CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-42634
9.8 CRITICAL

A Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03.06.42. As a result, attacker can execute OS commands with root …

Aug 16, 2024
CVE-2024-6098
5.3 MEDIUM

When performing an online tag generation to devices which communicate using the ControlLogix protocol, a machine-in-the-middle, or a device that is not configured correctly, could …

Aug 16, 2024
CVE-2024-6004
6.5 MEDIUM

A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to deny printer connections until the …

Aug 16, 2024
CVE-2024-5210
6.5 MEDIUM

A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to prevent printer services from being …

Aug 16, 2024
CVE-2024-5209
6.5 MEDIUM

A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to deny printing capabilities until the …

Aug 16, 2024
CVE-2024-4782
6.5 MEDIUM

A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to disrupt the printer's functionality until …

Aug 16, 2024
CVE-2024-4781
6.5 MEDIUM

A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to crash printer communications until the …

Aug 16, 2024
CVE-2024-4763
7.8 HIGH

An insecure driver vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM) that could allow a local attacker …

Aug 16, 2024
CVE-2024-43810
4.6 MEDIUM

In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin

Aug 16, 2024
CVE-2024-43809
3.5 LOW

In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page

Aug 16, 2024
CVE-2024-43808
3.7 LOW

In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin

Aug 16, 2024
CVE-2024-43807
4.6 MEDIUM

In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page

Aug 16, 2024
CVE-2024-43381
5.0 MEDIUM

reNgine is an automated reconnaissance framework for web applications. Versions 2.1.2 and prior are susceptible to Stored Cross-Site Scripting (XSS) attacks. This vulnerability occurs when …

Aug 16, 2024
CVE-2024-42486
5.4 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In versions on the 1.15.x branch prior to 1.15.8 and the 1.16.x branch …

Aug 16, 2024
CVE-2024-2175
7.8 HIGH

An insecure permissions vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM) that could allow a local attacker …

Aug 16, 2024
CVE-2024-7145
8.8 HIGH

The JetElements plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.6.20 via the 'progress_type' parameter. This makes …

Aug 16, 2024
CVE-2024-7144
6.4 MEDIUM

The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'slide_id' parameters in all versions up to, and including, 2.6.20 …

Aug 16, 2024
CVE-2024-42466
9.8 CRITICAL

Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Abuse.This issue affects upKeeper Manager: through 5.1.9.

Aug 16, 2024
CVE-2024-42465
9.8 CRITICAL

Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Abuse.This issue affects upKeeper Manager: through 5.1.9.

Aug 16, 2024
CVE-2024-42464
6.5 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Utilizing REST's Trust in the System Resource to Obtain Sensitive Data.This issue …

Aug 16, 2024
CVE-2024-42463
6.5 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Utilizing REST's Trust in the System Resource to Obtain Sensitive Data.This issue …

Aug 16, 2024
CVE-2024-42462
9.8 CRITICAL

Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This issue affects upKeeper Manager: through 5.1.9.

Aug 16, 2024
CVE-2024-7147
6.4 MEDIUM

The JetBlocks for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple placeholder parameters in all versions up to, and including, 1.3.12 …

Aug 16, 2024
CVE-2024-7146
8.8 HIGH

The JetTabs for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.3 via the 'switcher_preset' parameter. …

Aug 16, 2024
CVE-2024-7136
6.4 MEDIUM

The JetSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 3.5.2 due to …

Aug 16, 2024
CVE-2024-25008
6.8 MEDIUM

Ericsson RAN Compute and Site Controller 6610 contains a vulnerability in the Control System where Improper Input Validation can lead to arbitrary code execution, for …

Aug 16, 2024
CVE-2024-7501
4.2 MEDIUM

The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Aug 16, 2024
CVE-2024-6460
9.8 CRITICAL

The Grow by Tradedoubler WordPress plugin through 2.0.21 is vulnerable to Local File Inclusion via the component parameter. This makes it possible for attackers to …

Aug 16, 2024
CVE-2024-7301
7.2 HIGH

The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.24.8 …

Aug 16, 2024
CVE-2024-7422
4.3 MEDIUM

The Theme My Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.1.7. This is due to …

Aug 16, 2024
CVE-2024-7630
5.3 MEDIUM

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.22.2 (Free) and 2.25.1 …

Aug 16, 2024
CVE-2023-7049
4.3 MEDIUM

The Custom Field For WP Job Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2 …

Aug 16, 2024
CVE-2022-3399
4.4 MEDIUM

The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cookie_notice_options[refuse_code_head]' parameter in versions up …

Aug 16, 2024
CVE-2024-7853
6.3 MEDIUM

A vulnerability was found in SourceCodester Yoga Class Registration System up to 1.0. It has been classified as critical. Affected is an unknown function of …

Aug 16, 2024
CVE-2024-7852
3.5 LOW

A vulnerability was found in SourceCodester Yoga Class Registration System 1.0 and classified as problematic. This issue affects some unknown processing of the file /admin/inquiries/view_inquiry.php. …

Aug 16, 2024
CVE-2024-7851
6.3 MEDIUM

A vulnerability has been found in SourceCodester Yoga Class Registration System 1.0 and classified as critical. This vulnerability affects unknown code of the file /classes/Users.php?f=save …

Aug 16, 2024
CVE-2024-7849
8.8 HIGH

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, …

Aug 16, 2024
CVE-2024-7845
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Aug 16, 2024
CVE-2024-43378
7.8 HIGH

calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users who installed NixOS through the graphical installer who used manual disk partitioning …

Aug 16, 2024
CVE-2024-43374
4.5 MEDIUM

The UNIX editor Vim prior to version 9.1.0678 has a use-after-free error in argument list handling. When adding a new file to the argument list, …

Aug 16, 2024
CVE-2024-43370
7.2 HIGH

gettext.js is a GNU gettext port for node and the browser. There is a cross-site scripting (XSS) injection if `.po` dictionary definition files are corrupted. …

Aug 16, 2024
CVE-2024-43369
7.2 HIGH

Ibexa RichText Field Type is a Field Type for supporting rich formatted text stored in a structured XML format. In versions on the 4.6 branch …

Aug 16, 2024
CVE-2024-7844
3.5 LOW

A vulnerability has been found in SourceCodester Online Graduate Tracer System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of …

Aug 15, 2024
CVE-2024-7843
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0. Affected is an unknown function of the file /tracking/admin/exportcs.php. …

Aug 15, 2024
CVE-2024-7842
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in SourceCodester Online Graduate Tracer System 1.0. This issue affects some unknown processing of the …

Aug 15, 2024
CVE-2024-7841
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Clinics Patient Management System 1.0. This vulnerability affects unknown code of the file /pms/ajax/check_user_name.php. The manipulation …

Aug 15, 2024
CVE-2024-34743
7.8 HIGH

In setTransactionState of SurfaceFlinger.cpp, there is a possible way to perform tapjacking due to a logic error in the code. This could lead to local …

Aug 15, 2024
CVE-2024-34742
5.5 MEDIUM

In shouldWrite of OwnersData.java, there is a possible edge case that prevents MDM policies from being persisted due to a logic error in the code. …

Aug 15, 2024
CVE-2024-34741
7.8 HIGH

In setForceHideNonSystemOverlayWindowIfNeeded of WindowState.java, there is a possible way for message content to be visible on the screensaver while lock screen visibility settings are restricted …

Aug 15, 2024
CVE-2024-34740
7.8 HIGH

In attributeBytesBase64 and attributeBytesHex of BinaryXmlSerializer.java, there is a possible arbitrary XML injection due to an integer overflow. This could lead to local escalation of …

Aug 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.