CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4359
6.5 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to arbitrary file reads in …

Aug 12, 2024
CVE-2024-4350
4.8 MEDIUM

Concrete CMS versions 9.0.0 to 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in RSS Displayer when user input is stored and later embedded …

Aug 12, 2024
CVE-2024-43168
4.8 MEDIUM

DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet Labs) falls within the …

Aug 12, 2024
CVE-2024-42470
6.5 MEDIUM

openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. Several endpoints in versions prior to 4.2.1 of the CometVisu …

Aug 12, 2024
CVE-2024-42468
5.3 MEDIUM

openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. CometVisuServlet in versions prior to 4.2.1 is susceptible to an …

Aug 12, 2024
CVE-2024-42367
4.8 MEDIUM

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions on the 3.10 branch prior to version 3.10.2, static routes which contain …

Aug 12, 2024
CVE-2024-42165
6.3 MEDIUM

Insufficiently random values for generating activation token in FIWARE Keyrock <= 8.4 allow attackers to activate accounts of any user by predicting the token for …

Aug 12, 2024
CVE-2024-42164
4.3 MEDIUM

Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to disable two factor authorization of any user by predicting …

Aug 12, 2024
CVE-2024-41890
5.3 MEDIUM

Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. User sends multiple password reset emails, each …

Aug 12, 2024
CVE-2024-41888
5.3 MEDIUM

Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. The password reset link remains valid within …

Aug 12, 2024
CVE-2024-41482
6.1 MEDIUM

Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the MathJax component.

Aug 12, 2024
CVE-2024-41481
6.1 MEDIUM

Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the Mermaid component.

Aug 12, 2024
CVE-2024-41332
6.5 MEDIUM

Incorrect access control in the delete_category function of Sourcecodester Computer Laboratory Management System v1.0 allows authenticated attackers with low-level privileges to arbitrarily delete categories.

Aug 12, 2024
CVE-2024-40484
6.1 MEDIUM

A Reflected Cross Site Scripting (XSS) vulnerability was found in "/oahms/search.php" in PHPGurukul Old Age Home Management System v1.0, which allows remote attackers to execute …

Aug 12, 2024
CVE-2024-40481
5.4 MEDIUM

A Stored Cross Site Scripting (XSS) vulnerability was found in "/admin/view-enquiry.php" in PHPGurukul Old Age Home Management System v1.0, which allows remote attackers to execute …

Aug 12, 2024
CVE-2024-40478
5.4 MEDIUM

A Stored Cross Site Scripting (XSS) vulnerability was found in "/admin/afeedback.php" in Kashipara Online Exam System v1.0, which allows remote attackers to execute arbitrary code …

Aug 12, 2024
CVE-2024-40474
5.4 MEDIUM

A Reflected Cross Site Scripting (XSS) vulnerability was found in "edit-cate.php" in SourceCodester House Rental Management System v1.0.

Aug 12, 2024
CVE-2024-40473
5.4 MEDIUM

A Stored Cross Site Scripting (XSS) vulnerability was found in "manage_houses.php" in SourceCodester Best House Rental Management System v1.0. It allows remote attackers to execute …

Aug 12, 2024
CVE-2024-38219
6.5 MEDIUM

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Aug 12, 2024
CVE-2024-38200
6.5 MEDIUM

Microsoft Office Spoofing Vulnerability

Aug 12, 2024
CVE-2024-37283
6.5 MEDIUM

An issue was discovered whereby Elastic Agent will leak secrets from the agent policy elastic-agent.yml only when the log level is configured to debug. By …

Aug 12, 2024
CVE-2024-32765
4.2 MEDIUM

A vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow local authenticated administrators to gain access to and …

Aug 12, 2024
CVE-2024-22121
6.1 MEDIUM

A non-admin user can change or remove important features within the Zabbix Agent application, thus impacting the integrity and availability of the application.

