CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6569
5.3 MEDIUM

The Campaign Monitor for WordPress plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.8.15. This is due …

Jul 27, 2024
CVE-2024-6458
6.4 MEDIUM

The WooCommerce Product Table Lite plugin for WordPress is vulnerable to unauthorized post title modification due to a missing capability check on the wcpt_presets__duplicate_preset_to_table function …

Jul 27, 2024
CVE-2024-5969
5.8 MEDIUM

The AIomatic - Automatic AI Content Writer for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 2.0.5. This is …

Jul 27, 2024
CVE-2024-42029
6.3 MEDIUM

xdg-desktop-portal-hyprland (aka an XDG Desktop Portal backend for Hyprland) before 1.3.3 allows OS command execution, e.g., because single quotes are not used when sending a …

Jul 27, 2024
CVE-2024-6661
4.4 MEDIUM

The ParityPress – Parity Pricing with Discount Rules plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Discount Text' in all versions up to, …

Jul 27, 2024
CVE-2024-6634
6.4 MEDIUM

The Master Currency WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's currencyconverterform shortcode in all versions up to, and including, …

Jul 27, 2024
CVE-2024-6591
5.8 MEDIUM

The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized email creation and sending due to a missing capability check on the 'send_auction_email_callback' …

Jul 27, 2024
CVE-2024-6573
5.3 MEDIUM

The Intelligence plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.0. This is due the plugin not …

Jul 27, 2024
CVE-2024-6566
5.3 MEDIUM

The Aramex Shipping WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.1.21. This is due the …

Jul 27, 2024
CVE-2024-6549
5.3 MEDIUM

The Admin Post Navigation plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.1. This is due to …

Jul 27, 2024
CVE-2024-6548
5.3 MEDIUM

The Add Admin JavaScript plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0. This is due to …

Jul 27, 2024
CVE-2024-6547
5.3 MEDIUM

The Add Admin CSS plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1. This is due to …

Jul 27, 2024
CVE-2024-6546
5.3 MEDIUM

The One Click Close Comments plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.7.1. This is due …

Jul 27, 2024
CVE-2024-6545
5.3 MEDIUM

The Admin Trim Interface plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.5.1. This is due to …

Jul 27, 2024
CVE-2024-6431
8.8 HIGH

The Media.net Ads Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and missing capability check in the …

Jul 27, 2024
CVE-2024-6152
8.8 HIGH

The Flipbox Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5 via deserialization of untrusted input …

Jul 27, 2024
CVE-2024-4410
5.4 MEDIUM

The IgnitionDeck Crowdfunding Platform plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.9.8. This is due to missing capability …

Jul 27, 2024
CVE-2024-1804
4.3 MEDIUM

The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tutor_import_from_xml …

Jul 27, 2024
CVE-2024-1798
5.3 MEDIUM

The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the tutor_lp_export_xml …

Jul 27, 2024
CVE-2024-40433
8.8 HIGH

Insecure Permissions vulnerability in Tencent wechat v.8.0.37 allows an attacker to escalate privileges via the web-view component.

Jul 26, 2024
CVE-2024-37034
5.9 MEDIUM

An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with the Key-Value (KV) …

Jul 26, 2024
CVE-2024-41815
7.4 HIGH

Starship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily …

Jul 26, 2024
CVE-2024-41628
7.5 HIGH

Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and 2.1.0 before 2.1.0-9780 allows a remote attacker to include and display …

Jul 26, 2024
CVE-2024-41120
9.8 CRITICAL

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `url` variable on line 63 of `pages/9_🔲_Vector_Data_Visualization.py` takes user input, which …

Jul 26, 2024
CVE-2024-41119
9.8 CRITICAL

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 80 in `8_🏜️_Raster_Data_Visualization.py` takes user input, which …

Jul 26, 2024
CVE-2024-41118
7.5 HIGH

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `url` variable on line 47 of `pages/7_📦_Web_Map_Service.py` takes user input, which …

