CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7689
4.3 MEDIUM

The Snapshot Backup WordPress plugin through 2.1.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Sep 9, 2024
CVE-2024-7688
6.5 MEDIUM

The AZIndex WordPress plugin through 0.8.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin delete arbitrary …

Sep 9, 2024
CVE-2024-7687
4.3 MEDIUM

The AZIndex WordPress plugin through 0.8.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Sep 9, 2024
CVE-2024-6910
4.8 MEDIUM

The EventON WordPress plugin before 2.2.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Sep 9, 2024
CVE-2024-5561
4.8 MEDIUM

The Popup Maker WordPress plugin before 1.19.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Sep 9, 2024
CVE-2024-45625
6.1 MEDIUM

Cross-site scripting vulnerability exists in Forminator versions prior to 1.34.1. If this vulnerability is exploited, an arbitrary script may be executed on the web browser …

Sep 9, 2024
CVE-2024-8586
6.1 MEDIUM

WebITR from Uniong has an Open Redirect vulnerability, which allows unauthorized remote attackers to exploit this vulnerability to forge URLs. Users, believing they are accessing …

Sep 9, 2024
CVE-2024-8585
6.5 MEDIUM

Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowing a remote attacker with regular privileges to …

Sep 9, 2024
CVE-2024-8584
9.8 CRITICAL

Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege …

Sep 9, 2024
CVE-2024-8583
3.5 LOW

A vulnerability was found in SourceCodester Online Bank Management System and Online Bank Management System - 1.0. It has been classified as problematic. This affects …

Sep 8, 2024
CVE-2024-8582
3.5 LOW

A vulnerability was found in SourceCodester Food Ordering Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the …

Sep 8, 2024
CVE-2024-8580
8.1 HIGH

A vulnerability classified as critical was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. This vulnerability affects unknown code of the file /etc/shadow.sample. The manipulation leads to …

Sep 8, 2024
CVE-2024-8579
8.8 HIGH

A vulnerability classified as critical has been found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. This affects the function setWiFiRepeaterCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Sep 8, 2024
CVE-2024-8578
8.8 HIGH

A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. It has been rated as critical. Affected by this issue is the function setWiFiMeshName of the …

Sep 8, 2024
CVE-2024-8577
8.8 HIGH

A vulnerability was found in TOTOLINK AC1200 T8 and AC1200 T10 4.1.5cu.861_B20230220/4.1.8cu.5207. It has been declared as critical. Affected by this vulnerability is the function …

Sep 8, 2024
CVE-2024-8576
8.8 HIGH

A vulnerability was found in TOTOLINK AC1200 T8 and AC1200 T10 4.1.5cu.861_B20230220/4.1.8cu.5207. It has been classified as critical. Affected is the function setIpPortFilterRules of the …

Sep 8, 2024
CVE-2024-8575
8.8 HIGH

A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220 and classified as critical. This issue affects the function setWiFiScheduleCfg of the file /cgi-bin/cstecgi.cgi. The manipulation …

Sep 8, 2024
CVE-2024-42343
5.3 MEDIUM

Loway - CWE-204: Observable Response Discrepancy

Sep 8, 2024
CVE-2024-42342
4.3 MEDIUM

Loway - CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

Sep 8, 2024
CVE-2024-42341
6.1 MEDIUM

Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

Sep 8, 2024
CVE-2024-8574
6.3 MEDIUM

A vulnerability has been found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220 and classified as critical. This vulnerability affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The …

Sep 8, 2024
CVE-2024-8573
8.8 HIGH

A vulnerability, which was classified as critical, was found in TOTOLINK AC1200 T8 and AC1200 T10 4.1.5cu.861_B20230220/4.1.8cu.5207. This affects the function setParentalRules of the file …

Sep 8, 2024
CVE-2024-8572
3.5 LOW

A vulnerability was found in Gouniverse GoLang CMS 1.4.0. It has been declared as problematic. This vulnerability affects the function PageRenderHtmlByAlias of the file FrontendHandler.go. …