Aug 12, 2024
CVE-2024-22114
4.3 MEDIUM

User with no permission to any of the Hosts can access and view host count & other statistics through System Information Widget in Global View …

Aug 12, 2024
CVE-2024-21877
6.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability through a url parameter in Enphase IQ Gateway (formerly known as Envoy) allows …

Aug 12, 2024
CVE-2024-0115
6.1 MEDIUM

NVIDIA CV-CUDA for Ubuntu 20.04, Ubuntu 22.04, and Jetpack contains a vulnerability in Python APIs where a user may cause an uncontrolled resource consumption issue …

Aug 12, 2024
CVE-2023-50810
6.0 MEDIUM

In certain Sonos products before Sonos S1 Release 11.12 and S2 release 15.9, a vulnerability exists in the U-Boot component of the firmware that allow …

Aug 12, 2024
CVE-2023-38018
6.3 MEDIUM

IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the …

Aug 12, 2024
CVE-2024-42493
5.3 MEDIUM

Dorsett Controls InfoScan is vulnerable due to a leak of possible sensitive information through the response headers and the rendered JavaScript prior to user login.

Aug 8, 2024
CVE-2024-42408
5.3 MEDIUM

The InfoScan client download page can be intercepted with a proxy, to expose filenames located on the system, which could lead to additional information exposure.

Aug 8, 2024
CVE-2024-39287
5.3 MEDIUM

Dorsett Controls Central Server update server has potential information leaks with an unprotected file that contains passwords and API keys.

Aug 8, 2024
CVE-2024-0104
4.2 MEDIUM

NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause improper access. A …

Aug 8, 2024
CVE-2023-40261
6.8 MEDIUM

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR17, 4.0.0 SR07, 4.1.0 SR04, 4.2.0 SR04, and 4.3.0 SR02 fails to validate file attributes during the …

Aug 8, 2024
CVE-2023-33206
6.8 MEDIUM

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR16, 4.0.0 SR06, 4.1.0 SR04, 4.2.0 SR03, and 4.3.0 SR01 fails to validate symlinks during the Pre-Boot …

Aug 8, 2024
CVE-2023-28865
6.6 MEDIUM

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR15, 4.0.0 SR05, 4.1.0 SR03, and 4.2.0 SR02 fails to validate the directory contents of certain directories …

Aug 8, 2024
CVE-2023-24064
6.8 MEDIUM

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR4 fails to validate /etc/initab during the Pre-Boot Authorization (PBA) process. This can be exploited by a …

Aug 8, 2024
CVE-2023-24063
6.8 MEDIUM

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR10 fails to validate /etc/mtab during the Pre-Boot Authorization (PBA) process. This can be exploited by a …

Aug 8, 2024
CVE-2023-24062
6.8 MEDIUM

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR12, 4.0.0 SR04, 4.1.0 SR02, and 4.2.0 SR01 fails to validate the directory structure of the root …

Aug 8, 2024
CVE-2024-7394
4.8 MEDIUM

Concrete CMS versions 9 through 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in getAttributeSetName(). A rogue administrator could inject malicious code. The Concrete …

Aug 8, 2024
CVE-2024-7480
4.2 MEDIUM

An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interface (CLI) user with administrative privileges to read …

Aug 8, 2024
CVE-2024-7477
6.5 MEDIUM

A SQL injection vulnerability was found which could allow a command line interface (CLI) user with administrative privileges to execute arbitrary queries against the Avaya …

Aug 8, 2024
CVE-2024-41238
5.3 MEDIUM

A SQL injection vulnerability in /smsa/student_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter.

Aug 8, 2024
CVE-2024-42354
5.3 MEDIUM

Shopware is an open commerce platform. The store-API works with regular entities and not expose all fields for the public API; fields need to be …

Aug 8, 2024
CVE-2024-7610
4.3 MEDIUM

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 15.9 before 17.0.6, 17.1 prior to 17.1.4, and …

Aug 8, 2024
CVE-2024-7554
4.9 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.0.6, all versions starting from 17.1 before 17.1.4, all versions …

Aug 8, 2024
CVE-2024-5423
6.5 MEDIUM

Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting from 17.1 prior …

Aug 8, 2024
CVE-2024-4207
4.4 MEDIUM

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 prior 17.0.6, starting from 17.1 prior to 17.1.4, and starting …

Aug 8, 2024
CVE-2024-3958
5.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was …

Aug 8, 2024
CVE-2024-3114
4.3 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.10 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2, …

Aug 8, 2024
CVE-2024-3035
6.8 MEDIUM

A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 …

Aug 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.