CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8292
9.8 CRITICAL

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/account takeover in all versions up to, and including, 16.26.8. …

Sep 6, 2024
CVE-2024-7349
7.2 HIGH

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to blind SQL Injection via the 'order' parameter in …

Sep 6, 2024
CVE-2024-6792
3.5 LOW

The WP ULike WordPress plugin before 4.7.2.1 does not properly sanitize user display names when rendering on a public page.

Sep 6, 2024
CVE-2024-45751
5.9 MEDIUM

tgt (aka Linux target framework) before 1.0.93 attempts to achieve entropy by calling rand without srand. The PRNG seed is always 1, and thus the …

Sep 6, 2024
CVE-2024-39585
7.9 HIGH

Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x, contain(s) an Use of Hard-coded Password vulnerability. A low privileged attacker with remote access could …

Sep 6, 2024
CVE-2024-38486
7.5 HIGH

Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x , contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. …

Sep 6, 2024
CVE-2024-8480
8.8 HIGH

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Sep 6, 2024
CVE-2024-8247
8.8 HIGH

The Newsletters plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.9.9.2. This is due to the plugin not …

Sep 6, 2024
CVE-2024-7415
5.3 MEDIUM

The Remember Me Controls plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1. This is due to …

Sep 6, 2024
CVE-2024-40865
5.3 MEDIUM

The issue was addressed by suspending Persona when the virtual keyboard is active. This issue is fixed in visionOS 1.3. Inputs to the virtual keyboard …

Sep 6, 2024
CVE-2024-44082
4.3 MEDIUM

In OpenStack Ironic before 26.0.1 and ironic-python-agent before 9.13.1, there is a vulnerability in image processing, in which a crafted image could be used by …

Sep 6, 2024
CVE-2024-45400
6.1 MEDIUM

ckeditor-plugin-openlink is a plugin for the CKEditor JavaScript text editor that extends the context menu with a possibility to open a link in a new …

Sep 6, 2024
CVE-2024-42495
6.5 MEDIUM

Credentials to access device configuration were transmitted using an unencrypted protocol. These credentials would allow read-only access to network configuration information and terminal configuration data.

Sep 5, 2024
CVE-2024-39278
4.2 MEDIUM

Credentials to access device configuration information stored unencrypted in flash memory. These credentials would allow read-only access to network configuration information and terminal configuration data.

Sep 5, 2024
CVE-2024-8395
9.8 CRITICAL

FlyCASS CASS and KCM systems did not correctly filter SQL queries, which made them vulnerable to attack by outside attackers with no authentication.

Sep 5, 2024
CVE-2024-45159
9.8 CRITICAL

An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the client-provided …

Sep 5, 2024
CVE-2024-45158
9.8 CRITICAL

An issue was discovered in Mbed TLS 3.6 before 3.6.1. A stack buffer overflow in mbedtls_ecdsa_der_to_raw() and mbedtls_ecdsa_raw_to_der() can occur when the bits parameter is …

Sep 5, 2024
CVE-2024-45157
5.1 MEDIUM

An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used. Unlike previously documented, enabling …

Sep 5, 2024
CVE-2024-7591
10.0 CRITICAL

Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 …

Sep 5, 2024
CVE-2024-45401
7.5 HIGH

stripe-cli is a command-line tool for the payment processor Stripe. A vulnerability exists in stripe-cli starting in version 1.11.1 and prior to version 1.21.3 where …

Sep 5, 2024
CVE-2024-42491
5.7 MEDIUM

Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.24.3, 20.9.3, and 21.4.3 of Asterisk and versions 18.9-cert12 and 20.7-cert2 of certified-asterisk, if …

Sep 5, 2024
CVE-2024-45392
7.7 HIGH

SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficient access control checks allow a threat actor to delete …

Sep 5, 2024
CVE-2024-44728
6.1 MEDIUM

Sourcecodehero Event Management System 1.0 allows Stored Cross-Site Scripting via parameters Full Name, Address, Email, and contact# in /clientdetails/admin/regester.php.