Jul 26, 2024
CVE-2024-41117
9.8 CRITICAL

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 115 in `pages/10_🌍_Earth_Engine_Datasets.py` takes user input, which …

Jul 26, 2024
CVE-2024-41116
9.8 CRITICAL

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 1254 in `pages/1_📷_Timelapse.py` takes user input, which …

Jul 26, 2024
CVE-2024-41115
9.8 CRITICAL

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `palette` variable on line 488 in `pages/1_📷_Timelapse.py` takes user input, which …

Jul 26, 2024
CVE-2024-41114
9.8 CRITICAL

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `palette` variable on line 430 in `pages/1_📷_Timelapse.py` takes user input, which …

Jul 26, 2024
CVE-2024-4786
2.8 LOW

An improper validation vulnerability was reported in the Lenovo Tab K10 that could allow a specially crafted application to keep the device on.

Jul 26, 2024
CVE-2024-41113
9.8 CRITICAL

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 383 or line 390 in `pages/1_📷_Timelapse.py` takes …

Jul 26, 2024
CVE-2024-41112
9.8 CRITICAL

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the palette variable in `pages/1_📷_Timelapse.py` takes user input, which is later used …

Jul 26, 2024
CVE-2024-40117
9.8 CRITICAL

Incorrect access control in Solar-Log 1000 before v2.8.2 and build 52- 23.04.2013 allows attackers to obtain Administrative privileges via connecting to the web administration server. …

Jul 26, 2024
CVE-2024-40116
8.1 HIGH

An issue in Solar-Log 1000 before v2.8.2 and build 52-23.04.2013 was discovered to store plaintext passwords in the export.html, email.html, and sms.html files -- fixed …

Jul 26, 2024
CVE-2024-38512
7.2 HIGH

A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated privileges to perform command injection via specially crafted …

Jul 26, 2024
CVE-2024-38511
7.2 HIGH

A privilege escalation vulnerability was discovered in an upload processing functionality of XCC that could allow an authenticated XCC user with elevated privileges to perform …

Jul 26, 2024
CVE-2024-38510
7.2 HIGH

A privilege escalation vulnerability was discovered in the SSH captive command shell interface that could allow an authenticated XCC user with elevated privileges to perform …

Jul 26, 2024
CVE-2024-38509
7.2 HIGH

A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated privileges to execute arbitrary code via a specially …

Jul 26, 2024
CVE-2024-38508
7.2 HIGH

A privilege escalation vulnerability was discovered in the web interface or SSH captive command shell interface of XCC that could allow an authenticated XCC user …

Jul 26, 2024
CVE-2024-42007
5.8 MEDIUM

SPX (aka php-spx) through 0.4.15 allows SPX_UI_URI Directory Traversal to read arbitrary files.

Jul 26, 2024
CVE-2024-39304
8.8 HIGH

ChurchCRM is an open-source church management system. Versions of the application prior to 5.9.2 are vulnerable to an authenticated SQL injection due to an improper …

Jul 26, 2024
CVE-2024-38872
8.3 HIGH

Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the monitoring module.

Jul 26, 2024
CVE-2024-38871
8.3 HIGH

Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the reports module.

Jul 26, 2024
CVE-2024-41813
7.5 HIGH

txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Starting in version 1.4.0 and prior …

Jul 26, 2024
CVE-2024-41812
7.5 HIGH

txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Prior to version 1.7.0, a Server-Side …

Jul 26, 2024
CVE-2024-41375
6.1 MEDIUM

ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/terminal-xhr.php

Jul 26, 2024
CVE-2024-41374
6.1 MEDIUM

ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/settings-screen.php

Jul 26, 2024
CVE-2024-41373
6.3 MEDIUM

ICEcoder 8.1 contains a Path Traversal vulnerability via lib/backup-versions-preview-loader.php.

Jul 26, 2024
CVE-2024-41354
7.1 HIGH

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php

Jul 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.