CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-49253
8.6 HIGH

Relative Path Traversal vulnerability in JamesPark.ninja Analyse Uploads analyse-uploads allows Relative Path Traversal.This issue affects Analyse Uploads: from n/a through <= 0.5.

Oct 16, 2024
CVE-2024-49252
5.3 MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in VaultDweller Leyka leyka.This issue affects Leyka: from n/a through <= 3.31.6.

Oct 16, 2024
CVE-2024-49251
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Acnoo Maan Addons For Elementor maan-elementor-addons allows Local Code …

Oct 16, 2024
CVE-2024-49245
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in nahimsalami Ahime Image Printer ahime-image-printer.This issue affects Ahime Image Printer: from n/a …

Oct 16, 2024
CVE-2024-49242
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Shafiq Digital Lottery digital-lottery allows Upload a Web Shell to a Web Server.This issue affects Digital …

Oct 16, 2024
CVE-2024-49227
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in foter Free Stock Photos Foter free-stock-photos-foter allows Object Injection.This issue affects Free Stock Photos Foter: from n/a through <= …

Oct 16, 2024
CVE-2024-49226
8.8 HIGH

Deserialization of Untrusted Data vulnerability in taketin TAKETIN To WP Membership taketin-to-wp-membership allows Object Injection.This issue affects TAKETIN To WP Membership: from n/a through <= …

Oct 16, 2024
CVE-2024-49218
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Al Imran Akash Recently recently-viewed-most-viewed-and-sold-products-for-woocommerce allows Object Injection.This issue affects Recently: from n/a through <= 1.1.

Oct 16, 2024
CVE-2024-49216
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in jclay06 Feed Comments Number feed-comments-number allows Upload a Web Shell to a Web Server.This issue affects …

Oct 16, 2024
CVE-2024-48035
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in takayukii ACF Images Search And Insert acf-images-search-and-insert allows Upload a Web Shell to a Web Server.This …

Oct 16, 2024
CVE-2024-48034
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in fliperrr Creates 3D Flipbook, PDF Flipbook create-flipbook-from-pdf allows Upload a Web Shell to a Web Server.This …

Oct 16, 2024
CVE-2024-48030
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Webextends Telecash Ricaricaweb telecash-ricaricaweb allows Object Injection.This issue affects Telecash Ricaricaweb: from n/a through <= 2.2.

Oct 16, 2024
CVE-2024-48029
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hung Trang Si SB Random Posts Widget sb-random-posts-widget allows …

Oct 16, 2024
CVE-2024-48028
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Boyan Raichev IP Loc8 ip-loc8 allows Object Injection.This issue affects IP Loc8: from n/a through <= 1.1.

Oct 16, 2024
CVE-2024-48027
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in xaraartech External featured image from bing external-featured-image-from-bing allows Upload a Web Shell to a Web Server.This …

Oct 16, 2024
CVE-2024-48026
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in GMRobbins Disc Golf Manager disc-golf-manager allows Object Injection.This issue affects Disc Golf Manager: from n/a through <= 1.0.0.

Oct 16, 2024
CVE-2024-47649
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in THATplugin Iconize iconize.This issue affects Iconize: from n/a through <= 1.2.4.

Oct 16, 2024
CVE-2024-47645
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Danish Ali Malik Top Bar – PopUps – by WPOptin wpoptin allows …

Oct 16, 2024
CVE-2024-47637
8.8 HIGH

Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue affects LiteSpeed Cache: from n/a through <= 6.4.1.

Oct 16, 2024
CVE-2024-47351
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The CSSIgniter Team MaxSlider maxslider allows Path Traversal.This issue affects MaxSlider: from …

Oct 16, 2024
CVE-2024-22034
5.5 MEDIUM

Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc …

Oct 16, 2024
CVE-2024-22033
6.3 MEDIUM

The OBS service obs-service-download_url was vulnerable to a command injection vulnerability. The attacker could provide a configuration to the service that allowed to execute command …

Oct 16, 2024
CVE-2024-22032
6.5 MEDIUM

A vulnerability has been identified in which an RKE1 cluster keeps constantly reconciling when secrets encryption configuration is enabled. When reconciling, the Kube API secret …

