CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10658
6.3 MEDIUM

A vulnerability classified as critical was found in Tongda OA up to 11.10. Affected by this vulnerability is an unknown functionality of the file /pda/approve_center/check_seal.php. …

Nov 1, 2024
CVE-2024-10657
6.3 MEDIUM

A vulnerability classified as critical has been found in Tongda OA up to 11.10. Affected is an unknown function of the file /pda/approve_center/prcs_info.php. The manipulation …

Nov 1, 2024
CVE-2024-10656
6.3 MEDIUM

A vulnerability was found in Tongda OA 2017 up to 11.9. It has been rated as critical. This issue affects some unknown processing of the …

Nov 1, 2024
CVE-2024-51407
6.2 MEDIUM

Floodlight SDN OpenFlow Controller v.1.2 has an issue that allows local hosts to construct false broadcast ports causing inter-host communication anomalies.

Nov 1, 2024
CVE-2024-51406
6.2 MEDIUM

Floodlight SDN Open Flow Controller v.1.2 has an issue that allows local hosts to build fake LLDP packets that allow specific clusters to be missed …

Nov 1, 2024
CVE-2024-48270
7.5 HIGH

An issue in the component /logins of oasys v1.1 allows attackers to access sensitive information via a burst attack.

Nov 1, 2024
CVE-2024-37094
8.2 HIGH

Missing Authorization vulnerability in StylemixThemes MasterStudy LMS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MasterStudy LMS: from n/a through 3.2.12.

Nov 1, 2024
CVE-2024-10655
6.3 MEDIUM

A vulnerability was found in Tongda OA 2017 up to 11.9. It has been declared as critical. This vulnerability affects unknown code of the file …

Nov 1, 2024
CVE-2024-7456
9.8 CRITICAL

A SQL injection vulnerability exists in the `/api/v1/external-users` route of lunary-ai/lunary version v1.4.2. The `order by` clause of the SQL query uses `sql.unsafe` without prior …

Nov 1, 2024
CVE-2024-10654
5.3 MEDIUM

A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Nov 1, 2024
CVE-2024-10367
6.4 MEDIUM

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API …

Nov 1, 2024
CVE-2024-10653
7.2 HIGH

IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrative privileges to inject and …

Nov 1, 2024
CVE-2024-10652
6.1 MEDIUM

IDExpert from CHANGING Information Technology does not properly validate a parameter for a specific functionality, allowing unauthenticated remote attackers to inject JavsScript code and perform …

Nov 1, 2024
CVE-2024-10651
4.9 MEDIUM

IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrator privileges to exploit this …

Nov 1, 2024
CVE-2024-10232
6.4 MEDIUM

The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's atomchat shortcode in all versions …

Nov 1, 2024
CVE-2024-9655
6.4 MEDIUM

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon …

Nov 1, 2024
CVE-2024-7424
5.4 MEDIUM

The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to unauthorized modification of and access to data due to a missing capability …

Nov 1, 2024
CVE-2024-0106
8.7 HIGH

NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit (DPU) contains a vulnerability where an attacker may cause an improper handling of insufficient privileges …

Nov 1, 2024
CVE-2024-0105
8.9 HIGH

NVIDIA ConnectX Firmware contains a vulnerability where an attacker may cause an improper handling of insufficient privileges issue. A successful exploit of this vulnerability may …

Nov 1, 2024
CVE-2024-49501
5.7 MEDIUM

Sysmac Studio provided by OMRON Corporation contains an incorrect authorization vulnerability. If this vulnerability is exploited, an attacker may access the program which is protected …

Nov 1, 2024
CVE-2024-47939
7.7 HIGH

Stack-based buffer overflow vulnerability exists in multiple laser printers and MFPs which implement Ricoh Web Image Monitor. If this vulnerability is exploited, receiving a specially …

Nov 1, 2024
CVE-2024-21510
5.4 MEDIUM

Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making …

Nov 1, 2024
CVE-2024-10620
5.3 MEDIUM

A vulnerability was found in knightliao Disconf 2.6.36. It has been classified as critical. This affects an unknown part of the file /api/config/list of the …

Nov 1, 2024
CVE-2024-10619
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.10. Affected is an unknown function of the file /pda/reportshop/next_detail.php. …

Nov 1, 2024
CVE-2024-10618
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Tongda OA 2017 up to 11.10. This issue affects some unknown processing of the …

