CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-43807
4.6 MEDIUM

In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page

Aug 16, 2024
CVE-2024-43381
5.0 MEDIUM

reNgine is an automated reconnaissance framework for web applications. Versions 2.1.2 and prior are susceptible to Stored Cross-Site Scripting (XSS) attacks. This vulnerability occurs when …

Aug 16, 2024
CVE-2024-42486
5.4 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In versions on the 1.15.x branch prior to 1.15.8 and the 1.16.x branch …

Aug 16, 2024
CVE-2024-7144
6.4 MEDIUM

The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'slide_id' parameters in all versions up to, and including, 2.6.20 …

Aug 16, 2024
CVE-2024-42464
6.5 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Utilizing REST's Trust in the System Resource to Obtain Sensitive Data.This issue …

Aug 16, 2024
CVE-2024-42463
6.5 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Utilizing REST's Trust in the System Resource to Obtain Sensitive Data.This issue …

Aug 16, 2024
CVE-2024-7147
6.4 MEDIUM

The JetBlocks for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple placeholder parameters in all versions up to, and including, 1.3.12 …

Aug 16, 2024
CVE-2024-7136
6.4 MEDIUM

The JetSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 3.5.2 due to …

Aug 16, 2024
CVE-2024-25008
6.8 MEDIUM

Ericsson RAN Compute and Site Controller 6610 contains a vulnerability in the Control System where Improper Input Validation can lead to arbitrary code execution, for …

Aug 16, 2024
CVE-2024-7501
4.2 MEDIUM

The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Aug 16, 2024
CVE-2024-7422
4.3 MEDIUM

The Theme My Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.1.7. This is due to …

Aug 16, 2024
CVE-2024-7630
5.3 MEDIUM

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.22.2 (Free) and 2.25.1 …

Aug 16, 2024
CVE-2023-7049
4.3 MEDIUM

The Custom Field For WP Job Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2 …

Aug 16, 2024
CVE-2022-3399
4.4 MEDIUM

The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cookie_notice_options[refuse_code_head]' parameter in versions up …

Aug 16, 2024
CVE-2024-7853
6.3 MEDIUM

A vulnerability was found in SourceCodester Yoga Class Registration System up to 1.0. It has been classified as critical. Affected is an unknown function of …

Aug 16, 2024
CVE-2024-7851
6.3 MEDIUM

A vulnerability has been found in SourceCodester Yoga Class Registration System 1.0 and classified as critical. This vulnerability affects unknown code of the file /classes/Users.php?f=save …

Aug 16, 2024
CVE-2024-7845
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Aug 16, 2024
CVE-2024-43374
4.5 MEDIUM

The UNIX editor Vim prior to version 9.1.0678 has a use-after-free error in argument list handling. When adding a new file to the argument list, …

Aug 16, 2024
CVE-2024-7843
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0. Affected is an unknown function of the file /tracking/admin/exportcs.php. …

Aug 15, 2024
CVE-2024-7842
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in SourceCodester Online Graduate Tracer System 1.0. This issue affects some unknown processing of the …

Aug 15, 2024
CVE-2024-7841
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Clinics Patient Management System 1.0. This vulnerability affects unknown code of the file /pms/ajax/check_user_name.php. The manipulation …

Aug 15, 2024
CVE-2024-34742
5.5 MEDIUM

In shouldWrite of OwnersData.java, there is a possible edge case that prevents MDM policies from being persisted due to a logic error in the code. …

Aug 15, 2024
CVE-2024-42488
6.8 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.14.14 and 1.15.8, a race condition in the Cilium agent …

Aug 15, 2024
CVE-2024-42487
4.0 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In the 1.15 branch prior to 1.15.8 and the 1.16 branch prior to …

Aug 15, 2024
CVE-2024-7867
6.2 MEDIUM

In Xpdf 4.05 (and earlier), very large coordinates in a page box can cause an integer overflow and divide-by-zero.

Aug 15, 2024
CVE-2024-7866
5.5 MEDIUM

In Xpdf 4.05 (and earlier), a PDF object loop in a pattern resource leads to infinite recursion and a stack overflow.

