CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-37107
8.8 HIGH

Improper Privilege Management vulnerability in Membership Software WishList Member X allows Privilege Escalation.This issue affects WishList Member X: from n/a before 3.26.7.

Jun 24, 2024
CVE-2024-37092
8.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consulting Elementor Widgets allows PHP Local File Inclusion.This issue affects Consulting …

Jun 24, 2024
CVE-2024-36496
7.5 HIGH

The configuration file is encrypted with a static key derived from a static five-character password which allows an attacker to decrypt this file. The application …

Jun 24, 2024
CVE-2024-36495
7.7 HIGH

The application Faronics WINSelect (Standard + Enterprise) saves its configuration in an encrypted file on the file system which "Everyone" has read and write access …

Jun 24, 2024
CVE-2024-24554
8.2 HIGH

Bludit uses predictable methods in combination with the MD5 hashing algorithm to generate sensitive tokens such as the API token and the user token. This …

Jun 24, 2024
CVE-2024-24553
7.5 HIGH

Bludit uses the SHA-1 hashing algorithm to compute password hashes. Thus, attackers could determine cleartext passwords with brute-force attacks due to the inherent speed of …

Jun 24, 2024
CVE-2024-24552
8.8 HIGH

A session fixation vulnerability in Bludit allows an attacker to bypass the server's authentication if they can trick an administrator or any other user into …

Jun 24, 2024
CVE-2024-24551
8.8 HIGH

A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulnerability arises from improper handling …

Jun 24, 2024
CVE-2024-24550
8.1 HIGH

A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arbitrary files through the File API which …

Jun 24, 2024
CVE-2024-6268
7.3 HIGH

A vulnerability, which was classified as critical, has been found in lahirudanushka School Management System 1.0.0/1.0.1. Affected by this issue is some unknown functionality of …

Jun 23, 2024
CVE-2024-38319
7.5 HIGH

IBM Security SOAR 51.0.2.0 could allow an authenticated user to execute malicious code loaded from a specially crafted script. IBM X-Force ID: 294830.

Jun 22, 2024
CVE-2024-6253
7.3 HIGH

A vulnerability was found in itsourcecode Online Food Ordering System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Jun 22, 2024
CVE-2024-3593
7.2 HIGH

The UberMenu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.3. This is due to missing or …

Jun 22, 2024
CVE-2024-21518
7.2 HIGH

This affects versions of the package opencart/opencart from 4.0.0.0. A Zip Slip issue was identified via the marketplace installer due to improper sanitization of the …

Jun 22, 2024
CVE-2024-21514
7.4 HIGH

This affects versions of the package opencart/opencart from 0.0.0. An SQL Injection issue was identified in the Divido payment extension for OpenCart, which is included …

Jun 22, 2024
CVE-2024-5791
7.2 HIGH

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp_id' parameter in all …

Jun 22, 2024
CVE-2023-45673
8.9 HIGH

Joplin is a free, open source note taking and to-do application. A remote code execution (RCE) vulnerability in affected versions allows clicking on a link …

Jun 21, 2024
CVE-2023-39517
8.2 HIGH

Joplin is a free, open source note taking and to-do application. A Cross site scripting (XSS) vulnerability in affected versions allows clicking on an untrusted …

Jun 21, 2024
CVE-2023-38506
8.2 HIGH

Joplin is a free, open source note taking and to-do application. A Cross-site Scripting (XSS) vulnerability allows pasting untrusted data into the rich text editor …

Jun 21, 2024
CVE-2023-37898
8.2 HIGH

Joplin is a free, open source note taking and to-do application. A Cross-site Scripting (XSS) vulnerability allows an untrusted note opened in safe mode to …

Jun 21, 2024
CVE-2024-35537
7.5 HIGH

TVS Motor Company Limited TVS Connect Android v4.6.0 and IOS v5.0.0 was discovered to insecurely handle the RSA key pair, allowing attackers to possibly access …

Jun 21, 2024
CVE-2024-6240
7.7 HIGH

Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate …

Jun 21, 2024
CVE-2024-6239
7.5 HIGH

A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, …

Jun 21, 2024
CVE-2024-37212
8.3 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Ali2Woo Ali2Woo Lite.This issue affects Ali2Woo Lite: from n/a through 3.3.5.

Jun 21, 2024
CVE-2022-43453
8.8 HIGH

Missing Authorization vulnerability in Bill Minozzi WP Tools.This issue affects WP Tools: from n/a through 3.41.

