CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7700
6.5 MEDIUM

A command injection flaw was found in the "Host Init Config" template in the Foreman application via the "Install Packages" field on the "Register Host" …

Aug 12, 2024
CVE-2024-42627
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/delete/3.

Aug 12, 2024
CVE-2024-42626
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/add.

Aug 12, 2024
CVE-2024-42625
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/add

Aug 12, 2024
CVE-2024-42624
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/delete/10.

Aug 12, 2024
CVE-2024-42623
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/delete/1

Aug 12, 2024
CVE-2024-42474
6.5 MEDIUM

Streamlit is a data oriented application development framework for python. Snowflake Streamlit open source addressed a security vulnerability via the static file sharing feature. Users …

Aug 12, 2024
CVE-2024-41651
8.1 HIGH

An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disputed by …

Aug 12, 2024
CVE-2024-41475
8.8 HIGH

Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.

Aug 12, 2024
CVE-2024-40500
8.6 HIGH

Cross Site Scripting vulnerability in Martin Kucej i-librarian v.5.11.0 and before allows a local attacker to execute arbitrary code via the search function in the …

Aug 12, 2024
CVE-2024-42632
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/add.

Aug 12, 2024
CVE-2024-42631
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/edit/1.

Aug 12, 2024
CVE-2024-42630
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_file.

Aug 12, 2024
CVE-2024-42629
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/edit/10.

Aug 12, 2024
CVE-2024-42628
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/edit/3.

Aug 12, 2024
CVE-2024-42489
10.0 CRITICAL

Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the `CKEditor.HTMLConverter` page or edit or …

Aug 12, 2024
CVE-2024-42485
7.5 HIGH

Filament Excel enables excel export for Filament admin resources. The export download route `/filament-excel/{path}` allowed downloading any file without login when the webserver allows `../` …

Aug 12, 2024
CVE-2024-42482
4.8 MEDIUM

fish-shop/syntax-check is a GitHub action for syntax checking fish shell files. Improper neutralization of delimiters in the `pattern` input (specifically the command separator `;` and …

Aug 12, 2024
CVE-2024-42481
7.5 HIGH

Skyport Daemon (skyportd) is the daemon for the Skyport Panel. By making thousands of folders & files (easy due to skyport's lack of rate limiting …

Aug 12, 2024
CVE-2024-42480
8.1 HIGH

Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an "open at the top" range definition in RBAC …

Aug 12, 2024
CVE-2024-41909
5.9 MEDIUM

Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic …

Aug 12, 2024
CVE-2024-39091
8.8 HIGH

An OS command injection vulnerability in the ccm_debug component of MIPC Camera firmware prior to v5.4.1.240424171021 allows attackers within the same network to execute arbitrary …

Aug 12, 2024
CVE-2024-36877
8.2 HIGH

Micro-Star International Z-series motherboards (Z590, Z490, and Z790) and B-series motherboards (B760, B560, B660, and B460) with firmware 7D25v14, 7D25v17 to 7D25v19, and 7D25v1A to …

Aug 12, 2024
CVE-2023-7249
9.8 CRITICAL

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: …

Aug 12, 2024
CVE-2024-6917
9.8 CRITICAL

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Veribilim Software Veribase Order Management allows OS Command Injection.This issue …

Aug 12, 2024
CVE-2024-42520
9.8 CRITICAL

TOTOLINK A3002R v4.0.0-B20230531.1404 contains a buffer overflow vulnerability in /bin/boa via formParentControl.

Aug 12, 2024
CVE-2024-42479
10.0 CRITICAL

llama.cpp provides LLM inference in C/C++. The unsafe `data` pointer member in the `rpc_tensor` structure can cause arbitrary address writing. This vulnerability is fixed in …

Aug 12, 2024
CVE-2024-42478
5.3 MEDIUM

llama.cpp provides LLM inference in C/C++. The unsafe `data` pointer member in the `rpc_tensor` structure can cause arbitrary address reading. This vulnerability is fixed in …

Aug 12, 2024
CVE-2024-42477
5.3 MEDIUM

llama.cpp provides LLM inference in C/C++. The unsafe `type` member in the `rpc_tensor` structure can cause `global-buffer-overflow`. This vulnerability may lead to memory data leakage. …

Aug 12, 2024
CVE-2024-42258
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm: huge_memory: use !CONFIG_64BIT to relax huge page alignment on 32 bit machines Yves-Alexis Perez …

Aug 12, 2024
CVE-2024-38530
9.8 CRITICAL

The Open eClass platform (formerly known as GUnet eClass) is a complete Course Management System. An arbitrary file upload vulnerability in the "save" functionality of …

Aug 12, 2024
CVE-2024-33536
5.4 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The vulnerability occurs due to inadequate input validation of the res parameter, allowing an …

Aug 12, 2024
CVE-2024-33535
7.5 HIGH

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The vulnerability involves unauthenticated local file inclusion (LFI) in a web application, specifically impacting …

Aug 12, 2024
CVE-2024-33533
5.4 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0, issue 1 of 2. A reflected cross-site scripting (XSS) vulnerability has been identified in …

Aug 12, 2024
CVE-2024-27443
6.1 MEDIUM KEV

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail …

Aug 12, 2024
CVE-2024-27442
7.8 HIGH

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The zmmailboxdmgr binary, a component of ZCS, is intended to be executed by the …

Aug 12, 2024
CVE-2024-21550
6.1 MEDIUM

SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management …

Aug 12, 2024
CVE-2024-6639
6.4 MEDIUM

The MDx theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mdx_list_item' shortcode in all versions up to, and including, 2.0.3 due …

Aug 12, 2024
CVE-2024-7697
7.5 HIGH

Logical vulnerability in the mobile application (com.transsion.carlcare) may lead to user information leakage risks.

Aug 12, 2024
CVE-2024-7694
7.2 HIGH KEV

ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious …

Aug 12, 2024
CVE-2024-7693
7.5 HIGH

Raiden MAILD Remote Management System from Team Johnlong Software has a Relative Path Traversal vulnerability, allowing unauthenticated remote attackers to read arbitrary file on the …

Aug 12, 2024
CVE-2024-7686
3.5 LOW

A vulnerability, which was classified as problematic, was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. This affects an unknown part of the …

Aug 12, 2024
CVE-2024-7685
3.5 LOW

A vulnerability, which was classified as problematic, has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected by this issue is some …

Aug 12, 2024
CVE-2024-7684
3.5 LOW

A vulnerability classified as problematic was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected by this vulnerability is an unknown functionality of …

Aug 12, 2024
CVE-2024-7683
3.5 LOW

A vulnerability classified as problematic has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected is an unknown function of the file …

Aug 12, 2024
CVE-2024-7682
7.3 HIGH

A vulnerability was found in code-projects Job Portal 1.0. It has been rated as critical. This issue affects some unknown processing of the file rw_i_nat.php. …

Aug 12, 2024
CVE-2024-7681
7.3 HIGH

A vulnerability was found in code-projects College Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login.php …

Aug 12, 2024
CVE-2024-7680
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been classified as critical. This affects an unknown part of the file /incedit.php?id=4. …

Aug 12, 2024
CVE-2024-7678
3.5 LOW

A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown …

Aug 12, 2024
CVE-2024-7677
3.5 LOW

A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been declared as problematic. Affected by this vulnerability is the function …

Aug 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.