CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-42662
7.5 HIGH

An issue in apollocongif apollo v.2.2.0 allows a remote attacker to obtain sensitive information via a crafted request.

Aug 20, 2024
CVE-2024-42621
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_editor.php

Aug 20, 2024
CVE-2024-42618
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /module.php?module=karma

Aug 20, 2024
CVE-2024-42617
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_config.php?action=save&var_id=32

Aug 20, 2024
CVE-2024-42616
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.php?action=remove&widget=Statistics

Aug 20, 2024
CVE-2024-42613
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.php?action=install&widget=akismet

Aug 20, 2024
CVE-2024-42611
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/admin_page.php?link_id=1&mode=delete

Aug 20, 2024
CVE-2024-42610
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=files

Aug 20, 2024
CVE-2024-42609
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=avatars

Aug 20, 2024
CVE-2024-42607
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=database

Aug 20, 2024
CVE-2024-42606
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_log.php?clear=1

Aug 20, 2024
CVE-2024-42605
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/edit_page.php?link_id=1

Aug 20, 2024
CVE-2024-42604
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_group.php?mode=delete&group_id=3

Aug 20, 2024
CVE-2024-42603
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=clearall

Aug 20, 2024
CVE-2024-42369
4.1 MEDIUM

matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. A malicious homeserver can craft a room or room structure such that the predecessors form …

Aug 20, 2024
CVE-2024-39690
8.4 HIGH

Capsule is a multi-tenancy and policy-based framework for Kubernetes. In Capsule v0.7.0 and earlier, the tenant-owner can patch any arbitrary namespace that has not been …

Aug 20, 2024
CVE-2024-35540
9.0 CRITICAL

A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Aug 20, 2024
CVE-2024-30949
9.8 CRITICAL

An issue in newlib v.4.3.0 allows an attacker to execute arbitrary code via the time unit scaling in the _gettimeofday function.

Aug 20, 2024
CVE-2024-8005
7.3 HIGH

A vulnerability was found in demozx gf_cms 1.0/1.0.1. It has been classified as critical. This affects the function init of the file internal/logic/auth/auth.go of the …

Aug 20, 2024
CVE-2024-8003
3.5 LOW

A vulnerability was found in Go-Tribe gotribe-admin 1.0 and classified as problematic. Affected by this issue is the function InitRoutes of the file internal/app/routes/routes.go of …

Aug 20, 2024
CVE-2024-6379
7.7 HIGH

A reflected Cross-site Scripting (XSS) vulnerability affecting 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in …

Aug 20, 2024
CVE-2024-6378
8.7 HIGH

A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary …

Aug 20, 2024
CVE-2024-6377
8.1 HIGH

An URL redirection to untrusted site (open redirect) vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to …

Aug 20, 2024
CVE-2024-42608
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/submit_page.php.

Aug 20, 2024
CVE-2024-42006
7.5 HIGH

Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure.

Aug 20, 2024
CVE-2024-39094
5.4 MEDIUM

Friendica 2024.03 is vulnerable to Cross Site Scripting (XSS) in settings/profile via the homepage, xmpp, and matrix parameters.

Aug 20, 2024
CVE-2024-34458
7.5 HIGH

Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in information disclosure.

Aug 20, 2024
CVE-2024-33872
9.8 CRITICAL

Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code execution and escalation of privileges.

Aug 20, 2024
CVE-2024-6918
7.5 HIGH

CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause a crash of the Accutech Manager when receiving a …

Aug 20, 2024
CVE-2024-42586
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42585
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component delete_media.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42584
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component delete_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42583
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component delete_user.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42582
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component delete_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42581
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component delete_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42580
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component edit_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42579
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component add_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42578
8.0 HIGH

A Cross-Site Request Forgery (CSRF) in the component edit_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42577
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component add_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42576
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component edit_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42575
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at substaff.php.

Aug 20, 2024
CVE-2024-42574
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at attendance.php.

Aug 20, 2024
CVE-2024-42573
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at dtmarks.php.

Aug 20, 2024
CVE-2024-42572
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at unitmarks.php.

Aug 20, 2024
CVE-2024-42571
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at insertattendance.php.

Aug 20, 2024
CVE-2024-42570
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at admininsert.php.

Aug 20, 2024
CVE-2024-42569
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at paidclass.php.

Aug 20, 2024
CVE-2024-42568
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the transport parameter at vehicle.php.

Aug 20, 2024
CVE-2024-42567
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the sid parameter at /search.php?action=2.

Aug 20, 2024
CVE-2024-42566
9.8 CRITICAL

School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the password parameter at login.php

Aug 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.