a set of tools and components for attesting confidential guests and providing secrets to them. The ART (**Attestation Results Token**) token, generated by …

Nov 8, 2024
CVE-2024-51152
7.2 HIGH

File Upload vulnerability in Laravel CMS v.1.4.7 and before allows a remote attacker to execute arbitrary code via the shell.php a component.

Nov 8, 2024
CVE-2024-50634
8.8 HIGH

A vulnerability in a weak JWT token in Watcharr v1.43.0 and below allows attackers to perform privilege escalation using a crafted JWT token. This vulnerability …

Nov 8, 2024
CVE-2024-25431
7.8 HIGH

An issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges via a crafted file to the …

Nov 8, 2024
CVE-2024-50592
7.0 HIGH

An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a race condition in …

Nov 8, 2024
CVE-2024-50593
7.8 HIGH

An attacker with local access to the medical office computer can access restricted functions of the Elefant Service tool by using a hard-coded "Hotline" password …

Nov 8, 2024
CVE-2024-50591
7.8 HIGH

An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a command injection vulnerability …

Nov 8, 2024
CVE-2024-50590
7.8 HIGH

Attackers with local access to the medical office computer can escalate their Windows user privileges to "NT AUTHORITY\SYSTEM" by overwriting one of two Elefant service …

Nov 8, 2024
CVE-2024-50589
7.5 HIGH

An unauthenticated attacker with access to the local network of the medical office can query an unprotected Fast Healthcare Interoperability Resources (FHIR) API to get …

Nov 8, 2024
CVE-2024-10839
8.5 HIGH

Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management option.

Nov 8, 2024
CVE-2024-24409
8.8 HIGH

Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.

Nov 8, 2024
CVE-2024-10998
7.3 HIGH

A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Nov 8, 2024
CVE-2024-10996
7.3 HIGH

A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Nov 8, 2024
CVE-2024-10995
7.3 HIGH

A vulnerability was found in Codezips Hospital Appointment System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Nov 8, 2024
CVE-2024-50209
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Add a check for memory allocation __alloc_pbl() can return error when memory allocation fails. …

Nov 8, 2024
CVE-2024-50203
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf, arm64: Fix address emission with tag-based KASAN enabled When BPF_TRAMP_F_CALL_ORIG is enabled, the address …

Nov 8, 2024
CVE-2024-50193
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: x86/entry_32: Clear CPU buffers after register restore in NMI return CPU buffers are currently cleared …

Nov 8, 2024
CVE-2024-50186
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: explicitly clear the sk pointer, when pf->create fails We have recently noticed the exact …

Nov 8, 2024
CVE-2024-50180
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: fbdev: sisfb: Fix strbuf array overflow The values of the variables xres and yres are …

Nov 8, 2024
CVE-2024-21538
7.5 HIGH

Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input …

Nov 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.