CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7339
5.3 MEDIUM

A vulnerability has been found in TVT DVR TD-2104TS-CL, DVR TD-2108TS-HP, Provision-ISR DVR SH-4050A5-5L(MM) and AVISION DVR AV108T and classified as problematic. This vulnerability affects …

Aug 1, 2024
CVE-2024-6687
5.3 MEDIUM

The CTT Expresso para WooCommerce plugin for WordPress is vulnerable to sensitive information exposure in all versions up to and including 3.2.12 via the /wp-content/uploads/cepw …

Aug 1, 2024
CVE-2024-39607
6.8 MEDIUM

OS command injection vulnerability exists in ELECOM wireless LAN routers. A specially crafted request may be sent to the affected product by a logged-in user …

Aug 1, 2024
CVE-2024-34021
6.8 MEDIUM

Unrestricted upload of file with dangerous type vulnerability exists in ELECOM wireless LAN routers. A specially crafted file may be uploaded to the affected product …

Aug 1, 2024
CVE-2024-7330
6.3 MEDIUM

A vulnerability has been found in YouDianCMS 7 and classified as critical. Affected by this vulnerability is the function curl_exec of the file /App/Core/Extend/Function/ydLib.php. The …

Aug 1, 2024
CVE-2024-7329
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in YouDianCMS 7. Affected is an unknown function of the file /Public/ckeditor/plugins/multiimage/dialogs/image_upload.php. The manipulation of the …

Jul 31, 2024
CVE-2024-7328
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in YouDianCMS 7. This issue affects some unknown processing of the file /t.php?action=phpinfo. The manipulation …

Jul 31, 2024
CVE-2024-7327
6.3 MEDIUM

A vulnerability classified as critical was found in Xinhu RockOA 2.6.2. This vulnerability affects the function dataAction of the file /webmain/task/openapi/openmodhetongAction.php. The manipulation of the …

Jul 31, 2024
CVE-2024-4187
5.4 MEDIUM

Stored XSS vulnerability has been discovered in OpenText™ Filr product, affecting versions 24.1.1 and 24.2. The vulnerability could cause users to not be warned when …

Jul 31, 2024
CVE-2024-41258
5.3 MEDIUM

An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a …

Jul 31, 2024
CVE-2024-41256
5.9 MEDIUM

Default configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification process when sending out email verification codes, …

Jul 31, 2024
CVE-2024-41254
5.3 MEDIUM

An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a …

Jul 31, 2024
CVE-2017-3772
5.5 MEDIUM

A vulnerability was reported in Lenovo PC Manager versions prior to 2.6.40.3154 that could allow an attacker to cause a system reboot.

Jul 31, 2024
CVE-2024-41955
5.2 MEDIUM

Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. An open redirect vulnerability exist in MobSF …

Jul 31, 2024
CVE-2024-41954
5.3 MEDIUM

FOG is a cloning/imaging/rescue suite/inventory management system. The application stores plaintext service account credentials in the "/opt/fog/.fogsettings" file. This file is by default readable by …

Jul 31, 2024
CVE-2024-41951
4.4 MEDIUM

Pheonix App is a Python application designed to streamline various tasks, from managing files to playing mini-games. The issue is that the map of encoding/decoding …

Jul 31, 2024
CVE-2023-28149
6.1 MEDIUM

An issue was discovered in the IhisiServiceSmm module in Insyde InsydeH2O with kernel 5.2 before 05.28.42, 5.3 before 05.37.42, 5.4 before 05.45.39, 5.5 before 05.53.39, …

Jul 31, 2024
CVE-2024-23444
4.9 MEDIUM

It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order to create a new Certificate Signing …

Jul 31, 2024
CVE-2024-6978
5.6 MEDIUM

Cato Networks Windows SDP Client Local root certificates can be installed by low-privileged users.This issue affects SDP Client: before 5.10.28.

