CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-44946
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: kcm: Serialise kcm_sendmsg() for the same socket. syzkaller reported UAF in kcm_release(). [0] The scenario …

Aug 31, 2024
CVE-2022-4539
5.3 MEDIUM

The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1.2. This is due to insufficient …

Aug 31, 2024
CVE-2024-8108
6.4 MEDIUM

The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alignment' parameter in all versions up to, and including, 2.01 …

Aug 31, 2024
CVE-2024-0111
4.4 MEDIUM

NVIDIA CUDA Toolkit contains a vulnerability in command 'cuobjdump' where a user may cause a crash or produce incorrect output by passing a malformed ELF …

Aug 31, 2024
CVE-2024-0110
4.4 MEDIUM

NVIDIA CUDA Toolkit contains a vulnerability in command `cuobjdump` where a user may cause an out-of-bound write by passing in a malformed ELF file. A …

Aug 31, 2024
CVE-2022-4536
5.3 MEDIUM

The IP Vault – WP Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1. This is due …

Aug 31, 2024
CVE-2022-4100
5.3 MEDIUM

The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 due to the plugin improperly …

Aug 31, 2024
CVE-2024-8276
6.4 MEDIUM

The WPZOOM Portfolio Lite – Filterable Portfolio Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ attribute within the 'wp:wpzoom-blocks' Gutenberg …

Aug 31, 2024
CVE-2024-39579
6.7 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contains an incorrect privilege assignment vulnerability. A local high privileged attacker could potentially exploit this vulnerability to gain …

Aug 31, 2024
CVE-2024-39578
6.3 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.1 contains a UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, …

Aug 31, 2024
CVE-2024-5212
6.1 MEDIUM

The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ parameter in all versions up to, and including, 5.0 due …

Aug 31, 2024
CVE-2024-3886
6.1 MEDIUM

The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ parameter in all versions up to, and including, 5.0 due …

Aug 31, 2024
CVE-2024-8006
4.4 MEDIUM

Remote packet capture support is disabled by default in libpcap. When a user builds libpcap with remote packet capture support enabled, one of the functions …

Aug 31, 2024
CVE-2024-45304
5.3 MEDIUM

Cairo-Contracts are OpenZeppelin Contracts written in Cairo for Starknet, a decentralized ZK Rollup. This vulnerability can lead to unauthorized ownership transfer, contrary to the original …

Aug 31, 2024
CVE-2023-7256
4.4 MEDIUM

In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls getaddrinfo() and possibly freeaddrinfo(), but does not clearly …

Aug 31, 2024
CVE-2024-6585
5.4 MEDIUM

Multiple stored cross-site scripting (“XSS”) vulnerabilities in the markdown dashboard and dashboard comment functionality of Lightdash version 0.1024.6 allows remote authenticated threat actors to inject …

Aug 30, 2024
CVE-2024-8348
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management System 1.0. Affected by this issue is the function delete_category …

Aug 30, 2024
CVE-2024-8347
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Computer Laboratory Management System 1.0. Affected by this vulnerability is the function delete_record of the file …

Aug 30, 2024
CVE-2024-8285
5.9 MEDIUM

A flaw was found in Kroxylicious. When establishing the connection with the upstream Kafka server using a TLS secured connection, Kroxylicious fails to properly verify …

Aug 30, 2024
CVE-2024-44684
6.1 MEDIUM

TpMeCMS 1.3.3.2 is vulnerable to Cross Site Scripting (XSS) in /h.php/page?ref=addtabs via the "Title," "Images," and "Content" fields.

Aug 30, 2024
CVE-2024-44683
6.1 MEDIUM

Seacms v13 is vulnerable to Cross Site Scripting (XSS) via admin-video.php.

Aug 30, 2024
CVE-2024-44682
6.1 MEDIUM

ShopXO 6.2 is vulnerable to Cross Site Scripting (XSS) in the backend that allows attackers to execute code by changing POST parameters.

