CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-42477
5.3 MEDIUM

llama.cpp provides LLM inference in C/C++. The unsafe `type` member in the `rpc_tensor` structure can cause `global-buffer-overflow`. This vulnerability may lead to memory data leakage. …

Aug 12, 2024
CVE-2024-42258
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm: huge_memory: use !CONFIG_64BIT to relax huge page alignment on 32 bit machines Yves-Alexis Perez …

Aug 12, 2024
CVE-2024-33536
5.4 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The vulnerability occurs due to inadequate input validation of the res parameter, allowing an …

Aug 12, 2024
CVE-2024-33533
5.4 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0, issue 1 of 2. A reflected cross-site scripting (XSS) vulnerability has been identified in …

Aug 12, 2024
CVE-2024-27443
6.1 MEDIUM KEV

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail …

Aug 12, 2024
CVE-2024-21550
6.1 MEDIUM

SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management …

Aug 12, 2024
CVE-2024-6639
6.4 MEDIUM

The MDx theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mdx_list_item' shortcode in all versions up to, and including, 2.0.3 due …

Aug 12, 2024
CVE-2024-7680
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been classified as critical. This affects an unknown part of the file /incedit.php?id=4. …

Aug 12, 2024
CVE-2024-7676
6.3 MEDIUM

A vulnerability was found in Sourcecodester Car Driving School Management System 1.0. It has been classified as critical. Affected is the function save_package of the …

Aug 12, 2024
CVE-2024-7669
6.3 MEDIUM

A vulnerability was found in SourceCodester Car Driving School Management System 1.0 and classified as critical. This issue affects the function delete_enrollment of the file …

Aug 12, 2024
CVE-2024-7668
6.3 MEDIUM

A vulnerability has been found in SourceCodester Car Driving School Management System 1.0 and classified as critical. This vulnerability affects the function delete_package of the …

Aug 12, 2024
CVE-2024-7667
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Car Driving School Management System 1.0. This affects the function delete_users of the file …

Aug 12, 2024
CVE-2024-7666
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Car Driving School Management System 1.0. Affected by this issue is some unknown …

Aug 12, 2024
CVE-2024-7665
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Car Driving School Management System 1.0. Affected by this vulnerability is an unknown functionality of the …

Aug 12, 2024
CVE-2024-7664
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Car Driving School Management System 1.0. Affected is an unknown function of the file view_details.php. …

Aug 12, 2024
CVE-2024-7663
6.3 MEDIUM

A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been rated as critical. This issue affects some unknown processing of …

Aug 12, 2024
CVE-2024-7662
4.3 MEDIUM

A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been declared as problematic. This vulnerability affects the function save_package of …

Aug 12, 2024
CVE-2024-7661
4.3 MEDIUM

A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been classified as problematic. This affects the function save_users of the …

Aug 12, 2024
CVE-2024-7658
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in projectsend up to r1605. This issue affects the function get_preview of the file process.php. …

Aug 12, 2024
CVE-2024-7649
6.1 MEDIUM

The Opal Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via checkout form fields in all versions up to, and including, 1.2.4 due …

Aug 12, 2024
CVE-2024-7648
4.3 MEDIUM

The Opal Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.4 via the private notes functionality …

Aug 12, 2024
CVE-2024-7645
4.3 MEDIUM

A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file …

Aug 12, 2024
CVE-2024-7643
6.3 MEDIUM

A vulnerability was found in SourceCodester Leads Manager Tool 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Aug 12, 2024
CVE-2024-7642
6.3 MEDIUM

A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown …

Aug 12, 2024
CVE-2024-7641
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected is an unknown function of the …

Aug 12, 2024
CVE-2024-7640
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. This issue affects some unknown processing …

Aug 12, 2024
CVE-2024-7639
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. This vulnerability affects unknown code of the file delete_act.php. …

Aug 12, 2024
CVE-2024-7638
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. This affects an unknown part of the file …

Aug 12, 2024
CVE-2024-7621
5.4 MEDIUM

The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Aug 12, 2024
CVE-2024-7616
5.5 MEDIUM

A vulnerability was found in Edimax IC-6220DC and IC-5150W up to 3.06. It has been rated as critical. Affected by this issue is the function …

Aug 12, 2024
CVE-2024-7574
6.1 MEDIUM

The Christmasify! plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.5. This is due to missing nonce validation …

Aug 12, 2024
CVE-2024-7512
4.8 MEDIUM

Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in Board instances. A rogue administrator could inject malicious code. The Concrete …

Aug 12, 2024
CVE-2024-7416
5.3 MEDIUM

The Reveal Template plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.7. This is due to the …

Aug 12, 2024
CVE-2024-7414
5.3 MEDIUM

The PDF Builder for WPForms plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.116. This is due …

Aug 12, 2024
CVE-2024-7413
5.3 MEDIUM

The Obfuscate Email plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.8.1. This is due to the …

Aug 12, 2024
CVE-2024-7412
5.3 MEDIUM

The No Update Nag plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.12. This is due to …

Aug 12, 2024
CVE-2024-7410
5.3 MEDIUM

The My Custom CSS PHP & ADS plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.3. This …

Aug 12, 2024
CVE-2024-7408
6.5 MEDIUM

This vulnerability exists in Airveda Air Quality Monitor PM2.5 PM10 due to transmission of sensitive information in plain text during AP pairing mode. An attacker …

Aug 12, 2024
CVE-2024-7382
5.3 MEDIUM

The Linkify Text plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.9.1. This is due to the …

Aug 12, 2024
CVE-2024-7272
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in FFmpeg up to 5.1.5. This affects the function fill_audiodata of the file /libswresample/swresample.c. The manipulation …

Aug 12, 2024
CVE-2024-6759
5.3 MEDIUM

When mounting a remote filesystem using NFS, the kernel did not sanitize remotely provided filenames for the path separator character, "/". This allows readdir(3) and …

Aug 12, 2024
CVE-2024-6758
6.5 MEDIUM

Improper Privilege Management in Sprecher Automation SPRECON-E below version 8.71j allows a remote attacker with low privileges to save unauthorized protection assignments.

Aug 12, 2024
CVE-2024-6691
4.4 MEDIUM

The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Aug 12, 2024
CVE-2024-6640
6.3 MEDIUM

In ICMPv6 Neighbor Discovery (ND), the ID is always 0. When pf is configured to allow ND and block incoming Echo Requests, a crafted Echo …

Aug 12, 2024
CVE-2024-6562
5.3 MEDIUM

The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.5.5. This is …

Aug 12, 2024
CVE-2024-6158
4.8 MEDIUM

The Category Posts Widget WordPress plugin before 4.9.17, term-and-category-based-posts-widget WordPress plugin before 4.9.13 does not validate and escape some of its "Category Posts" widget settings …

Aug 12, 2024
CVE-2024-6136
5.4 MEDIUM

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted …

Aug 12, 2024
CVE-2024-6134
5.4 MEDIUM

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Aug 12, 2024
CVE-2024-6133
6.5 MEDIUM

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Aug 12, 2024
CVE-2024-4360
6.4 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Aug 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.