CVE Database

38969+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-47187
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, missing initialization of the random seed …

Oct 16, 2024
CVE-2024-45797
7.5 HIGH

LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Prior to version 0.5.49, unbounded processing of HTTP request and …

Oct 16, 2024
CVE-2024-45795
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, rules using datasets with the non-functional …

Oct 16, 2024
CVE-2024-4690
8.0 HIGH

Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.

Oct 16, 2024
CVE-2024-4189
8.0 HIGH

Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.

Oct 16, 2024
CVE-2024-4184
8.0 HIGH

Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.

Oct 16, 2024
CVE-2024-38814
8.8 HIGH

An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A malicious authenticated user with non-administrator privileges may be able to enter …

Oct 16, 2024
CVE-2024-20458
8.2 HIGH

A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to view or …

Oct 16, 2024
CVE-2024-20421
7.1 HIGH

A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to conduct a …

Oct 16, 2024
CVE-2024-49268
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sunburntkamel disconnected allows Reflected XSS.This issue affects disconnected: from n/a through …

Oct 16, 2024
CVE-2024-45844
7.2 HIGH

BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings. Note: Software versions which have reached End …

Oct 16, 2024
CVE-2024-49253
8.6 HIGH

Relative Path Traversal vulnerability in JamesPark.ninja Analyse Uploads analyse-uploads allows Relative Path Traversal.This issue affects Analyse Uploads: from n/a through <= 0.5.

Oct 16, 2024
CVE-2024-49251
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Acnoo Maan Addons For Elementor maan-elementor-addons allows Local Code …

Oct 16, 2024
CVE-2024-49245
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in nahimsalami Ahime Image Printer ahime-image-printer.This issue affects Ahime Image Printer: from n/a …

Oct 16, 2024
CVE-2024-49226
8.8 HIGH

Deserialization of Untrusted Data vulnerability in taketin TAKETIN To WP Membership taketin-to-wp-membership allows Object Injection.This issue affects TAKETIN To WP Membership: from n/a through <= …

Oct 16, 2024
CVE-2024-48029
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hung Trang Si SB Random Posts Widget sb-random-posts-widget allows …

Oct 16, 2024
CVE-2024-47645
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Danish Ali Malik Top Bar – PopUps – by WPOptin wpoptin allows …

Oct 16, 2024
CVE-2024-47637
8.8 HIGH

Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue affects LiteSpeed Cache: from n/a through <= 6.4.1.

Oct 16, 2024
CVE-2024-47351
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The CSSIgniter Team MaxSlider maxslider allows Path Traversal.This issue affects MaxSlider: from …

Oct 16, 2024
CVE-2024-22030
8.0 HIGH

A vulnerability has been identified within Rancher that can be exploited in narrow circumstances through a man-in-the-middle (MITM) attack. An attacker would need to have …

Oct 16, 2024
CVE-2024-22029
7.8 HIGH

Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root

Oct 16, 2024
CVE-2023-32194
7.2 HIGH

A vulnerability has been identified when granting a create or * global role for a resource type of "namespaces"; no matter the API group, the …

Oct 16, 2024
CVE-2023-32193
8.3 HIGH

A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in Norman's public API endpoint can be exploited. This can lead to an attacker …

Oct 16, 2024
CVE-2023-32192
8.3 HIGH

A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in the API Server's public API endpoint can be exploited, allowing an attacker to …

Oct 16, 2024
CVE-2024-8040
7.7 HIGH

An authorization bypass through user-controlled key vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an authenticated attacker to access some unauthorized data.

Oct 16, 2024
CVE-2024-6380
8.7 HIGH

A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary …

Oct 16, 2024
CVE-2023-32190
7.8 HIGH

mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.

Oct 16, 2024
CVE-2024-9858
7.8 HIGH

There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windows installs. A local "m2cuser" was greated …

Oct 16, 2024
CVE-2023-22650
8.8 HIGH

A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from the configured authentication provider (AP). …

Oct 16, 2024
CVE-2024-9061
7.3 HIGH

The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary shortcode execution via the wp_ajax_nopriv_shortcode_Api_Add AJAX …

Oct 16, 2024
CVE-2024-45715
7.1 HIGH

The SolarWinds Platform was susceptible to a Cross-Site Scripting vulnerability when performing an edit function to existing elements.

Oct 16, 2024
CVE-2024-45711
7.5 HIGH

SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible depending on privileges given to the authenticated user. This issue …

Oct 16, 2024
CVE-2024-45710
7.8 HIGH

SolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This requires a low privilege account and local access to the …

Oct 16, 2024
CVE-2024-45693
8.0 HIGH

Users logged into the Apache CloudStack's web interface can be tricked to submit malicious CSRF requests due to missing validation of the origin of the …

Oct 16, 2024
CVE-2024-45219
8.5 HIGH

Account users in Apache CloudStack by default are allowed to upload and register templates for deploying instances and volumes for attaching them as data disks …

Oct 16, 2024
CVE-2024-45217
8.1 HIGH

Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore command, which copy a configSet from the backup …

Oct 16, 2024
CVE-2023-22649
8.4 HIGH

A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. [Rancher Audit Logging](https://ranchermanager.docs.rancher.com/how-to-guides/advanced-user-guides/enable-api-audit-log) is an opt-in feature, only …

Oct 16, 2024
CVE-2021-4452
7.1 HIGH

The Google Language Translator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions up to, and including, 6.0.9 due to …

Oct 16, 2024
CVE-2020-36842
8.8 HIGH

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvivid_upload_import_files and …

Oct 16, 2024
CVE-2020-36840
7.3 HIGH

The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_route_url() function …

Oct 16, 2024
CVE-2024-8918
7.4 HIGH

The File Manager Pro plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 8.3.9. This is due …

Oct 16, 2024
CVE-2024-8746
7.5 HIGH

The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing file type validation via the 'mk_file_folder_manager_shortcode' …

Oct 16, 2024
CVE-2024-8507
8.8 HIGH

The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.3.9. This is due to …

Oct 16, 2024
CVE-2023-7294
7.1 HIGH

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the create_mollie_profile …

Oct 16, 2024
CVE-2023-7291
7.1 HIGH

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Oct 16, 2024
CVE-2022-4972
7.5 HIGH

The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in …

Oct 16, 2024
CVE-2021-4450
8.8 HIGH

The Post Grid plugin for WordPress is vulnerable to blind SQL Injection via post metadata in versions up to, and including, 2.1.12 due to insufficient …

Oct 16, 2024
CVE-2021-4448
7.3 HIGH

The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.0.1 due to insufficient capability checking …

Oct 16, 2024
CVE-2021-4447
8.8 HIGH

The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of …

Oct 16, 2024
CVE-2021-4444
7.3 HIGH

The Product Filter by WooBeWoo plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.4.9 due to missing authorization checks …

Oct 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.