CVE Database

9973+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-51424
9.8 CRITICAL

Improper Privilege Management vulnerability in Saleswonder Team WebinarIgnition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through 3.05.0.

May 17, 2024
CVE-2024-31351
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Copymatic Copymatic – AI Content Writer & Generator.This issue affects Copymatic – AI Content Writer & …

May 17, 2024
CVE-2023-37999
9.8 CRITICAL

Improper Privilege Management vulnerability in HasThemes HT Mega allows Privilege Escalation.This issue affects HT Mega: from n/a through 2.2.0.

May 17, 2024
CVE-2023-32297
9.0 CRITICAL

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LWS LWS Affiliation allows PHP Local File Inclusion.This issue affects LWS Affiliation: …

May 17, 2024
CVE-2023-32244
9.8 CRITICAL

Improper Privilege Management vulnerability in xtemos Woodmart Core allows Privilege Escalation.This issue affects Woodmart Core: from n/a through 1.0.36.

May 17, 2024
CVE-2023-26540
9.8 CRITICAL

Improper Privilege Management vulnerability in Favethemes Houzez allows Privilege Escalation.This issue affects Houzez: from n/a through 2.7.1.

May 17, 2024
CVE-2023-26009
9.8 CRITICAL

Improper Privilege Management vulnerability in Favethemes Houzez Login Register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through 2.6.3.

May 17, 2024
CVE-2023-25701
9.8 CRITICAL

Improper Privilege Management vulnerability in WhatArmy WatchTowerHQ allows Privilege Escalation.This issue affects WatchTowerHQ: from n/a through 3.6.16.

May 17, 2024
CVE-2023-25444
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Using Malicious …

May 17, 2024
CVE-2023-23645
9.9 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in MainWP MainWP Code Snippets Extension allows Code Injection.This issue affects MainWP Code Snippets Extension: from …

May 17, 2024
CVE-2024-3551
9.8 CRITICAL

The Penci Soledad Data Migrator plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.0 via the 'data' …

May 17, 2024
CVE-2024-22476
10.0 CRITICAL

Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially enable escalation of privilege via remote …

May 16, 2024
CVE-2024-4609
9.8 CRITICAL

A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor to inject a malicious SQL statement if …

May 16, 2024
CVE-2024-35187
9.1 CRITICAL

Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, attackers who achieved Arbitrary Code Execution as the stalwart-mail user (including web interface …

May 16, 2024
CVE-2023-48643
9.8 CRITICAL

Shrubbery tac_plus 2.x, 3.x. and 4.x through F4.0.4.28 allows unauthenticated Remote Command Execution. The product allows users to configure authorization checks as shell commands through …

May 16, 2024
CVE-2024-4992
9.8 CRITICAL

Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_kuliah/aksi_kuliah.php parameter in nim. This vulnerability could allow a remote attacker to send a specially …

May 16, 2024
CVE-2024-4991
9.8 CRITICAL

Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_pass/aksi_pass.php parameter in nama_lengkap. This vulnerability could allow a remote attacker to send a specially …

May 16, 2024
CVE-2024-4826
9.8 CRITICAL

SQL injection vulnerability in Simple PHP Shopping Cart affecting version 0.9. This vulnerability could allow an attacker to retrieve all the information stored in the …

May 16, 2024
CVE-2024-4326
9.8 CRITICAL

A vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulnerability stems from insufficient protection of the `/apply_settings` and …

May 16, 2024
CVE-2024-4223
9.8 CRITICAL

The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check …

May 16, 2024
CVE-2024-4078
9.8 CRITICAL

A vulnerability in the parisneo/lollms, specifically in the `/unInstall_binding` endpoint, allows for arbitrary code execution due to insufficient sanitization of user input. The issue arises …

May 16, 2024
CVE-2024-2366
9.0 CRITICAL

A remote code execution vulnerability exists in the parisneo/lollms-webui application, specifically within the reinstall_binding functionality in lollms_core/lollms/server/endpoints/lollms_binding_infos.py of the latest version. The vulnerability arises due …

May 16, 2024
CVE-2024-2361
9.6 CRITICAL

A vulnerability in the parisneo/lollms-webui allows for arbitrary file upload and read due to insufficient sanitization of user-supplied input. Specifically, the issue resides in the …

May 16, 2024
CVE-2024-2358
9.8 CRITICAL

A path traversal vulnerability in the '/apply_settings' endpoint of parisneo/lollms-webui allows attackers to execute arbitrary code. The vulnerability arises due to insufficient sanitization of user-supplied …

May 16, 2024
CVE-2024-4947
9.6 CRITICAL KEV

Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

May 15, 2024
CVE-2024-34025
9.8 CRITICAL

CyberPower PowerPanel business application code contains a hard-coded set of authentication credentials. This could result in an attacker bypassing authentication and gaining administrator privileges.

