CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23475
9.6 CRITICAL

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file …

Jul 17, 2024
CVE-2024-23474
7.6 HIGH

The SolarWinds Access Rights Manager was found to be susceptible to an Arbitrary File Deletion and Information Disclosure vulnerability.

Jul 17, 2024
CVE-2024-23472
9.6 CRITICAL

SolarWinds Access Rights Manager (ARM) is susceptible to Directory Traversal vulnerability. This vulnerability allows an authenticated user to arbitrary read and delete files in ARM.

Jul 17, 2024
CVE-2024-23471
9.6 CRITICAL

The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to …

Jul 17, 2024
CVE-2024-23470
9.6 CRITICAL

The SolarWinds Access Rights Manager was found to be susceptible to a pre-authentication remote code execution vulnerability. If exploited, this vulnerability allows an unauthenticated user …

Jul 17, 2024
CVE-2024-23469
9.6 CRITICAL

SolarWinds Access Rights Manager (ARM) is susceptible to a Remote Code Execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to perform the actions …

Jul 17, 2024
CVE-2024-23468
7.6 HIGH

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file …

Jul 17, 2024
CVE-2024-23467
9.6 CRITICAL

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform remote code …

Jul 17, 2024
CVE-2024-23466
9.6 CRITICAL

SolarWinds Access Rights Manager (ARM) is susceptible to a Directory Traversal Remote Code Execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to perform …

Jul 17, 2024
CVE-2024-23465
8.3 HIGH

The SolarWinds Access Rights Manager was found to be susceptible to an authentication bypass vulnerability. This vulnerability allows an unauthenticated user to gain domain admin …

Jul 17, 2024
CVE-2023-7272
8.6 HIGH

In Eclipse Parsson before 1.0.4 and 1.1.3, a document with a large depth of nested objects can allow an attacker to cause a Java stack …

Jul 17, 2024
CVE-2024-6765

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 17, 2024
CVE-2024-5471
8.8 HIGH

Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to agent takeover vulnerability due to the hard-coded sensitive keys.

Jul 17, 2024
CVE-2024-27311
5.5 MEDIUM

Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to directory traversal vulnerability which allows the user to upload new files to the server …

Jul 17, 2024
CVE-2024-31411
8.8 HIGH

Unrestricted Upload of File with dangerous type vulnerability in Apache StreamPipes. Such a dangerous type might be an executable file that may lead to a …

Jul 17, 2024
CVE-2024-40617
6.5 MEDIUM

Path traversal vulnerability exists in FUJITSU Network Edgiot GW1500 (M2M-GW for FENICS). If a remote authenticated attacker with User Class privilege sends a specially crafted …

Jul 17, 2024
CVE-2024-36491
9.8 CRITICAL

FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allow an administrative user to execute an arbitrary OS command, obtain …

Jul 17, 2024
CVE-2024-36475
8.8 HIGH

FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. contain an active debug code vulnerability. If a user who knows …

Jul 17, 2024
CVE-2024-31979
4.3 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Apache StreamPipes during installation process of pipeline elements. Previously, StreamPipes allowed users to configure custom endpoints from which to …

Jul 17, 2024
CVE-2024-31070
9.1 CRITICAL

Initialization of a resource with an insecure default vulnerability in FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allows …

Jul 17, 2024
CVE-2024-30471
3.7 LOW

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache StreamPipes in user self-registration. This allows an attacker to potentially request the creation of multiple accounts with …

Jul 17, 2024
CVE-2024-29737
4.7 MEDIUM

In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, …

Jul 17, 2024
CVE-2023-52291
4.7 MEDIUM

In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, …

Jul 17, 2024
CVE-2024-6220
9.8 CRITICAL

The 简数采集器 (Keydatas) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the keydatas_downloadImages function in all versions …

Jul 17, 2024
CVE-2024-5703
4.3 MEDIUM

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized API access due …

Jul 17, 2024
CVE-2024-5582
6.4 MEDIUM

The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' attribute within the …

Jul 17, 2024
CVE-2024-39877
8.8 HIGH

Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that could …

Jul 17, 2024
CVE-2024-39863
5.4 MEDIUM

Apache Airflow versions before 2.9.3 have a vulnerability that allows an authenticated attacker to inject a malicious link when installing a provider. Users are recommended …

Jul 17, 2024
CVE-2024-6669
5.5 MEDIUM

The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and …

Jul 17, 2024
CVE-2024-6660
8.8 HIGH

The BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to …

Jul 17, 2024
CVE-2024-6467
8.8 HIGH

The BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin plugin for WordPress is vulnerable to Arbitrary File Read to Arbitrary File Creation in …

Jul 17, 2024
CVE-2024-6033
4.3 MEDIUM

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized data importation due to a missing capability check on …

Jul 17, 2024
CVE-2024-5255
6.4 MEDIUM

The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_dual_color shortcode in all versions up to, and …

Jul 17, 2024
CVE-2024-5254
6.4 MEDIUM

The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_info_banner shortcode in all versions up to, and …

Jul 17, 2024
CVE-2024-5253
6.4 MEDIUM

The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ult_team shortcode in all versions up to, and …

Jul 17, 2024
CVE-2024-5252
6.4 MEDIUM

The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_info_table shortcode in all versions up to, and …

Jul 17, 2024
CVE-2024-5251
6.4 MEDIUM

The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_pricing shortcode in all versions up to, and …

Jul 17, 2024
CVE-2024-41010
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix too early release of tcx_entry Pedro Pinto and later independently also Hyunwoo Kim …

Jul 17, 2024
CVE-2024-41009
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix overrunning reservations in ringbuf The BPF ring buffer internally is implemented as a …

Jul 17, 2024
CVE-2024-6808
7.3 HIGH

A vulnerability was found in itsourcecode Simple Task List 1.0. It has been classified as critical. This affects the function insertUserRecord of the file signUp.php. …

Jul 17, 2024
CVE-2024-6807
2.4 LOW

A vulnerability was found in SourceCodester Student Study Center Desk Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality …

Jul 17, 2024
CVE-2024-6803
5.5 MEDIUM

A vulnerability has been found in itsourcecode Document Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Jul 17, 2024
CVE-2024-6535
5.3 MEDIUM

A flaw was found in Skupper. When Skupper is initialized with the console-enabled and with console-auth set to Openshift, it configures the openshift oauth-proxy with …

Jul 17, 2024
CVE-2024-6802
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Computer Laboratory Management System 1.0. Affected is an unknown function of the file /lms/classes/Master.php?f=save_record. …

Jul 17, 2024
CVE-2024-6801
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Online Student Management System 1.0. This issue affects some unknown processing of the …

Jul 17, 2024
CVE-2024-6595
3.0 LOW

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from …

Jul 17, 2024
CVE-2024-5500
6.5 MEDIUM

Inappropriate implementation in Sign-In in Google Chrome prior to 1.3.36.351 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security …

Jul 16, 2024
CVE-2024-40637
4.2 MEDIUM

dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications. When a user installs …

Jul 16, 2024
CVE-2024-3176
8.8 HIGH

Out of bounds write in SwiftShader in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to perform an out of bounds memory write via …

Jul 16, 2024
CVE-2024-3175
6.3 MEDIUM

Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform privilege escalation via a crafted Chrome Extension. (Chromium …

Jul 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.