CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7156
5.3 MEDIUM

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as problematic. Affected by this issue is some unknown functionality of the file /cgi-bin/ExportSettings.sh of …

Jul 28, 2024
CVE-2024-7154
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is an unknown function of the file /wizard.html of the component …

Jul 28, 2024
CVE-2024-42055
5.4 MEDIUM

Cervantes through 0.5-alpha allows stored XSS.

Jul 28, 2024
CVE-2024-42054
5.4 MEDIUM

Cervantes through 0.5-alpha accepts insecure file uploads.

Jul 28, 2024
CVE-2024-7153
5.3 MEDIUM

A vulnerability classified as problematic has been found in Netgear WN604 up to 20240719. Affected is an unknown function of the file siteSurvey.php. The manipulation …

Jul 27, 2024
CVE-2024-6703
4.9 MEDIUM

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site …

Jul 27, 2024
CVE-2024-6897
6.4 MEDIUM

The aThemes Starter Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.53 …

Jul 27, 2024
CVE-2024-6627
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's PDF View widget in all versions up to, …

Jul 27, 2024
CVE-2024-6521
4.4 MEDIUM

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site …

Jul 27, 2024
CVE-2024-6520
4.4 MEDIUM

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site …

Jul 27, 2024
CVE-2024-6518
4.4 MEDIUM

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site …

Jul 27, 2024
CVE-2024-5614
5.3 MEDIUM

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.29 via the 'pafe_posts_list' …

Jul 27, 2024
CVE-2024-6569
5.3 MEDIUM

The Campaign Monitor for WordPress plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.8.15. This is due …

Jul 27, 2024
CVE-2024-6458
6.4 MEDIUM

The WooCommerce Product Table Lite plugin for WordPress is vulnerable to unauthorized post title modification due to a missing capability check on the wcpt_presets__duplicate_preset_to_table function …

Jul 27, 2024
CVE-2024-5969
5.8 MEDIUM

The AIomatic - Automatic AI Content Writer for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 2.0.5. This is …

Jul 27, 2024
CVE-2024-42029
6.3 MEDIUM

xdg-desktop-portal-hyprland (aka an XDG Desktop Portal backend for Hyprland) before 1.3.3 allows OS command execution, e.g., because single quotes are not used when sending a …

Jul 27, 2024
CVE-2024-6661
4.4 MEDIUM

The ParityPress – Parity Pricing with Discount Rules plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Discount Text' in all versions up to, …

Jul 27, 2024
CVE-2024-6634
6.4 MEDIUM

The Master Currency WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's currencyconverterform shortcode in all versions up to, and including, …

Jul 27, 2024
CVE-2024-6591
5.8 MEDIUM

The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized email creation and sending due to a missing capability check on the 'send_auction_email_callback' …

Jul 27, 2024
CVE-2024-6573
5.3 MEDIUM

The Intelligence plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.0. This is due the plugin not …

Jul 27, 2024
CVE-2024-6566
5.3 MEDIUM

The Aramex Shipping WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.1.21. This is due the …

Jul 27, 2024
CVE-2024-6549
5.3 MEDIUM

The Admin Post Navigation plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.1. This is due to …

Jul 27, 2024
CVE-2024-6548
5.3 MEDIUM

The Add Admin JavaScript plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0. This is due to …

Jul 27, 2024
CVE-2024-6547
5.3 MEDIUM

The Add Admin CSS plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1. This is due to …

Jul 27, 2024
CVE-2024-6546
5.3 MEDIUM

The One Click Close Comments plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.7.1. This is due …

Jul 27, 2024
CVE-2024-6545
5.3 MEDIUM

The Admin Trim Interface plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.5.1. This is due to …

Jul 27, 2024
CVE-2024-4410
5.4 MEDIUM

The IgnitionDeck Crowdfunding Platform plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.9.8. This is due to missing capability …

Jul 27, 2024
CVE-2024-1804
4.3 MEDIUM

The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tutor_import_from_xml …

Jul 27, 2024
CVE-2024-1798
5.3 MEDIUM

The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the tutor_lp_export_xml …

Jul 27, 2024
CVE-2024-37034
5.9 MEDIUM

An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with the Key-Value (KV) …

Jul 26, 2024
CVE-2024-42007
5.8 MEDIUM

SPX (aka php-spx) through 0.4.15 allows SPX_UI_URI Directory Traversal to read arbitrary files.

Jul 26, 2024
CVE-2024-41375
6.1 MEDIUM

ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/terminal-xhr.php

Jul 26, 2024
CVE-2024-41374
6.1 MEDIUM

ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/settings-screen.php

Jul 26, 2024
CVE-2024-41373
6.3 MEDIUM

ICEcoder 8.1 contains a Path Traversal vulnerability via lib/backup-versions-preview-loader.php.

Jul 26, 2024
CVE-2024-27357
5.8 MEDIUM

An issue was discovered in WithSecure Elements Agent through 23.x for macOS, WithSecure Elements Client Security through 23.x for macOS, and WithSecure MDR through 23.x …

Jul 26, 2024
CVE-2024-41356
4.7 MEDIUM

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\firewall-zones\zones-edit-network.php.

Jul 26, 2024
CVE-2024-41355
6.5 MEDIUM

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.php.

Jul 26, 2024
CVE-2024-41805
6.1 MEDIUM

Tracks, a Getting Things Done (GTD) web application, is vulnerable to reflected cross-site scripting in versions prior to 2.7.1. Reflected cross-site scripting enables execution of …

Jul 26, 2024
CVE-2024-7128
5.3 MEDIUM

A flaw was found in the OpenShift console. Several endpoints in the application use the authHandler() and authHandlerWithUser() middleware functions. When the default authentication provider …

Jul 26, 2024
CVE-2024-40689
6.0 MEDIUM

IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to …

Jul 26, 2024
CVE-2024-41691
4.6 MEDIUM

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of FTP credentials in plaintext within the SquashFS-root filesystem associated with the router's firmware. An …

Jul 26, 2024
CVE-2024-41690
4.6 MEDIUM

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of default username and password credentials in plaintext within the router's firmware/ database. An attacker …

Jul 26, 2024
CVE-2024-41689
4.6 MEDIUM

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials within the router's firmware/ database. An attacker with physical access …

Jul 26, 2024
CVE-2024-41688
4.6 MEDIUM

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due lack of encryption in storing of usernames and passwords within the router's firmware/ database. An attacker with …

Jul 26, 2024
CVE-2024-41684
5.3 MEDIUM

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing secure flag for the session cookies associated with the router's web management interface. An attacker …

Jul 26, 2024
CVE-2024-25090
5.4 MEDIUM

Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of Apache Roller on …

Jul 26, 2024
CVE-2024-6490
6.5 MEDIUM

During testing of the Master Slider WordPress plugin through 3.9.10, a CSRF vulnerability was found, which allows an unauthorized user to manipulate requests on behalf …

Jul 26, 2024
CVE-2024-40897
6.7 MEDIUM

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with …

Jul 26, 2024
CVE-2024-7120
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. This affects an unknown part of the file …

Jul 26, 2024
CVE-2024-7119
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. Affected by this issue is some unknown functionality of …

Jul 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.