CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-44115
4.3 MEDIUM

The RFC enabled function module allows a low privileged user to add URLs to any user's workplace favourites. This vulnerability could be utilized to identify …

Sep 10, 2024
CVE-2024-44113
4.3 MEDIUM

Due to missing authorization checks, SAP Business Warehouse (BEx Analyzer) allows an authenticated attacker to access information over the network which is otherwise restricted. On …

Sep 10, 2024
CVE-2024-42380
4.3 MEDIUM

The RFC enabled function module allows a low privileged user to read any user's workplace favourites and user menu along with all the specific data …

Sep 10, 2024
CVE-2024-42378
6.1 MEDIUM

Due to weak encoding of user-controlled inputs, eProcurement on SAP S/4HANA allows malicious scripts to be executed in the application, potentially leading to a Reflected …

Sep 10, 2024
CVE-2024-42371
5.4 MEDIUM

The RFC enabled function module allows a low privileged user to delete the workplace favourites of any user. This vulnerability could be utilized to identify …

Sep 10, 2024
CVE-2024-41729
4.3 MEDIUM

Due to missing authorization checks, SAP BEx Analyzer allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation …

Sep 10, 2024
CVE-2024-38270
5.3 MEDIUM

An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel …

Sep 10, 2024
CVE-2024-8611
6.3 MEDIUM

A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file ssms.php. …

Sep 9, 2024
CVE-2024-27365
4.4 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, …

Sep 9, 2024
CVE-2024-44085
6.1 MEDIUM

ONLYOFFICE Docs before 8.1.0 allows XSS via a GeneratorFunction Object attack against a macro. This is related to use of an immediately-invoked function expression (IIFE) …

Sep 9, 2024
CVE-2024-27387
6.7 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_rx_range_done_ind(), there is …

Sep 9, 2024
CVE-2024-27383
6.7 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_get_scan_extra_ies(), there is …

Sep 9, 2024
CVE-2024-27368
4.4 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos Mobile Processor, Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, …

Sep 9, 2024
CVE-2024-27367
4.4 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, …

Sep 9, 2024
CVE-2024-27366
4.4 MEDIUM

An issue was discovered in Samsung Mobile Processor, Wearable Processor Exynos Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, …

Sep 9, 2024
CVE-2024-27364
4.4 MEDIUM

An issue was discovered in Mobile Processor, Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, …

Sep 9, 2024
CVE-2023-50883
6.1 MEDIUM

ONLYOFFICE Docs before 8.0.1 allows XSS because a macro is an immediately-invoked function expression (IIFE), and therefore a sandbox escape is possible by directly calling …

Sep 9, 2024
CVE-2024-7318
4.8 MEDIUM

A vulnerability was found in Keycloak. Expired OTP codes are still usable when using FreeOTP when the OTP token period is set to 30 seconds …

Sep 9, 2024
CVE-2024-7260
6.1 MEDIUM

An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and referrer_uri parameters are made to trick …

Sep 9, 2024
CVE-2024-42759
6.3 MEDIUM

An issue in Ellevo v.6.2.0.38160 allows a remote attacker to escalate privileges via the /api/usuario/cadastrodesuplente endpoint.

Sep 9, 2024
CVE-2024-24510
6.1 MEDIUM

Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function to the mail component.

Sep 9, 2024
CVE-2024-45406
5.5 MEDIUM

Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fields with user input.

Sep 9, 2024
CVE-2024-8605
4.3 MEDIUM

A vulnerability classified as problematic was found in code-projects Inventory Management 1.0. This vulnerability affects unknown code of the file /view/registration.php of the component Registration …

Sep 9, 2024
CVE-2024-8604
4.3 MEDIUM

A vulnerability classified as problematic has been found in SourceCodester Online Food Ordering System 2.0. This affects an unknown part of the file index.php of …

Sep 9, 2024
CVE-2024-8373
4.8 MEDIUM

Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can …

Sep 9, 2024
CVE-2024-8372
4.8 MEDIUM

Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a …

Sep 9, 2024
CVE-2024-8601
6.5 MEDIUM

This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on certain API endpoints. An authenticated remote attacker …

Sep 9, 2024
CVE-2024-45203
4.3 MEDIUM

Improper authorization in handler for custom URL scheme issue in "@cosme" App for Android versions prior 5.69.0 and "@cosme" App for iOS versions prior to …

Sep 9, 2024
CVE-2024-7918
4.8 MEDIUM

The Pocket Widget WordPress plugin through 0.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Sep 9, 2024
CVE-2024-7689
4.3 MEDIUM

The Snapshot Backup WordPress plugin through 2.1.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Sep 9, 2024
CVE-2024-7688
6.5 MEDIUM

The AZIndex WordPress plugin through 0.8.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin delete arbitrary …

Sep 9, 2024
CVE-2024-7687
4.3 MEDIUM

The AZIndex WordPress plugin through 0.8.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Sep 9, 2024
CVE-2024-6910
4.8 MEDIUM

The EventON WordPress plugin before 2.2.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Sep 9, 2024
CVE-2024-5561
4.8 MEDIUM

The Popup Maker WordPress plugin before 1.19.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Sep 9, 2024
CVE-2024-45625
6.1 MEDIUM

Cross-site scripting vulnerability exists in Forminator versions prior to 1.34.1. If this vulnerability is exploited, an arbitrary script may be executed on the web browser …

Sep 9, 2024
CVE-2024-8586
6.1 MEDIUM

WebITR from Uniong has an Open Redirect vulnerability, which allows unauthorized remote attackers to exploit this vulnerability to forge URLs. Users, believing they are accessing …

Sep 9, 2024
CVE-2024-8585
6.5 MEDIUM

Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowing a remote attacker with regular privileges to …

Sep 9, 2024
CVE-2024-42343
5.3 MEDIUM

Loway - CWE-204: Observable Response Discrepancy

Sep 8, 2024
CVE-2024-42342
4.3 MEDIUM

Loway - CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

Sep 8, 2024
CVE-2024-42341
6.1 MEDIUM

Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

Sep 8, 2024
CVE-2024-8574
6.3 MEDIUM

A vulnerability has been found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220 and classified as critical. This vulnerability affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The …

Sep 8, 2024
CVE-2024-8570
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Sep 8, 2024
CVE-2024-6925
4.3 MEDIUM

The TrueBooker WordPress plugin before 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged …

Sep 8, 2024
CVE-2024-6859
5.4 MEDIUM

The WP MultiTasking WordPress plugin through 0.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Sep 8, 2024
CVE-2024-6856
4.3 MEDIUM

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Sep 8, 2024
CVE-2024-6855
4.3 MEDIUM

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating exit popups, which could allow attackers to make logged admins perform …

Sep 8, 2024
CVE-2024-6853
4.3 MEDIUM

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating welcome popups, which could allow attackers to make logged admins perform …

Sep 8, 2024
CVE-2024-6852
4.3 MEDIUM

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Sep 8, 2024
CVE-2024-8568
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Mini-Tmall up to 20240901. Affected is the function rewardMapper.select of the file tmall/admin/order/1/1. The manipulation …

Sep 8, 2024
CVE-2024-8566
4.3 MEDIUM

A vulnerability classified as problematic was found in code-projects Online Shop Store 1.0. This vulnerability affects unknown code of the file /settings.php. The manipulation of …

Sep 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.