CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-3934
6.5 MEDIUM

The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to Path Traversal in versions 7.3.0 to 7.5.1 via the mercadopagoDownloadLog function. This makes …

Jul 20, 2024
CVE-2024-6560
5.3 MEDIUM

The Addonify – Quick View For WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.16. This …

Jul 20, 2024
CVE-2024-2337
6.4 MEDIUM

The Easy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'testimonials_grid ' shortcode in all versions up to, and including, …

Jul 20, 2024
CVE-2024-5804
4.3 MEDIUM

The Conditional Fields for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.13. This is …

Jul 20, 2024
CVE-2024-41599
6.1 MEDIUM

Cross Site Scripting vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the file upload method

Jul 19, 2024
CVE-2024-41597
4.2 MEDIUM

Cross Site Request Forgery vulnerability in ProcessWire v.3.0.229 allows a remote attacker to execute arbitrary code via a crafted HTML file to the comments functionality.

Jul 19, 2024
CVE-2024-41124
6.3 MEDIUM

Puncia is the Official CLI utility for Subdomain Center & Exploit Observer. `API_URLS` is utilizing HTTP instead of HTTPS for communication that can lead to …

Jul 19, 2024
CVE-2024-41122
7.5 HIGH

Woodpecker is a simple yet powerful CI/CD engine with great extensibility. The server allow to create any user who can trigger a pipeline run malicious …

Jul 19, 2024
CVE-2024-41121
8.8 HIGH

Woodpecker is a simple yet powerful CI/CD engine with great extensibility. The server allow to create any user who can trigger a pipeline run malicious …

Jul 19, 2024
CVE-2024-39906
8.3 HIGH

A command injection vulnerability was found in the IndieAuth functionality of the Ruby on Rails based Haven blog web application. The affected functionality requires authentication, …

Jul 19, 2024
CVE-2024-39123
5.4 MEDIUM

In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization performed by the clean_string function. …

Jul 19, 2024
CVE-2024-40400
8.8 HIGH

An arbitrary file upload vulnerability in the image upload function of Automad v2.0.0 allows attackers to execute arbitrary code via a crafted file.

Jul 19, 2024
CVE-2024-41600
7.5 HIGH

Insecure Permissions vulnerability in lin-CMS Springboot v.0.2.1 and before allows a remote attacker to obtain sensitive information via the login method in the UserController.java component.

Jul 19, 2024
CVE-2024-41603
9.6 CRITICAL

Spina CMS v2.18.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the URI /admin/layout.

Jul 19, 2024
CVE-2024-41602
8.8 HIGH

Cross Site Request Forgery vulnerability in Spina CMS v.2.18.0 and before allows a remote attacker to escalate privileges via a crafted URL

Jul 19, 2024
CVE-2024-41601
7.5 HIGH

Insecure Permissions vulnerability in lin-CMS v.0.2.0 and before allows a remote attacker to obtain sensitive information via the login method in the UserController.java component.

Jul 19, 2024
CVE-2024-41492
7.5 HIGH

A stack overflow in Tenda AX1806 v1.0.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Jul 19, 2024
CVE-2024-41281
8.8 HIGH

Linksys WRT54G v4.21.5 has a stack overflow vulnerability in get_merge_mac function.

Jul 19, 2024
CVE-2024-29080
6.5 MEDIUM

Potential vulnerabilities have been identified in the HP Display Control software component within the HP Application Enabling Software Driver which might allow escalation of privilege.

Jul 19, 2024
CVE-2024-24970
6.5 MEDIUM

Potential vulnerabilities have been identified in the HP Display Control software component within the HP Application Enabling Software Driver which might allow escalation of privilege.

Jul 19, 2024
CVE-2024-6908

Improper privilege management in Yugabyte Platform allows authenticated admin users to escalate privileges to SuperAdmin via a crafted PUT HTTP request, potentially leading to unauthorized …

Jul 19, 2024
CVE-2024-6895

Insufficient authentication in user account management in Yugabyte Platform allows local network attackers with a compromised user session to change critical security information without re-authentication. …

Jul 19, 2024
CVE-2024-39963
8.0 HIGH

AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX9 V22.03.01.46 and AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX12 V1.0 V22.03.01.46 were discovered to contain an authenticated remote …

Jul 19, 2024
CVE-2024-39962
9.8 CRITICAL

D-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router v21_D240126 was discovered to contain a remote code execution (RCE) vulnerability in the ntp_zone_val parameter at /goform/set_ntp. This …

Jul 19, 2024
CVE-2024-27489
7.5 HIGH

An issue in the DelFile() function of WMCMS v4.4 allows attackers to delete arbitrary files via a crafted POST request.

