CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8564
6.3 MEDIUM

A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/update.php. The …

Sep 7, 2024
CVE-2024-8561
6.3 MEDIUM

A vulnerability has been found in SourceCodester PHP CRUD 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file …

Sep 7, 2024
CVE-2024-8560
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Simple Invoice Generator System 1.0. Affected is an unknown function of the file /save_invoice.php. …

Sep 7, 2024
CVE-2024-8559
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Online Food Menu 1.0. This issue affects some unknown processing of the file …

Sep 7, 2024
CVE-2024-42022
5.3 MEDIUM

An incorrect permission assignment vulnerability allows an attacker to modify product configuration files.

Sep 7, 2024
CVE-2024-42021
6.5 MEDIUM

An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.

Sep 7, 2024
CVE-2024-42020
5.4 MEDIUM

A Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection.

Sep 7, 2024
CVE-2024-8558
4.3 MEDIUM

A vulnerability classified as problematic was found in SourceCodester Food Ordering Management System 1.0. This vulnerability affects unknown code of the file /foms/routers/place-order.php of the …

Sep 7, 2024
CVE-2023-39333
5.3 MEDIUM

Maliciously crafted export names in an imported WebAssembly module can inject JavaScript code. The injected code may be able to access data and functions that …

Sep 7, 2024
CVE-2023-30582
5.3 MEDIUM

A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flag is used with a non-* …

Sep 7, 2024
CVE-2024-8557
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Food Ordering Management System 1.0. This affects an unknown part of the file /foms/routers/cancel-order.php. The …

Sep 7, 2024
CVE-2024-8555
4.3 MEDIUM

A vulnerability was found in SourceCodester Clinics Patient Management System 2.0. It has been classified as problematic. Affected is an unknown function of the file …

Sep 7, 2024
CVE-2024-40680
5.5 MEDIUM

IBM MQ 9.3 CD and 9.4 LTS/CD could allow a local user to cause a denial of service due to improper memory allocation causing a …

Sep 7, 2024
CVE-2024-37068
5.9 MEDIUM

IBM Maximo Application Suite - Manage Component 8.10, 8.11, and 9.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly …

Sep 7, 2024
CVE-2024-7620
6.6 MEDIUM

The Customizer Export/Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '_import' function in all versions …

Sep 7, 2024
CVE-2024-6010
5.3 MEDIUM

The Cost Calculator Builder PRO plugin for WordPress is vulnerable to price manipulation in all versions up to, and including, 3.2.1. This is due to …

Sep 7, 2024
CVE-2024-8538
4.3 MEDIUM

The Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and …

Sep 7, 2024
CVE-2024-8523
4.7 MEDIUM

A vulnerability was found in lmxcms up to 1.4 and classified as critical. Affected by this issue is the function formatData of the file /admin.php?m=Acquisi&a=testcj&lid=1 …

Sep 7, 2024
CVE-2024-6849
6.4 MEDIUM

The Preloader Plus – WordPress Loading Screen Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up …

Sep 7, 2024
CVE-2024-8521
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Wavelog up to 1.8.0. Affected is the function index of the file /qso of the …

Sep 7, 2024
CVE-2024-34155
4.3 MEDIUM

Calling any of the Parse functions on Go source code which contains deeply nested literals can cause a panic due to stack exhaustion.

Sep 6, 2024
CVE-2024-8394
6.5 MEDIUM

When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash. This vulnerability …

Sep 6, 2024
CVE-2024-38640
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via …

Sep 6, 2024
CVE-2024-27126
6.3 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow authenticated users to inject malicious code …

Sep 6, 2024
CVE-2024-27122
6.3 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow authenticated users to inject malicious code …

Sep 6, 2024
CVE-2024-21906
4.7 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Sep 6, 2024
CVE-2024-21904
5.9 MEDIUM

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents …

Sep 6, 2024
CVE-2024-21903
6.6 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Sep 6, 2024
CVE-2023-51368
5.4 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to launch a …

Sep 6, 2024
CVE-2023-51367
5.4 MEDIUM

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Sep 6, 2024
CVE-2023-50366
4.3 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to inject …

Sep 6, 2024
CVE-2023-45038
4.3 MEDIUM

An improper authentication vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to compromise the security of the system …

Sep 6, 2024
CVE-2023-34979
6.6 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Sep 6, 2024
CVE-2022-27592
6.7 MEDIUM

An unquoted search path or element vulnerability has been reported to affect QVR Smart Client. If exploited, the vulnerability could allow local authenticated administrators to …

Sep 6, 2024
CVE-2024-25584
5.3 MEDIUM

Dovecot accepts dot LF DOT LF symbol as end of DATA command. RFC requires that it should always be CR LF DOT CR LF. This …

Sep 6, 2024
CVE-2024-7622
4.3 MEDIUM

The Revision Manager TMC plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to a missing capability check on the _a_ajaxQuickEmailTestCallback() function in …

Sep 6, 2024
CVE-2024-7611
6.4 MEDIUM

The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' attribute of the Events …

Sep 6, 2024
CVE-2024-7599
6.4 MEDIUM

The Advanced Sermons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sermon_video_embed’ parameter in all versions up to, and including, 3.3 due …

Sep 6, 2024
CVE-2024-44837
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in the component \bean\Manager.java of Drug v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Sep 6, 2024
CVE-2024-45405
6.0 MEDIUM

`gix-path` is a crate of the `gitoxide` project (an implementation of `git` written in Rust) dealing paths and their conversions. Prior to version 0.10.11, `gix-path` …

Sep 6, 2024
CVE-2024-45299
6.5 MEDIUM

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5, the preloaded data as json is …

Sep 6, 2024
CVE-2024-45040
5.9 MEDIUM

gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.11.0, commitments to private witnesses in Groth16 as …

Sep 6, 2024
CVE-2024-45039
6.2 MEDIUM

gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Versions prior to 0.11.0 have a soundness issue - in case …

Sep 6, 2024
CVE-2023-52915
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb-v2: af9035: Fix null-ptr-deref in af9035_i2c_master_xfer In af9035_i2c_master_xfer, msg is controlled by user. When …

Sep 6, 2024
CVE-2024-8427
4.3 MEDIUM

The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Sep 6, 2024
CVE-2024-8317
6.4 MEDIUM

The WP AdCenter – Ad Manager & Adsense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ad_alignment’ attribute in all versions …

Sep 6, 2024
CVE-2024-45751
5.9 MEDIUM

tgt (aka Linux target framework) before 1.0.93 attempts to achieve entropy by calling rand without srand. The PRNG seed is always 1, and thus the …

Sep 6, 2024
CVE-2024-7415
5.3 MEDIUM

The Remember Me Controls plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1. This is due to …

Sep 6, 2024
CVE-2024-40865
5.3 MEDIUM

The issue was addressed by suspending Persona when the virtual keyboard is active. This issue is fixed in visionOS 1.3. Inputs to the virtual keyboard …

Sep 6, 2024
CVE-2024-44082
4.3 MEDIUM

In OpenStack Ironic before 26.0.1 and ironic-python-agent before 9.13.1, there is a vulnerability in image processing, in which a crafted image could be used by …

Sep 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.