CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5939
5.3 MEDIUM

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on …

Aug 20, 2024
CVE-2024-5932
10.0 CRITICAL

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 …

Aug 20, 2024
CVE-2024-7943
6.3 MEDIUM

A vulnerability was found in itsourcecode Laravel Property Management System 1.0 and classified as critical. This issue affects the function upload of the file PropertiesController.php. …

Aug 20, 2024
CVE-2024-7942
3.5 LOW

A vulnerability has been found in SourceCodester Leads Manager Tool 1.0 and classified as problematic. This vulnerability affects unknown code of the file update-leads.php. The …

Aug 20, 2024
CVE-2024-7937
6.3 MEDIUM

A vulnerability classified as critical was found in itsourcecode Project Expense Monitoring System 1.0. This vulnerability affects unknown code of the file printtransfer.php. The manipulation …

Aug 20, 2024
CVE-2024-7936
6.3 MEDIUM

A vulnerability classified as critical has been found in itsourcecode Project Expense Monitoring System 1.0. This affects an unknown part of the file transferred_report.php. The …

Aug 20, 2024
CVE-2024-7305
7.8 HIGH

A maliciously crafted DWF file, when parsed in AdDwfPdk.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability …

Aug 20, 2024
CVE-2024-7935
6.3 MEDIUM

A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Aug 19, 2024
CVE-2024-7934
6.3 MEDIUM

A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Aug 19, 2024
CVE-2024-7933
7.3 HIGH

A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Aug 19, 2024
CVE-2024-7931
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0 and classified as critical. This issue affects some unknown processing of the file /tracking/admin/view_csprofile.php. …

Aug 19, 2024
CVE-2024-7930
6.3 MEDIUM

A vulnerability has been found in SourceCodester Clinics Patient Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /pms/ajax/get_packings.php. …

Aug 19, 2024
CVE-2024-7929
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in SourceCodester Simple Forum Website 1.0. This affects an unknown part of the file /registration.php of …

Aug 19, 2024
CVE-2024-7928
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in FastAdmin up to 1.3.3.20220121. Affected by this issue is some unknown functionality of the …

Aug 19, 2024
CVE-2024-4785
7.6 HIGH

BT: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Division by Zero

Aug 19, 2024
CVE-2024-35539
6.5 MEDIUM

Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerability allows attackers to post several comments before the …

Aug 19, 2024
CVE-2024-35538
5.3 MEDIUM

Typecho v1.3.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as …

Aug 19, 2024
CVE-2024-7958

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 19, 2024
CVE-2024-7927
7.3 HIGH

A vulnerability classified as critical was found in ZZCMS 2023. Affected by this vulnerability is an unknown functionality of the file /admin/class.php?dowhat=modifyclass. The manipulation of …

Aug 19, 2024
CVE-2024-7926
7.3 HIGH

A vulnerability classified as critical has been found in ZZCMS 2023. Affected is an unknown function of the file /admin/about_edit.php?action=modify. The manipulation of the argument …

Aug 19, 2024
CVE-2024-43354
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2.

Aug 19, 2024
CVE-2024-43345
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PluginOps Landing Page Builder allows PHP Local File Inclusion.This issue affects Landing …

Aug 19, 2024
CVE-2024-43328
8.3 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper EmbedPress allows PHP Local File Inclusion.This issue affects EmbedPress: from n/a …

Aug 19, 2024
CVE-2024-43326
5.4 MEDIUM

Missing Authorization vulnerability in Jamie Bergen Plugin Notes Plus allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Plugin Notes Plus: from n/a through …

Aug 19, 2024
CVE-2024-43317
4.3 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Metagauss User Registration Team RegistrationMagic allows Cross-Site Scripting (XSS).This issue affects …

Aug 19, 2024
CVE-2024-43311
9.8 CRITICAL

Improper Privilege Management vulnerability in Geek Code Lab Login As Users allows Privilege Escalation.This issue affects Login As Users: from n/a through 1.4.2.

