CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8417
3.1 LOW

A vulnerability was found in 云课网络科技有限公司 Yunke Online School System up to 1.5.5. It has been declared as problematic. This vulnerability affects unknown code of …

Sep 4, 2024
CVE-2024-8416
6.3 MEDIUM

A vulnerability was found in SourceCodester Food Ordering Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Sep 4, 2024
CVE-2024-45177
5.4 MEDIUM

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to improper input validation, the C-MOR web interface is vulnerable to persistent …

Sep 4, 2024
CVE-2024-8415
6.3 MEDIUM

A vulnerability was found in SourceCodester Food Ordering Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Sep 4, 2024
CVE-2024-8414
4.3 MEDIUM

A vulnerability has been found in SourceCodester Insurance Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation …

Sep 4, 2024
CVE-2024-45174
8.1 HIGH

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to improper validation of user-supplied data, different functionalities of the C-MOR web …

Sep 4, 2024
CVE-2024-45170
8.1 HIGH

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper or missing access control, low privileged users can use administrative functions of …

Sep 4, 2024
CVE-2024-20503
5.5 MEDIUM

A vulnerability in Cisco Duo Epic for Hyperdrive could allow an authenticated, local attacker to view sensitive information in cleartext on an affected system. This …

Sep 4, 2024
CVE-2024-20497
4.3 MEDIUM

A vulnerability in Cisco Expressway Edge (Expressway-E) could allow an authenticated, remote attacker to masquerade as another user on an affected system. This vulnerability is …

Sep 4, 2024
CVE-2024-20469
6.0 MEDIUM

A vulnerability in specific CLI commands in Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command injection attacks on the …

Sep 4, 2024
CVE-2024-20440
7.5 HIGH

A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in …

Sep 4, 2024
CVE-2024-20439
9.8 CRITICAL KEV

A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative …

Sep 4, 2024
CVE-2024-8412
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in LinuxOSsk Shakal-NG up to 1.3.3. Affected is an unknown function of the file comments/views.py. The …

Sep 4, 2024
CVE-2024-8391
7.5 HIGH

In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GAV: io.vertx:vertx-grpc-server and io.vertx:vertx-grpc-client). This …

Sep 4, 2024
CVE-2024-45314
3.6 LOW

Flask-AppBuilder is an application development framework. Prior to version 4.5.1, the auth DB login form default cache directives allows browser to locally store sensitive data. …

Sep 4, 2024
CVE-2024-45076
9.9 CRITICAL

IBM webMethods Integration 10.15 could allow an authenticated user to upload and execute arbitrary files which could be executed on the underlying operating system.

Sep 4, 2024
CVE-2024-45075
8.8 HIGH

IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to escalate their privileges to administrator due to …

Sep 4, 2024
CVE-2024-45074
6.5 MEDIUM

IBM webMethods Integration 10.15 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing …

Sep 4, 2024
CVE-2024-45053
9.1 CRITICAL

Fides is an open-source privacy engineering platform. Starting in version 2.19.0 and prior to version 2.44.0, the Email Templating feature uses Jinja2 without proper input …

Sep 4, 2024
CVE-2024-45052
5.3 MEDIUM

Fides is an open-source privacy engineering platform. Prior to version 2.44.0, a timing-based username enumeration vulnerability exists in Fides Webserver authentication. This vulnerability allows an …

Sep 4, 2024
CVE-2024-45050
7.1 HIGH

Ringer server is the server code for the Ringer messaging app. Prior to version 1.3.1, there is an issue with the messages loading route where …

Sep 4, 2024
CVE-2024-44859
8.0 HIGH

Tenda FH1201 v1.2.0.14 has a stack buffer overflow vulnerability in `formWrlExtraGet`.

Sep 4, 2024
CVE-2024-44821
5.3 MEDIUM

ZZCMS 2023 contains a vulnerability in the captcha reuse logic located in /inc/function.php. The checkyzm function does not properly refresh the captcha value after a …

Sep 4, 2024
CVE-2024-44818
5.4 MEDIUM

Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the HTTP_Referer header of the caina.php component.

Sep 4, 2024
CVE-2024-44817
8.8 HIGH

SQL Injection vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the id parameter in the adv2.php component.

Sep 4, 2024
CVE-2024-44808
9.8 CRITICAL

An issue in Vypor Attack API System v.1.0 allows a remote attacker to execute arbitrary code via the user GET parameter.