Sep 5, 2024
CVE-2024-44727
9.8 CRITICAL

Sourcecodehero Event Management System1.0 is vulnerable to SQL Injection via the parameter 'username' in /event/admin/login.php.

Sep 5, 2024
CVE-2024-24759
9.3 CRITICAL

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection …

Sep 5, 2024
CVE-2024-45589
5.9 MEDIUM

RapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts and allows a remote attacker to cause a denial of service via …

Sep 5, 2024
CVE-2024-45176
6.1 MEDIUM

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper input validation, the C-MOR web interface is vulnerable to reflected cross-site scripting …

Sep 5, 2024
CVE-2024-45175
8.8 HIGH

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Sensitive information is stored in cleartext. It was found out that sensitive information, for example …

Sep 5, 2024
CVE-2024-45171
8.8 HIGH

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to upload dangerous files, for instance …

Sep 5, 2024
CVE-2024-45098
6.8 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.

Sep 5, 2024
CVE-2024-45097
5.9 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.

Sep 5, 2024
CVE-2024-45096
6.5 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user with access to the package to obtain sensitive information through a directory listing.

Sep 5, 2024
CVE-2024-42885
9.1 CRITICAL

SQL Injection vulnerability in ESAFENET CDG 5.6 and before allows an attacker to execute arbitrary code via the id parameter of the data.jsp page.

Sep 5, 2024
CVE-2023-51712
4.7 MEDIUM

An issue was discovered in Trusted Firmware-M through 2.0.0. The lack of argument verification in the logging subsystem allows attackers to read sensitive data via …

Sep 5, 2024
CVE-2024-8445
5.7 MEDIUM

The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while …

Sep 5, 2024
CVE-2024-45178
7.1 HIGH

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to download arbitrary files from the …

Sep 5, 2024
CVE-2024-45173
8.8 HIGH

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper privilege management concerning sudo privileges, C-MOR is vulnerable to a privilege escalation …

Sep 5, 2024
CVE-2024-44587
8.8 HIGH

itsourcecode Alton Management System 1.0 is vulnerable to SQL Injection in /noncombo_save.php via the "menu" parameter.

Sep 5, 2024
CVE-2024-8473
6.3 MEDIUM

Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of …

Sep 5, 2024
CVE-2024-8472
6.3 MEDIUM

Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of …

Sep 5, 2024
CVE-2024-8471
6.3 MEDIUM

Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of …

Sep 5, 2024
CVE-2024-8470
9.8 CRITICAL

SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/vacancy/controller.php, and retrieve all the information stored in …

Sep 5, 2024
CVE-2024-8469
9.8 CRITICAL

SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/employee/index.php, and retrieve all the information stored in …

Sep 5, 2024
CVE-2024-8468
9.8 CRITICAL

SQL injection vulnerability, by which an attacker could send a specially designed query through search parameter in /jobportal/index.php, and retrieve all the information stored in …

Sep 5, 2024
CVE-2024-8467
9.8 CRITICAL

SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/category/index.php, and retrieve all the information stored in …

Sep 5, 2024
CVE-2024-8466
9.8 CRITICAL

SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/category/controller.php, and retrieve all the information stored in …

Sep 5, 2024
CVE-2024-8465
9.8 CRITICAL

SQL injection vulnerability, by which an attacker could send a specially designed query through user_id parameter in /jobportal/admin/user/controller.php, and retrieve all the information stored in …

Sep 5, 2024
CVE-2024-8464
9.8 CRITICAL

SQL injection vulnerability, by which an attacker could send a specially designed query through JOBREGID parameter in /jobportal/admin/applicants/controller.php, and retrieve all the information stored in …

Sep 5, 2024
CVE-2024-8463
9.9 CRITICAL

File upload restriction bypass vulnerability in PHPGurukul Job Portal 1.0, the exploitation of which could allow an authenticated user to execute an RCE via webshell.

Sep 5, 2024
CVE-2024-8462
3.7 LOW

A vulnerability was found in Windmill 1.380.0. It has been classified as problematic. Affected is an unknown function of the file backend/windmill-api/src/users.rs of the component …

Sep 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.