CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6017
6.1 MEDIUM

The Music Request Manager WordPress plugin through 1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which …

Sep 12, 2024
CVE-2024-5799
4.8 MEDIUM

The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which could allow high privilege users …

Sep 12, 2024
CVE-2024-3163
4.3 MEDIUM

The Easy Property Listings WordPress plugin before 3.5.4 does not have CSRF check when deleting contacts in bulk, which could allow attackers to make a …

Sep 12, 2024
CVE-2024-8711
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in SourceCodester Food Ordering Management System 1.0. Affected by this issue is some unknown functionality …

Sep 12, 2024
CVE-2024-8710
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Inventory Management 1.0. Affected by this vulnerability is an unknown functionality of the file /model/viewProduct.php of …

Sep 12, 2024
CVE-2024-8709
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. Affected is the function delete_user/save_user of the file /admin_class.php. …

Sep 12, 2024
CVE-2024-38222
6.5 MEDIUM

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Sep 12, 2024
CVE-2024-8707
4.3 MEDIUM

A vulnerability was found in 云课网络科技有限公司 Yunke Online School System up to 3.0.6. It has been declared as problematic. This vulnerability affects the function downfile …

Sep 12, 2024
CVE-2024-8706
4.3 MEDIUM

A vulnerability was found in JFinalCMS up to 20240903. It has been classified as problematic. This affects the function update of the file /admin/template/update of …

Sep 12, 2024
CVE-2024-8705
6.3 MEDIUM

A vulnerability was found in Shandong Star Measurement and Control Equipment Heating Network Wireless Monitoring System 5.6.2 and classified as critical. Affected by this issue …

Sep 11, 2024
CVE-2024-8692
5.3 MEDIUM

A vulnerability classified as critical was found in TDuckCloud TDuckPro up to 6.3. Affected by this vulnerability is an unknown functionality. The manipulation leads to …

Sep 11, 2024
CVE-2024-8690
4.4 MEDIUM

A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows administrator privileges to …

Sep 11, 2024
CVE-2024-8688
4.4 MEDIUM

An improper neutralization of matching symbols vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables authenticated administrators (including read-only administrators) with access …

Sep 11, 2024
CVE-2024-44573
4.7 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the VLAN configuration of RELY-PCIe v22.2.1 to v23.1.0 allows attackers to execute arbitrary web scripts or HTML via …

Sep 11, 2024
CVE-2024-20390
5.3 MEDIUM

A vulnerability in the Dedicated XML Agent feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service …

Sep 11, 2024
CVE-2024-20343
5.5 MEDIUM

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to read any file in the file system of …

Sep 11, 2024
CVE-2024-7312
6.1 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from …

Sep 11, 2024
CVE-2024-46672
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: cfg80211: Handle SSID based pmksa deletion wpa_supplicant 2.11 sends since 1efdba5fdc2c ("Handle PMKSA …

Sep 11, 2024
CVE-2024-45030
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: igb: cope with large MAX_SKB_FRAGS Sabrina reports that the igb driver does not cope well …

Sep 11, 2024
CVE-2024-45029
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i2c: tegra: Do not mark ACPI devices as irq safe On ACPI machines, the tegra …

Sep 11, 2024
CVE-2024-45028
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mmc: mmc_test: Fix NULL dereference on allocation failure If the "test->highmem = alloc_pages()" allocation fails …

Sep 11, 2024
CVE-2024-45027
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Check for xhci->interrupters being allocated in xhci_mem_clearup() If xhci_mem_init() fails, it calls into …

Sep 11, 2024
CVE-2024-45025
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE copy_fd_bitmaps(new, old, count) is expected to copy the …

Sep 11, 2024
CVE-2024-45024
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix hugetlb vs. core-mm PT locking We recently made GUP's common page table walking …

Sep 11, 2024
CVE-2024-45022
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: fix page mapping if vm_area_alloc_pages() with high order fallback to order 0 The __vmap_pages_range_noflush() …