Jul 31, 2024
CVE-2024-6977
6.5 MEDIUM

A vulnerability in Cato Networks SDP Client on Windows allows the insertion of sensitive information into the log file, which can lead to an account …

Jul 31, 2024
CVE-2024-41953
4.3 MEDIUM

Zitadel is an open source identity management system. ZITADEL uses HTML for emails and renders certain information such as usernames dynamically. That information can be …

Jul 31, 2024
CVE-2024-41952
5.3 MEDIUM

Zitadel is an open source identity management system. ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to …

Jul 31, 2024
CVE-2024-39694
4.7 MEDIUM

Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. It is possible for an attacker to craft malicious Urls that certain …

Jul 31, 2024
CVE-2024-39318
5.4 MEDIUM

The Ibexa Admin UI Bundle contains all the necessary parts to run the Ibexa DXP Back Office interface. The file upload widget is vulnerable to …

Jul 31, 2024
CVE-2024-37900
6.4 MEDIUM

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When uploading an attachment with a malicious filename, …

Jul 31, 2024
CVE-2024-37898
4.3 MEDIUM

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When a user has view but not edit …

Jul 31, 2024
CVE-2024-3082
4.2 MEDIUM

A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in …

Jul 31, 2024
CVE-2024-31201
6.5 MEDIUM

A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service. Such misconfiguration could be abused in scenarios where incorrect permissions were assigned to the …

Jul 31, 2024
CVE-2024-31200
4.2 MEDIUM

A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative account allows an attacker with physical access to the machine to retrieve the …

Jul 31, 2024
CVE-2024-6208
6.4 MEDIUM

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packages' shortcode in all versions up to, and including, 3.2.97 …

Jul 31, 2024
CVE-2024-39379
5.5 MEDIUM

Acrobat for Edge versions 126.0.2592.81 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Jul 31, 2024
CVE-2024-7321
4.3 MEDIUM

A vulnerability classified as problematic was found in itsourcecode Online Blood Bank Management System 1.0. This vulnerability affects unknown code of the file signup.php of …

Jul 31, 2024
CVE-2024-7135
6.5 MEDIUM

The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_file' function in all versions …

Jul 31, 2024
CVE-2024-6725
4.9 MEDIUM

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Jul 31, 2024
CVE-2024-7308
6.3 MEDIUM

A vulnerability was found in SourceCodester Establishment Billing Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Jul 31, 2024
CVE-2024-7307
6.3 MEDIUM

A vulnerability has been found in SourceCodester Establishment Billing Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Jul 31, 2024
CVE-2024-37129
6.7 MEDIUM

Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability. A local authenticated malicious user could potentially exploit this vulnerability, leading to arbitrary …

Jul 31, 2024
CVE-2024-2508
5.3 MEDIUM

The WP Mobile Menu plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_menu_item_icon function in …

Jul 31, 2024
CVE-2024-7306
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Establishment Billing Management System 1.0. Affected is an unknown function of the file /manage_block.php. …

Jul 31, 2024
CVE-2024-7264
6.5 MEDIUM

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might …

Jul 31, 2024
CVE-2023-28074
6.2 MEDIUM

Dell BSAFE Crypto-C Micro Edition, version 4.1.5, and Dell BSAFE Micro Edition Suite, versions 4.0 through 4.6.1 and version 5.0, contains an Out-of-bounds Read vulnerability. …

Jul 31, 2024
CVE-2024-7290
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Establishment Billing Management System 1.0. This affects an unknown part of the file /manage_tenant.php. The …

Jul 31, 2024
CVE-2024-7289
6.3 MEDIUM

A vulnerability was found in SourceCodester Establishment Billing Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Jul 31, 2024
CVE-2024-6412
6.5 MEDIUM

The HTML Forms WordPress plugin before 1.3.34 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

Jul 31, 2024
CVE-2024-6408
5.4 MEDIUM

The Slider by 10Web WordPress plugin before 1.2.57 does not sanitise and escape its Slider Title, which could allow high privilege users such as editors …

Jul 31, 2024
CVE-2024-6272
6.1 MEDIUM

The SpiderContacts WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jul 31, 2024
CVE-2024-6165
4.8 MEDIUM

The WANotifier WordPress plugin before 2.6.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jul 31, 2024
CVE-2024-7288
6.3 MEDIUM

A vulnerability was found in SourceCodester Establishment Billing Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Jul 31, 2024
CVE-2024-7287
6.3 MEDIUM

A vulnerability was found in SourceCodester Establishment Billing Management System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Jul 31, 2024
CVE-2024-39947
6.5 MEDIUM

A vulnerability has been found in Dahua products.After obtaining the ordinary user's username and password, the attacker can send a carefully crafted data packet to …

Jul 31, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.