CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-38895
5.3 MEDIUM

WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information.

Jun 24, 2024
CVE-2024-38894
5.3 MEDIUM

WAVLINK WN551K1 found a command injection vulnerability through the IP parameter of /cgi-bin/touchlist_sync.cgi.

Jun 24, 2024
CVE-2024-38892
6.5 MEDIUM

An issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh component.

Jun 24, 2024
CVE-2024-37681
6.5 MEDIUM

An issue the background management system of Shanxi Internet Chuangxiang Technology Co., Ltd v1.0.1 allows a remote attacker to cause a denial of service via …

Jun 24, 2024
CVE-2024-37678
5.3 MEDIUM

Cross Site Scripting vulnerability in Hangzhou Meisoft Information Technology Co., Ltd. Finesoft v.8.0 and before allows a remote attacker to execute arbitrary code via a …

Jun 24, 2024
CVE-2024-34312
6.1 MEDIUM

Virtual Programming Lab for Moodle up to v4.2.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component vplide.js.

Jun 24, 2024
CVE-2024-37732
6.1 MEDIUM

Cross Site Scripting vulnerability in Anchor CMS v.0.12.7 allows a remote attacker to execute arbitrary code via a crafted .pdf file.

Jun 24, 2024
CVE-2024-37680
6.1 MEDIUM

Hangzhou Meisoft Information Technology Co., Ltd. FineSoft <=8.0 is affected by Cross Site Scripting (XSS) which allows remote attackers to execute arbitrary code. Enter any …

Jun 24, 2024
CVE-2024-37679
6.1 MEDIUM

Cross Site Scripting vulnerability in Hangzhou Meisoft Information Technology Co., Ltd. Finesoft v.8.0 and before allows a remote attacker to execute arbitrary code via a …

Jun 24, 2024
CVE-2021-45785
6.5 MEDIUM

TruDesk Help Desk/Ticketing Solution v1.1.11 is vulnerable to a Cross-Site Request Forgery (CSRF) attack which would allow an attacker to restart the server, causing a …

Jun 24, 2024
CVE-2023-49793
6.5 MEDIUM

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Zip files uploaded to the server endpoint …

Jun 24, 2024
CVE-2024-6104
6.0 MEDIUM

go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth …

Jun 24, 2024
CVE-2024-33881
5.3 MEDIUM

An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows an NTLMv2 hash leak via a …

Jun 24, 2024
CVE-2024-33880
5.3 MEDIUM

An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. It discloses full pathnames via Virto.SharePoint.FileDownloader/Api/Download.ashx?action=archive.

Jun 24, 2024
CVE-2024-39292
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: um: Add winch to winch_handlers before registering winch IRQ Registering a winch IRQ is racy, …

Jun 24, 2024
CVE-2024-38663
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix list corruption from resetting io stat Since commit 3b8cc6298724 ("blk-cgroup: Optimize blkcg_rstat_flush()"), each …

Jun 24, 2024
CVE-2024-37825
5.4 MEDIUM

An issue in EnvisionWare Computer Access & Reservation Control SelfCheck v1.0 (fixed in OneStop 3.2.0.27184 Hotfix May 2024) allows unauthenticated attackers on the same network …

Jun 24, 2024
CVE-2024-37026
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Only use reserved BCS instances for usm migrate exec queue The GuC context scheduling …

Jun 24, 2024
CVE-2024-37021
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fpga: manager: add owner module and take its refcount The current implementation of the fpga …

Jun 24, 2024
CVE-2024-36479
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fpga: bridge: add owner module and take its refcount The current implementation of the fpga …

Jun 24, 2024
CVE-2024-35247
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fpga: region: add owner module and take its refcount The current implementation of the fpga …

Jun 24, 2024
CVE-2024-34030
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI: of_property: Return error for int_map allocation failure Return -ENOMEM from of_pci_prop_intr_map() if kcalloc() fails …

Jun 24, 2024
CVE-2024-33847
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: don't allow unaligned truncation on released compress inode f2fs image may be corrupted …

Jun 24, 2024
CVE-2024-32936
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: ti: j721e-csi2rx: Fix races while restarting DMA After the frame is submitted to DMA, …

Jun 24, 2024
CVE-2024-3264
5.3 MEDIUM

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Mia Technology Inc. Mia-Med Health Aplication allows Signature Spoofing by Improper Validation.This issue affects Mia-Med …

Jun 24, 2024
CVE-2024-37233
4.3 MEDIUM

Improper Authentication vulnerability in Play.Ht allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Play.Ht: from n/a through 3.6.4.