Sep 8, 2024
CVE-2024-8571
3.5 LOW

A vulnerability was found in erjemin roll_cms up to 1484fe2c4e0805946a7bcf46218509fcb34883a9. It has been classified as problematic. This affects an unknown part of the file roll_cms/roll_cms/views.py. …

Sep 8, 2024
CVE-2024-8570
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Sep 8, 2024
CVE-2024-6928
9.8 CRITICAL

The Opti Marketing WordPress plugin through 2.0.9 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX …

Sep 8, 2024
CVE-2024-6925
4.3 MEDIUM

The TrueBooker WordPress plugin before 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged …

Sep 8, 2024
CVE-2024-6924
9.8 CRITICAL

The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action …

Sep 8, 2024
CVE-2024-6859
5.4 MEDIUM

The WP MultiTasking WordPress plugin through 0.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Sep 8, 2024
CVE-2024-6856
4.3 MEDIUM

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Sep 8, 2024
CVE-2024-6855
4.3 MEDIUM

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating exit popups, which could allow attackers to make logged admins perform …

Sep 8, 2024
CVE-2024-6853
4.3 MEDIUM

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating welcome popups, which could allow attackers to make logged admins perform …

Sep 8, 2024
CVE-2024-6852
4.3 MEDIUM

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Sep 8, 2024
CVE-2024-8569
7.3 HIGH

A vulnerability has been found in code-projects Hospital Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Sep 8, 2024
CVE-2024-8568
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Mini-Tmall up to 20240901. Affected is the function rewardMapper.select of the file tmall/admin/order/1/1. The manipulation …

Sep 8, 2024
CVE-2024-8567
7.3 HIGH

A vulnerability, which was classified as critical, has been found in itsourcecode Payroll Management System 1.0. This issue affects some unknown processing of the file …

Sep 8, 2024
CVE-2024-8566
4.3 MEDIUM

A vulnerability classified as problematic was found in code-projects Online Shop Store 1.0. This vulnerability affects unknown code of the file /settings.php. The manipulation of …

Sep 8, 2024
CVE-2024-8565
7.3 HIGH

A vulnerability was found in SourceCodesters Clinics Patient Management System 2.0. It has been rated as critical. This issue affects some unknown processing of the …

Sep 7, 2024
CVE-2024-8564
6.3 MEDIUM

A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/update.php. The …

Sep 7, 2024
CVE-2024-8563
3.5 LOW

A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/update.php. The …

Sep 7, 2024
CVE-2024-8562
3.5 LOW

A vulnerability was found in SourceCodester PHP CRUD 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /endpoint/Add.php. …

Sep 7, 2024
CVE-2024-8561
6.3 MEDIUM

A vulnerability has been found in SourceCodester PHP CRUD 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file …

Sep 7, 2024
CVE-2024-8560
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Simple Invoice Generator System 1.0. Affected is an unknown function of the file /save_invoice.php. …

Sep 7, 2024
CVE-2024-8559
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Online Food Menu 1.0. This issue affects some unknown processing of the file …

Sep 7, 2024
CVE-2024-42024
8.8 HIGH

A vulnerability that allows an attacker in possession of the Veeam ONE Agent service account credentials to perform remote code execution on the machine where …

Sep 7, 2024
CVE-2024-42023
8.8 HIGH

An improper access control vulnerability allows low-privileged users to execute code with Administrator privileges remotely.

Sep 7, 2024
CVE-2024-42022
5.3 MEDIUM

An incorrect permission assignment vulnerability allows an attacker to modify product configuration files.

Sep 7, 2024
CVE-2024-42021
6.5 MEDIUM

An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.

Sep 7, 2024
CVE-2024-42020
5.4 MEDIUM

A Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection.

Sep 7, 2024
CVE-2024-42019
8.0 HIGH

A vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service service account. This attack requires user interaction and data …

Sep 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.