CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-47164
6.5 MEDIUM

Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to the **bypass of directory traversal checks** within the `is_in_or_equal` function. This …

Oct 10, 2024
CVE-2024-9809
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as critical. Affected by this vulnerability is the function delete_product of …

Oct 10, 2024
CVE-2024-9808
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/?page=products/view_product. …

Oct 10, 2024
CVE-2024-47648
4.7 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Metagauss EventPrime eventprime-event-calendar-management.This issue affects EventPrime: from n/a through <= 4.0.4.5.

Oct 10, 2024
CVE-2024-47354
4.7 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wp.insider Simple Membership After Login Redirection simple-membership-after-login-redirection.This issue affects Simple Membership After Login Redirection: from n/a …

Oct 10, 2024
CVE-2024-9804
4.7 MEDIUM

A vulnerability was found in code-projects Blood Bank System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/campsdetails.php. …

Oct 10, 2024
CVE-2024-9794
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Codezips Online Shopping Portal 1.0. This issue affects some unknown processing of the file …

Oct 10, 2024
CVE-2024-9793
6.3 MEDIUM

A vulnerability classified as critical was found in Tenda AC1206 up to 15.03.06.23. This vulnerability affects the function ate_iwpriv_set/ate_ifconfig_set of the file /goform/ate. The manipulation …

Oct 10, 2024
CVE-2024-9790
4.7 MEDIUM

A vulnerability was found in LyLme_spage 1.9.5. It has been classified as critical. Affected is an unknown function of the file /admin/sou.php. The manipulation of …

Oct 10, 2024
CVE-2024-9789
4.7 MEDIUM

A vulnerability was found in LyLme_spage 1.9.5 and classified as critical. This issue affects some unknown processing of the file /admin/apply.php. The manipulation of the …

Oct 10, 2024
CVE-2024-9788
4.7 MEDIUM

A vulnerability has been found in LyLme_spage 1.9.5 and classified as critical. This vulnerability affects unknown code of the file /admin/tag.php. The manipulation of the …

Oct 10, 2024
CVE-2024-9787
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Contemporary Control System BASrouter BACnet BASRT-B 2.7.2. This affects an unknown part of the component …

Oct 10, 2024
CVE-2024-6157
5.1 MEDIUM

An attacker who successfully exploited these vulnerabilities could cause the robot to stop. A vulnerability exists in the PROFINET stack included in the RobotWare versions …

Oct 10, 2024
CVE-2024-48902
5.4 MEDIUM

In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API

Oct 10, 2024
CVE-2024-9623
4.9 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from …

Oct 10, 2024
CVE-2024-45132
6.5 MEDIUM

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. A low-privileged attacker …

Oct 10, 2024
CVE-2024-45131
5.4 MEDIUM

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A …

Oct 10, 2024
CVE-2024-45130
4.3 MEDIUM

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. …

Oct 10, 2024
CVE-2024-45129
4.3 MEDIUM

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A low-privileged …

Oct 10, 2024
CVE-2024-45128
5.4 MEDIUM

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A …

Oct 10, 2024
CVE-2024-45127
4.8 MEDIUM

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin …

Oct 10, 2024
CVE-2024-45125
4.3 MEDIUM

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A …

Oct 10, 2024
CVE-2024-45124
5.3 MEDIUM

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. …

Oct 10, 2024
CVE-2024-45123
6.1 MEDIUM

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince …

Oct 10, 2024
CVE-2024-45122
4.3 MEDIUM

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. …

Oct 10, 2024
CVE-2024-45121
4.3 MEDIUM

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. …

Oct 10, 2024
CVE-2024-45119
4.9 MEDIUM

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system …

Oct 10, 2024
CVE-2024-45118
6.5 MEDIUM

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. …

Oct 10, 2024
CVE-2024-22068
6.0 MEDIUM

Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 64 bit allows Functionality Bypass.This issue affects ZXR10 1800-2S series …

Oct 10, 2024
CVE-2024-9802
5.3 MEDIUM

The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific information about the service, including …

Oct 10, 2024
CVE-2024-7049
5.4 MEDIUM

In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the …

Oct 10, 2024
CVE-2024-6747
5.3 MEDIUM

Information leakage in mknotifyd in Checkmk before 2.3.0p18, 2.2.0p36, 2.1.0p49 and in 2.0.0p39 (EOL) allows attacker to get potentially sensitive data

Oct 10, 2024
CVE-2024-9520
6.3 MEDIUM

The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in …

Oct 10, 2024
CVE-2024-9074
6.4 MEDIUM

The Advanced Blocks Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 …

Oct 10, 2024
CVE-2024-9067
4.3 MEDIUM

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due …

Oct 10, 2024
CVE-2024-8477
4.3 MEDIUM

The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up …

Oct 10, 2024
CVE-2024-9685
4.3 MEDIUM

The Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing capability check on the 'nftb_test_action' function in …

Oct 10, 2024
CVE-2024-9457
6.4 MEDIUM

The WP Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.0.7 due …

Oct 10, 2024
CVE-2024-9377
6.1 MEDIUM

The Products, Order & Customers Export for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg …

Oct 10, 2024
CVE-2024-9205
6.1 MEDIUM

The Maximum Products per User for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping …

Oct 10, 2024
CVE-2024-9072
6.4 MEDIUM

The GDPR-Extensions-com – Consent Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Oct 10, 2024
CVE-2024-9066
6.4 MEDIUM

The Marketing and SEO Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Oct 10, 2024
CVE-2024-9065
5.3 MEDIUM

The WP Helper Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'whp_smtp_send_mail_test' function in …

Oct 10, 2024
CVE-2024-9064
6.4 MEDIUM

The Elementor Inline SVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.0 …

Oct 10, 2024
CVE-2024-9057
6.4 MEDIUM

The Curator.io: Show all your social media posts in a beautiful feed. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘feed_id’ attribute …

Oct 10, 2024
CVE-2024-8987
6.4 MEDIUM

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Oct 10, 2024
CVE-2024-8729
6.1 MEDIUM

The Easy Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …

Oct 10, 2024
CVE-2024-8513
5.3 MEDIUM

The QA Analytics – Web Analytics Tool with Heatmaps & Session Replay Across All Pages plugin for WordPress is vulnerable to unauthorized modification of data …

Oct 10, 2024
CVE-2024-7048
5.4 MEDIUM

In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/documents/ and POST /rag/api/v1/doc. This vulnerability allows a lower-privileged …

Oct 10, 2024
CVE-2024-48942
5.9 MEDIUM

The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to easily brute-force the 2FA PIN via the plugins/servlet/twofactor/public/pinvalidation …

Oct 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.