Jun 24, 2024
CVE-2024-36038
6.3 MEDIUM

Zoho ManageEngine ITOM products versions from 128234 to 128248 are affected by the stored cross-site scripting vulnerability in the proxy server option.

Jun 24, 2024
CVE-2024-4754
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Next4Biz CRM & BPM Software Business Process Manangement (BPM) allows Stored XSS.This issue …

Jun 24, 2024
CVE-2024-27136
6.1 MEDIUM

XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive information …

Jun 24, 2024
CVE-2024-4900
6.1 MEDIUM

The SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contributor and above role to perform …

Jun 24, 2024
CVE-2024-4899
5.0 MEDIUM

The SEOPress WordPress plugin before 7.8 does not sanitise and escape some of its Post settings, which could allow high privilege users such as contributor …

Jun 24, 2024
CVE-2024-6280
6.3 MEDIUM

A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as critical. This affects an unknown part of the file …

Jun 24, 2024
CVE-2024-6279
6.3 MEDIUM

A vulnerability was found in lahirudanushka School Management System 1.0.0/1.0.1 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jun 24, 2024
CVE-2024-6278
4.7 MEDIUM

A vulnerability has been found in lahirudanushka School Management System 1.0.0/1.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Jun 24, 2024
CVE-2024-6277
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in lahirudanushka School Management System 1.0.0/1.0.1. Affected is an unknown function of the file student.php of …

Jun 24, 2024
CVE-2024-4499
6.3 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability exists in the XTTS server of parisneo/lollms version 9.6 due to a lax CORS policy. The vulnerability allows attackers …

Jun 24, 2024
CVE-2024-6276
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in lahirudanushka School Management System 1.0.0/1.0.1. This issue affects some unknown processing of the file …

Jun 24, 2024
CVE-2024-6275
4.7 MEDIUM

A vulnerability classified as critical was found in lahirudanushka School Management System 1.0.0/1.0.1. This vulnerability affects unknown code of the file parent.php of the component …

Jun 24, 2024
CVE-2024-6274
4.7 MEDIUM

A vulnerability classified as critical has been found in lahirudanushka School Management System 1.0.0/1.0.1. This affects an unknown part of the file /attendancelist.php of the …

Jun 24, 2024
CVE-2024-39337
6.5 MEDIUM

Click Studios Passwordstate Core before 9.8 build 9858 allows Authentication Bypass.

Jun 24, 2024
CVE-2024-39334
6.5 MEDIUM

MENDELSON AS4 before 2024 B376 has a client-side vulnerability when a trading partner provides prepared XML data. When a victim opens the details of this …

Jun 23, 2024
CVE-2024-6273
4.3 MEDIUM

A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been declared as problematic. Affected by this vulnerability is the function save_patient of …

Jun 23, 2024
CVE-2024-6269
4.7 MEDIUM

A vulnerability has been found in Ruijie RG-UAC 1.0 and classified as critical. This vulnerability affects the function get_ip.addr_details of the file /view/vpn/autovpn/sxh_vpnlic.php of the …

Jun 23, 2024
CVE-2024-6266
6.3 MEDIUM

A vulnerability classified as critical has been found in Pear Admin Boot up to 2.0.2. Affected is an unknown function of the file /system/dictData/loadDictItem. The …

Jun 23, 2024
CVE-2024-38379
4.8 MEDIUM

Apache Allura's neighborhood settings are vulnerable to a stored XSS attack. Only neighborhood admins can access these settings, so the scope of risk is limited …

Jun 22, 2024
CVE-2024-5596
6.3 MEDIUM

The ARMember Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.7. This is due to incorrectly implemented …

Jun 22, 2024
CVE-2024-4940
6.1 MEDIUM

An open redirect vulnerability exists in the gradio-app/gradio, affecting the latest version. The vulnerability allows an attacker to redirect users to arbitrary websites, which can …

Jun 22, 2024
CVE-2024-4874
4.3 MEDIUM

The Bricks Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.8 via the postId parameter …

Jun 22, 2024
CVE-2024-21519
6.6 MEDIUM

This affects versions of the package opencart/opencart from 4.0.0.0. An Arbitrary File Creation issue was identified via the database restoration functionality. By injecting PHP code …

Jun 22, 2024
CVE-2024-21517
4.2 MEDIUM

This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the redirect parameter of customer account/login route. An attacker …

Jun 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.