CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7467
6.3 MEDIUM

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90 and classified as critical. Affected by this issue is the function sslvpn_config_mod of …

Aug 5, 2024
CVE-2024-7466
2.4 LOW

A vulnerability has been found in PMWeb 7.2.00 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Web Application …

Aug 5, 2024
CVE-2024-7465
8.8 HIGH

A vulnerability, which was classified as critical, was found in TOTOLINK CP450 4.1.0cu.747_B20191224. Affected is the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Aug 5, 2024
CVE-2024-7464
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in TOTOLINK CP900 6.3c.566. This issue affects the function setTelnetCfg of the component Telnet Service. …

Aug 5, 2024
CVE-2024-7463
8.8 HIGH

A vulnerability classified as critical was found in TOTOLINK CP900 6.3c.566. This vulnerability affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Aug 5, 2024
CVE-2024-7462
8.8 HIGH

A vulnerability classified as critical has been found in TOTOLINK N350RT 9.3.5u.6139_B20201216. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Aug 5, 2024
CVE-2024-7461
7.3 HIGH

A vulnerability was found in ForIP Tecnologia Administração PABX 1.x. It has been rated as critical. Affected by this issue is some unknown functionality of …

Aug 5, 2024
CVE-2024-7460
4.3 MEDIUM

A vulnerability was found in OSWAPP Warehouse Inventory System 1.0/2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Aug 4, 2024
CVE-2024-7459
4.3 MEDIUM

A vulnerability was found in OSWAPP Warehouse Inventory System 1.0/2.0. It has been classified as problematic. Affected is an unknown function of the file /edit_account.php. …

Aug 4, 2024
CVE-2024-7458
5.5 MEDIUM

A vulnerability was found in elunez eladmin up to 2.7 and classified as critical. This issue affects some unknown processing of the file /api/deploy/upload /api/database/upload …

Aug 4, 2024
CVE-2024-35143
6.7 MEDIUM

IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it …

Aug 4, 2024
CVE-2024-7455
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System 1.0. This affects an unknown part of the file partedit.php. The …

Aug 4, 2024
CVE-2024-7454
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Clinics Patient Management System 1.0. Affected by this issue is the function patient_name …

Aug 4, 2024
CVE-2024-7453
2.4 LOW

A vulnerability was found in FastAdmin 1.5.0.20240328. It has been declared as problematic. This vulnerability affects unknown code of the file /[admins_url].php/general/attachment/edit/ids/4?dialog=1 of the component …

Aug 4, 2024
CVE-2024-7452
6.3 MEDIUM

A vulnerability was found in itsourcecode Placement Management System 1.0. It has been classified as critical. This affects an unknown part of the file view_company.php. …

Aug 4, 2024
CVE-2024-7451
6.3 MEDIUM

A vulnerability was found in itsourcecode Placement Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Aug 4, 2024
CVE-2024-7450
6.3 MEDIUM

A vulnerability has been found in itsourcecode Placement Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Aug 4, 2024
CVE-2024-7449
7.3 HIGH

A vulnerability, which was classified as critical, was found in itsourcecode Placement Management System 1.0. Affected is an unknown function of the file login.php. The …

Aug 4, 2024
CVE-2024-6331
7.5 HIGH

stitionai/devika main branch as of commit cdfb782b0e634b773b10963c8034dc9207ba1f9f is vulnerable to Local File Read (LFI) by Prompt Injection. The integration of Google Gimini 1.0 Pro with …

Aug 4, 2024
CVE-2024-7446
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Ticket Reservation System 1.0. This affects an unknown part of the file list_tickets.php. The …

Aug 3, 2024
CVE-2024-7445
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in itsourcecode Ticket Reservation System 1.0. Affected by this issue is some unknown functionality of …

Aug 3, 2024
CVE-2024-7444
7.3 HIGH

A vulnerability classified as critical was found in itsourcecode Ticket Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file login.php …

Aug 3, 2024
CVE-2024-7443
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Vivotek IB8367A VVTK-0100b. Affected is the function getenv of the file …

Aug 3, 2024
CVE-2024-7442
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek SD9364 VVTK-0103f. It has been rated as critical. This issue affects the function getenv …

