CVE Database

9973+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-36522
9.8 CRITICAL

The default configuration of XSLTResourceStream.java is vulnerable to remote code execution via XSLT injection when processing input from an untrusted source without validation. Users are …

Jul 12, 2024
CVE-2024-6328
9.8 CRITICAL

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in all versions up …

Jul 12, 2024
CVE-2024-6396
9.8 CRITICAL

A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host server and exfiltrate arbitrary data. …

Jul 12, 2024
CVE-2024-36435
9.8 CRITICAL

An issue was discovered on Supermicro BMC firmware in select X11, X12, H12, B12, X13, H13, and B13 motherboards (and CMM6 modules). An unauthenticated user …

Jul 11, 2024
CVE-2024-6407
9.8 CRITICAL

CWE-200: Information Exposure vulnerability exists that could cause disclosure of credentials when a specially crafted message is sent to the device.

Jul 11, 2024
CVE-2024-6624
9.8 CRITICAL

The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3. This is due to improper …

Jul 11, 2024
CVE-2024-6385
9.6 CRITICAL

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from …

Jul 11, 2024
CVE-2024-6397
9.8 CRITICAL

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 0.1.0.44. …

Jul 11, 2024
CVE-2024-40618
9.6 CRITICAL

Whale browser before 3.26.244.21 allows an attacker to execute malicious JavaScript due to improper sanitization when processing a built-in extension.

Jul 11, 2024
CVE-2024-6037
9.1 CRITICAL

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir). …

Jul 10, 2024
CVE-2024-6036
9.1 CRITICAL

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to restart the server at will by sending a specific request to the `/queue/join?` endpoint with …

Jul 10, 2024
CVE-2024-37310
9.0 CRITICAL

EVerest is an EV charging software stack. An integer overflow in the "v2g_incoming_v2gtp" function in the v2g_server.cpp implementation can allow a remote attacker to overflow …

Jul 10, 2024
CVE-2024-25077
9.8 CRITICAL

An issue was discovered on Renesas SmartBond DA14691, DA14695, DA14697, and DA14699 devices. The Nonce used for on-the-fly decryption of flash images is stored in …

Jul 10, 2024
CVE-2024-5910
9.8 CRITICAL KEV

Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to …

Jul 10, 2024
CVE-2024-37770
9.1 CRITICAL

14Finger v1.1 was discovered to contain a remote command execution (RCE) vulnerability in the fingerprint function. This vulnerability allows attackers to execute arbitrary commands via …

Jul 10, 2024
CVE-2024-37113
9.8 CRITICAL

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7.

Jul 10, 2024
CVE-2024-5217
9.8 CRITICAL KEV

ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an …

Jul 10, 2024
CVE-2024-4879
9.8 CRITICAL KEV

ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user …

Jul 10, 2024
CVE-2024-6422
9.8 CRITICAL

An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data.

Jul 10, 2024
CVE-2024-39071
9.8 CRITICAL

Fujian Kelixun <=7.6.6.4391 is vulnerable to SQL Injection in send_event.php.

Jul 9, 2024
CVE-2024-37873
9.8 CRITICAL

SQL injection vulnerability in view_payslip.php in Itsourcecode Payroll Management System Project In PHP With Source Code 1.0 allows remote attackers to execute arbitrary SQL commands …

Jul 9, 2024
CVE-2024-37870
9.8 CRITICAL

SQL injection vulnerability in processscore.php in Learning Management System Project In PHP With Source Code 1.0 allows attackers to execute arbitrary SQL commands via the …

Jul 9, 2024
CVE-2023-48194
9.8 CRITICAL

Vulnerability in Tenda AC8v4 .V16.03.34.09 due to sscanf and the last digit of s8 being overwritten with \x0. After executing set_client_qos, control over the gp …

Jul 9, 2024
CVE-2024-39171
9.8 CRITICAL

Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via writing specific statements to .htaccess …

Jul 9, 2024
CVE-2024-38089
9.1 CRITICAL

Microsoft Defender for IoT Elevation of Privilege Vulnerability

Jul 9, 2024
CVE-2024-38077
9.8 CRITICAL

Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-38076
9.8 CRITICAL

Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-38074
9.8 CRITICAL

Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-36526
9.8 CRITICAL

ZKTeco ZKBio CVSecurity v6.1.1 was discovered to contain a hardcoded cryptographic key.

