CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7606
6.4 MEDIUM

The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'user-search' shortcode in all versions up to, and including, …

Aug 29, 2024
CVE-2024-7418
4.3 MEDIUM

The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Sensitive Information Exposure in all …

Aug 29, 2024
CVE-2024-7132
4.8 MEDIUM

The Page Builder Gutenberg Blocks WordPress plugin before 3.1.13 does not escape the content of post embed via one of its block, which could allow …

Aug 29, 2024
CVE-2024-6927
4.8 MEDIUM

The Viral Signup WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Aug 29, 2024
CVE-2024-6551
5.3 MEDIUM

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.15.1. …

Aug 29, 2024
CVE-2024-5987
5.4 MEDIUM

The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_contrast_variations' and …

Aug 29, 2024
CVE-2024-5857
5.3 MEDIUM

The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to unauthorized loss …

Aug 29, 2024
CVE-2024-5624
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) in Shift Logbook application of B&R APROL <= R 4.4-00P3 may allow a network-based attacker to execute arbitrary JavaScript code in …

Aug 29, 2024
CVE-2024-5623
7.8 HIGH

An untrusted search path vulnerability in B&R APROL <= R 4.4-00P3 may be used by an authenticated local attacker to get other users to execute …

Aug 29, 2024
CVE-2024-5622
7.8 HIGH

An untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL <= R 4.2.-07P3 and <= R 4.4-00P3 may allow an authenticated local attacker to …

Aug 29, 2024
CVE-2024-5417
5.4 MEDIUM

The Gutentor WordPress plugin before 3.3.6 does not validate and escape some of its block options before outputting them back in a page/post where the …

Aug 29, 2024
CVE-2024-4428
9.8 CRITICAL

Missing Authentication for Critical Function, Missing Authorization vulnerability in Menulux Information Technologies Managment Portal allows Collect Data as Provided by Users.This issue affects Managment Portal: …

Aug 29, 2024
CVE-2024-45440
5.3 MEDIUM

core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of a file that …

Aug 29, 2024
CVE-2024-43986
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MagePeople Team Taxi Booking Manager for WooCommerce allows Stored XSS.This issue …

Aug 29, 2024
CVE-2024-43700
7.8 HIGH

xfpt versions prior to 1.01 fails to handle appropriately some parameters inside the input data, resulting in a stack-based buffer overflow vulnerability. When a user …

Aug 29, 2024
CVE-2024-3944
4.4 MEDIUM

The WP To Do plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, and including, 1.3.0 due to …

Aug 29, 2024
CVE-2024-38304
3.8 LOW

Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker …

Aug 29, 2024
CVE-2024-38303
5.3 MEDIUM

Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Improper Input Validation vulnerability. A high privileged attacker with local access could potentially …

Aug 29, 2024
CVE-2024-29731
9.8 CRITICAL

SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by …

Aug 29, 2024
CVE-2024-29730
9.8 CRITICAL

SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by …

Aug 29, 2024
CVE-2024-29729
9.8 CRITICAL

SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by …

Aug 29, 2024
CVE-2024-29728
9.8 CRITICAL

SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by …

Aug 29, 2024
CVE-2024-29727
9.8 CRITICAL

SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by …

Aug 29, 2024
CVE-2024-29726
9.8 CRITICAL

SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by …

Aug 29, 2024
CVE-2024-29725
9.8 CRITICAL

SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by …

Aug 29, 2024
CVE-2024-29724
9.8 CRITICAL

SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by …

Aug 29, 2024
CVE-2024-29723
9.8 CRITICAL

SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by …

Aug 29, 2024
CVE-2022-2440
7.2 HIGH

The Theme Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'images_array' parameter in versions up to, and including 2.8. This …

Aug 29, 2024
CVE-2021-4442
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tcp: add sanity tests to TCP_QUEUE_SEQ Qingyu Li reported a syzkaller bug where the repro …

Aug 29, 2024
CVE-2024-7857
6.5 MEDIUM

The Media Library Folders plugin for WordPress is vulnerable to second order SQL Injection via the 'sort_type' parameter of the 'mlf_change_sort_type' AJAX action in all …

Aug 29, 2024
CVE-2024-45436
7.5 HIGH

extractFromZipFile in model.go in Ollama before 0.1.47 can extract members of a ZIP archive outside of the parent directory.

Aug 29, 2024
CVE-2024-45435
9.8 CRITICAL

Chartist 1.x through 1.3.0 allows Prototype Pollution via the extend function.

Aug 29, 2024
CVE-2024-41918
6.1 MEDIUM

'Rakuten Ichiba App' for Android 12.4.0 and earlier and 'Rakuten Ichiba App' for iOS 11.7.0 and earlier are vulnerable to improper authorization in handler for …

Aug 29, 2024
CVE-2024-8250
7.8 HIGH

NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file

Aug 29, 2024
CVE-2024-45233
9.8 CRITICAL

An issue was discovered in powermail extension through 12.3.5 for TYPO3. Several actions in the OutputController can directly be called, due to missing or insufficiently …

Aug 29, 2024
CVE-2024-45232
5.3 MEDIUM

An issue was discovered in powermail extension through 12.3.5 for TYPO3. It fails to validate the mail parameter of the confirmationAction, resulting in Insecure Direct …

Aug 29, 2024
CVE-2024-8198
8.8 HIGH

Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap …

Aug 28, 2024
CVE-2024-8194
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Aug 28, 2024
CVE-2024-8193
8.8 HIGH

Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap …

Aug 28, 2024
CVE-2024-45059
8.8 HIGH

i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. A SQL Injection vulnerability was …

Aug 28, 2024
CVE-2024-45058
8.1 HIGH

i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. Prior to the 2.9 branch, …

Aug 28, 2024
CVE-2024-45057
6.1 MEDIUM

i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. A Reflected Cross-Site Scripting (XSS) …

Aug 28, 2024
CVE-2024-45048
8.8 HIGH

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions are subject to a bypassing of a filter which allows for …

Aug 28, 2024
CVE-2024-45046
5.4 MEDIUM

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In affected versions `\PhpOffice\PhpSpreadsheet\Writer\Html` doesn't sanitize spreadsheet styling information such as font names, …

Aug 28, 2024
CVE-2024-45054
2.8 LOW

Hwameistor is an HA local storage system for cloud-native stateful workloads. This ClusterRole has * verbs of * resources. If a malicious user can access …

Aug 28, 2024
CVE-2024-45043
5.3 MEDIUM

The OpenTelemetry Collector module AWS firehose receiver is for ingesting AWS Kinesis Data Firehose delivery stream messages and parsing the records received based on the …

Aug 28, 2024
CVE-2024-44760
7.5 HIGH

Incorrect access control in the component /servlet/SnoopServlet of Shenzhou News Union Enterprise Management System v5.0 through v18.8 allows attackers to access sensitive information regarding the …

Aug 28, 2024
CVE-2024-43805
7.6 HIGH

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. This vulnerability depends on user interaction by opening a …

Aug 28, 2024
CVE-2024-42793
8.0 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via a crafted request to the /music/ajax.php?action=save_user page.

Aug 28, 2024
CVE-2024-34195
9.8 CRITICAL

TOTOLINK AC1200 Wireless Router A3002R Firmware V1.1.1-B20200824 is vulnerable to Buffer Overflow. In the boa server program's CGI handling function formWlEncrypt, there is a lack …

Aug 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.