CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-41353
7.1 HIGH

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\groups\edit-group.php

Jul 26, 2024
CVE-2024-27358
3.3 LOW

An issue was discovered in WithSecure Elements Agent through 23.x for macOS and WithSecure Elements Client Security through 23.x for macOS. Local users can block …

Jul 26, 2024
CVE-2024-27357
5.8 MEDIUM

An issue was discovered in WithSecure Elements Agent through 23.x for macOS, WithSecure Elements Client Security through 23.x for macOS, and WithSecure MDR through 23.x …

Jul 26, 2024
CVE-2024-26520
9.8 CRITICAL

An issue in Hangzhou Xiongwei Technology Development Co., Ltd. Restaurant Digital Comprehensive Management platform v1 allows an attacker to bypass authentication and perform arbitrary password …

Jul 26, 2024
CVE-2024-24257
7.5 HIGH

An issue in skteco.com Central Control Attendance Machine web management platform v.3.0 allows an attacker to obtain sensitive information via a crafted script to the …

Jul 26, 2024
CVE-2023-50700
7.8 HIGH

Insecure Permissions vulnerability in Deepin dde-file-manager 6.0.54 and earlier allows privileged operations to be called by unprivileged users via the D-Bus method.

Jul 26, 2024
CVE-2024-7050

Improper Authentication vulnerability in OpenText OpenText Directory Services may allow Multi-factor Authentication Bypass in particular scenarios.This issue affects OpenText Directory Services: 24.2.

Jul 26, 2024
CVE-2024-41357
7.1 HIGH

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.

Jul 26, 2024
CVE-2024-41356
4.7 MEDIUM

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\firewall-zones\zones-edit-network.php.

Jul 26, 2024
CVE-2024-41355
6.5 MEDIUM

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.php.

Jul 26, 2024
CVE-2024-41805
6.1 MEDIUM

Tracks, a Getting Things Done (GTD) web application, is vulnerable to reflected cross-site scripting in versions prior to 2.7.1. Reflected cross-site scripting enables execution of …

Jul 26, 2024
CVE-2024-41670
7.5 HIGH

In the module "PayPal Official" for PrestaShop 7+ releases prior to version 6.4.2 and for PrestaShop 1.6 releases prior to version 3.18.1, a malicious customer …

Jul 26, 2024
CVE-2024-7128
5.3 MEDIUM

A flaw was found in the OpenShift console. Several endpoints in the application use the authHandler() and authHandlerWithUser() middleware functions. When the default authentication provider …

Jul 26, 2024
CVE-2024-6922

Automation Anywhere Automation 360 v21-v32 is vulnerable to Server-Side Request Forgery in a web API component. An attacker with unauthenticated access to the Automation 360 …

Jul 26, 2024
CVE-2024-40689
6.0 MEDIUM

IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to …

Jul 26, 2024
CVE-2024-41692

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to presence of root terminal access on a serial interface without proper access control. An attacker with …

Jul 26, 2024
CVE-2024-7062
8.8 HIGH

Nimble Commander suffers from a privilege escalation vulnerability due to the server (info.filesmanager.Files.PrivilegedIOHelperV2) performing improper/insufficient validation of a client’s authorization before executing an operation. Consequently, …

Jul 26, 2024
CVE-2024-41691
4.6 MEDIUM

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of FTP credentials in plaintext within the SquashFS-root filesystem associated with the router's firmware. An …

Jul 26, 2024
CVE-2024-41690
4.6 MEDIUM

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of default username and password credentials in plaintext within the router's firmware/ database. An attacker …

Jul 26, 2024
CVE-2024-41689
4.6 MEDIUM

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials within the router's firmware/ database. An attacker with physical access …

Jul 26, 2024
CVE-2024-41688
4.6 MEDIUM

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due lack of encryption in storing of usernames and passwords within the router's firmware/ database. An attacker with …

Jul 26, 2024
CVE-2024-41687
7.5 HIGH

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text. A remote attacker could exploit this vulnerability by intercepting transmission …

Jul 26, 2024
CVE-2024-41686
3.3 LOW

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to improper implementation of password policies. A local attacker could exploit this by creating password that do …

Jul 26, 2024
CVE-2024-41685
7.5 HIGH

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies associated with the router's web management interface. An attacker …