Jun 21, 2024
CVE-2024-35766
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ollybach WPPizza allows Reflected XSS.This issue affects WPPizza: from n/a through …

Jun 21, 2024
CVE-2024-39277
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: dma-mapping: benchmark: handle NUMA_NO_NODE correctly cpumask_of_node() can be called for NUMA_NO_NODE inside do_map_benchmark() resulting in …

Jun 21, 2024
CVE-2024-36477
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: tpm_tis_spi: Account for SPI header when allocating TPM SPI xfer buffer The TPM SPI transfer …

Jun 21, 2024
CVE-2024-34777
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: dma-mapping: benchmark: fix node id validation While validating node ids in map_benchmark_ioctl(), node_possible() may be …

Jun 21, 2024
CVE-2024-38659
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: enic: Validate length of nl attributes in enic_set_vf_port enic_set_vf_port assumes that the nl attribute IFLA_PORT_PROFILE …

Jun 21, 2024
CVE-2024-38635
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: soundwire: cadence: fix invalid PDI offset For some reason, we add an offset to the …

Jun 21, 2024
CVE-2024-38631
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: adc: PAC1934: fix accessing out of bounds array index Fix accessing out of bounds …

Jun 21, 2024
CVE-2024-38630
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: watchdog: cpu5wdt.c: Fix use-after-free bug caused by cpu5wdt_trigger When the cpu5wdt module is removing, the …

Jun 21, 2024
CVE-2024-38629
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Avoid unnecessary destruction of file_ida file_ida is allocated during cdev open and is …

Jun 21, 2024
CVE-2024-38627
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: stm class: Fix a double free in stm_register_device() The put_device(&stm->dev) call will trigger stm_device_release() which …

Jun 21, 2024
CVE-2024-38621
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: stk1160: fix bounds checking in stk1160_copy_video() The subtract in this condition is reversed. The …

Jun 21, 2024
CVE-2024-38381
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: nfc: nci: Fix uninit-value in nci_rx_work syzbot reported the following uninit-value access issue [1] nci_rx_work() …

Jun 21, 2024
CVE-2024-31890
7.8 HIGH

IBM i 7.3, 7.4, and 7.5 product IBM TCP/IP Connectivity Utilities for i contains a local privilege escalation vulnerability. A malicious actor with command line …

Jun 21, 2024
CVE-2024-2003
7.3 HIGH

Local privilege escalation vulnerability allowed an attacker to misuse ESET's file operations during a restore operation from quarantine.

Jun 21, 2024
CVE-2021-47621
7.5 HIGH

ClassGraph before 4.8.112 was not resistant to XML eXternal Entity (XXE) attacks.

Jun 21, 2024
CVE-2024-5455
8.8 HIGH

The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.5.4 via …

Jun 21, 2024
CVE-2024-6218
7.3 HIGH

A vulnerability, which was classified as critical, has been found in itsourcecode Vehicle Management System 1.0. Affected by this issue is some unknown functionality of …

Jun 21, 2024
CVE-2024-5503
8.8 HIGH

The WP Blog Post Layouts plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.3. This makes it …

Jun 21, 2024
CVE-2024-6213
7.3 HIGH

A vulnerability was found in SourceCodester Food Ordering Management System up to 1.0. It has been classified as critical. This affects an unknown part of …

Jun 21, 2024
CVE-2024-35246
7.5 HIGH

An attacker may be able to cause a denial-of-service condition by sending many packets repeatedly.

Jun 20, 2024
CVE-2024-32943
7.5 HIGH

An attacker may be able to cause a denial-of-service condition by sending many SSH packets repeatedly.

Jun 20, 2024
CVE-2024-5746
7.6 HIGH

A Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with the Site Administrator role to gain arbitrary code execution …

Jun 20, 2024
CVE-2024-29390
7.3 HIGH

Daily Expenses Management System version 1.0, developed by PHP Gurukul, contains a time-based blind SQL injection vulnerability in the 'add-expense.php' page. An attacker can exploit …

Jun 20, 2024
CVE-2024-6153
7.8 HIGH

Parallels Desktop Updater Protection Mechanism Failure Software Downgrade Vulnerability. This vulnerability allows local attackers to downgrade Parallels software on affected installations of Parallels Desktop. An …

Jun 20, 2024
CVE-2024-6147
7.8 HIGH

Poly Plantronics Hub Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Poly Plantronics Hub. An …

Jun 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.