CVE Database

38971+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-42623
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/delete/1

Aug 12, 2024
CVE-2024-41651
8.1 HIGH

An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disputed by …

Aug 12, 2024
CVE-2024-41475
8.8 HIGH

Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.

Aug 12, 2024
CVE-2024-40500
8.6 HIGH

Cross Site Scripting vulnerability in Martin Kucej i-librarian v.5.11.0 and before allows a local attacker to execute arbitrary code via the search function in the …

Aug 12, 2024
CVE-2024-42632
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/add.

Aug 12, 2024
CVE-2024-42631
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/edit/1.

Aug 12, 2024
CVE-2024-42630
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_file.

Aug 12, 2024
CVE-2024-42629
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/edit/10.

Aug 12, 2024
CVE-2024-42628
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/edit/3.

Aug 12, 2024
CVE-2024-42485
7.5 HIGH

Filament Excel enables excel export for Filament admin resources. The export download route `/filament-excel/{path}` allowed downloading any file without login when the webserver allows `../` …

Aug 12, 2024
CVE-2024-42481
7.5 HIGH

Skyport Daemon (skyportd) is the daemon for the Skyport Panel. By making thousands of folders & files (easy due to skyport's lack of rate limiting …

Aug 12, 2024
CVE-2024-42480
8.1 HIGH

Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an "open at the top" range definition in RBAC …

Aug 12, 2024
CVE-2024-39091
8.8 HIGH

An OS command injection vulnerability in the ccm_debug component of MIPC Camera firmware prior to v5.4.1.240424171021 allows attackers within the same network to execute arbitrary …

Aug 12, 2024
CVE-2024-36877
8.2 HIGH

Micro-Star International Z-series motherboards (Z590, Z490, and Z790) and B-series motherboards (B760, B560, B660, and B460) with firmware 7D25v14, 7D25v17 to 7D25v19, and 7D25v1A to …

Aug 12, 2024
CVE-2024-33535
7.5 HIGH

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The vulnerability involves unauthenticated local file inclusion (LFI) in a web application, specifically impacting …

Aug 12, 2024
CVE-2024-27442
7.8 HIGH

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The zmmailboxdmgr binary, a component of ZCS, is intended to be executed by the …

Aug 12, 2024
CVE-2024-7697
7.5 HIGH

Logical vulnerability in the mobile application (com.transsion.carlcare) may lead to user information leakage risks.

Aug 12, 2024
CVE-2024-7694
7.2 HIGH KEV

ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious …

Aug 12, 2024
CVE-2024-7693
7.5 HIGH

Raiden MAILD Remote Management System from Team Johnlong Software has a Relative Path Traversal vulnerability, allowing unauthenticated remote attackers to read arbitrary file on the …

Aug 12, 2024
CVE-2024-7682
7.3 HIGH

A vulnerability was found in code-projects Job Portal 1.0. It has been rated as critical. This issue affects some unknown processing of the file rw_i_nat.php. …

Aug 12, 2024
CVE-2024-7681
7.3 HIGH

A vulnerability was found in code-projects College Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login.php …

Aug 12, 2024
CVE-2024-7637
7.3 HIGH

A vulnerability was found in code-projects Online Polling 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Aug 12, 2024
CVE-2024-7636
7.3 HIGH

A vulnerability was found in code-projects Simple Ticket Booking 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Aug 12, 2024
CVE-2024-7635
7.3 HIGH

A vulnerability was found in code-projects Simple Ticket Booking 1.0. It has been classified as critical. Affected is an unknown function of the file register_insert.php …

Aug 12, 2024
CVE-2024-7615
8.8 HIGH

A vulnerability was found in Tenda FH1206 1.2.0.8. It has been declared as critical. Affected by this vulnerability is the function fromSafeClientFilter/fromSafeMacFilter/fromSafeUrlFilter. The manipulation leads …

