CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9076
4.7 MEDIUM

A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affects some unknown processing of the file /dede/article_string_mix.php. …

Sep 22, 2024
CVE-2024-8680
4.4 MEDIUM

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.9.16 …

Sep 21, 2024
CVE-2024-6787
5.3 MEDIUM

This vulnerability occurs when an attacker exploits a race condition between the time a file is checked and the time it is used (TOCTOU). By …

Sep 21, 2024
CVE-2024-6786
6.5 MEDIUM

The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling them to read arbitrary files on the system. This …

Sep 21, 2024
CVE-2024-6785
5.5 MEDIUM

The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, potentially resulting in the service …

Sep 21, 2024
CVE-2024-46647
6.5 MEDIUM

eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via upload_files.

Sep 20, 2024
CVE-2024-46646
6.5 MEDIUM

eNMS up to 4.7.1 is vulnerable to Directory Traversal via /download/file.

Sep 20, 2024
CVE-2024-46644
6.5 MEDIUM

eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via edit_file.

Sep 20, 2024
CVE-2024-45793
4.8 MEDIUM

Confidant is a open source secret management service that provides user-friendly storage and access to secrets. The following endpoints are subject to a cross site …

Sep 20, 2024
CVE-2024-46654
4.8 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows attackers to execute arbitrary web scripts or HTML via …

Sep 20, 2024
CVE-2024-45229
6.6 MEDIUM

The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device registration, do …

Sep 20, 2024
CVE-2024-42351
6.5 MEDIUM

Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. An attacker can potentially replace …

Sep 20, 2024
CVE-2024-42697
6.1 MEDIUM

Cross Site Scripting vulnerability in Leotheme Leo Product Search Module v.2.1.6 and earlier allows a remote attacker to execute arbitrary code via the q parameter …

Sep 20, 2024
CVE-2024-9041
6.3 MEDIUM

A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file …

Sep 20, 2024
CVE-2024-37879
4.8 MEDIUM

Improper input validation in /admin/config/save in User-friendly SVN (USVN) before v1.0.12 and below allows administrators to execute arbitrary code via the fields "siteTitle", "siteIco" and …

Sep 20, 2024
CVE-2024-9038
4.3 MEDIUM

A vulnerability classified as problematic was found in Codezips Online Shopping Portal 1.0. Affected by this vulnerability is an unknown functionality of the file insert-product.php. …

Sep 20, 2024
CVE-2024-9036
6.3 MEDIUM

A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin_add.php. …

Sep 20, 2024
CVE-2024-9032
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Simple Forum-Discussion System 1.0. Affected is an unknown function of the file /index.php. The …

Sep 20, 2024
CVE-2024-9011
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Crud Operation System 1.0. Affected is an unknown function of the file updata.php. The …

Sep 20, 2024
CVE-2024-9009
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Online Quiz Site 1.0. This issue affects some unknown processing of the file …

Sep 20, 2024
CVE-2024-47060
4.3 MEDIUM

Zitadel is an open source identity management platform. In Zitadel, even after an organization is deactivated, associated projects, respectively their applications remain active. Users across …

Sep 20, 2024
CVE-2024-45810
6.5 MEDIUM

Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy will crash when the http async client is handling `sendLocalReply` under some circumstance, e.g., websocket upgrade, and …

Sep 20, 2024
CVE-2024-45809
5.3 MEDIUM

Envoy is a cloud-native high-performance edge/middle/service proxy. Jwt filter will lead to an Envoy crash when clear route cache with remote JWKs. In the following …

Sep 20, 2024
CVE-2024-45808
6.5 MEDIUM

Envoy is a cloud-native high-performance edge/middle/service proxy. A vulnerability has been identified in Envoy that allows malicious attackers to inject unexpected content into access logs. …

Sep 20, 2024
CVE-2024-45806
6.5 MEDIUM

Envoy is a cloud-native high-performance edge/middle/service proxy. A security vulnerability in Envoy allows external clients to manipulate Envoy headers, potentially leading to unauthorized access or …

Sep 20, 2024
CVE-2024-9008
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Best Online News Portal 1.0. This vulnerability affects unknown code of the file /news-details.php of the …

Sep 19, 2024
CVE-2024-9006
6.3 MEDIUM

A vulnerability was found in jeanmarc77 123solar 1.8.4.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file …

Sep 19, 2024
CVE-2024-45614
5.4 MEDIUM

Puma is a Ruby/Rack web server built for parallelism. In affected versions clients could clobber values set by intermediate proxies (such as X-Forwarded-For) by providing …

Sep 19, 2024
CVE-2024-9004
6.3 MEDIUM

A vulnerability classified as critical has been found in D-Link DAR-7000 up to 20240912. Affected is an unknown function of the file /view/DBManage/Backup_Server_commit.php. The manipulation …

Sep 19, 2024
CVE-2024-9003
4.3 MEDIUM

A vulnerability was found in Jinan Chicheng Company JFlow 2.0.0. It has been rated as problematic. This issue affects the function AttachmentUploadController of the file …

Sep 19, 2024
CVE-2024-43496
6.5 MEDIUM

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Sep 19, 2024
CVE-2024-43489
6.5 MEDIUM

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Sep 19, 2024
CVE-2024-38221
4.3 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Sep 19, 2024
CVE-2024-9001
6.3 MEDIUM

A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. This vulnerability affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The …

Sep 19, 2024
CVE-2024-25673
6.1 MEDIUM

Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.

Sep 19, 2024
CVE-2024-47162
4.1 MEDIUM

In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page

Sep 19, 2024
CVE-2024-47160
4.3 MEDIUM

In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible

Sep 19, 2024
CVE-2024-47159
4.3 MEDIUM

In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project

Sep 19, 2024
CVE-2024-8653
6.1 MEDIUM

A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific paths on the site. This …

Sep 19, 2024
CVE-2024-8652
6.1 MEDIUM

A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific path on the site. This …

Sep 19, 2024
CVE-2024-8651
5.3 MEDIUM

A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whether a user exists …

Sep 19, 2024
CVE-2024-8883
6.1 MEDIUM

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' …

Sep 19, 2024
CVE-2024-8354
5.5 MEDIUM

A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from …

Sep 19, 2024
CVE-2024-45770
4.4 MEDIUM

A vulnerability was found in Performance Co-Pilot (PCP). This flaw can only be exploited if an attacker has access to a compromised PCP system account. …

Sep 19, 2024
CVE-2024-45769
5.5 MEDIUM

A vulnerability was found in Performance Co-Pilot (PCP). This flaw allows an attacker to send specially crafted data to the system, which could cause the …

Sep 19, 2024
CVE-2024-47089
6.5 MEDIUM

This vulnerability exists in the Apex Softcell LD Geo due to improper validation of the transaction token ID in the API endpoint. An authenticated remote …

Sep 19, 2024
CVE-2024-47087
6.5 MEDIUM

This vulnerability exists in Apex Softcell LD Geo due to improper validation of the certain parameters (Client ID, DPID or BOID) in the API endpoint. …

Sep 19, 2024
CVE-2024-47086
6.5 MEDIUM

This vulnerability exists in Apex Softcell LD DP Back Office due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote …

Sep 19, 2024
CVE-2024-47085
6.5 MEDIUM

This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClicentcode and cLdClientCode) in the API endpoint. An …

Sep 19, 2024
CVE-2024-8850
6.1 MEDIUM

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email' parameter when a placeholder such as {email} is …

Sep 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.