CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7811
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Daily Expenses Monitoring App 1.0. This affects an unknown part of the file /endpoint/delete-expense.php. The …

Aug 15, 2024
CVE-2024-7628
8.1 HIGH

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in versions up to, …

Aug 15, 2024
CVE-2024-7624
8.1 HIGH

The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.101. This is due to …

Aug 15, 2024
CVE-2024-7420
5.8 MEDIUM

The Insert PHP Code Snippet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.6. This is due …

Aug 15, 2024
CVE-2024-6533
5.4 MEDIUM

Directus v10.13.0 allows an authenticated external attacker to execute arbitrary JavaScript on the client. This is possible because the application injects an attacker-controlled parameter that …

Aug 15, 2024
CVE-2024-25024
5.5 MEDIUM

IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores user credentials in plain clear text which can …

Aug 15, 2024
CVE-2024-7810
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Aug 15, 2024
CVE-2024-7809
5.3 MEDIUM

A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality …

Aug 15, 2024
CVE-2024-7808
7.3 HIGH

A vulnerability was found in code-projects Job Portal 1.0. It has been classified as critical. Affected is an unknown function of the file logindbc.php. The …

Aug 15, 2024
CVE-2024-7800
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Simple Online Bidding System 1.0. This affects an unknown part of the file /simple-online-bidding-system/bidding/admin/ajax.php?action=delete_product. The …

Aug 15, 2024
CVE-2024-7799
5.3 MEDIUM

A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Aug 15, 2024
CVE-2024-7798
7.3 HIGH

A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Aug 15, 2024
CVE-2024-7797
7.3 HIGH

A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Aug 15, 2024
CVE-2024-7625
5.8 MEDIUM

In HashiCorp Nomad and Nomad Enterprise from 0.6.1 up to 1.6.13, 1.7.10, and 1.8.2, the archive unpacking process is vulnerable to writes outside the allocation …

Aug 15, 2024
CVE-2024-43368
6.5 MEDIUM

The Trix editor, versions prior to 2.1.4, is vulnerable to XSS when pasting malicious code. This vulnerability is a bypass of the fix put in …

Aug 14, 2024
CVE-2024-7794
6.3 MEDIUM

A vulnerability was found in itsourcecode Vehicle Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Aug 14, 2024
CVE-2024-7793
3.5 LOW

A vulnerability was found in SourceCodester Task Progress Tracker 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Aug 14, 2024
CVE-2024-42353
6.1 MEDIUM

WebOb provides objects for HTTP requests and responses. When WebOb normalizes the HTTP Location header to include the request hostname, it does so by parsing …

Aug 14, 2024
CVE-2024-7515
7.5 HIGH

CVE-2024-7515 IMPACT A denial-of-service vulnerability exists in the affected products. A malformed PTP management packet can cause a major nonrecoverable fault in the controller.

Aug 14, 2024
CVE-2024-7513
8.8 HIGH

CVE-2024-7513 IMPACT A code execution vulnerability exists in the affected product. The vulnerability occurs due to improper default file permissions allowing any user to edit …

Aug 14, 2024
CVE-2024-7507
6.5 MEDIUM

CVE-2024-7507 IMPACT A denial-of-service vulnerability exists in the affected products. This vulnerability occurs when a malformed PCCC message is received, causing a fault in the …

Aug 14, 2024
CVE-2024-6078

CVE-2024-6078 IMPACT An improper authentication vulnerability exists in the affected product, which could allow a malicious user to generate cookies for any user ID without …

Aug 14, 2024
CVE-2024-42360
9.8 CRITICAL

SequenceServer lets you rapidly set up a BLAST+ server with an intuitive user interface for personal or group use. Several HTTP endpoints did not properly …

Aug 14, 2024
CVE-2024-40620
7.5 HIGH

CVE-2024-40620 IMPACT A vulnerability exists in the affected product due to lack of encryption of sensitive information. The vulnerability results in data being sent between …

Aug 14, 2024
CVE-2024-40619
7.5 HIGH

CVE-2024-40619 IMPACT A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sent over the network to the …

Aug 14, 2024
CVE-2024-27120
7.5 HIGH

A Local File Inclusion vulnerability has been found in ComfortKey, a product of Celsius Benelux. Using this vulnerability, an unauthenticated attacker may retrieve sensitive information …

Aug 14, 2024
CVE-2024-7792
6.3 MEDIUM

A vulnerability was found in SourceCodester Task Progress Tracker 1.0. It has been classified as critical. Affected is an unknown function of the file /endpoint/delete-task.php. …

Aug 14, 2024
CVE-2024-37529
6.5 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 could allow an authenticated user to cause a denial of service …

Aug 14, 2024
CVE-2024-35152
6.5 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to cause a denial of service with a …

Aug 14, 2024
CVE-2024-35136
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) federated server 10.5, 11.1, and 11.5 is vulnerable to denial of service with a …

Aug 14, 2024
CVE-2024-31882
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service, under specific non default …

Aug 14, 2024
CVE-2023-50314
5.3 MEDIUM

IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.8 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit …

Aug 14, 2024
CVE-2024-5916
4.4 MEDIUM

An information exposure vulnerability in Palo Alto Networks PAN-OS software enables a local system administrator to unintentionally disclose secrets, passwords, and tokens of external systems. …

Aug 14, 2024
CVE-2024-5915
7.8 HIGH

A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges.

Aug 14, 2024
CVE-2024-5914
9.8 CRITICAL

A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an …

Aug 14, 2024
CVE-2024-42441
6.2 MEDIUM

Incorrect privilege assignment in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before …

Aug 14, 2024
CVE-2024-42440
6.2 MEDIUM

Improper privilege management in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before …

Aug 14, 2024
CVE-2024-42439
6.5 MEDIUM

Untrusted search path in the installer for Zoom Workplace Desktop App for macOS and Zoom Meeting SDK for macOS before 6.1.0 may allow a privileged …

Aug 14, 2024
CVE-2024-42438
6.5 MEDIUM

Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via …

Aug 14, 2024
CVE-2024-42437
6.5 MEDIUM

Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via …

Aug 14, 2024
CVE-2024-42436
6.5 MEDIUM

Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via …

Aug 14, 2024
CVE-2024-42435
4.9 MEDIUM

Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via …

Aug 14, 2024
CVE-2024-42434
4.9 MEDIUM

Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network …

Aug 14, 2024
CVE-2024-39825
8.5 HIGH

Buffer overflow in some Zoom Workplace Apps and Rooms Clients may allow an authenticated user to conduct an escalation of privilege via network access.

Aug 14, 2024
CVE-2024-39824
4.9 MEDIUM

Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network …

Aug 14, 2024
CVE-2024-39823
4.9 MEDIUM

Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network …

Aug 14, 2024
CVE-2024-39822
6.5 MEDIUM

Sensitive information exposure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct an information disclosure via …

Aug 14, 2024
CVE-2024-39818
7.5 HIGH

Protection mechanism failure for some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct information disclosure via network access.

Aug 14, 2024
CVE-2023-50315
5.3 MEDIUM

IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this …

Aug 14, 2024
CVE-2024-28799
5.6 MEDIUM

IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 displays sensitive data improperly to a local privileged user, …

Aug 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.