CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-39157
3.8 LOW

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ipRecord_deal.php?mudi=del&dataType=&dataID=1.

Jun 27, 2024
CVE-2024-39156
3.8 LOW

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mudi=add.

Jun 27, 2024
CVE-2024-39155
6.8 MEDIUM

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ipRecord_deal.php?mudi=add.

Jun 27, 2024
CVE-2024-39154
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mudi=del&dataType=word&dataTypeCN.

Jun 27, 2024
CVE-2024-39153
4.7 MEDIUM

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/info_deal.php?mudi=del&dataType=news&dataTypeCN.

Jun 27, 2024
CVE-2024-1153
4.6 MEDIUM

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talya Informatics Travel APPS allows Exploiting Incorrectly Configured Access Control Security …

Jun 27, 2024
CVE-2024-6373
7.3 HIGH

A vulnerability has been found in itsourcecode Online Food Ordering System up to 1.0 and classified as critical. This vulnerability affects unknown code of the …

Jun 27, 2024
CVE-2024-6372
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System 1.0. This affects an unknown part of the file customeradd.php. The …

Jun 27, 2024
CVE-2024-6371
7.3 HIGH

A vulnerability, which was classified as critical, has been found in itsourcecode Pool of Bethesda Online Reservation System 1.0. Affected by this issue is some …

Jun 27, 2024
CVE-2024-38515

Rejected reason: This CVE is a duplicate of CVE-2024-38374.

Jun 27, 2024
CVE-2024-1107
9.8 CRITICAL

Authorization Bypass Through User-Controlled Key vulnerability in Talya Informatics Travel APPS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travel APPS: before v17.0.68.

Jun 27, 2024
CVE-2024-6370
3.5 LOW

A vulnerability classified as problematic was found in LabVantage LIMS 2017. Affected by this vulnerability is an unknown functionality of the file /labvantage/rc?command=file&file=WEB-OPAL/pagetypes/bulletins/sendbulletin.jsp of the …

Jun 27, 2024
CVE-2024-6369
3.5 LOW

A vulnerability classified as problematic has been found in LabVantage LIMS 2017. Affected is an unknown function of the file /labvantage/rc?command=page&sdcid=LV_ReagentLot of the component POST …

Jun 27, 2024
CVE-2024-6368
3.5 LOW

A vulnerability was found in LabVantage LIMS 2017. It has been rated as problematic. This issue affects some unknown processing of the file /labvantage/rc?command=page of …

Jun 27, 2024
CVE-2024-6367
3.5 LOW

A vulnerability was found in LabVantage LIMS 2017. It has been declared as problematic. This vulnerability affects unknown code of the file /labvantage/rc?command=file&file=WEB-CORE/elements/files/filesembedded.jsp of the …

Jun 27, 2024
CVE-2024-6262
6.4 MEDIUM

The Portfolio Gallery – Image Gallery Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'PFG' shortcode in all versions up …

Jun 27, 2024
CVE-2024-5535
9.1 CRITICAL

Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer may cause a crash or memory contents to be sent …

Jun 27, 2024
CVE-2024-0949
9.8 CRITICAL

Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektraweb allows Authentication Bypass.This issue affects Elektraweb: before …

Jun 27, 2024
CVE-2024-0947
9.8 CRITICAL

Reliance on Cookies without Validation and Integrity Checking vulnerability in Talya Informatics Elektraweb allows Session Credential Falsification through Manipulation, Accessing/Intercepting/Modifying HTTP Cookies, Manipulating Opaque Client-based …

Jun 27, 2024
CVE-2023-7270
5.3 MEDIUM

An issue was discovered in SoftMaker Office 2024 / NX before revision 1214 and SoftMaker FreeOffice 2014 before revision 1215. FreeOffice 2021 is also affected, …

Jun 27, 2024
CVE-2024-4983
6.4 MEDIUM

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jun 27, 2024
CVE-2024-5601
6.4 MEDIUM

The Create by Mediavine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Schema Meta shortcode in all versions up to, and …

Jun 27, 2024
CVE-2024-22232
7.7 HIGH

A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user can read an arbitrary …

Jun 27, 2024
CVE-2024-22231
5.0 MEDIUM

Syndic cache directory creation is vulnerable to a directory traversal attack in salt project which can lead a malicious attacker to create an arbitrary directory …

Jun 27, 2024
CVE-2024-4704
6.1 MEDIUM

The Contact Form 7 WordPress plugin before 5.9.5 has an open redirect that allows an attacker to utilize a false URL and redirect to the …

Jun 27, 2024
CVE-2024-4664
4.8 MEDIUM

The WP Chat App WordPress plugin before 3.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jun 27, 2024
CVE-2024-3111
5.4 MEDIUM

The Interactive Content WordPress plugin before 1.15.8 does not validate uploads which could allow a Contributors and above to update malicious SVG files, leading to …

Jun 27, 2024
CVE-2024-1330
4.3 MEDIUM

The kadence-blocks-pro WordPress plugin before 2.3.8 does not prevent users with at least the contributor role using some of its shortcode's functionalities to leak arbitrary …

Jun 27, 2024
CVE-2024-6283
5.4 MEDIUM

The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL parameter of the De Gallery widget in all versions …

Jun 27, 2024
CVE-2024-4570
6.4 MEDIUM

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in versions up to, and including, 1.13.5 due …

Jun 27, 2024
CVE-2024-4569
6.4 MEDIUM

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in versions up to, and including, 1.13.5 due …

Jun 27, 2024
CVE-2024-6054
8.8 HIGH

The Auto Featured Image plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'create_post_attachment_from_url' function in all …

Jun 27, 2024
CVE-2024-5289
6.4 MEDIUM

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps …

Jun 27, 2024
CVE-2024-6323
7.5 HIGH

Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior to 17.0.3 and 17.1 prior to …

Jun 27, 2024
CVE-2024-5655
9.6 CRITICAL

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from …

Jun 27, 2024
CVE-2024-5430
6.8 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from …

Jun 27, 2024
CVE-2024-4901
8.7 HIGH

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from …

Jun 27, 2024
CVE-2024-4557
6.5 MEDIUM

Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 16.11.5, starting from 17.0 prior …

Jun 27, 2024
CVE-2024-4011
3.1 LOW

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from …

Jun 27, 2024
CVE-2024-3959
6.5 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from …

Jun 27, 2024
CVE-2024-3115
4.3 MEDIUM

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from …

Jun 27, 2024
CVE-2024-2191
5.3 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from …

Jun 27, 2024
CVE-2024-1816
5.3 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 12.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from …

Jun 27, 2024
CVE-2024-1493
6.5 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 9.2 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from …

Jun 27, 2024
CVE-2024-28984
8.8 HIGH

Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin …

Jun 26, 2024
CVE-2024-28983
8.8 HIGH

Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin …

Jun 26, 2024
CVE-2024-28982
7.1 HIGH

Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User …

Jun 26, 2024
CVE-2024-37734
9.8 CRITICAL

An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.

Jun 26, 2024
CVE-2024-37571
4.3 MEDIUM

Buffer Overflow vulnerability in SAS Broker 9.2 build 1495 allows attackers to cause denial of service or obtain sensitive information via crafted payload to the …

Jun 26, 2024
CVE-2024-37248
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Anima allows Stored XSS.This issue affects Anima: from n/a through …

Jun 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.