CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6312
6.5 MEDIUM

The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 3.7.3.2 via the 'af2DeleteFontFile' function. This …

Aug 28, 2024
CVE-2024-4556
5.7 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText NetIQ Access Manager allows access the sensitive information. This issue affects …

Aug 28, 2024
CVE-2021-38122
6.2 MEDIUM

A Cross-Site Scripting vulnerable identified in NetIQ Advance Authentication that impacts the server functionality and disclose sensitive information. This issue affects NetIQ Advance Authentication before …

Aug 28, 2024
CVE-2021-38120
5.1 MEDIUM

A vulnerability identified in Advance Authentication that allows bash command Injection in administrative controlled functionality of backup due to improper handling in provided command parameters. …

Aug 28, 2024
CVE-2021-22529
6.3 MEDIUM

A vulnerability identified in NetIQ Advance Authentication that leaks sensitive server information. This issue affects NetIQ Advance Authentication version before 6.3.5.1

Aug 28, 2024
CVE-2024-39771
6.8 MEDIUM

QBiC CLOUD CC-2L v1.1.30 and earlier and Safie One v1.8.2 and earlier do not properly validate certificates, which may allow a network-adjacent unauthenticated attacker to …

Aug 28, 2024
CVE-2023-43078
6.7 MEDIUM

Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege …

Aug 28, 2024
CVE-2024-6448
5.3 MEDIUM

The Mollie Payments for WooCommerce plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 7.7.0. This is due to …

Aug 28, 2024
CVE-2024-7573
5.3 MEDIUM

The Relevanssi Live Ajax Search plugin for WordPress is vulnerable to argument injection in all versions up to, and including, 2.4. This is due to …

Aug 28, 2024
CVE-2024-8223
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Music Gallery Site 1.0. This vulnerability affects unknown code of the file /classes/Master.php?f=delete_category. The manipulation of …

Aug 27, 2024
CVE-2024-8222
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Music Gallery Site 1.0. This affects an unknown part of the file /admin/?page=musics/manage_music. The manipulation …

Aug 27, 2024
CVE-2024-8221
6.3 MEDIUM

A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Aug 27, 2024
CVE-2024-8220
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Aug 27, 2024
CVE-2024-8216
5.4 MEDIUM

A vulnerability, which was classified as critical, has been found in nafisulbari/itsourcecode Insurance Management System 1.0. Affected by this issue is some unknown functionality of …

Aug 27, 2024
CVE-2024-8214
6.3 MEDIUM

A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, …

Aug 27, 2024
CVE-2024-8213
6.3 MEDIUM

A vulnerability classified as critical has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, …

Aug 27, 2024
CVE-2024-8212
6.3 MEDIUM

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 …

Aug 27, 2024
CVE-2024-8211
6.3 MEDIUM

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 …

Aug 27, 2024
CVE-2024-8210
6.3 MEDIUM

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 …

Aug 27, 2024
CVE-2024-5814
5.3 MEDIUM

A malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ciphersuite that it did not agree to and achieve a …

Aug 27, 2024
CVE-2024-5288
5.1 MEDIUM

An issue was discovered in wolfSSL before 5.7.0. A safe-error attack via Rowhammer, namely FAULT+PROBE, leads to ECDSA key disclosure. When WOLFSSL_CHECK_SIG_FAULTS is used in …

Aug 27, 2024
CVE-2024-45037
6.4 MEDIUM

The AWS Cloud Development Kit (CDK) is an open-source framework for defining cloud infrastructure using code. Customers use it to create their own applications which …

Aug 27, 2024
CVE-2024-1544
4.1 MEDIUM

Generating the ECDSA nonce k samples a random number r and then truncates this randomness with a modular reduction mod n where n is the …

Aug 27, 2024
CVE-2022-39996
4.8 MEDIUM

Cross Site Scripting vulnerability in Teldats Router RS123, RS123w allows attacker to execute arbitrary code via the cmdcookie parameter to the upgrade/query.php page.