Sep 11, 2024
CVE-2024-45021
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: memcg_write_event_control(): fix a user-triggerable oops we are *not* guaranteed that anything past the terminating NUL …

Sep 11, 2024
CVE-2024-45020
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix a kernel verifier crash in stacksafe() Daniel Hodges reported a kernel verifier crash …

Sep 11, 2024
CVE-2024-45019
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Take state lock during tx timeout reporter mlx5e_safe_reopen_channels() requires the state lock taken. The …

Sep 11, 2024
CVE-2024-45018
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: initialise extack before use Fix missing initialisation of extack in flow offload.

Sep 11, 2024
CVE-2024-45017
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix IPsec RoCE MPV trace call Prevent the call trace below from happening, by …

Sep 11, 2024
CVE-2024-45016
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netem: fix return value if duplicate enqueue fails There is a bug in netem_enqueue() introduced …

Sep 11, 2024
CVE-2024-45015
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: move dpu_encoder's connector assignment to atomic_enable() For cases where the crtc's connectors_changed was set …

Sep 11, 2024
CVE-2024-45014
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: s390/boot: Avoid possible physmem_info segment corruption When physical memory for the kernel image is allocated …

Sep 11, 2024
CVE-2024-45013
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvme: move stopping keep-alive into nvme_uninit_ctrl() Commit 4733b65d82bd ("nvme: start keep-alive after admin queue setup") …

Sep 11, 2024
CVE-2024-45012
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nouveau/firmware: use dma non-coherent allocator Currently, enabling SG_DEBUG in the kernel will cause nouveau to …

Sep 11, 2024
CVE-2024-45011
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: char: xillybus: Check USB endpoints when probing device Ensure, as the driver probes the device, …

Sep 11, 2024
CVE-2024-45010
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: only mark 'subflow' endp as available Adding the following warning ... WARN_ON_ONCE(msk->pm.local_addr_used == …

Sep 11, 2024
CVE-2024-45009
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: only decrement add_addr_accepted for MPJ req Adding the following warning ... WARN_ON_ONCE(msk->pm.add_addr_accepted == …

Sep 11, 2024
CVE-2024-44851
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Discussion section of Perfex CRM v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a …

Sep 11, 2024
CVE-2024-41868
5.5 MEDIUM

Audition versions 24.4.1, 23.6.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Sep 11, 2024
CVE-2024-4465
6.0 MEDIUM

An access control vulnerability was discovered in the Reports section due to a specific access restriction not being properly enforced for users with limited privileges. …

Sep 11, 2024
CVE-2024-43793
6.3 MEDIUM

Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.19.0 of the Halo project. This vulnerability …

Sep 11, 2024
CVE-2024-8646
6.1 MEDIUM

In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed. This vulnerability is caused by the vulnerability (CVE-2023-41080) in the …

Sep 11, 2024
CVE-2024-5416
5.4 MEDIUM

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url parameter of …

Sep 11, 2024
CVE-2024-45789
4.3 MEDIUM

This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper validation of the ‘mode’ parameter in the API endpoint used during the registration process. …

Sep 11, 2024
CVE-2024-45787
6.5 MEDIUM

This vulnerability exists in Reedos aiM-Star version 2.0.1 due to transmission of sensitive information in plain text in certain API endpoints. An authenticated remote attacker …

Sep 11, 2024
CVE-2024-45786
6.5 MEDIUM

This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper access controls on its certain API endpoints. An authenticated remote attacker could exploit this …

Sep 11, 2024
CVE-2024-8096
6.5 MEDIUM

When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is …

Sep 11, 2024
CVE-2019-25212
4.9 MEDIUM

The video carousel slider with lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, …

Sep 11, 2024
CVE-2024-8045
6.4 MEDIUM

The Advanced WordPress Backgrounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘imageTag’ parameter in all versions up to, and including, 1.12.3 …

Sep 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.