Jul 19, 2024
CVE-2024-0006

Information exposure in the logging system in Yugabyte Platform allows local attackers with access to application logs to obtain database user credentials in log files, …

Jul 19, 2024
CVE-2024-37066
6.8 MEDIUM

A command injection vulnerability exists in Wyze V4 Pro firmware versions before 4.50.4.9222, which allows attackers to execute arbitrary commands over Bluetooth as root during …

Jul 19, 2024
CVE-2024-6916
5.9 MEDIUM

A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a terminal using the '--show-inputs-only' flag.

Jul 19, 2024
CVE-2024-5977
5.4 MEDIUM

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Jul 19, 2024
CVE-2024-41107
8.1 HIGH

The CloudStack SAML authentication (disabled by default) does not enforce signature check. In CloudStack environments where SAML authentication is enabled, an attacker that initiates CloudStack …

Jul 19, 2024
CVE-2024-6907
3.5 LOW

A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file sort.php. …

Jul 19, 2024
CVE-2024-6906
6.3 MEDIUM

A vulnerability was found in SourceCodester Record Management System 1.0 and classified as critical. This issue affects some unknown processing of the file add_leave_non_user.php. The …

Jul 19, 2024
CVE-2024-6905
6.3 MEDIUM

A vulnerability has been found in SourceCodester Record Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file view_info_user.php. The …

Jul 19, 2024
CVE-2024-6904
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Record Management System 1.0. This affects an unknown part of the file sort2_user.php. The …

Jul 19, 2024
CVE-2024-41172
7.5 HIGH

In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances …

Jul 19, 2024
CVE-2024-39457
5.4 MEDIUM

Cybozu Garoon 6.0.0 to 6.0.1 contains a cross-site scripting vulnerability in PDF preview. If this vulnerability is exploited, an arbitrary script may be executed on …

Jul 19, 2024
CVE-2024-32007
7.5 HIGH

An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a …

Jul 19, 2024
CVE-2024-29736
9.1 CRITICAL

A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks …

Jul 19, 2024
CVE-2024-6903
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Record Management System 1.0. Affected by this issue is some unknown functionality of …

Jul 19, 2024
CVE-2024-6902
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Record Management System 1.0. Affected by this vulnerability is an unknown functionality of the file sort_user.php. …

Jul 19, 2024
CVE-2024-6799
4.3 MEDIUM

The YITH Essential Kit for WooCommerce #1 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Jul 19, 2024
CVE-2024-6338
8.8 HIGH

The FV Flowplayer Video Player plugin for WordPress is vulnerable to time-based SQL Injection via the ‘exclude’ parameter in all versions up to, and including, …

Jul 19, 2024
CVE-2024-40724
7.8 HIGH

Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.2 allows a local attacker to execute arbitrary code by inputting a specially crafted file into …

Jul 19, 2024
CVE-2024-6901
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Record Management System 1.0. Affected is an unknown function of the file entry.php. The manipulation …

Jul 19, 2024
CVE-2024-6900
6.3 MEDIUM

A vulnerability was found in SourceCodester Record Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Jul 19, 2024
CVE-2024-6205
9.8 CRITICAL

The PayPlus Payment Gateway WordPress plugin before 6.6.9 does not properly sanitise and escape a parameter before using it in a SQL statement via a …

Jul 19, 2024
CVE-2024-5604
5.9 MEDIUM

The Bug Library WordPress plugin before 2.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jul 19, 2024
CVE-2023-7269
7.5 HIGH

The ArtPlacer Widget WordPress plugin before 2.21.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Jul 19, 2024
CVE-2023-7268
6.5 MEDIUM

The ArtPlacer Widget WordPress plugin before 2.21.2 does not have authorisation check in place when deleting widgets, allowing ay authenticated users, such as subscriber, to …

Jul 19, 2024
CVE-2024-6899
6.3 MEDIUM

A vulnerability was found in SourceCodester Record Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file view_info.php. …

Jul 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.