CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9090
6.3 MEDIUM

A vulnerability was found in SourceCodester Modern Loan Management System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Sep 23, 2024
CVE-2024-9089
3.5 LOW

A vulnerability was found in SourceCodester Modern Loan Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file update_loan_record.php. …

Sep 23, 2024
CVE-2024-43989
7.5 HIGH

Server-Side Request Forgery (SSRF) vulnerability in Firsh Justified Image Grid justified-image-grid.This issue affects Justified Image Grid: from n/a through <= 4.6.1.

Sep 23, 2024
CVE-2024-9088
6.3 MEDIUM

A vulnerability has been found in SourceCodester Telecom Billing Management System 1.0 and classified as critical. This vulnerability affects the function login. The manipulation of …

Sep 22, 2024
CVE-2024-9087
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Vehicle Management 1.0. This affects an unknown part of the file /edit1.php. The manipulation …

Sep 22, 2024
CVE-2024-9086
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Restaurant Reservation System 1.0. Affected is an unknown function of the file /filter.php. The manipulation …

Sep 22, 2024
CVE-2024-40703
5.5 MEDIUM

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker …

Sep 22, 2024
CVE-2024-9084
3.5 LOW

A vulnerability classified as problematic was found in code-projects Blood Bank System 1.0. This vulnerability affects unknown code of the file bbms.php. The manipulation of …

Sep 22, 2024
CVE-2024-9083
2.4 LOW

A vulnerability classified as problematic has been found in SourceCodester Employee Management System 1.0. This affects an unknown part of the file /Admin/add-admin.php. The manipulation …

Sep 22, 2024
CVE-2024-9085
7.3 HIGH

A vulnerability was found in code-projects Restaurant Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Sep 22, 2024
CVE-2024-9082
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Sep 22, 2024
CVE-2024-9081
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Sep 22, 2024
CVE-2024-9080
7.3 HIGH

A vulnerability was found in code-projects Student Record System 1.0. It has been classified as critical. Affected is an unknown function of the file /pincode-verification.php. …

Sep 22, 2024
CVE-2024-9079
7.3 HIGH

A vulnerability was found in code-projects Student Record System 1.0 and classified as critical. This issue affects some unknown processing of the file /marks.php. The …

Sep 22, 2024
CVE-2024-9078
7.3 HIGH

A vulnerability has been found in code-projects Student Record System 1.0 and classified as critical. This vulnerability affects unknown code of the file /course.php. The …

Sep 22, 2024
CVE-2024-9077
3.5 LOW

A vulnerability classified as problematic has been found in dingfangzu up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. Affected is an unknown function of the file scripts/order.js of the component …

Sep 22, 2024
CVE-2024-47226
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An …

Sep 22, 2024
CVE-2024-9076
4.7 MEDIUM

A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affects some unknown processing of the file /dede/article_string_mix.php. …

Sep 22, 2024
CVE-2024-47221
7.5 HIGH

CheckUser in ScadaServerEngine/MainLogic.cs in Rapid SCADA through 5.8.4 allows an empty password.

Sep 22, 2024
CVE-2024-47220

An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a …

Sep 22, 2024
CVE-2024-47219
9.8 CRITICAL

An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection.

Sep 22, 2024
CVE-2024-47218
9.8 CRITICAL

An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication.

Sep 22, 2024
CVE-2024-9075
2.6 LOW

A vulnerability was found in Stirling-Tools Stirling-PDF up to 0.28.3. It has been declared as problematic. This vulnerability affects unknown code of the component Markdown-to-PDF. …

Sep 21, 2024
CVE-2024-47210
8.8 HIGH

Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be used in updateMySelf in server/api/controllers/user.controller.js.

Sep 21, 2024
CVE-2024-42323
8.8 HIGH

SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating). This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat …

Sep 21, 2024
CVE-2024-9048
3.1 LOW

A vulnerability was found in y_project RuoYi up to 4.7.9. It has been declared as problematic. Affected by this vulnerability is the function SysUserServiceImpl of …

Sep 21, 2024
CVE-2024-8680
4.4 MEDIUM

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.9.16 …

Sep 21, 2024
CVE-2024-6787
5.3 MEDIUM

This vulnerability occurs when an attacker exploits a race condition between the time a file is checked and the time it is used (TOCTOU). By …

Sep 21, 2024
CVE-2024-6786
6.5 MEDIUM

The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling them to read arbitrary files on the system. This …

Sep 21, 2024
CVE-2024-6785
5.5 MEDIUM

The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, potentially resulting in the service …

Sep 21, 2024
CVE-2024-46649
7.5 HIGH

eNMS up to 4.7.1 is vulnerable to Directory Traversal via download/folder.

Sep 20, 2024
CVE-2024-46648
7.5 HIGH

eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via scan_folder.

Sep 20, 2024
CVE-2024-46647
6.5 MEDIUM

eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via upload_files.

Sep 20, 2024
CVE-2024-46646
6.5 MEDIUM

eNMS up to 4.7.1 is vulnerable to Directory Traversal via /download/file.

Sep 20, 2024
CVE-2024-46645
7.5 HIGH

eNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files.

Sep 20, 2024
CVE-2024-46644
6.5 MEDIUM

eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via edit_file.

Sep 20, 2024
CVE-2024-46640
9.8 CRITICAL

SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not …

Sep 20, 2024
CVE-2024-46103
9.8 CRITICAL

SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.

Sep 20, 2024
CVE-2024-46101
9.8 CRITICAL

GDidees CMS <= v3.9.1 has a file upload vulnerability.

Sep 20, 2024
CVE-2024-45793
4.8 MEDIUM

Confidant is a open source secret management service that provides user-friendly storage and access to secrets. The following endpoints are subject to a cross site …

Sep 20, 2024
CVE-2024-47062
8.8 HIGH

Navidrome is an open source web-based music collection server and streamer. Navidrome automatically adds parameters in the URL to SQL queries. This can be exploited …

Sep 20, 2024
CVE-2024-47061
8.3 HIGH

Plate is a javascript toolkit that makes it easier for you to develop with Slate, a popular framework for building text editors. One longstanding feature …

Sep 20, 2024
CVE-2024-46654
4.8 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows attackers to execute arbitrary web scripts or HTML via …

Sep 20, 2024
CVE-2024-45229
6.6 MEDIUM

The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device registration, do …

Sep 20, 2024
CVE-2024-42351
6.5 MEDIUM

Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. An attacker can potentially replace …

Sep 20, 2024
CVE-2024-42346
7.6 HIGH

Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. The editor visualization, /visualizations endpoint, …

Sep 20, 2024
CVE-2024-8612
3.8 LOW

A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set in virtio_scsi_complete_req / virtio_blk_req_complete / virito_crypto_req_complete …

Sep 20, 2024
CVE-2024-42697
6.1 MEDIUM

Cross Site Scripting vulnerability in Leotheme Leo Product Search Module v.2.1.6 and earlier allows a remote attacker to execute arbitrary code via the q parameter …

Sep 20, 2024
CVE-2024-9041
6.3 MEDIUM

A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file …

Sep 20, 2024
CVE-2024-9040
2.3 LOW

A vulnerability, which was classified as problematic, was found in code-projects Blood Bank Management System 1.0. This affects an unknown part of the component Password …

Sep 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.