CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9232
6.1 MEDIUM

The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without …

Oct 11, 2024
CVE-2024-9221
6.1 MEDIUM

The Tainacan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all …

Oct 11, 2024
CVE-2024-9211
6.1 MEDIUM

The FULL – Cliente plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on …

Oct 11, 2024
CVE-2024-9164
9.6 CRITICAL

An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from …

Oct 11, 2024
CVE-2024-9051
6.4 MEDIUM

The WP Ultimate Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpupg-grid-with-filters shortcode in all versions up to, and …

Oct 11, 2024
CVE-2024-8970
8.2 HIGH

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from …

Oct 11, 2024
CVE-2024-8913
4.3 MEDIUM

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in …

Oct 11, 2024
CVE-2024-7514
6.5 MEDIUM

The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient file path validation during the comments …

Oct 11, 2024
CVE-2024-6971
4.4 MEDIUM

A path traversal vulnerability exists in the parisneo/lollms-webui repository, specifically in the `lollms_file_system.py` file. The functions `add_rag_database`, `toggle_mount_rag_database`, and `vectorize_folder` do not implement security measures …

Oct 11, 2024
CVE-2024-5005
4.3 MEDIUM

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all …

Oct 11, 2024
CVE-2024-48987
6.6 MEDIUM

Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exacerbated by .env files, available from …

Oct 11, 2024
CVE-2024-45317
7.5 HIGH

A Server-Side Request Forgery (SSRF) vulnerability in SMA1000 appliance firmware versions 12.4.3-02676 and earlier allows a remote, unauthenticated attacker to cause the SMA1000 server-side application …

Oct 11, 2024
CVE-2024-45316
7.8 HIGH

The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard …

Oct 11, 2024
CVE-2024-45315
5.5 MEDIUM

The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard …

Oct 11, 2024
CVE-2024-21534
9.8 CRITICAL

All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on …

Oct 11, 2024
CVE-2023-42133
6.7 MEDIUM

PAX Android based POS devices allow for escalation of privilege via improperly configured scripts. An attacker must have shell access with system account privileges in …

Oct 11, 2024
CVE-2024-9822
9.8 CRITICAL

The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5. This is due to insufficient restriction on …

Oct 11, 2024
CVE-2024-9818
7.3 HIGH

A vulnerability classified as critical has been found in SourceCodester Online Veterinary Appointment System 1.0. Affected is an unknown function of the file /admin/categories/manage_category.php. The …

Oct 10, 2024
CVE-2024-9817
6.3 MEDIUM

A vulnerability was found in code-projects Blood Bank System 1.0. It has been classified as critical. This affects an unknown part of the file /update.php. …

Oct 10, 2024
CVE-2024-47872
5.4 MEDIUM

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **Cross-Site Scripting (XSS)** on any Gradio server that allows file uploads. Authenticated …

Oct 10, 2024
CVE-2024-47871
9.1 CRITICAL

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **insecure communication** between the FRP (Fast Reverse Proxy) client and server when …

Oct 10, 2024
CVE-2024-47870
8.1 HIGH

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **race condition** in the `update_root_in_config` function, allowing an attacker to modify …

Oct 10, 2024
CVE-2024-47869
3.7 LOW

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **timing attack** in the way Gradio compares hashes for the `analytics_dashboard` …

Oct 10, 2024
CVE-2024-47868
7.5 HIGH

Gradio is an open-source Python package designed for quick prototyping. This is a **data validation vulnerability** affecting several Gradio components, which allows arbitrary file leaks …

Oct 10, 2024
CVE-2024-47867
7.5 HIGH

Gradio is an open-source Python package designed for quick prototyping. This vulnerability is a **lack of integrity check** on the downloaded FRP client, which could …

Oct 10, 2024
CVE-2024-9816
4.7 MEDIUM

A vulnerability was found in Codezips Tourist Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Oct 10, 2024
CVE-2024-9815
4.7 MEDIUM