Jul 26, 2024
CVE-2024-41684
5.3 MEDIUM

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing secure flag for the session cookies associated with the router's web management interface. An attacker …

Jul 26, 2024
CVE-2024-35296
8.2 HIGH

Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This issue affects Apache Traffic Server: from 8.0.0 through …

Jul 26, 2024
CVE-2024-35161
7.5 HIGH

Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for request smuggling and may also lead cache poisoning …

Jul 26, 2024
CVE-2023-38522
7.5 HIGH

Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for …

Jul 26, 2024
CVE-2024-25090
5.4 MEDIUM

Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of Apache Roller on …

Jul 26, 2024
CVE-2024-6490
6.5 MEDIUM

During testing of the Master Slider WordPress plugin through 3.9.10, a CSRF vulnerability was found, which allows an unauthorized user to manipulate requests on behalf …

Jul 26, 2024
CVE-2024-40897
6.7 MEDIUM

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with …

Jul 26, 2024
CVE-2024-7120
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. This affects an unknown part of the file …

Jul 26, 2024
CVE-2024-7119
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. Affected by this issue is some unknown functionality of …

Jul 26, 2024
CVE-2023-49921
5.2 MEDIUM

An issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This could lead to raw contents …

Jul 26, 2024
CVE-2024-7118
6.3 MEDIUM

A vulnerability classified as critical was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. Affected by this vulnerability is an unknown functionality of the file /department_viewmore.php. …

Jul 26, 2024
CVE-2024-7117
6.3 MEDIUM

A vulnerability classified as critical has been found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. Affected is an unknown function of the file /shift_viewmore.php. The manipulation …

Jul 26, 2024
CVE-2024-7116
6.3 MEDIUM

A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. It has been rated as critical. This issue affects some unknown processing of the file …

Jul 26, 2024
CVE-2024-7115
6.3 MEDIUM

A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. It has been declared as critical. This vulnerability affects unknown code of the file /designation_viewmore.php. …

Jul 26, 2024
CVE-2024-7114
6.3 MEDIUM

A vulnerability was found in Tianchoy Blog up to 1.8.8. It has been classified as critical. This affects an unknown part of the file /so.php. …

Jul 26, 2024
CVE-2024-4447
9.9 CRITICAL

In the System → Maintenance tool, the Logged Users tab surfaces sessionId data for all users via the Direct Web Remoting API (UserSessionAjax.getSessionList.dwr) calls. While …

Jul 26, 2024
CVE-2024-41473
9.8 CRITICAL

Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/WriteFacMac

Jul 25, 2024
CVE-2024-41468
9.8 CRITICAL

Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the cmdinput parameter at /goform/exeCommand

Jul 25, 2024
CVE-2024-3938
5.4 MEDIUM

The "reset password" login page accepted an HTML injection via URL parameters. This has already been rectified via patch, and as such it cannot be …

Jul 25, 2024
CVE-2024-38103
5.9 MEDIUM

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Jul 25, 2024
CVE-2024-24623
8.8 HIGH

Softaculous Webuzo contains a command injection vulnerability in the FTP management functionality. A remote, authenticated attacker can exploit this vulnerability to gain code execution on …

Jul 25, 2024
CVE-2024-24622
8.8 HIGH

Softaculous Webuzo contains a command injection in the password reset functionality. A remote, authenticated attacker can exploit this vulnerability to gain code execution on the …

Jul 25, 2024
CVE-2024-24621
9.8 CRITICAL

Softaculous Webuzo contains an authentication bypass vulnerability through the password reset functionality. Remote, anonymous attackers can exploit this vulnerability to gain full server access as …

Jul 25, 2024
CVE-2024-7106
4.3 MEDIUM

A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation …

Jul 25, 2024
CVE-2024-7105
6.3 MEDIUM

A vulnerability classified as critical has been found in ForIP Tecnologia Administração PABX 1.x. Affected is an unknown function of the file /detalheIdUra of the …

Jul 25, 2024
CVE-2024-41809
7.2 HIGH

OpenObserve is an open-source observability platform. Starting in version 0.4.4 and prior to version 0.10.0, OpenObserve contains a cross-site scripting vulnerability in line 32 of …

Jul 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.