CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9915
8.8 HIGH

A vulnerability classified as critical was found in D-Link DIR-619L B1 2.06. Affected by this vulnerability is the function formVirtualServ of the file /goform/formVirtualServ. The …

Oct 13, 2024
CVE-2024-9914
8.8 HIGH

A vulnerability classified as critical has been found in D-Link DIR-619L B1 2.06. Affected is the function formSetWizardSelectMode of the file /goform/formSetWizardSelectMode. The manipulation of …

Oct 13, 2024
CVE-2024-9913
8.8 HIGH

A vulnerability was found in D-Link DIR-619L B1 2.06. It has been rated as critical. This issue affects the function formSetRoute of the file /goform/formSetRoute. …

Oct 13, 2024
CVE-2024-9912
8.8 HIGH

A vulnerability was found in D-Link DIR-619L B1 2.06. It has been declared as critical. This vulnerability affects the function formSetQoS of the file /goform/formSetQoS. …

Oct 13, 2024
CVE-2024-9911
8.8 HIGH

A vulnerability was found in D-Link DIR-619L B1 2.06. It has been classified as critical. This affects the function formSetPortTr of the file /goform/formSetPortTr. The …

Oct 13, 2024
CVE-2024-9910
8.8 HIGH

A vulnerability was found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this issue is the function formSetPassword of the file /goform/formSetPassword. …

Oct 13, 2024
CVE-2024-9909
8.8 HIGH

A vulnerability has been found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this vulnerability is the function formSetMuti of the file …

Oct 13, 2024
CVE-2024-6959
7.1 HIGH

A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack when uploading an audio file. If an attacker appends a large …

Oct 13, 2024
CVE-2024-9908
5.5 MEDIUM

A vulnerability, which was classified as critical, was found in D-Link DIR-619L B1 2.06. Affected is the function formSetMACFilter of the file /goform/formSetMACFilter. The manipulation …

Oct 13, 2024
CVE-2024-9907
3.7 LOW

A vulnerability classified as problematic was found in QileCMS up to 1.1.3. This vulnerability affects the function sendEmail of the file /qilecms/user/controller/Forget.php of the component …

Oct 13, 2024
CVE-2024-9906
3.5 LOW

A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /admin/?page=inventory/view_inventory&id=2. The …

Oct 13, 2024
CVE-2024-9905
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the file …

Oct 13, 2024
CVE-2024-9904
4.7 MEDIUM

A vulnerability classified as critical was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This vulnerability affects the function pictureUpload of the file /admin/File/pictureUpload. …

Oct 13, 2024
CVE-2024-9903
4.7 MEDIUM

A vulnerability classified as critical has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This affects the function fileUpload of the file /admin/File/fileUpload. …

Oct 12, 2024
CVE-2024-49193
7.5 HIGH

Zendesk before 2024-07-02 allows remote attackers to read ticket history via e-mail spoofing, because Cc fields are extracted from incoming e-mail messages and used to …

Oct 12, 2024
CVE-2024-9894
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Blood Bank System 1.0. Affected is an unknown function of the file reset.php. The …

Oct 12, 2024
CVE-2024-8902
4.3 MEDIUM

The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.8 via the render_column function …

Oct 12, 2024
CVE-2024-8757
7.2 HIGH

The WP Post Author – Boost Your Blog's Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form …

Oct 12, 2024
CVE-2024-9696
6.4 MEDIUM

The Rescue Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rescue_tab' shortcode in all versions up to, and including, 2.8 …

Oct 12, 2024
CVE-2024-9595
6.4 MEDIUM

The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the table cell content in all versions …

Oct 12, 2024
CVE-2024-8915
6.4 MEDIUM

The Category Icon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due …

Oct 12, 2024
CVE-2024-8760
5.3 MEDIUM

The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to CSS Injection in all versions up to, and including, 3.13.6. This makes …

Oct 12, 2024
CVE-2024-9756
4.3 MEDIUM

The Order Attachments for WooCommerce plugin for WordPress is vulnerable to unauthorized limited arbitrary file uploads due to a missing capability check on the wcoa_add_attachment …

Oct 12, 2024
CVE-2024-9704
6.4 MEDIUM

The Social Sharing (by Danny) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dvk_social_sharing' shortcode in all versions up to, and …