A vulnerability has been found in Codezips Tourist Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Oct 10, 2024
CVE-2024-9814
7.3 HIGH

A vulnerability, which was classified as critical, was found in Codezips Pharmacy Management System 1.0. Affected is an unknown function of the file product/update.php. The …

Oct 10, 2024
CVE-2024-9487
9.1 CRITICAL

An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unauthorized provisioning …

Oct 10, 2024
CVE-2024-47168
4.3 MEDIUM

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves data exposure due to the enable_monitoring flag not properly disabling monitoring when …

Oct 10, 2024
CVE-2024-47167
9.8 CRITICAL

Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **Server-Side Request Forgery (SSRF)** in the `/queue/join` endpoint. Gradio’s `async_save_url_to_cache` function …

Oct 10, 2024
CVE-2024-47166
5.3 MEDIUM

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **one-level read path traversal** in the `/custom_component` endpoint. Attackers can exploit …

Oct 10, 2024
CVE-2024-47165
5.4 MEDIUM

Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **CORS origin validation accepting a null origin**. When a Gradio server …

Oct 10, 2024
CVE-2024-47164
6.5 MEDIUM

Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to the **bypass of directory traversal checks** within the `is_in_or_equal` function. This …

Oct 10, 2024
CVE-2024-47084
8.3 HIGH

Gradio is an open-source Python package designed for quick prototyping. This vulnerability is related to **CORS origin validation**, where the Gradio server fails to validate …

Oct 10, 2024
CVE-2024-9813
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Codezips Pharmacy Management System 1.0. This issue affects some unknown processing of the file …

Oct 10, 2024
CVE-2024-9812
7.3 HIGH

A vulnerability classified as critical was found in code-projects Crud Operation System 1.0. This vulnerability affects unknown code of the file delete.php. The manipulation of …

Oct 10, 2024
CVE-2024-9811
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Restaurant Reservation System 1.0. This affects an unknown part of the file filter3.php. The manipulation …

Oct 10, 2024
CVE-2024-9180
7.2 HIGH

A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s privileges to Vault’s root policy. …

Oct 10, 2024
CVE-2024-9810
3.5 LOW

A vulnerability was found in SourceCodester Record Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of …

Oct 10, 2024
CVE-2024-9809
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as critical. Affected by this vulnerability is the function delete_product of …

Oct 10, 2024
CVE-2024-9808
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/?page=products/view_product. …

Oct 10, 2024
CVE-2024-9807
2.4 LOW

A vulnerability was found in Craig Rodway Classroombookings 2.8.7 and classified as problematic. This issue affects some unknown processing of the file /sessions of the …

Oct 10, 2024
CVE-2024-9806
3.5 LOW

A vulnerability has been found in Craig Rodway Classroombookings up to 2.8.6 and classified as problematic. This vulnerability affects unknown code of the file /rooms/fields …

Oct 10, 2024
CVE-2024-47648
4.7 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Metagauss EventPrime eventprime-event-calendar-management.This issue affects EventPrime: from n/a through <= 4.0.4.5.

Oct 10, 2024
CVE-2024-47354
4.7 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wp.insider Simple Membership After Login Redirection simple-membership-after-login-redirection.This issue affects Simple Membership After Login Redirection: from n/a …

Oct 10, 2024
CVE-2024-9805
3.5 LOW

A vulnerability was found in code-projects Blood Bank System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file …

Oct 10, 2024
CVE-2024-9804
4.7 MEDIUM

A vulnerability was found in code-projects Blood Bank System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/campsdetails.php. …

Oct 10, 2024
CVE-2024-47966
7.8 HIGH

Delta Electronics CNCSoft-G2 lacks proper initialization of memory prior to accessing it. An attacker can manipulate users to visit a malicious page or file to …

Oct 10, 2024
CVE-2024-47965
7.8 HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can …

Oct 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.