Aug 27, 2024
CVE-2024-43788
6.4 MEDIUM

Webpack is a module bundler. Its main purpose is to bundle JavaScript files for usage in a browser, yet it is also capable of transforming, …

Aug 27, 2024
CVE-2024-8200
4.3 MEDIUM

The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to Cross-Site Request Forgery …

Aug 27, 2024
CVE-2024-8199
4.3 MEDIUM

The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to unauthorized modification of …

Aug 27, 2024
CVE-2024-40395
6.5 MEDIUM

An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, including PII, regardless of access level.

Aug 27, 2024
CVE-2024-7941
4.3 MEDIUM

An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the …

Aug 27, 2024
CVE-2024-8207
6.4 MEDIUM

In certain highly specific configurations of the host system and MongoDB server binary installation on Linux Operating Systems, it may be possible for a unintended …

Aug 27, 2024
CVE-2024-7791
6.4 MEDIUM

The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘arrow’ parameter within the …

Aug 27, 2024
CVE-2024-6789
6.5 MEDIUM

A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 23.8.12892.0 SR6 allows authenticated user to …

Aug 27, 2024
CVE-2024-8046
6.4 MEDIUM

The Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads …

Aug 27, 2024
CVE-2024-7608
5.9 MEDIUM

An authenticated user can access the restricted files from NX, EX, FX, AX, IVX and CMS using path traversal.

Aug 27, 2024
CVE-2024-41175
5.5 MEDIUM

The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local denial-of-service attack by a low privileged attacker.

Aug 27, 2024
CVE-2024-7304
6.4 MEDIUM

The Ninja Tables – Easiest Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up …

Aug 27, 2024
CVE-2024-6804
6.4 MEDIUM

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.7 …

Aug 27, 2024
CVE-2024-6688
4.3 MEDIUM

The Oxygen Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the oxy_save_css_from_admin AJAX action in …

Aug 27, 2024
CVE-2024-45036
4.3 MEDIUM

Tophat is a mobile applications testing harness. An Improper Access Control vulnerability can expose the `TOPHAT_APP_TOKEN` token stored in `~/.tophatrc` through use of a malicious …

Aug 26, 2024
CVE-2024-43916
4.3 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.102.

Aug 26, 2024
CVE-2024-43915
5.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager allows Reflected XSS.This issue affects Zephyr …

Aug 26, 2024
CVE-2024-43356
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in bobbingwide.This issue affects oik: from n/a through 4.12.0.

Aug 26, 2024
CVE-2024-43340
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Nasirahmed Advanced Form Integration.This issue affects Advanced Form Integration: from n/a through 1.89.4.

Aug 26, 2024
CVE-2024-43339
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress allows Cross-Site Scripting (XSS).This issue affects WebinarPress: from n/a through 1.33.20.

Aug 26, 2024
CVE-2024-43337
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Brave Brave Popup Builder.This issue affects Brave Popup Builder: from n/a through 0.7.0.

Aug 26, 2024
CVE-2024-43336
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in WP User Manager WP User Manager wp-user-manager.This issue affects WP User Manager: from n/a through <= 2.9.10.

Aug 26, 2024
CVE-2024-43325
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Naiche Dark Mode for WP Dashboard.This issue affects Dark Mode for WP Dashboard: from n/a through 1.2.3.

Aug 26, 2024
CVE-2024-43316
5.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Checkout Plugins Stripe Payments For WooCommerce by Checkout.This issue affects Stripe Payments For WooCommerce by Checkout: from n/a through …

Aug 26, 2024
CVE-2024-43299
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Softaculous SpeedyCache speedycache.This issue affects SpeedyCache: from n/a through <= 1.1.8.

Aug 26, 2024
CVE-2024-43295
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Passionate Programmers B.V. WP Data Access.This issue affects WP Data Access: from n/a through 5.5.7.

Aug 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.