CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-49921
5.2 MEDIUM

An issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This could lead to raw contents …

Jul 26, 2024
CVE-2024-7118
6.3 MEDIUM

A vulnerability classified as critical was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. Affected by this vulnerability is an unknown functionality of the file /department_viewmore.php. …

Jul 26, 2024
CVE-2024-7117
6.3 MEDIUM

A vulnerability classified as critical has been found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. Affected is an unknown function of the file /shift_viewmore.php. The manipulation …

Jul 26, 2024
CVE-2024-7116
6.3 MEDIUM

A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. It has been rated as critical. This issue affects some unknown processing of the file …

Jul 26, 2024
CVE-2024-7115
6.3 MEDIUM

A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. It has been declared as critical. This vulnerability affects unknown code of the file /designation_viewmore.php. …

Jul 26, 2024
CVE-2024-7114
6.3 MEDIUM

A vulnerability was found in Tianchoy Blog up to 1.8.8. It has been classified as critical. This affects an unknown part of the file /so.php. …

Jul 26, 2024
CVE-2024-3938
5.4 MEDIUM

The "reset password" login page accepted an HTML injection via URL parameters. This has already been rectified via patch, and as such it cannot be …

Jul 25, 2024
CVE-2024-38103
5.9 MEDIUM

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Jul 25, 2024
CVE-2024-7106
4.3 MEDIUM

A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation …

Jul 25, 2024
CVE-2024-7105
6.3 MEDIUM

A vulnerability classified as critical has been found in ForIP Tecnologia Administração PABX 1.x. Affected is an unknown function of the file /detalheIdUra of the …

Jul 25, 2024
CVE-2024-6558
6.3 MEDIUM

HMS Industrial Networks Anybus-CompactCom 30 products are vulnerable to a XSS attack caused by the lack of input sanitation checks. As a consequence, it is …

Jul 25, 2024
CVE-2024-40324
5.4 MEDIUM

A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) characters into input fields, leading to HTTP …

Jul 25, 2024
CVE-2024-29069
4.8 MEDIUM

In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap. The snap format is a …

Jul 25, 2024
CVE-2024-29068
5.8 MEDIUM

In snapd versions prior to 2.62, snapd failed to properly check the file type when extracting a snap. The snap format is a squashfs file-system …

Jul 25, 2024
CVE-2024-1724
6.3 MEDIUM

In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. In Ubuntu, …

Jul 25, 2024
CVE-2024-40873
4.5 MEDIUM

There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.07. Attackers with system administrator permissions …

Jul 25, 2024
CVE-2024-28772
6.8 MEDIUM

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary …

Jul 25, 2024
CVE-2022-32759
5.3 MEDIUM

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses insufficient session expiration which could allow an unauthorized user to obtain sensitive …

Jul 25, 2024
CVE-2024-41801
4.7 MEDIUM

OpenProject is open source project management software. Prior to version 14.3.0, using a forged HOST header in the default configuration of packaged installations and using …

Jul 25, 2024
CVE-2024-41800
4.8 MEDIUM

Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able …

Jul 25, 2024
CVE-2024-41806
5.3 MEDIUM

The Open edX Platform is a learning management platform. Instructors can upload csv files containing learner information to create cohorts in the instructor dashboard. These …

Jul 25, 2024
CVE-2024-36111
6.3 MEDIUM

KubePi is a K8s panel. Starting in version 1.6.3 and prior to version 1.8.0, there is a defect in the KubePi JWT token verification. The …

Jul 25, 2024
CVE-2024-39674
6.2 MEDIUM

Plaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect availability.

Jul 25, 2024
CVE-2024-39673
6.8 MEDIUM

Vulnerability of serialisation/deserialisation mismatch in the iAware module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jul 25, 2024
CVE-2024-39670
6.2 MEDIUM

Privilege escalation vulnerability in the account synchronisation module. Impact: Successful exploitation of this vulnerability will affect availability.

Jul 25, 2024
CVE-2023-7271
5.5 MEDIUM

Privilege escalation vulnerability in the NMS module Impact: Successful exploitation of this vulnerability will affect availability.

