CVE Database

11833+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-42781
9.8 CRITICAL

A SQL injection vulnerability in "/music/ajax.php?action=login" of Kashipara Music Management System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the …

Aug 21, 2024
CVE-2024-42777
9.8 CRITICAL

An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management System v1.0, which allows attackers to execute arbitrary code via uploading a …

Aug 21, 2024
CVE-2024-40453
9.8 CRITICAL

squirrellyjs squirrelly v9.0.0 and fixed in v.9.0.1 was discovered to contain a code injection vulnerability via the component options.varName.

Aug 21, 2024
CVE-2024-28000
9.8 CRITICAL

Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1.

Aug 21, 2024
CVE-2024-5335
9.8 CRITICAL

The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin is vulnerable to PHP Object …

Aug 21, 2024
CVE-2024-7854
10.0 CRITICAL

The Woo Inquiry plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 0.1 due to insufficient escaping on the …

Aug 21, 2024
CVE-2024-6800
9.8 CRITICAL

An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity providers utilizing publicly exposed signed federation …

Aug 20, 2024
CVE-2024-38175
9.6 CRITICAL

An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network.

Aug 20, 2024
CVE-2024-42919
9.8 CRITICAL

eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.

Aug 20, 2024
CVE-2024-27185
9.1 CRITICAL

The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors.

Aug 20, 2024
CVE-2024-43404
9.8 CRITICAL

MEGABOT is a fully customized Discord bot for learning and fun. The `/math` command and functionality of MEGABOT versions < 1.5.0 contains a remote code …

Aug 20, 2024
CVE-2024-35540
9.0 CRITICAL

A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Aug 20, 2024
CVE-2024-30949
9.8 CRITICAL

An issue in newlib v.4.3.0 allows an attacker to execute arbitrary code via the time unit scaling in the _gettimeofday function.

Aug 20, 2024
CVE-2024-33872
9.8 CRITICAL

Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code execution and escalation of privileges.

Aug 20, 2024
CVE-2024-42575
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at substaff.php.

Aug 20, 2024
CVE-2024-42574
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at attendance.php.

Aug 20, 2024
CVE-2024-42573
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at dtmarks.php.

Aug 20, 2024
CVE-2024-42572
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at unitmarks.php.

Aug 20, 2024
CVE-2024-42571
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at insertattendance.php.

Aug 20, 2024
CVE-2024-42570
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at admininsert.php.

Aug 20, 2024
CVE-2024-42569
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at paidclass.php.

Aug 20, 2024
CVE-2024-42568
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the transport parameter at vehicle.php.

Aug 20, 2024
CVE-2024-42567
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the sid parameter at /search.php?action=2.

Aug 20, 2024
CVE-2024-42566
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the password parameter at login.php

Aug 20, 2024
CVE-2024-42565
9.8 CRITICAL

ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/contact/delete?action=delete.

Aug 20, 2024
CVE-2024-42563
9.8 CRITICAL

An arbitrary file upload vulnerability in ERP commit 44bd04 allows attackers to execute arbitrary code via uploading a crafted HTML file.

Aug 20, 2024
CVE-2024-42562
9.8 CRITICAL

Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at preview.php.

Aug 20, 2024
CVE-2024-42559
9.8 CRITICAL

An issue in the login component (process_login.php) of Hotel Management System commit 79d688 allows attackers to authenticate without providing a valid password.

Aug 20, 2024
CVE-2024-42558
9.8 CRITICAL

Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_modify_room.php.

Aug 20, 2024
CVE-2024-42556
9.8 CRITICAL

Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_removed.php.

Aug 20, 2024
CVE-2024-43202
9.8 CRITICAL

Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgrade Apache DolphinScheduler to version 3.2.2, …

Aug 20, 2024
CVE-2024-6847
9.8 CRITICAL

The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to …

Aug 20, 2024
CVE-2024-7777
9.0 CRITICAL

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable …

Aug 20, 2024
CVE-2024-5932
10.0 CRITICAL

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 …

Aug 20, 2024
CVE-2024-43354
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2.

Aug 19, 2024
CVE-2024-43311
9.8 CRITICAL

Improper Privilege Management vulnerability in Geek Code Lab Login As Users allows Privilege Escalation.This issue affects Login As Users: from n/a through 1.4.2.

Aug 19, 2024
CVE-2024-42815
9.8 CRITICAL

In the TP-Link RE365 V1_180213, there is a buffer overflow vulnerability due to the lack of length verification for the USER_AGENT field in /usr/bin/httpd. Attackers …

Aug 19, 2024
CVE-2024-42813
9.8 CRITICAL

In TRENDnet TEW-752DRU FW1.03B01, there is a buffer overflow vulnerability due to the lack of length verification for the service field in gena.cgi. Attackers who …

Aug 19, 2024
CVE-2024-42812
9.8 CRITICAL

In D-Link DIR-860L v2.03, there is a buffer overflow vulnerability due to the lack of length verification for the SID field in gena.cgi. Attackers who …

Aug 19, 2024
CVE-2024-43261
9.6 CRITICAL

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hamed Naderfar Compute Links allows PHP Remote File Inclusion.This …

Aug 19, 2024
CVE-2024-43252
9.0 CRITICAL

Deserialization of Untrusted Data vulnerability in Crew HRM Crew HRM hr-management.This issue affects Crew HRM: from n/a through <= 1.1.1.

Aug 19, 2024
CVE-2024-43249
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form Pro allows Command Injection.This issue affects Bit Form Pro: from n/a through …

Aug 19, 2024
CVE-2024-43245
9.8 CRITICAL

Improper Privilege Management vulnerability in eyecix JobSearch allows Privilege Escalation.This issue affects JobSearch: from n/a through 2.3.4.

Aug 19, 2024
CVE-2024-43242
9.0 CRITICAL

Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.

Aug 19, 2024
CVE-2024-43401
9.0 CRITICAL

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can trick a …

Aug 19, 2024
CVE-2024-43400
9.0 CRITICAL

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible for a user without Script …

Aug 19, 2024
CVE-2024-43240
9.4 CRITICAL

Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.

Aug 19, 2024
CVE-2024-42658
9.8 CRITICAL

An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's parameter

Aug 19, 2024
CVE-2024-37099
10.0 CRITICAL

Deserialization of Untrusted Data vulnerability in Liquid Web GiveWP allows Object Injection.This issue affects GiveWP: from n/a through 3.14.1.

Aug 19, 2024
CVE-2024-6330
9.8 CRITICAL

The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files in PHP's execution context, which leads to Remote …

Aug 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.