CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-45047
5.4 MEDIUM

svelte performance oriented web framework. A potential mXSS vulnerability exists in Svelte for versions up to but not including 4.2.19. Svelte improperly escapes HTML on …

Aug 30, 2024
CVE-2024-44918
3.5 LOW

A cross-site scripting (XSS) vulnerability in the component admin_datarelate.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Aug 30, 2024
CVE-2024-8343
7.3 HIGH

A vulnerability, which was classified as critical, was found in SourceCodester Sentiment Based Movie Rating System 1.0. Affected is an unknown function of the file …

Aug 30, 2024
CVE-2024-8342
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Petshop Management System 1.0. This issue affects some unknown processing of the file …

Aug 30, 2024
CVE-2024-8064

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 30, 2024
CVE-2024-7712

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 30, 2024
CVE-2024-7051

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 30, 2024
CVE-2024-44916
7.2 HIGH

Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php file and could result in …

Aug 30, 2024
CVE-2024-8341
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Petshop Management System 1.0. This vulnerability affects unknown code of the file /controllers/add_user.php. The manipulation of …

Aug 30, 2024
CVE-2024-8340
7.3 HIGH

A vulnerability classified as critical has been found in SourceCodester Electric Billing Management System 1.0. This affects an unknown part of the file /Actions.php?a=login. The …

Aug 30, 2024
CVE-2024-8339
6.3 MEDIUM

A vulnerability was found in SourceCodester Electric Billing Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Aug 30, 2024
CVE-2024-8338
6.3 MEDIUM

A vulnerability was found in HFO4 shudong-share 2.4.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file …

Aug 30, 2024
CVE-2024-8337
3.5 LOW

A vulnerability, which was classified as problematic, has been found in SourceCodester Contact Manager with Export to VCF 1.0. Affected by this issue is some …

Aug 30, 2024
CVE-2024-8336
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Music Gallery Site 1.0. Affected by this vulnerability is an unknown functionality of the file /php-music/classes/Master.php?f=delete_music. …

Aug 30, 2024
CVE-2024-8335
6.3 MEDIUM

A vulnerability classified as critical has been found in OpenRapid RapidCMS up to 1.3.1. Affected is an unknown function of the file /resource/runlogon.php. The manipulation …

Aug 30, 2024
CVE-2024-8334
4.3 MEDIUM

A vulnerability was found in master-nan Sweet-CMS up to 5f441e022b8876f07cde709c77b5be6d2f262e3f. It has been rated as problematic. This issue affects the function LogHandler of the file …

Aug 30, 2024
CVE-2024-8260
6.1 MEDIUM

A SMB force-authentication vulnerability exists in all versions of OPA for Windows prior to v0.68.0. The vulnerability exists because of improper input validation, allowing a …

Aug 30, 2024
CVE-2024-8332
6.3 MEDIUM

A vulnerability was found in master-nan Sweet-CMS up to 5f441e022b8876f07cde709c77b5be6d2f262e3f. It has been declared as critical. This vulnerability affects unknown code of the file /table/index. …

Aug 30, 2024
CVE-2024-8331
6.3 MEDIUM

A vulnerability was found in OpenRapid RapidCMS up to 1.3.1. It has been classified as critical. This affects an unknown part of the file /admin/user/user-move-run.php. …

Aug 30, 2024
CVE-2022-48944
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched: Fix yet more sched_fork() races Where commit 4ef0c5c6b5ba ("kernel/sched: Fix sched_fork() access an invalid …

Aug 30, 2024
CVE-2024-8274
6.1 MEDIUM

The WP Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters from 'timeline_obj' in all versions up to, and including, …

Aug 30, 2024
CVE-2024-8252
8.8 HIGH

The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 via the 'template' attribute of …

Aug 30, 2024
CVE-2024-7858
6.3 MEDIUM

The Media Library Folders plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several AJAX functions in the media-library-plus.php file …

Aug 30, 2024
CVE-2024-7122
6.4 MEDIUM

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.13.6 due …

Aug 30, 2024
CVE-2024-8319
4.3 MEDIUM

The Tourfic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.11.20. This is due to missing or …

Aug 30, 2024
CVE-2024-44944
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: use helper function to calculate expect ID Delete expectation path is missing a …

Aug 30, 2024
CVE-2024-8016
9.1 CRITICAL

The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.0.2 via deserialization of untrusted …

Aug 30, 2024
CVE-2024-42412
6.1 MEDIUM

Cross-site scripting vulnerability exists in ELECOM wireless access points due to improper processing of input values in menu.cgi. If a user views a malicious web …

Aug 30, 2024
CVE-2024-39300
3.7 LOW

Missing authentication vulnerability exists in Telnet function of WAB-I1750-PS v1.5.10 and earlier. When Telnet function of the product is enabled, a remote attacker may login …

Aug 30, 2024
CVE-2024-34577
6.1 MEDIUM

Cross-site scripting vulnerability exists in WRC-X3000GS2-B, WRC-X3000GS2-W, WRC-X3000GS2A-B and WRC-X3000GST2-B due to improper processing of input values in easysetup.cgi. If a user views a malicious …

Aug 30, 2024
CVE-2024-8333

Rejected reason: Test CVE

Aug 30, 2024
CVE-2024-3673
9.1 CRITICAL

The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), which could lead to Local File …

Aug 30, 2024
CVE-2024-5879
6.4 MEDIUM

The HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute of …

Aug 30, 2024
CVE-2024-3998
6.4 MEDIUM

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, 27.5.6 …

Aug 30, 2024
CVE-2024-2694
8.8 HIGH

The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via deserialization of untrusted input of …

Aug 30, 2024
CVE-2024-5784
7.1 HIGH

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing capability checks on multiple functions like treport_quiz_atttempt_delete …

Aug 30, 2024
CVE-2024-5061
6.4 MEDIUM

The Enfold - Responsive Multi-Purpose Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wrapper_class’ and 'class' parameters in all versions up …

Aug 30, 2024
CVE-2024-5024
6.1 MEDIUM

The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mepr_screenname' and 'mepr_key' parameter in all versions up to, and including, 1.11.29 …

Aug 30, 2024
CVE-2024-4401
6.4 MEDIUM

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ and 'eae_slider_animation' parameters in all versions up to, and …

Aug 30, 2024
CVE-2024-8330
8.8 HIGH

6SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload web shell scripts and use …

Aug 30, 2024
CVE-2024-8329
8.8 HIGH

6SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers with regular privilege to inject SQL command to read, …

Aug 30, 2024
CVE-2024-8328
5.4 MEDIUM

Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular …

Aug 30, 2024
CVE-2024-8327
8.8 HIGH

Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular …

Aug 30, 2024
CVE-2024-45492
9.8 CRITICAL

An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

Aug 30, 2024
CVE-2024-45491
9.8 CRITICAL

An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

Aug 30, 2024
CVE-2024-45490
7.5 HIGH

An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.

Aug 30, 2024
CVE-2024-45488
9.8 CRITICAL

One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware …

Aug 30, 2024
CVE-2024-8234
7.5 HIGH

** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the functions formSysCmd(), formUpgradeCert(), and formDelcert() in the Zyxel NWA1100-N firmware version 1.00(AACE.1)C0 could allow …

Aug 30, 2024
CVE-2024-2881
6.7 MEDIUM

Fault Injection vulnerability in wc_ed25519_sign_msg function in wolfssl/wolfcrypt/src/ed25519.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remote attacker co-resides in the same system with a victim process …

Aug 30, 2024
CVE-2024-1545
5.9 MEDIUM

Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remote attacker co-resides in the same system with a victim process …

Aug 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.