Aug 3, 2024
CVE-2024-7441
8.8 HIGH

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek SD9364 VVTK-0103f. It has been declared as critical. This vulnerability affects the function read …

Aug 3, 2024
CVE-2024-7440
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek CC8160 VVTK-0100d. It has been classified as critical. This affects the function getenv of …

Aug 3, 2024
CVE-2024-7439
8.8 HIGH

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek CC8160 VVTK-0100d and classified as critical. Affected by this issue is the function read …

Aug 3, 2024
CVE-2024-7438
4.3 MEDIUM

A vulnerability has been found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php?action=profile;u=2;area=showalerts;do=read …

Aug 3, 2024
CVE-2024-37286
5.7 MEDIUM

APM server logs contain document body from a partially failed bulk index request. For example, in case of unavailable_shards_exception for a specific document, since the …

Aug 3, 2024
CVE-2024-7437
5.4 MEDIUM

A vulnerability, which was classified as critical, was found in SimpleMachines SMF 2.1.4. Affected is an unknown function of the file /index.php?action=profile;u=2;area=showalerts;do=remove of the component …

Aug 3, 2024
CVE-2024-7436
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in D-Link DI-8100 16.07. This issue affects the function msp_info_htm of the file msp_info.htm. The …

Aug 3, 2024
CVE-2024-38321
5.3 MEDIUM

IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2, and 24.0.0 stores potentially sensitive information in log files under certain situations that could be read by an …

Aug 3, 2024
CVE-2024-6872
4.3 MEDIUM

The Build Your Dream Website Fast with 400+ Starter Templates and Landing Pages, No Coding Needed, One-Click Import for Elementor & Gutenberg Blocks! – TemplateSpare …

Aug 3, 2024
CVE-2024-6709
4.3 MEDIUM

The Sync Post With Other Site plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sps_add_update_post' …

Aug 3, 2024
CVE-2024-7356
6.4 MEDIUM

The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘filename’ parameter in all versions up to, and including, 3.3.100 …

Aug 3, 2024
CVE-2024-7257
9.8 CRITICAL

The YayExtra – WooCommerce Extra Product Options plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_upload_file …

Aug 3, 2024
CVE-2024-7031
7.5 HIGH

The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'njt_fs_saveSettingRestrictions' …

Aug 3, 2024
CVE-2024-7291
7.2 HIGH

The JetFormBuilder plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.4.1. This is due to improper restriction on …

Aug 3, 2024
CVE-2024-6477
7.5 HIGH

The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could allow unauthenticated attackers to download them and retrieve …

Aug 3, 2024
CVE-2024-6390
5.9 MEDIUM

The Quiz and Survey Master (QSM) WordPress plugin before 9.1.0 does not properly sanitise and escape some of its Quizz settings, which could allow high …

Aug 3, 2024
CVE-2024-7319
5.0 MEDIUM

An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature …

Aug 2, 2024
CVE-2024-3056
7.7 HIGH

A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configured to share the same …

Aug 2, 2024
CVE-2024-38891
7.5 HIGH

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Sniffing Network Traffic …

Aug 2, 2024
CVE-2024-38887
9.8 CRITICAL

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand control over the operating …

Aug 2, 2024
CVE-2024-42349
5.3 MEDIUM

FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.4 and earlier can leak authorized and rejected logins via logs stored directly on the root …

Aug 2, 2024
CVE-2024-42348
9.3 CRITICAL

FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.2 can leak AD username and password when registering a computer. This vulnerability is fixed in …

Aug 2, 2024
CVE-2024-38889
9.8 CRITICAL

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform SQL Injection due to …

Aug 2, 2024
CVE-2024-38888
6.8 MEDIUM

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform a Password Brute Forcing …

Aug 2, 2024
CVE-2024-28298
8.8 HIGH

SQL injection vulnerability in BM SOFT BMPlanning 1.0.0.1 allows authenticated users to execute arbitrary SQL commands via the SEC_IDF, LIE_IDF, PLANF_IDF, CLI_IDF, DOS_IDF, and possibly …

Aug 2, 2024
CVE-2024-28297
7.5 HIGH

SQL injection vulnerability in AzureSoft MyHorus 4.3.5 allows authenticated users to execute arbitrary SQL commands via unspecified vectors.

Aug 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.