CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-27321
7.8 HIGH

An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its multilabel classification tasks handle …

Sep 12, 2024
CVE-2024-27320
7.8 HIGH

An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its classification tasks handle provided …

Sep 12, 2024
CVE-2022-26322
4.9 MEDIUM

Possible Insertion of Sensitive Information into Log File Vulnerability in Identity Manager has been discovered in OpenText™ Identity Manager REST Driver. This impact version before …

Sep 12, 2024
CVE-2021-38133
7.4 HIGH

Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.

Sep 12, 2024
CVE-2021-38132
5.3 MEDIUM

Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.

Sep 12, 2024
CVE-2021-38131
5.4 MEDIUM

Possible Cross-Site Scripting (XSS) Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.5.0000.

Sep 12, 2024
CVE-2021-22533
6.5 MEDIUM

Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.4.0000.

Sep 12, 2024
CVE-2021-22532
7.6 HIGH

Possible NLDAP Denial of Service attack Vulnerability in eDirectory has been discovered in OpenText™ eDirectory before 9.2.4.0000.

Sep 12, 2024
CVE-2021-22518
5.8 MEDIUM

A vulnerability identified in OpenText™ Identity Manager AzureAD Driver that allows logging of sensitive information into log file. This impacts all versions before 5.1.4.0

Sep 12, 2024
CVE-2021-22503
5.4 MEDIUM

Possible Improper Neutralization of Input During Web Page Generation Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.3.0000.

Sep 12, 2024
CVE-2024-8750
5.4 MEDIUM

Cross-site Scripting (XSS) vulnerability in idoit pro version 28. This vulnerability allows an attacker to retrieve session details of an authenticated user due to lack …

Sep 12, 2024
CVE-2024-8749
8.8 HIGH

SQL injection vulnerability in idoit pro version 28. This vulnerability could allow an attacker to send a specially crafted query to the ID parameter in …

Sep 12, 2024
CVE-2024-8622
6.1 MEDIUM

The amCharts: Charts and Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'amcharts_javascript' parameter in all versions up to, and including, …

Sep 12, 2024
CVE-2024-8529
10.0 CRITICAL

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter of the /wp-json/lp/v1/courses/archive-course REST API endpoint in …

Sep 12, 2024
CVE-2024-8522
10.0 CRITICAL

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress/v1/courses REST API endpoint in …

Sep 12, 2024
CVE-2024-2010
6.1 MEDIUM

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in TE Informatics V5 allows Reflected XSS.This issue affects V5: before 6.2.

Sep 12, 2024
CVE-2024-8056
6.1 MEDIUM

The MM-Breaking News WordPress plugin through 0.7.9 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected …

Sep 12, 2024
CVE-2024-8054
6.1 MEDIUM

The MM-Breaking News WordPress plugin through 0.7.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Sep 12, 2024
CVE-2024-7862
6.5 MEDIUM

The blogintroduction-wordpress-plugin WordPress plugin through 0.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged …

Sep 12, 2024
CVE-2024-7861
6.1 MEDIUM

The Misiek Paypal WordPress plugin through 1.1.20090324 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Sep 12, 2024
CVE-2024-7860
6.1 MEDIUM

The Simple Headline Rotator WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which …

Sep 12, 2024
CVE-2024-7859
6.5 MEDIUM

The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Sep 12, 2024
CVE-2024-7822
6.1 MEDIUM

The Quick Code WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Sep 12, 2024
CVE-2024-7820
6.5 MEDIUM

The ILC Thickbox WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Sep 12, 2024
CVE-2024-7818
6.1 MEDIUM

The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which …

Sep 12, 2024
CVE-2024-7817
6.5 MEDIUM

The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF checks in some places, which could allow attackers to make logged in users …

Sep 12, 2024
CVE-2024-7816
6.1 MEDIUM

The Gixaw Chat WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Sep 12, 2024
CVE-2024-7766
7.2 HIGH

The Adicon Server WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform …

Sep 12, 2024
CVE-2024-6887
4.8 MEDIUM

The Giveaways and Contests by RafflePress WordPress plugin before 1.12.16 does not sanitise and escape some of its Giveaways settings, which could allow high privilege …

Sep 12, 2024
CVE-2024-6019
6.1 MEDIUM

The Music Request Manager WordPress plugin through 1.3 does not sanitise and escape incoming music requests, which could allow unauthenticated users to perform Cross-Site Scripting …

Sep 12, 2024
CVE-2024-6018
6.1 MEDIUM

The Music Request Manager WordPress plugin through 1.3 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to …

Sep 12, 2024
CVE-2024-6017
6.1 MEDIUM

The Music Request Manager WordPress plugin through 1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which …

Sep 12, 2024
CVE-2024-5799
4.8 MEDIUM

The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which could allow high privilege users …

Sep 12, 2024
CVE-2024-3163
4.3 MEDIUM

The Easy Property Listings WordPress plugin before 3.5.4 does not have CSRF check when deleting contacts in bulk, which could allow attackers to make a …

Sep 12, 2024
CVE-2024-45624
7.5 HIGH

Exposure of sensitive information due to incompatible policies issue exists in Pgpool-II. If a database user accesses a query cache, table data unauthorized for the …

Sep 12, 2024
CVE-2024-8711
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in SourceCodester Food Ordering Management System 1.0. Affected by this issue is some unknown functionality …

Sep 12, 2024
CVE-2024-8710
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Inventory Management 1.0. Affected by this vulnerability is an unknown functionality of the file /model/viewProduct.php of …

Sep 12, 2024
CVE-2024-8709
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. Affected is the function delete_user/save_user of the file /admin_class.php. …

Sep 12, 2024
CVE-2024-38222
6.5 MEDIUM

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Sep 12, 2024
CVE-2024-8708
3.5 LOW

A vulnerability was found in SourceCodester Best House Rental Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of …

Sep 12, 2024
CVE-2024-37397
8.2 HIGH

An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote …

Sep 12, 2024
CVE-2024-34785
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-34783
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-34779
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-32848
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-32846
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-32845
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-32843
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-32842
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-32840
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.