Oct 12, 2024
CVE-2024-9047
9.8 CRITICAL

The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. This makes it …

Oct 12, 2024
CVE-2024-9824
4.3 MEDIUM

The ImagePress – Image Gallery plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the …

Oct 12, 2024
CVE-2024-9778
4.3 MEDIUM

The ImagePress – Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.2. This is due …

Oct 12, 2024
CVE-2024-9776
4.4 MEDIUM

The ImagePress – Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.2 …

Oct 12, 2024
CVE-2024-9670
6.1 MEDIUM

The 2D Tag Cloud plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Oct 12, 2024
CVE-2024-9656
6.4 MEDIUM

The Mynx Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.27.8 …

Oct 12, 2024
CVE-2024-9187
4.3 MEDIUM

The Read more By Adam plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the deleteRm() function …

Oct 12, 2024
CVE-2024-7489
4.4 MEDIUM

The Forms for Mailchimp by Optin Cat – Grow Your MailChimp List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form color …

Oct 12, 2024
CVE-2024-9860
5.4 MEDIUM

The Bridge Core plugin for WordPress is vulnerable to unauthorized modification of data or loss of data due to a missing capability check on the …

Oct 12, 2024
CVE-2024-9821
8.8 HIGH

The Bot for Telegram on WooCommerce plugin for WordPress is vulnerable to sensitive information disclosure due to missing authorization checks on the 'stm_wpcfto_get_settings' AJAX action …

Oct 12, 2024
CVE-2024-9592
6.1 MEDIUM

The Easy PayPal Gift Certificate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to …

Oct 12, 2024
CVE-2024-45754
7.2 HIGH

An issue was discovered in the centreon-bi-server component in Centreon BI Server 24.04.x before 24.04.3, 23.10.x before 23.10.8, 23.04.x before 23.04.11, and 22.10.x before 22.10.11. …

Oct 11, 2024
CVE-2024-35522
8.4 HIGH

Netgear EX3700 ' AC750 WiFi Range Extender Essentials Edition before 1.0.0.98 contains an authenticated command injection in operating_mode.cgi via the ap_mode parameter with ap_24g_manual set …

Oct 11, 2024
CVE-2024-35517
8.4 HIGH

Netgear XR1000 v1.0.0.64 is vulnerable to command injection in usb_remote_smb_conf.cgi via the share_name parameter.

Oct 11, 2024
CVE-2024-48938
7.5 HIGH

Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows DoS/ReDos via email. Parsing the content of emails where HTML code is copied from …

Oct 11, 2024
CVE-2024-48937
6.1 MEDIUM

Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows XSS. JavaScript code in the short description of the SLA field in Activity Dialogues …

Oct 11, 2024
CVE-2024-48788
7.5 HIGH

An issue in YESCAM (com.yescom.YesCam.zwave) 1.0.2 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 11, 2024
CVE-2024-48772
9.1 CRITICAL

An issue in C-CHIP (com.cchip.cchipamaota) v.1.2.8 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 11, 2024
CVE-2024-46468
7.5 HIGH

A Server-Side Request Forgery (SSRF) vulnerability exists in the jpress <= v5.1.1, which can be exploited by an attacker to obtain sensitive information, resulting in …

Oct 11, 2024
CVE-2024-45184
6.2 MEDIUM

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with chipset Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, …

Oct 11, 2024
CVE-2024-48787
9.1 CRITICAL

An issue in Revic Optics Revic Ops (us.revic.revicops) 1.12.5 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 11, 2024
CVE-2024-48786
9.1 CRITICAL

An issue in SWITCHBOT INC SwitchBot (com.theswitchbot.switchbot) 5.0.4 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 11, 2024
CVE-2024-48784
9.8 CRITICAL

An Incorrect Access Control issue in SAMPMAX com.sampmax.homemax 2.1.2.7 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 11, 2024
CVE-2024-48778
9.1 CRITICAL

An issue in GIANT MANUFACTURING CO., LTD RideLink (tw.giant.ridelink) 2.0.7 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 11, 2024
CVE-2024-48777
7.5 HIGH

LEDVANCE com.ledvance.smartplus.eu 2.1.10 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 11, 2024
CVE-2024-48776
7.5 HIGH

An issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information via the firmware update process

Oct 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.