May 15, 2024
CVE-2024-33625
9.8 CRITICAL

CyberPower PowerPanel business application code contains a hard-coded JWT signing key. This could result in an attacker forging JWT tokens to bypass authentication.

May 15, 2024
CVE-2024-32053
9.8 CRITICAL

Hard-coded credentials are used by the CyberPower PowerPanel platform to authenticate to the database, other services, and the cloud. This could result in an attacker …

May 15, 2024
CVE-2024-32047
9.8 CRITICAL

Hard-coded credentials for the CyberPower PowerPanel test server can be found in the production code. This might result in an attacker gaining access to the …

May 15, 2024
CVE-2024-3319
9.1 CRITICAL

An issue was identified in the Identity Security Cloud (ISC) Transform preview and IdentityProfile preview API endpoints that allowed an authenticated administrator to execute user-defined …

May 15, 2024
CVE-2024-34955
9.8 CRITICAL

Code-projects Budget Management 1.0 is vulnerable to SQL Injection via the delete parameter.

May 15, 2024
CVE-2024-4893
9.8 CRITICAL

DigiWin EasyFlow .NET lacks validation for certain input parameters, allowing remote attackers to inject arbitrary SQL commands. This vulnerability enables unauthorized access to read, modify, …

May 15, 2024
CVE-2024-32888
10.0 CRITICAL

The Amazon JDBC Driver for Redshift is a Type 4 JDBC driver that provides database connectivity through the standard JDBC application program interfaces (APIs) available …

May 15, 2024
CVE-2024-31473
9.8 CRITICAL

There is a command injection vulnerability in the underlying deauthentication service that could lead to unauthenticated remote code execution by sending specially crafted packets destined …

May 14, 2024
CVE-2024-31472
9.8 CRITICAL

There are command injection vulnerabilities in the underlying Soft AP Daemon service that could lead to unauthenticated remote code execution by sending specially crafted packets …

May 14, 2024
CVE-2024-31471
9.8 CRITICAL

There is a command injection vulnerability in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets …

May 14, 2024
CVE-2024-31470
9.8 CRITICAL

There is a buffer overflow vulnerability in the underlying SAE (Simultaneous Authentication of Equals) service that could lead to unauthenticated remote code execution by sending …

May 14, 2024
CVE-2024-31469
9.8 CRITICAL

There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined …

May 14, 2024
CVE-2024-31468
9.8 CRITICAL

There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined …

May 14, 2024
CVE-2024-31467
9.8 CRITICAL

There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to …

May 14, 2024
CVE-2024-31466
9.8 CRITICAL

There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to …

May 14, 2024
CVE-2024-32002
9.0 CRITICAL

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a …

May 14, 2024
CVE-2024-4778
9.8 CRITICAL

Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of …

May 14, 2024
CVE-2024-4764
9.8 CRITICAL

Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects Firefox < 126.

May 14, 2024
CVE-2024-33485
9.8 CRITICAL

SQL Injection vulnerability in CASAP Automated Enrollment System using PHP/MySQLi with Source Code V1.0 allows a remote attacker to obtain sensitive information via a crafted …

May 14, 2024
CVE-2024-27107
9.6 CRITICAL

Weak account password in GE HealthCare EchoPAC products

May 14, 2024
CVE-2024-34716
9.6 CRITICAL

PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-thread feature flag enabled is present starting …

May 14, 2024
CVE-2024-34256
9.8 CRITICAL

OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.

May 14, 2024
CVE-2024-33868
9.8 CRITICAL

An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection.

May 14, 2024
CVE-2024-33863
9.8 CRITICAL

An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/Cdn/GetFile local file inclusion.

May 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.