Aug 12, 2024
CVE-2024-7614
8.8 HIGH

A vulnerability was found in Tenda FH1206 1.2.0.8(8155). It has been classified as critical. Affected is the function fromqossetting of the file /goform/qossetting. The manipulation …

Aug 12, 2024
CVE-2024-7613
8.8 HIGH

A vulnerability was found in Tenda FH1206 1.2.0.8(8155) and classified as critical. This issue affects the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer. The manipulation of …

Aug 12, 2024
CVE-2024-7589
8.1 HIGH

A signal handler in sshd(8) may call a logging function that is not async-signal-safe. The signal handler is invoked when a client does not authenticate …

Aug 12, 2024
CVE-2024-7557
8.8 HIGH

A vulnerability was found in OpenShift AI that allows for authentication bypass and privilege escalation across models within the same namespace. When deploying AI models, …

Aug 12, 2024
CVE-2024-7399
8.8 HIGH KEV

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as …

Aug 12, 2024
CVE-2024-7006
7.5 HIGH

A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, …

Aug 12, 2024
CVE-2024-6760
7.5 HIGH

A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it should have, allowing unprivileged …

Aug 12, 2024
CVE-2024-5800
7.5 HIGH

Diffie-Hellman groups with insufficient strength are used in the SSL/TLS stack of B&R Automation Runtime versions before 6.0.2, allowing a network attacker to decrypt the …

Aug 12, 2024
CVE-2024-5651
8.8 HIGH

A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) primitive by supplying an arbitrary command …

Aug 12, 2024
CVE-2024-5527
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in file auditing configuration.

Aug 12, 2024
CVE-2024-5487
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's export option.

Aug 12, 2024
CVE-2024-42473
7.5 HIGH

OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses `but not` …

Aug 12, 2024
CVE-2024-42370
8.3 HIGH

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions 2.10.0 and prior, Litestar's `docs-preview.yml` workflow is vulnerable to Environment Variable injection which may …

Aug 12, 2024
CVE-2024-42163
8.3 HIGH

Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to take over the account of any user by predicting …

Aug 12, 2024
CVE-2024-42001
8.6 HIGH

An improper authentication vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior enables an unauthenticated remote attacker to …

Aug 12, 2024
CVE-2024-41936
7.5 HIGH

A directory traversal vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enables an unauthenticated remote attacker to …

Aug 12, 2024
CVE-2024-40488
8.8 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability was found in the Kashipara Live Membership System v1.0. This could lead to an attacker tricking the administrator into …

Aug 12, 2024
CVE-2024-40487
7.6 HIGH

A Stored Cross Site Scripting (XSS) vulnerability was found in "/view_type.php" of Kashipara Live Membership System v1.0, which allows remote attackers to execute arbitrary code …

Aug 12, 2024
CVE-2024-40479
8.1 HIGH

A SQL injection vulnerability in "/admin/quizquestion.php" in Kashipara Online Exam System v1.0 allows remote attackers to execute arbitrary SQL commands via the "eid" parameter.

Aug 12, 2024
CVE-2024-40476
8.0 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability was found in SourceCodester Best House Rental Management System v1.0. This could lead to an attacker tricking the administrator …

Aug 12, 2024
CVE-2024-40475
8.8 HIGH

SourceCodester Best House Rental Management System v1.0 is vulnerable to Incorrect Access Control via /rental/payment_report.php, /rental/balance_report.php, /rental/invoices.php, /rental/tenants.php, and /rental/users.php.

Aug 12, 2024
CVE-2024-39338
7.5 HIGH

axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs.

Aug 12, 2024
CVE-2024-38218
8.4 HIGH

Microsoft Edge (HTML-based) Memory Corruption Vulnerability

Aug 12, 2024
CVE-2024-37826
7.5 HIGH

A NULL pointer dereference in vercot Serva v4.6.0 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

Aug 12, 2024
CVE-2024-36518
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's dashboard.

Aug 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.