CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7676
6.3 MEDIUM

A vulnerability was found in Sourcecodester Car Driving School Management System 1.0. It has been classified as critical. Affected is the function save_package of the …

Aug 12, 2024
CVE-2024-7669
6.3 MEDIUM

A vulnerability was found in SourceCodester Car Driving School Management System 1.0 and classified as critical. This issue affects the function delete_enrollment of the file …

Aug 12, 2024
CVE-2024-7668
6.3 MEDIUM

A vulnerability has been found in SourceCodester Car Driving School Management System 1.0 and classified as critical. This vulnerability affects the function delete_package of the …

Aug 12, 2024
CVE-2024-7667
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Car Driving School Management System 1.0. This affects the function delete_users of the file …

Aug 12, 2024
CVE-2024-7666
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Car Driving School Management System 1.0. Affected by this issue is some unknown …

Aug 12, 2024
CVE-2024-7665
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Car Driving School Management System 1.0. Affected by this vulnerability is an unknown functionality of the …

Aug 12, 2024
CVE-2024-7664
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Car Driving School Management System 1.0. Affected is an unknown function of the file view_details.php. …

Aug 12, 2024
CVE-2024-7663
6.3 MEDIUM

A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been rated as critical. This issue affects some unknown processing of …

Aug 12, 2024
CVE-2024-7662
4.3 MEDIUM

A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been declared as problematic. This vulnerability affects the function save_package of …

Aug 12, 2024
CVE-2024-7661
4.3 MEDIUM

A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been classified as problematic. This affects the function save_users of the …

Aug 12, 2024
CVE-2024-7660
3.5 LOW

A vulnerability has been found in SourceCodester File Manager App 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

Aug 12, 2024
CVE-2024-7659
3.7 LOW

A vulnerability, which was classified as problematic, was found in projectsend up to r1605. Affected is the function generate_random_string of the file includes/functions.php of the …

Aug 12, 2024
CVE-2024-7658
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in projectsend up to r1605. This issue affects the function get_preview of the file process.php. …

Aug 12, 2024
CVE-2024-7657
3.5 LOW

A vulnerability classified as problematic was found in Gila CMS 1.10.9. This vulnerability affects unknown code of the file /cm/update_rows/page?id=2 of the component HTTP POST …

Aug 12, 2024
CVE-2024-7649
6.1 MEDIUM

The Opal Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via checkout form fields in all versions up to, and including, 1.2.4 due …

Aug 12, 2024
CVE-2024-7648
4.3 MEDIUM

The Opal Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.4 via the private notes functionality …

Aug 12, 2024
CVE-2024-7645
4.3 MEDIUM

A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file …

Aug 12, 2024
CVE-2024-7644
3.5 LOW

A vulnerability was found in SourceCodester Leads Manager Tool 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/add-leads.php …

Aug 12, 2024
CVE-2024-7643
6.3 MEDIUM

A vulnerability was found in SourceCodester Leads Manager Tool 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Aug 12, 2024
CVE-2024-7642
6.3 MEDIUM

A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown …

Aug 12, 2024
CVE-2024-7641
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected is an unknown function of the …

Aug 12, 2024
CVE-2024-7640
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. This issue affects some unknown processing …

Aug 12, 2024
CVE-2024-7639
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. This vulnerability affects unknown code of the file delete_act.php. …

Aug 12, 2024
CVE-2024-7638
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. This affects an unknown part of the file …

Aug 12, 2024
CVE-2024-7637
7.3 HIGH

A vulnerability was found in code-projects Online Polling 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Aug 12, 2024
CVE-2024-7636
7.3 HIGH

A vulnerability was found in code-projects Simple Ticket Booking 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Aug 12, 2024
CVE-2024-7635
7.3 HIGH

A vulnerability was found in code-projects Simple Ticket Booking 1.0. It has been classified as critical. Affected is an unknown function of the file register_insert.php …

Aug 12, 2024
CVE-2024-7633

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

Aug 12, 2024
CVE-2024-7621
5.4 MEDIUM

The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Aug 12, 2024
CVE-2024-7616
5.5 MEDIUM

A vulnerability was found in Edimax IC-6220DC and IC-5150W up to 3.06. It has been rated as critical. Affected by this issue is the function …

Aug 12, 2024
CVE-2024-7615
8.8 HIGH

A vulnerability was found in Tenda FH1206 1.2.0.8. It has been declared as critical. Affected by this vulnerability is the function fromSafeClientFilter/fromSafeMacFilter/fromSafeUrlFilter. The manipulation leads …

Aug 12, 2024
CVE-2024-7614
8.8 HIGH

A vulnerability was found in Tenda FH1206 1.2.0.8(8155). It has been classified as critical. Affected is the function fromqossetting of the file /goform/qossetting. The manipulation …

Aug 12, 2024
CVE-2024-7613
8.8 HIGH

A vulnerability was found in Tenda FH1206 1.2.0.8(8155) and classified as critical. This issue affects the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer. The manipulation of …

Aug 12, 2024
CVE-2024-7589
8.1 HIGH

A signal handler in sshd(8) may call a logging function that is not async-signal-safe. The signal handler is invoked when a client does not authenticate …

Aug 12, 2024
CVE-2024-7574
6.1 MEDIUM

The Christmasify! plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.5. This is due to missing nonce validation …

Aug 12, 2024
CVE-2024-7557
8.8 HIGH

A vulnerability was found in OpenShift AI that allows for authentication bypass and privilege escalation across models within the same namespace. When deploying AI models, …

Aug 12, 2024
CVE-2024-7512
4.8 MEDIUM

Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in Board instances. A rogue administrator could inject malicious code. The Concrete …

Aug 12, 2024
CVE-2024-7503
9.8 CRITICAL

The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.5. This is due to the …

Aug 12, 2024
CVE-2024-7416
5.3 MEDIUM

The Reveal Template plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.7. This is due to the …

Aug 12, 2024
CVE-2024-7414
5.3 MEDIUM

The PDF Builder for WPForms plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.116. This is due …

Aug 12, 2024
CVE-2024-7413
5.3 MEDIUM

The Obfuscate Email plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.8.1. This is due to the …

Aug 12, 2024
CVE-2024-7412
5.3 MEDIUM

The No Update Nag plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.12. This is due to …

Aug 12, 2024
CVE-2024-7410
5.3 MEDIUM

The My Custom CSS PHP & ADS plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.3. This …

Aug 12, 2024
CVE-2024-7408
6.5 MEDIUM

This vulnerability exists in Airveda Air Quality Monitor PM2.5 PM10 due to transmission of sensitive information in plain text during AP pairing mode. An attacker …

Aug 12, 2024
CVE-2024-7399
8.8 HIGH KEV

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as …

Aug 12, 2024
CVE-2024-7382
5.3 MEDIUM

The Linkify Text plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.9.1. This is due to the …

Aug 12, 2024
CVE-2024-7272
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in FFmpeg up to 5.1.5. This affects the function fill_audiodata of the file /libswresample/swresample.c. The manipulation …

Aug 12, 2024
CVE-2024-7006
7.5 HIGH

A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, …

Aug 12, 2024
CVE-2024-6760
7.5 HIGH

A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it should have, allowing unprivileged …

Aug 12, 2024
CVE-2024-6759
5.3 MEDIUM

When mounting a remote filesystem using NFS, the kernel did not sanitize remotely provided filenames for the path separator character, "/". This allows readdir(3) and …

Aug 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.