CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7008
5.4 MEDIUM

Unsanitized user-input in Calibre <= 7.15.0 allow attackers to perform reflected cross-site scripting.

Aug 6, 2024
CVE-2024-28962
6.5 MEDIUM

Dell Command | Update, Dell Update, and Alienware Update UWP, versions prior to 5.4, contain an Exposed Dangerous Method or Function vulnerability. An unauthenticated attacker …

Aug 6, 2024
CVE-2024-7499
6.3 MEDIUM

A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Aug 6, 2024
CVE-2024-5963
6.7 MEDIUM

Unquoted Executable Path vulnerability in Hitachi Device Manager on Windows (Device Manager Server component).This issue affects Hitachi Device Manager: before 8.8.7-00.

Aug 6, 2024
CVE-2024-7497
6.3 MEDIUM

A vulnerability was found in itsourcecode Airline Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/index.php. The …

Aug 6, 2024
CVE-2024-7496
6.3 MEDIUM

A vulnerability has been found in itsourcecode Airline Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file /index.php. The …

Aug 6, 2024
CVE-2024-7495
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Laravel Accounting System 1.0. This affects an unknown part of the file app/Http/Controllers/HomeController.php. The …

Aug 6, 2024
CVE-2024-7537
5.5 MEDIUM

oFono QMI SMS Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. Authentication is …

Aug 6, 2024
CVE-2024-7494
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Clinics Patient Management System 1.0. Affected by this issue is some unknown functionality …

Aug 5, 2024
CVE-2024-34343
6.3 MEDIUM

Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. The `navigateTo` function attempts to blockthe `javascript:` protocol, but …

Aug 5, 2024
CVE-2024-41958
6.6 MEDIUM

mailcow: dockerized is an open source groupware/email suite based on docker. A vulnerability has been discovered in the two-factor authentication (2FA) mechanism. This flaw allows …

Aug 5, 2024
CVE-2024-41820
6.0 MEDIUM

Kubean is a cluster lifecycle management toolchain based on kubespray and other cluster LCM engine. The ClusterRole has `*` verbs of `*` resources. If a …

Aug 5, 2024
CVE-2024-41816
5.4 MEDIUM

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the ‘[cooked-timer]’ shortcode in versions …

Aug 5, 2024
CVE-2024-6361
5.4 MEDIUM

Improper Neutralization vulnerability (XSS) has been discovered in OpenText™ ALM Octane. The vulnerability affects all version prior to version 23.4. The vulnerability could cause remote …

Aug 5, 2024
CVE-2024-41381
6.1 MEDIUM

microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php.

Aug 5, 2024
CVE-2024-41380
6.1 MEDIUM

microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_tagging_tagged.php.

Aug 5, 2024
CVE-2024-41200
5.5 MEDIUM

A segmentation fault in KMPlayer v4.2.2.65 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file.

Aug 5, 2024
CVE-2024-21978
6.0 MEDIUM

Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption.

Aug 5, 2024
CVE-2023-31355
6.0 MEDIUM

Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially allowing reading of memory from …

Aug 5, 2024
CVE-2024-23357
6.2 MEDIUM

Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.

Aug 5, 2024
CVE-2024-23350
6.5 MEDIUM

Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integrity check has failed, and the other is …

Aug 5, 2024
CVE-2024-21467
6.5 MEDIUM

Information disclosure while handling beacon probe frame during scan entry generation in client side.

Aug 5, 2024
CVE-2024-21459
6.5 MEDIUM

Information disclosure while handling beacon or probe response frame in STA.