Aug 19, 2024
CVE-2024-42815
9.8 CRITICAL

In the TP-Link RE365 V1_180213, there is a buffer overflow vulnerability due to the lack of length verification for the USER_AGENT field in /usr/bin/httpd. Attackers …

Aug 19, 2024
CVE-2024-42813
9.8 CRITICAL

In TRENDnet TEW-752DRU FW1.03B01, there is a buffer overflow vulnerability due to the lack of length verification for the service field in gena.cgi. Attackers who …

Aug 19, 2024
CVE-2024-42812
9.8 CRITICAL

In D-Link DIR-860L v2.03, there is a buffer overflow vulnerability due to the lack of length verification for the SID field in gena.cgi. Attackers who …

Aug 19, 2024
CVE-2024-7592
7.5 HIGH

There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contained backslashes for quoted characters in the …

Aug 19, 2024
CVE-2024-23729
6.1 MEDIUM

The ColorOS Internet Browser com.heytap.browser application 45.10.3.4.1 for Android allows a remote attacker to execute arbitrary JavaScript code via the com.android.browser.RealBrowserActivity component.

Aug 19, 2024
CVE-2024-7925
4.3 MEDIUM

A vulnerability was found in ZZCMS 2023. It has been rated as problematic. This issue affects some unknown processing of the file 3/E_bak5.1/upload/eginfo.php. The manipulation …

Aug 19, 2024
CVE-2024-7924
5.3 MEDIUM

A vulnerability was found in ZZCMS 2023. It has been declared as critical. This vulnerability affects unknown code of the file /I/list.php. The manipulation of …

Aug 19, 2024
CVE-2024-43281
5.3 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in VOID CODERS Void Elementor Post Grid Addon for Elementor Page builder allows …

Aug 19, 2024
CVE-2024-43280
4.7 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking system: from n/a through 10.8.1.

Aug 19, 2024
CVE-2024-43272
5.3 MEDIUM

Missing Authentication for Critical Function vulnerability in icegram Icegram allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Icegram: from n/a through 3.1.24.

Aug 19, 2024
CVE-2024-43271
8.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themelocation Woo Products Widgets For Elementor allows PHP Local File Inclusion.This issue …

Aug 19, 2024
CVE-2024-43261
9.6 CRITICAL

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hamed Naderfar Compute Links allows PHP Remote File Inclusion.This …

Aug 19, 2024
CVE-2024-43256
7.1 HIGH

Missing Authorization vulnerability in nouthemes Leopard - WordPress offload media allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Leopard - WordPress offload media: …

Aug 19, 2024
CVE-2024-43252
9.0 CRITICAL

Deserialization of Untrusted Data vulnerability in Crew HRM Crew HRM hr-management.This issue affects Crew HRM: from n/a through <= 1.1.1.

Aug 19, 2024
CVE-2024-43250
7.1 HIGH

Incorrect Authorization vulnerability in Bit Apps Bit Form Pro bitformpro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bit Form Pro: from n/a …

Aug 19, 2024
CVE-2024-43249
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form Pro allows Command Injection.This issue affects Bit Form Pro: from n/a through …

Aug 19, 2024
CVE-2024-43248
8.6 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bit Apps Bit Form Pro allows File Manipulation.This issue affects Bit Form …

Aug 19, 2024
CVE-2024-43247
8.8 HIGH

Missing Authorization vulnerability in creativeon WHMpress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WHMpress: from n/a through 6.2-revision-5.

Aug 19, 2024
CVE-2024-43245
9.8 CRITICAL

Improper Privilege Management vulnerability in eyecix JobSearch allows Privilege Escalation.This issue affects JobSearch: from n/a through 2.3.4.

Aug 19, 2024
CVE-2024-43242
9.0 CRITICAL

Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.

Aug 19, 2024
CVE-2024-43401
9.0 CRITICAL

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can trick a …

Aug 19, 2024
CVE-2024-43400
9.0 CRITICAL

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible for a user without Script …

Aug 19, 2024
CVE-2024-43240
9.4 CRITICAL

Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.

Aug 19, 2024
CVE-2024-43236
4.7 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Scott Paterson Easy PayPal Buy Now Button.This issue affects Easy PayPal Buy Now Button: from n/a …

Aug 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.