CVE Database

9968+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-44217
9.1 CRITICAL

A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in iOS 18 and iPadOS 18. Password autofill …

Oct 28, 2024
CVE-2024-50496
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in webandprint AR For WordPress ar-for-wordpress allows Upload a Web Shell to a Web Server.This issue affects …

Oct 28, 2024
CVE-2024-50495
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in nunomorgadinho Plugin Propagator wp-propagator allows Upload a Web Shell to a Web Server.This issue affects Plugin …

Oct 28, 2024
CVE-2024-48356
9.8 CRITICAL

LyLme Spage <=1.6.0 is vulnerable to SQL Injection via /admin/group.php.

Oct 28, 2024
CVE-2024-40867
9.6 CRITICAL

A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in iOS 18.1 and iPadOS 18.1. A remote attacker …

Oct 28, 2024
CVE-2024-48465
9.8 CRITICAL

The MRBS version 1.5.0 has an SQL injection vulnerability in the edit_entry_handler.php file, specifically in the rooms%5B%5D parameter

Oct 28, 2024
CVE-2024-48357
9.8 CRITICAL

LyLme Spage 1.2.0 through 1.6.0 is vulnerable to SQL Injection via /admin/apply.php.

Oct 28, 2024
CVE-2024-39205
9.8 CRITICAL

An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a crafted HTTP request.

Oct 28, 2024
CVE-2024-50491
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MicahBlu RSVP ME rsvp-me allows SQL Injection.This issue affects RSVP ME: …

Oct 28, 2024
CVE-2024-50483
9.8 CRITICAL

Authorization Bypass Through User-Controlled Key vulnerability in Tareq Hasan Meetup meetup allows Privilege Escalation.This issue affects Meetup: from n/a through <= 0.1.

Oct 28, 2024
CVE-2024-50479
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chenyenming Woocommerce Quote Calculator woo-quote-calculator-order allows Blind SQL Injection.This issue affects …

Oct 28, 2024
CVE-2024-50478
9.8 CRITICAL

Authentication Bypass by Primary Weakness vulnerability in Swoop 1-Click Login: Passwordless Authentication allows Authentication Bypass.This issue affects 1-Click Login: Passwordless Authentication: 1.4.5.

Oct 28, 2024
CVE-2024-50498
10.0 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Ajit Bohra WP Query Console wp-query-console allows Code Injection.This issue affects WP Query Console: from …

Oct 28, 2024
CVE-2024-50489
9.8 CRITICAL

Authentication Bypass Using an Alternate Path or Channel vulnerability in realtyworkstation Realty Workstation realty-workstation allows Authentication Bypass.This issue affects Realty Workstation: from n/a through <= …

Oct 28, 2024
CVE-2024-50487
9.8 CRITICAL

Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo MaanStore API maanstore-api allows Authentication Bypass.This issue affects MaanStore API: from n/a through <= …

Oct 28, 2024
CVE-2024-50486
9.8 CRITICAL

Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo Acnoo Flutter API acnoo-flutter-api allows Authentication Bypass.This issue affects Acnoo Flutter API: from n/a …

Oct 28, 2024
CVE-2024-50477
9.8 CRITICAL

Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentication Bypass.This issue affects Stacks Mobile App Builder: …

Oct 28, 2024
CVE-2024-38821
9.1 CRITICAL

Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances. For this to impact an application, all …

Oct 28, 2024
CVE-2024-10440
9.8 CRITICAL

The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL command to read, modify, and delete database …

Oct 28, 2024
CVE-2024-50623
9.8 CRITICAL KEV

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote …

Oct 28, 2024
CVE-2024-9501
9.8 CRITICAL

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.0.7. This …

Oct 26, 2024
CVE-2024-9933
9.8 CRITICAL

The WatchTowerHQ plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.10.1. This is due to the 'watchtower_ota_token' default value …

Oct 26, 2024
CVE-2024-9932
9.8 CRITICAL

The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in versions …

Oct 26, 2024
CVE-2024-9931
9.8 CRITICAL

The Wux Blog Editor plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.0. This is due to missing validation …

Oct 26, 2024
CVE-2024-9930
9.8 CRITICAL

The Extensions by HocWP Team plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.2.3.2. This is due to missing …

Oct 26, 2024
CVE-2024-47821
9.1 CRITICAL

pyLoad is a free and open-source Download Manager. The folder `/.pyload/scripts` has scripts which are run when certain actions are completed, for e.g. a download …

Oct 25, 2024
CVE-2024-48237
9.8 CRITICAL

WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController.class.php.