Aug 5, 2024
CVE-2024-6710
5.4 MEDIUM

The Ditty WordPress plugin before 3.1.45 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to …

Aug 5, 2024
CVE-2024-6498
4.8 MEDIUM

The Chatbot for WordPress by Collect.chat ⚡️ WordPress plugin before 2.4.4 does not sanitise and escape some of its settings, which could allow high privilege …

Aug 5, 2024
CVE-2024-6270
4.8 MEDIUM

The Community Events WordPress plugin before 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Aug 5, 2024
CVE-2024-5081
6.1 MEDIUM

The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Aug 5, 2024
CVE-2024-3636
5.4 MEDIUM

The Pinpoint Booking System WordPress plugin before 2.9.9.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Aug 5, 2024
CVE-2024-7470
6.3 MEDIUM

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been rated as critical. This issue affects the function sslvpn_config_mod of …

Aug 5, 2024
CVE-2024-7469
6.3 MEDIUM

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been declared as critical. This vulnerability affects the function sslvpn_config_mod of …

Aug 5, 2024
CVE-2024-7468
6.3 MEDIUM

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been classified as critical. This affects the function sslvpn_config_mod of the …

Aug 5, 2024
CVE-2024-7467
6.3 MEDIUM

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90 and classified as critical. Affected by this issue is the function sslvpn_config_mod of …

Aug 5, 2024
CVE-2024-7464
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in TOTOLINK CP900 6.3c.566. This issue affects the function setTelnetCfg of the component Telnet Service. …

Aug 5, 2024
CVE-2024-7460
4.3 MEDIUM

A vulnerability was found in OSWAPP Warehouse Inventory System 1.0/2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Aug 4, 2024
CVE-2024-7459
4.3 MEDIUM

A vulnerability was found in OSWAPP Warehouse Inventory System 1.0/2.0. It has been classified as problematic. Affected is an unknown function of the file /edit_account.php. …

Aug 4, 2024
CVE-2024-7458
5.5 MEDIUM

A vulnerability was found in elunez eladmin up to 2.7 and classified as critical. This issue affects some unknown processing of the file /api/deploy/upload /api/database/upload …

Aug 4, 2024
CVE-2024-35143
6.7 MEDIUM

IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it …

Aug 4, 2024
CVE-2024-7455
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System 1.0. This affects an unknown part of the file partedit.php. The …

Aug 4, 2024
CVE-2024-7454
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Clinics Patient Management System 1.0. Affected by this issue is the function patient_name …

Aug 4, 2024
CVE-2024-7452
6.3 MEDIUM

A vulnerability was found in itsourcecode Placement Management System 1.0. It has been classified as critical. This affects an unknown part of the file view_company.php. …

Aug 4, 2024
CVE-2024-7451
6.3 MEDIUM

A vulnerability was found in itsourcecode Placement Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Aug 4, 2024
CVE-2024-7450
6.3 MEDIUM

A vulnerability has been found in itsourcecode Placement Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Aug 4, 2024
CVE-2024-7446
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Ticket Reservation System 1.0. This affects an unknown part of the file list_tickets.php. The …

Aug 3, 2024
CVE-2024-7445
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in itsourcecode Ticket Reservation System 1.0. Affected by this issue is some unknown functionality of …

Aug 3, 2024
CVE-2024-7443
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Vivotek IB8367A VVTK-0100b. Affected is the function getenv of the file …

Aug 3, 2024
CVE-2024-7442
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek SD9364 VVTK-0103f. It has been rated as critical. This issue affects the function getenv …

Aug 3, 2024
CVE-2024-7440
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek CC8160 VVTK-0100d. It has been classified as critical. This affects the function getenv of …

Aug 3, 2024
CVE-2024-7438
4.3 MEDIUM

A vulnerability has been found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php?action=profile;u=2;area=showalerts;do=read …

Aug 3, 2024
CVE-2024-37286
5.7 MEDIUM

APM server logs contain document body from a partially failed bulk index request. For example, in case of unavailable_shards_exception for a specific document, since the …

Aug 3, 2024
CVE-2024-7437
5.4 MEDIUM

A vulnerability, which was classified as critical, was found in SimpleMachines SMF 2.1.4. Affected is an unknown function of the file /index.php?action=profile;u=2;area=showalerts;do=remove of the component …

Aug 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.