Oct 16, 2024
CVE-2024-22030
8.0 HIGH

A vulnerability has been identified within Rancher that can be exploited in narrow circumstances through a man-in-the-middle (MITM) attack. An attacker would need to have …

Oct 16, 2024
CVE-2024-22029
7.8 HIGH

Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root

Oct 16, 2024
CVE-2023-32189
5.9 MEDIUM

Insecure handling of ssh keys used to bootstrap clients allows local attackers to potentially gain access to the keys

Oct 16, 2024
CVE-2024-49271
9.1 CRITICAL

Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Command Injection.This issue affects Unlimited Elements For …

Oct 16, 2024
CVE-2024-49257
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Denis Azz Anonim Posting azz-anonim-posting allows Upload a Web Shell to a Web Server.This issue affects …

Oct 16, 2024
CVE-2024-49247
9.8 CRITICAL

Authentication Bypass Using an Alternate Path or Channel vulnerability in SK BuddyPress Better Registration better-bp-registration allows Authentication Bypass.This issue affects BuddyPress Better Registration: from n/a …

Oct 16, 2024
CVE-2024-48042
9.1 CRITICAL

Deserialization of Untrusted Data vulnerability in supsystic Contact Form by Supsystic contact-form-by-supsystic allows Command Injection.This issue affects Contact Form by Supsystic: from n/a through <= …

Oct 16, 2024
CVE-2024-10024
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Pharmacy Management System 1.0. This issue affects some unknown processing of the file …

Oct 16, 2024
CVE-2024-10023
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Pharmacy Management System 1.0. This vulnerability affects unknown code of the file /php/add_new_medicine.php. The manipulation of …

Oct 16, 2024
CVE-2023-32196
6.6 MEDIUM

A vulnerability has been identified whereby privilege escalation checks are not properly enforced for RoleTemplateobjects when external=true, which in specific scenarios can lead to privilege …

Oct 16, 2024
CVE-2023-32194
7.2 HIGH

A vulnerability has been identified when granting a create or * global role for a resource type of "namespaces"; no matter the API group, the …

Oct 16, 2024
CVE-2023-32193
8.3 HIGH

A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in Norman's public API endpoint can be exploited. This can lead to an attacker …

Oct 16, 2024
CVE-2023-32192
8.3 HIGH

A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in the API Server's public API endpoint can be exploited, allowing an attacker to …

Oct 16, 2024
CVE-2023-32191
9.9 CRITICAL

When RKE provisions a cluster, it stores the cluster state in a configmap called `full-cluster-state` inside the `kube-system` namespace of the cluster itself. The information …

Oct 16, 2024
CVE-2020-36841
5.3 MEDIUM

The WooCommerce Smart Coupons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the woocommerce_coupon_admin_init function in versions up …

Oct 16, 2024
CVE-2024-8040
7.7 HIGH

An authorization bypass through user-controlled key vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an authenticated attacker to access some unauthorized data.

Oct 16, 2024
CVE-2024-6380
8.7 HIGH

A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary …

Oct 16, 2024
CVE-2024-10022
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. This affects an unknown part of the file /php/manage_supplier.php?action=search. The manipulation …

Oct 16, 2024
CVE-2024-10021
6.3 MEDIUM

A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Oct 16, 2024
CVE-2023-32190
7.8 HIGH

mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.

Oct 16, 2024
CVE-2024-8921
6.4 MEDIUM

The Zita Elementor Site Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Oct 16, 2024
CVE-2024-9444
6.4 MEDIUM

The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Oct 16, 2024
CVE-2024-9858
7.8 HIGH

There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windows installs. A local "m2cuser" was greated …

Oct 16, 2024
CVE-2023-32188

A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to …

Oct 16, 2024
CVE-2023-22650
8.8 HIGH

A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from the configured authentication provider (AP). …

Oct 16, 2024
CVE-2024-9540
4.3 MEDIUM

The Sina Extension for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.7 via the render …

Oct 16, 2024
CVE-2024-9061
7.3 HIGH

The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary shortcode execution via the wp_ajax_nopriv_shortcode_Api_Add AJAX …

Oct 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.