Oct 25, 2024
CVE-2024-10386
9.8 CRITICAL

CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages to …

Oct 25, 2024
CVE-2024-48581
9.8 CRITICAL

File Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the admin_class.php component.

Oct 25, 2024
CVE-2024-48580
9.8 CRITICAL

SQL Injection vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the email parameter of the …

Oct 25, 2024
CVE-2024-48579
9.8 CRITICAL

SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to execute arbitrary code via the username parameter …

Oct 25, 2024
CVE-2024-48204
9.8 CRITICAL

SQL injection vulnerability in Hanzhou Haobo network management system 1.0 allows a remote attacker to execute arbitrary code via a crafted script.

Oct 25, 2024
CVE-2022-30355
9.8 CRITICAL

OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is …

Oct 25, 2024
CVE-2024-48428
9.8 CRITICAL

An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function.

Oct 25, 2024
CVE-2024-10381
9.8 CRITICAL

This vulnerability exists in Matrix Door Controller Cosec Vega FAXQ due to improper implementation of session management at the web-based management interface. A remote attacker …

Oct 25, 2024
CVE-2024-47406
9.1 CRITICAL

Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulnerability.

Oct 25, 2024
CVE-2024-9488
9.8 CRITICAL

The Comments – wpDiscuz plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.6.24. This is due to insufficient …

Oct 25, 2024
CVE-2024-41618
9.8 CRITICAL

Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to SQL Injection in the `transaction_delete_group` function. The vulnerability is due to improper sanitization of user input …

Oct 24, 2024
CVE-2024-41617
9.8 CRITICAL

Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to Incorrect Access Control. The `redirect_if_not_loggedin` function in `functions_security.php` fails to terminate script execution after redirecting unauthenticated …

Oct 24, 2024
CVE-2024-7763
9.8 CRITICAL

In WhatsUp Gold versions released before 2024.0.0, an Authentication Bypass issue exists which allows an attacker to obtain encrypted user credentials.

Oct 24, 2024
CVE-2024-47883
9.1 CRITICAL

The OpenRefine fork of the MIT Simile Butterfly server is a modular web application framework. The Butterfly framework uses the `java.net.URL` class to refer to …

Oct 24, 2024
CVE-2024-48145
9.1 CRITICAL

A prompt injection vulnerability in the chatbox of Netangular Technologies ChatNet AI Version v1.0 allows attackers to access and exfiltrate all previous and subsequent chat …

Oct 24, 2024
CVE-2024-48144
9.1 CRITICAL

A prompt injection vulnerability in the chatbox of Fusion Chat Chat AI Assistant Ask Me Anything v1.2.4.0 allows attackers to access and exfiltrate all previous …

Oct 24, 2024
CVE-2024-48143
9.1 CRITICAL

A lack of rate limiting in the OTP validation component of Digitory Multi Channel Integrated POS v1.0 allows attackers to gain access to the ordering …

Oct 24, 2024
CVE-2024-48514
9.8 CRITICAL

php-heic-to-jpg <= 1.0.5 is vulnerable to code injection (fixed in 1.0.6). An attacker who can upload heic images is able to execute code on the …

Oct 24, 2024
CVE-2024-46478
9.8 CRITICAL

HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681.

Oct 24, 2024
CVE-2024-48548
9.3 CRITICAL

The APK file in Cloud Smart Lock v2.0.1 has a leaked a URL that can call an API for binding physical devices. This vulnerability allows …

Oct 24, 2024
CVE-2024-48539
9.8 CRITICAL

Neye3C v4.5.2.0 was discovered to contain a hardcoded encryption key in the firmware update mechanism.

Oct 24, 2024
CVE-2024-44206
9.3 CRITICAL

An issue in the handling of URL protocols was addressed with improved logic. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, …

Oct 24, 2024
CVE-2024-48538
9.8 CRITICAL

Incorrect access control in the firmware update and download processes of Neye3C v4.5.2.0 allows attackers to access sensitive information by analyzing the code and data …

Oct 24, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.