CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4899
5.0 MEDIUM

The SEOPress WordPress plugin before 7.8 does not sanitise and escape some of its Post settings, which could allow high privilege users such as contributor …

Jun 24, 2024
CVE-2024-6280
6.3 MEDIUM

A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as critical. This affects an unknown part of the file …

Jun 24, 2024
CVE-2024-6279
6.3 MEDIUM

A vulnerability was found in lahirudanushka School Management System 1.0.0/1.0.1 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jun 24, 2024
CVE-2024-6278
4.7 MEDIUM

A vulnerability has been found in lahirudanushka School Management System 1.0.0/1.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Jun 24, 2024
CVE-2024-6277
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in lahirudanushka School Management System 1.0.0/1.0.1. Affected is an unknown function of the file student.php of …

Jun 24, 2024
CVE-2024-4499
6.3 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability exists in the XTTS server of parisneo/lollms version 9.6 due to a lax CORS policy. The vulnerability allows attackers …

Jun 24, 2024
CVE-2024-6276
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in lahirudanushka School Management System 1.0.0/1.0.1. This issue affects some unknown processing of the file …

Jun 24, 2024
CVE-2024-6275
4.7 MEDIUM

A vulnerability classified as critical was found in lahirudanushka School Management System 1.0.0/1.0.1. This vulnerability affects unknown code of the file parent.php of the component …

Jun 24, 2024
CVE-2024-6274
4.7 MEDIUM

A vulnerability classified as critical has been found in lahirudanushka School Management System 1.0.0/1.0.1. This affects an unknown part of the file /attendancelist.php of the …

Jun 24, 2024
CVE-2024-3121
3.3 LOW

A remote code execution vulnerability exists in the create_conda_env function of the parisneo/lollms repository, version 5.9.0. The vulnerability arises from the use of shell=True in …

Jun 24, 2024
CVE-2024-39337
6.5 MEDIUM

Click Studios Passwordstate Core before 9.8 build 9858 allows Authentication Bypass.

Jun 24, 2024
CVE-2024-39334
6.5 MEDIUM

MENDELSON AS4 before 2024 B376 has a client-side vulnerability when a trading partner provides prepared XML data. When a victim opens the details of this …

Jun 23, 2024
CVE-2024-6273
4.3 MEDIUM

A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been declared as problematic. Affected by this vulnerability is the function save_patient of …

Jun 23, 2024
CVE-2024-39331
9.8 CRITICAL

In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org …

Jun 23, 2024
CVE-2024-4841
3.3 LOW

A Path Traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'add_reference_to_local_mode' function due to the lack of input sanitization. This vulnerability affects versions v9.6 …

Jun 23, 2024
CVE-2024-6269
4.7 MEDIUM

A vulnerability has been found in Ruijie RG-UAC 1.0 and classified as critical. This vulnerability affects the function get_ip.addr_details of the file /view/vpn/autovpn/sxh_vpnlic.php of the …

Jun 23, 2024
CVE-2024-6268
7.3 HIGH

A vulnerability, which was classified as critical, has been found in lahirudanushka School Management System 1.0.0/1.0.1. Affected by this issue is some unknown functionality of …

Jun 23, 2024
CVE-2024-6267
2.4 LOW

A vulnerability classified as problematic was found in SourceCodester Service Provider Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jun 23, 2024
CVE-2024-6266
6.3 MEDIUM

A vulnerability classified as critical has been found in Pear Admin Boot up to 2.0.2. Affected is an unknown function of the file /system/dictData/loadDictItem. The …

Jun 23, 2024
CVE-2024-38319
7.5 HIGH

IBM Security SOAR 51.0.2.0 could allow an authenticated user to execute malicious code loaded from a specially crafted script. IBM X-Force ID: 294830.

Jun 22, 2024
CVE-2024-5443
9.8 CRITICAL

CVE-2024-4320 describes a vulnerability in the parisneo/lollms software, specifically within the `ExtensionBuilder().build_extension()` function. The vulnerability arises from the `/mount_extension` endpoint, where a path traversal issue …

Jun 22, 2024
CVE-2024-6253
7.3 HIGH

A vulnerability was found in itsourcecode Online Food Ordering System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Jun 22, 2024
CVE-2024-6252
2.4 LOW

A vulnerability has been found in Zorlan SkyCaiji up to 2.8 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

Jun 22, 2024
CVE-2024-6251
2.4 LOW

A vulnerability, which was classified as problematic, was found in playSMS 1.4.3. Affected is an unknown function of the file /index.php?app=main&inc=feature_phonebook&op=phonebook_list of the component New …

Jun 22, 2024
CVE-2024-38379
4.8 MEDIUM

Apache Allura's neighborhood settings are vulnerable to a stored XSS attack. Only neighborhood admins can access these settings, so the scope of risk is limited …