Nov 1, 2024
CVE-2024-10617
6.3 MEDIUM

A vulnerability classified as critical was found in Tongda OA up to 11.10. This vulnerability affects unknown code of the file /pda/workflow/check_seal.php. The manipulation of …

Nov 1, 2024
CVE-2024-10616
6.3 MEDIUM

A vulnerability classified as critical has been found in Tongda OA up to 11.9. This affects an unknown part of the file /pda/workflow/webSignSubmit.php. The manipulation …

Nov 1, 2024
CVE-2024-10615
6.3 MEDIUM

A vulnerability was found in Tongda OA 2017 up to 11.10. It has been rated as critical. Affected by this issue is some unknown functionality …

Nov 1, 2024
CVE-2024-10613
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. Affected by this vulnerability is the function delSystemEncryptPolicy of the file …

Nov 1, 2024
CVE-2024-10612
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. Affected is the function removeHookInvalidCourse of the file /com/esafenet/servlet/system/HookInvalidCourseService.java. The manipulation …

Nov 1, 2024
CVE-2024-10611
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5 and classified as critical. This issue affects the function delProtocol of the file /com/esafenet/servlet/system/PrintScreenListService.java. The manipulation of …

Nov 1, 2024
CVE-2024-10610
6.3 MEDIUM

A vulnerability has been found in ESAFENET CDG 5 and classified as critical. This vulnerability affects the function delProtocol of the file /com/esafenet/servlet/system/ProtocolService.java. The manipulation …

Nov 1, 2024
CVE-2024-10609
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System Project 1.0. This affects an unknown part of the file typeadd.php. …

Nov 1, 2024
CVE-2024-10608
7.3 HIGH

A vulnerability was found in code-projects Courier Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Nov 1, 2024
CVE-2024-10607
7.3 HIGH

A vulnerability was found in code-projects Courier Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /track-result.php. …

Nov 1, 2024
CVE-2024-10605
4.3 MEDIUM

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as problematic. This affects an unknown part of the file …

Nov 1, 2024
CVE-2024-10602
6.3 MEDIUM

A vulnerability was found in Tongda OA 2017 up to 11.9 and classified as critical. Affected by this issue is some unknown functionality of the …

Nov 1, 2024
CVE-2024-10601
6.3 MEDIUM

A vulnerability has been found in Tongda OA 2017 up to 11.10 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Oct 31, 2024
CVE-2024-10600
7.3 HIGH

A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.6. Affected is an unknown function of the file pda/appcenter/submenu.php. …

Oct 31, 2024
CVE-2024-6480
6.4 MEDIUM

The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'no_of_reviews' attribute in the woocommerce_reviews shortcode in all …

Oct 31, 2024
CVE-2024-6479
6.5 MEDIUM

The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'no_of_reviews' attribute in the woocommerce_reviews shortcode in all versions …

Oct 31, 2024
CVE-2024-10599
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Tongda OA 2017 up to 11.7. This issue affects some unknown processing of the …

Oct 31, 2024
CVE-2024-10598
5.3 MEDIUM

A vulnerability classified as critical was found in Tongda OA 11.2/11.3/11.4/11.5/11.6. This vulnerability affects unknown code of the file general/hr/setting/attendance/leave/data.php of the component Annual Leave …

Oct 31, 2024
CVE-2024-10597
6.3 MEDIUM

A vulnerability classified as critical has been found in ESAFENET CDG 5. This affects the function delPolicyAction of the file /com/esafenet/servlet/system/PolicyActionService.java. The manipulation of the …

Oct 31, 2024
CVE-2024-10596
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. Affected by this issue is the function delEntryptPolicySort of the file …

Oct 31, 2024
CVE-2024-10595
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. Affected by this vulnerability is the function delFile/delDifferCourseList of the file …

Oct 31, 2024
CVE-2024-10594
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. Affected is the function docHistory of the file /com/esafenet/servlet/fileManagement/FileDirectoryService.java. The manipulation …

Oct 31, 2024
CVE-2024-48360
7.5 HIGH

Qualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /request/viewValidacao.php.

Oct 31, 2024
CVE-2024-48359
9.8 CRITICAL

Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parameter.

Oct 31, 2024
CVE-2024-39722
7.5 HIGH

An issue was discovered in Ollama before 0.1.46. It exposes which files exist on the server on which it is deployed via path traversal in …

Oct 31, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.