Aug 15, 2024
CVE-2024-42476
6.5 MEDIUM

In the OAuth library for nim prior to version 0.11, the Authorization Code grant and Implicit grant both rely on the `state` parameter to prevent …

Aug 15, 2024
CVE-2024-42475
6.5 MEDIUM

In the OAuth library for nim prior to version 0.11, the `state` values generated by the `generateState` function do not have sufficient entropy. These can …

Aug 15, 2024
CVE-2024-27731
6.1 MEDIUM

Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the lack of file type filtering in the file …

Aug 15, 2024
CVE-2024-27729
6.1 MEDIUM

Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the location parameter of the calendar event feature.

Aug 15, 2024
CVE-2024-27728
6.1 MEDIUM

Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the text parameter of the babel debug feature.

Aug 15, 2024
CVE-2024-25633
5.4 MEDIUM

eLabFTW is an open source electronic lab notebook for research labs. In an eLabFTW system, one can configure who is allowed to create new user …

Aug 15, 2024
CVE-2024-32231
6.3 MEDIUM

Stash up to v0.25.1 was discovered to contain a SQL injection vulnerability via the sort parameter.

Aug 15, 2024
CVE-2024-22219
6.3 MEDIUM

XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows authenticated users to submit malicious XML via …

Aug 15, 2024
CVE-2024-22217
6.5 MEDIUM

A Server-Side Request Forgery (SSRF) vulnerability in Terminalfour before 8.3.19 allows authenticated users to use specific features to access internal services including sensitive information on …

Aug 15, 2024
CVE-2024-40705
6.5 MEDIUM

IBM InfoSphere Information Server could allow an authenticated user to consume file space resources due to unrestricted file uploads. IBM X-Force ID: 298279.

Aug 15, 2024
CVE-2024-40704
4.9 MEDIUM

IBM InfoSphere Information Server 11.7 could allow a privileged user to obtain sensitive information from authentication request headers. IBM X-Force ID: 298277.

Aug 15, 2024
CVE-2024-31905
5.9 MEDIUM

IBM QRadar Network Packet Capture 7.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport …

Aug 15, 2024
CVE-2024-31800
6.8 MEDIUM

Authentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privileged command shell via the UART Debugging …

Aug 15, 2024
CVE-2024-31799
4.6 MEDIUM

Information Disclosure in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to read the WiFi passphrase via the UART Debugging Port.

Aug 15, 2024
CVE-2024-31798
6.8 MEDIUM

Identical Hardcoded Root Password for All Devices in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to retrieve the root password …

Aug 15, 2024
CVE-2024-6347
6.5 MEDIUM

* Unprotected privileged mode access through UDS session in the Blind Spot Detection Sensor ECU firmware in Nissan Altima (2022) allows attackers to trigger denial-of-service …

Aug 15, 2024
CVE-2024-7833
6.3 MEDIUM

A vulnerability was found in D-Link DI-8100 16.07. It has been classified as critical. This affects the function upgrade_filter_asp of the file upgrade_filter.asp. The manipulation …

Aug 15, 2024
CVE-2024-42680
5.5 MEDIUM

An issue in Super easy enterprise management system v.1.0.0 and before allows a local attacker to obtain the server absolute path by entering a single …

Aug 15, 2024
CVE-2024-42678
6.1 MEDIUM

Cross Site Scripting vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker to execute arbitrary code via a crafted script …

Aug 15, 2024
CVE-2024-42677
5.5 MEDIUM

An issue in Huizhi enterprise resource management system v.1.0 and before allows a local attacker to obtain sensitive information via the /nssys/common/filehandle. Aspx component

Aug 15, 2024
CVE-2024-7411
5.3 MEDIUM

The Newsletters plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 4.9.9. This is due the plugin not …

Aug 15, 2024
CVE-2024-7064
6.4 MEDIUM

The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 3.6.5 due to …

Aug 15, 2024
CVE-2024-7063
4.3 MEDIUM

The ElementsKit Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.6 via the 'render_raw' function. This …

Aug 15, 2024
CVE-2024-6534
4.3 MEDIUM

Directus v10.13.0 allows an authenticated external attacker to modify presets created by the same user to assign them to another user. This is possible because …

Aug 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.