Jun 22, 2024
CVE-2024-5596
6.3 MEDIUM

The ARMember Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.7. This is due to incorrectly implemented …

Jun 22, 2024
CVE-2024-4940
6.1 MEDIUM

An open redirect vulnerability exists in the gradio-app/gradio, affecting the latest version. The vulnerability allows an attacker to redirect users to arbitrary websites, which can …

Jun 22, 2024
CVE-2024-3593
7.2 HIGH

The UberMenu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.3. This is due to missing or …

Jun 22, 2024
CVE-2024-4874
4.3 MEDIUM

The Bricks Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.8 via the postId parameter …

Jun 22, 2024
CVE-2024-21519
6.6 MEDIUM

This affects versions of the package opencart/opencart from 4.0.0.0. An Arbitrary File Creation issue was identified via the database restoration functionality. By injecting PHP code …

Jun 22, 2024
CVE-2024-21518
7.2 HIGH

This affects versions of the package opencart/opencart from 4.0.0.0. A Zip Slip issue was identified via the marketplace installer due to improper sanitization of the …

Jun 22, 2024
CVE-2024-21517
4.2 MEDIUM

This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the redirect parameter of customer account/login route. An attacker …

Jun 22, 2024
CVE-2024-21516
4.2 MEDIUM

This affects versions of the package opencart/opencart from 4.0.0.0 and before 4.1.0.0. A reflected XSS issue was identified in the directory parameter of admin common/filemanager.list …

Jun 22, 2024
CVE-2024-21515
4.2 MEDIUM

This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the filename parameter of the admin tool/log route. An …

Jun 22, 2024
CVE-2024-21514
7.4 HIGH

This affects versions of the package opencart/opencart from 0.0.0. An SQL Injection issue was identified in the Divido payment extension for OpenCart, which is included …

Jun 22, 2024
CVE-2024-5966
6.4 MEDIUM

The Grey Opaque theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Download-Button shortcode in all versions up …

Jun 22, 2024
CVE-2024-5965
6.4 MEDIUM

The Mosaic theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter within the theme's Button shortcode in all versions up to, …

Jun 22, 2024
CVE-2024-5791
7.2 HIGH

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp_id' parameter in all …

Jun 22, 2024
CVE-2024-5346
6.4 MEDIUM

The Flatsome theme for WordPress is vulnerable to Stored Cross-Site Scripting via the UX Countdown, Video Button, UX Video, UX Slider, UX Sidebar, and UX …

Jun 22, 2024
CVE-2024-4313
6.4 MEDIUM

The Table Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, …

Jun 22, 2024
CVE-2024-2484
6.4 MEDIUM

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Services and Post Type Grid widgets in all versions …

Jun 22, 2024
CVE-2024-6120
6.5 MEDIUM

The Sparkle Demo Importer plugin for WordPress is vulnerable to unauthorized database reset and demo data import due to a missing capability check on the …

Jun 22, 2024
CVE-2024-37694

Rejected reason: This submission has been rejected by the CNA of record. Authentication is user configurable as described in our documentation. https://enterprise.arcgis.com/en/server/latest/administer/windows/configuring-arcgis-server-security.htm

Jun 21, 2024
CVE-2024-37654
6.1 MEDIUM

An issue in BAS-IP AV-01D, AV-01MD, AV-01MFD, AV-01ED, AV-01KD, AV-01BD, AV-01KBD, AV-02D, AV-02IDE, AV-02IDR, AV-02IPD, AV-02FDE, AV-02FDR, AV-03D, AV-03BD, AV-04AFD, AV-04ASD, AV-04FD, AV-04SD, AV-05FD, AV-05SD, …

Jun 21, 2024
CVE-2024-36532
10.0 CRITICAL

Insecure permissions in kruise v1.6.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Jun 21, 2024
CVE-2024-34989
9.8 CRITICAL

In the module RSI PDF/HTML catalog evolution (prestapdf) <= 7.0.0 from RSI for PrestaShop, a guest can perform SQL injection via `PrestaPDFProductListModuleFrontController::queryDb().'

Jun 21, 2024
CVE-2024-34452
6.1 MEDIUM

CMSimple_XH 1.7.6 allows XSS by uploading a crafted SVG document.

Jun 21, 2024
CVE-2022-42974
4.8 MEDIUM

In Kostal PIKO 1.5-1 MP plus HMI OEM p 1.0.1, the web application for the Solar Panel is vulnerable to a Stored Cross-Site Scripting (XSS) …

Jun 21, 2024
CVE-2014-5470
9.8 CRITICAL

Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for part of the input data passed to an eval …

Jun 21, 2024
CVE-2012-6664
9.1 CRITICAL

Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remote attackers to read or write arbitrary files via …

Jun 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.