Jul 9, 2024
CVE-2024-6611
9.8 CRITICAL

A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128.

Jul 9, 2024
CVE-2024-6602
9.8 CRITICAL

A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, …

Jul 9, 2024
CVE-2024-3596
9.0 CRITICAL

RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to …

Jul 9, 2024
CVE-2024-39872
9.6 CRITICAL

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly assign rights to temporary …

Jul 9, 2024
CVE-2024-37424
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Automattic Newspack Blocks allows Upload a Web Shell to a Web Server.This issue affects Newspack Blocks: …

Jul 9, 2024
CVE-2024-37420
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in WPZita Zita Elementor Site Library allows Upload a Web Shell to a Web Server.This issue affects …

Jul 9, 2024
CVE-2024-37418
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.4.6.

Jul 9, 2024
CVE-2023-3287
9.9 CRITICAL

A BOLA vulnerability in POST /admins allows a low privileged user to create a high privileged user (admin) in the system. This results in privilege …

Jul 9, 2024
CVE-2023-38055
9.6 CRITICAL

A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} allows a low privileged user to fetch, modify or delete the services of any user (including admin). …

Jul 9, 2024
CVE-2023-38054
9.9 CRITICAL

A BOLA vulnerability in GET, PUT, DELETE /customers/{customerId} allows a low privileged user to fetch, modify or delete a low privileged user (customer). This results …

Jul 9, 2024
CVE-2023-38053
9.9 CRITICAL

A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} allows a low privileged user to fetch, modify or delete the settings of any user (including admin). …

Jul 9, 2024
CVE-2023-38052
9.9 CRITICAL

A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} allows a low privileged user to fetch, modify or delete a high privileged user (admin). This results …

Jul 9, 2024
CVE-2023-38051
9.9 CRITICAL

A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} allows a low privileged user to fetch, modify or delete a low privileged user (secretary). This results …

Jul 9, 2024
CVE-2023-38050
9.1 CRITICAL

A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} allows a low privileged user to fetch, modify or delete a webhook of any user (including admin). …

Jul 9, 2024
CVE-2023-38049
9.9 CRITICAL

A BOLA vulnerability in GET, PUT, DELETE /appointments/{appointmentId} allows a low privileged user to fetch, modify or delete an appointment of any user (including admin). …

Jul 9, 2024
CVE-2023-38048
9.9 CRITICAL

A BOLA vulnerability in GET, PUT, DELETE /providers/{providerId} allows a low privileged user to fetch, modify or delete a privileged user (provider). This results in …

Jul 9, 2024
CVE-2024-3604
9.9 CRITICAL

The OSM – OpenStreetMap plugin for WordPress is vulnerable to SQL Injection via the 'tagged_filter' attribute of the 'osm_map_v3' shortcode in all versions up to, …

Jul 9, 2024
CVE-2024-37112
10.0 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from …

Jul 9, 2024
CVE-2024-6314
9.8 CRITICAL

The IQ Testimonials plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'process_image_upload' function in versions up …

Jul 9, 2024
CVE-2024-6313
9.8 CRITICAL

The Gutenberg Forms plugin for WordPress is vulnerable to arbitrary file uploads due to the users can specify the allowed file types in the 'upload' …

Jul 9, 2024
CVE-2024-37555
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in ZealousWeb Generate PDF using Contact Form 7 generate-pdf-using-contact-form-7.This issue affects Generate PDF using Contact Form 7: …

Jul 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.