Aug 30, 2024
CVE-2024-8346
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Computer Laboratory Management System 1.0. Affected is the function update_settings_info of the file /classes/SystemSettings.php?f=update_settings. The …

Aug 30, 2024
CVE-2024-21658
4.3 MEDIUM

discourse-calendar is a discourse plugin which adds the ability to create a dynamic calendar in the first post of a topic. The limit on region …

Aug 30, 2024
CVE-2024-8345
6.3 MEDIUM

A vulnerability was found in SourceCodester Music Gallery Site 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Aug 30, 2024
CVE-2024-8344
6.3 MEDIUM

A vulnerability has been found in Campcodes Supplier Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Aug 30, 2024
CVE-2024-8235
6.2 MEDIUM

A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms …

Aug 30, 2024
CVE-2024-45047
5.4 MEDIUM

svelte performance oriented web framework. A potential mXSS vulnerability exists in Svelte for versions up to but not including 4.2.19. Svelte improperly escapes HTML on …

Aug 30, 2024
CVE-2024-8342
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Petshop Management System 1.0. This issue affects some unknown processing of the file …

Aug 30, 2024
CVE-2024-8341
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Petshop Management System 1.0. This vulnerability affects unknown code of the file /controllers/add_user.php. The manipulation of …

Aug 30, 2024
CVE-2024-8339
6.3 MEDIUM

A vulnerability was found in SourceCodester Electric Billing Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Aug 30, 2024
CVE-2024-8338
6.3 MEDIUM

A vulnerability was found in HFO4 shudong-share 2.4.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file …

Aug 30, 2024
CVE-2024-8336
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Music Gallery Site 1.0. Affected by this vulnerability is an unknown functionality of the file /php-music/classes/Master.php?f=delete_music. …

Aug 30, 2024
CVE-2024-8335
6.3 MEDIUM

A vulnerability classified as critical has been found in OpenRapid RapidCMS up to 1.3.1. Affected is an unknown function of the file /resource/runlogon.php. The manipulation …

Aug 30, 2024
CVE-2024-8334
4.3 MEDIUM

A vulnerability was found in master-nan Sweet-CMS up to 5f441e022b8876f07cde709c77b5be6d2f262e3f. It has been rated as problematic. This issue affects the function LogHandler of the file …

Aug 30, 2024
CVE-2024-8260
6.1 MEDIUM

A SMB force-authentication vulnerability exists in all versions of OPA for Windows prior to v0.68.0. The vulnerability exists because of improper input validation, allowing a …

Aug 30, 2024
CVE-2024-8332
6.3 MEDIUM

A vulnerability was found in master-nan Sweet-CMS up to 5f441e022b8876f07cde709c77b5be6d2f262e3f. It has been declared as critical. This vulnerability affects unknown code of the file /table/index. …

Aug 30, 2024
CVE-2024-8331
6.3 MEDIUM

A vulnerability was found in OpenRapid RapidCMS up to 1.3.1. It has been classified as critical. This affects an unknown part of the file /admin/user/user-move-run.php. …

Aug 30, 2024
CVE-2022-48944
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched: Fix yet more sched_fork() races Where commit 4ef0c5c6b5ba ("kernel/sched: Fix sched_fork() access an invalid …

Aug 30, 2024
CVE-2024-8274
6.1 MEDIUM

The WP Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters from 'timeline_obj' in all versions up to, and including, …

Aug 30, 2024
CVE-2024-7858
6.3 MEDIUM

The Media Library Folders plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several AJAX functions in the media-library-plus.php file …

Aug 30, 2024
CVE-2024-7122
6.4 MEDIUM

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.13.6 due …

Aug 30, 2024
CVE-2024-8319
4.3 MEDIUM

The Tourfic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.11.20. This is due to missing or …

Aug 30, 2024
CVE-2024-44944
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: use helper function to calculate expect ID Delete expectation path is missing a …

Aug 30, 2024
CVE-2024-42412
6.1 MEDIUM

Cross-site scripting vulnerability exists in ELECOM wireless access points due to improper processing of input values in menu.cgi. If a user views a malicious web …

Aug 30, 2024
CVE-2024-34577
6.1 MEDIUM

Cross-site scripting vulnerability exists in WRC-X3000GS2-B, WRC-X3000GS2-W, WRC-X3000GS2A-B and WRC-X3000GST2-B due to improper processing of input values in easysetup.cgi. If a user views a malicious …

Aug 30, 2024
CVE-2024-5879
6.4 MEDIUM

The HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute of …

Aug 30, 2024
CVE-2024-3998
6.4 MEDIUM

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, 27.5.6 …

Aug 30, 2024
CVE-2024-5061
6.4 MEDIUM

The Enfold - Responsive Multi-Purpose Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wrapper_class’ and 'class' parameters in all versions up …

Aug 30, 2024
CVE-2024-5024
6.1 MEDIUM

The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mepr_screenname' and 'mepr_key' parameter in all versions up to, and including, 1.11.29 …

Aug 30, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.