Jul 25, 2024
CVE-2024-41707
4.8 MEDIUM

An issue was discovered in Archer Platform 6 before 2024.06. Authenticated users can achieve HTML content injection. A remote authenticated malicious Archer user could potentially …

Jul 25, 2024
CVE-2024-6972
6.5 MEDIUM

In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the task log in clear-text.

Jul 25, 2024
CVE-2024-7057
4.3 MEDIUM

An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from …

Jul 25, 2024
CVE-2024-7091
4.1 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from …

Jul 24, 2024
CVE-2024-5067
4.4 MEDIUM

An issue was discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from …

Jul 24, 2024
CVE-2024-7081
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jul 24, 2024
CVE-2024-41136
6.8 MEDIUM

An authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command Line Interface. Successful exploitation of this vulnerability results in the …

Jul 24, 2024
CVE-2024-7080
5.3 MEDIUM

A vulnerability was found in SourceCodester Insurance Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Jul 24, 2024
CVE-2024-40137
5.5 MEDIUM

Dolibarr ERP CRM before 19.0.2-php8.2 was discovered to contain a remote code execution (RCE) vulnerability via the Computed field parameter under the Users Module Setup …

Jul 24, 2024
CVE-2024-41666
4.7 MEDIUM

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD has a Web-based terminal that allows users to get a shell inside …

Jul 24, 2024
CVE-2024-21684
4.3 MEDIUM

There is a low severity open redirect vulnerability within affected versions of Bitbucket Data Center. Versions of Bitbucket DC from 8.0.0 to 8.9.12 and 8.19.0 …

Jul 24, 2024
CVE-2024-7079
6.5 MEDIUM

A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation of a Helm chart from a …

Jul 24, 2024
CVE-2024-7069
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. This issue affects some unknown …

Jul 24, 2024
CVE-2024-40575
5.5 MEDIUM

An issue in Huawei Technologies opengauss (openGauss 5.0.0 build) v.7.3.0 allows a local attacker to cause a denial of service via the modification of table …

Jul 24, 2024
CVE-2024-22444
6.1 MEDIUM

A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against …

Jul 24, 2024
CVE-2024-31971
4.8 MEDIUM

Multiple stored cross-site scripting (XSS) vulnerabilities on AdTran NetVanta 3120 18.01.01.00.E devices allow remote attackers to inject arbitrary JavaScript, as demonstrated by /mainPassword.html, /processIdentity.html, /public.html, …

Jul 24, 2024
CVE-2024-7067
6.3 MEDIUM

A vulnerability was found in kirilkirkov Ecommerce-Laravel-Bootstrap up to 1f1097a3448ce8ec53e034ea0f70b8e2a0e64a87. It has been rated as critical. Affected by this issue is the function getCartProductsIds of …

Jul 24, 2024
CVE-2024-5818
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored DOM-based Cross-Site Scripting via the plugin's Magazine Grid/Slider widget in all versions …

Jul 24, 2024
CVE-2024-3896
6.4 MEDIUM

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the Gallery title field in …

Jul 24, 2024
CVE-2024-6896
6.4 MEDIUM

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up …

Jul 24, 2024
CVE-2024-7065
4.3 MEDIUM

A vulnerability was found in Spina CMS up to 2.18.0. It has been classified as problematic. Affected is an unknown function of the file /admin/pages/. …

Jul 24, 2024
CVE-2024-6930
6.4 MEDIUM

The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute within the plugin's bookingform shortcode in all versions …

Jul 24, 2024
CVE-2024-6874
4.3 MEDIUM

libcurl's URL API function [curl_url_get()](https://curl.se/libcurl/c/curl_url_get.html) offers punycode conversions, to and from IDN. Asking to convert a name that is exactly 256 bytes, libcurl ends up …

Jul 24, 2024
CVE-2024-3297
6.5 MEDIUM

An issue in the Certificate Authenticated Session Establishment (CASE) protocol for establishing secure sessions between two devices, as implemented in the Matter protocol versions before …

Jul 24, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.