Sep 4, 2024
CVE-2024-43405
7.4 HIGH

Nuclei is a vulnerability scanner powered by YAML based templates. Starting in version 3.0.0 and prior to version 3.3.2, a vulnerability in Nuclei's template signature …

Sep 4, 2024
CVE-2024-43402
8.1 HIGH

Rust is a programming language. The fix for CVE-2024-24576, where `std::process::Command` incorrectly escaped arguments when invoking batch files on Windows, was incomplete. Prior to Rust …

Sep 4, 2024
CVE-2024-8418
7.5 HIGH

A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An …

Sep 4, 2024
CVE-2024-8411
3.5 LOW

A vulnerability was determined in ABCD ABCD2 up to 2.2.0-beta-1. Impacted is an unknown function of the file /buscar_integrada.php. Executing a manipulation of the argument …

Sep 4, 2024
CVE-2024-8410
4.3 MEDIUM

A vulnerability classified as problematic was found in ABCD ABCD2 up to 2.2.0-beta-1. This vulnerability affects unknown code of the file /abcd/opac/php/otros_sitios.php. The manipulation of …

Sep 4, 2024
CVE-2024-8409
4.3 MEDIUM

A vulnerability classified as problematic has been found in ABCD ABCD2 up to 2.2.0-beta-1. This affects an unknown part of the file /common/show_image.php. The manipulation …

Sep 4, 2024
CVE-2024-7078
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Semtek Informatics Software Consulting Inc. Semtek Sempos allows SQL Injection.This issue …

Sep 4, 2024
CVE-2024-7077
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Semtek Informatics Software Consulting Inc. Semtek Sempos allows Reflected XSS.This issue affects Semtek …

Sep 4, 2024
CVE-2024-7076
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Semtek Informatics Software Consulting Inc. Semtek Sempos allows Blind SQL Injection.This …

Sep 4, 2024
CVE-2024-45506
7.5 HIGH

HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a …

Sep 4, 2024
CVE-2024-44820
6.1 MEDIUM

A sensitive information disclosure vulnerability exists in ZZCMS v.2023 and before within the eginfo.php file located at /3/E_bak5.1/upload/. When accessed with the query parameter phome=ShowPHPInfo, …

Sep 4, 2024
CVE-2024-44819
6.1 MEDIUM

Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via a crafted script to the pagename parameter …

Sep 4, 2024
CVE-2024-8408
6.3 MEDIUM

A vulnerability was found in Linksys WRT54G 4.21.5. It has been rated as critical. Affected by this issue is the function validate_services_port of the file …

Sep 4, 2024
CVE-2024-8407
3.5 LOW

A vulnerability was found in alwindoss akademy up to 35caccea888ed63d5489e211c99edff1f62efdba. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Sep 4, 2024
CVE-2024-7923
9.8 CRITICAL

An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore configuration. This issue arises …

Sep 4, 2024
CVE-2024-7012
9.8 CRITICAL

An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configuration. This issue arises from Apache's mod_proxy …

Sep 4, 2024
CVE-2024-7834
7.8 HIGH

A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-writeable folder in SYSTEM context on launch. …

Sep 4, 2024
CVE-2024-44400
9.8 CRITICAL

A vulnerability was discovered in DI_8400-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the …

Sep 4, 2024
CVE-2024-44383
6.8 MEDIUM

WAYOS FBM-291W v19.09.11 is vulnerable to Command Execution via msp_info_htm.

Sep 4, 2024
CVE-2024-8413
5.4 MEDIUM

Cross Site Scripting (XSS) vulnerability through the action parameter in index.php. Affected product codebase https://github.com/Bioshox/Raspcontrol and forks such as https://github.com/harmon25/raspcontrol . An attacker could exploit …

Sep 4, 2024
CVE-2024-7821

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 4, 2024
CVE-2024-8289
9.8 CRITICAL

The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to privilege escalation/de-escalation and account takeover due to an insufficient capability …

Sep 4, 2024
CVE-2024-7870
6.5 MEDIUM

The PixelYourSite – Your smart PIXEL (TAG) & API Manager and the PixelYourSite PRO plugins for WordPress are vulnerable to Sensitive Information Exposure in all …

Sep 4, 2024
CVE-2024-45507
9.8 CRITICAL

Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are …

Sep 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.