CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5370
3.5 LOW

A vulnerability was found in Kashipara College Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of …

May 26, 2024
CVE-2024-5369
3.5 LOW

A vulnerability was found in Kashipara College Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

May 26, 2024
CVE-2024-5368
3.5 LOW

A vulnerability was found in Kashipara College Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file delete_faculty.php. …

May 26, 2024
CVE-2024-5367
3.5 LOW

A vulnerability was found in Kashipara College Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file each_extracurricula_activities.php. The …

May 26, 2024
CVE-2024-5366
6.3 MEDIUM

A vulnerability has been found in SourceCodester Best House Rental Management System up to 1.0 and classified as critical. This vulnerability affects unknown code of …

May 26, 2024
CVE-2024-5272
4.3 MEDIUM

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to restrict the audience of the "custom_playbooks_playbook_run_updated" webhook event, which allows a guest …

May 26, 2024
CVE-2024-5270
4.3 MEDIUM

Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to check if the email signup configuration option is …

May 26, 2024
CVE-2024-36255
5.7 MEDIUM

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper input validation on post actions which allows an attacker …

May 26, 2024
CVE-2024-36241
3.1 LOW

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to enforce proper access controls which allows user to view arbitrary post …

May 26, 2024
CVE-2024-34152
4.3 MEDIUM

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper access control which allows a guest to get the …

May 26, 2024
CVE-2024-34029
4.3 MEDIUM

Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1 and 8.1.x <= 8.1.12 fail to perform a proper authorization check in the /api/v4/groups/<group-id>/channels/<channel-id>/link endpoint which allows …

May 26, 2024
CVE-2024-32045
5.9 MEDIUM

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access controls for channel and team membership when linking a …

May 26, 2024
CVE-2024-31859
4.3 MEDIUM

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper authorization checks which allows a member running a playbook …

May 26, 2024
CVE-2024-29215
4.3 MEDIUM

Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access control which allows a user to …

May 26, 2024
CVE-2024-5365
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Best House Rental Management System up to 1.0. This affects an unknown part of …

May 26, 2024
CVE-2024-5364
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Best House Rental Management System up to 1.0. Affected by this issue is …

May 26, 2024
CVE-2024-5363
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Best House Rental Management System up to 1.0. Affected by this vulnerability is an unknown functionality …

May 26, 2024
CVE-2024-5362
7.3 HIGH

A vulnerability classified as critical has been found in SourceCodester Online Hospital Management System 1.0. Affected is an unknown function of the file departmentDoctor.php. The …

May 26, 2024
CVE-2024-5361
6.3 MEDIUM

A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been rated as critical. This issue affects some unknown processing of the file …

May 26, 2024
CVE-2024-5360
6.3 MEDIUM

A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been declared as critical. This vulnerability affects unknown code of the file /admin/foreigner-bwdates-reports-details.php. …

May 26, 2024
CVE-2024-5359
6.3 MEDIUM

A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been classified as critical. This affects an unknown part of the file /admin/foreigner-search.php. …

May 26, 2024
CVE-2024-5358
6.3 MEDIUM

A vulnerability was found in PHPGurukul Zoo Management System 2.1 and classified as critical. Affected by this issue is some unknown functionality of the file …

May 26, 2024
CVE-2024-5357
7.3 HIGH

A vulnerability has been found in PHPGurukul Zoo Management System 2.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

May 26, 2024
CVE-2024-5356
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in anji-plus AJ-Report up to 1.4.1. Affected is an unknown function of the file /dataSet/testTransform;swagger-ui. The …

May 26, 2024
CVE-2024-5355
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in anji-plus AJ-Report up to 1.4.1. This issue affects the function IGroovyHandler. The manipulation leads …

May 26, 2024
CVE-2024-5354
4.3 MEDIUM

A vulnerability classified as problematic was found in anji-plus AJ-Report up to 1.4.1. This vulnerability affects unknown code of the file /reportShare/detailByCode. The manipulation of …

May 26, 2024
CVE-2024-5353
6.3 MEDIUM

A vulnerability classified as critical has been found in anji-plus AJ-Report up to 1.4.1. This affects the function decompress of the component ZIP File Handler. …

May 26, 2024
CVE-2024-5352
6.3 MEDIUM

A vulnerability was found in anji-plus AJ-Report up to 1.4.1. It has been rated as critical. Affected by this issue is the function validationRules of …

May 26, 2024
CVE-2024-5351
6.3 MEDIUM

A vulnerability was found in anji-plus AJ-Report up to 1.4.1. It has been declared as critical. Affected by this vulnerability is the function getValueFromJs of …

May 26, 2024
CVE-2024-5350
6.3 MEDIUM

A vulnerability was found in anji-plus AJ-Report up to 1.4.1. It has been classified as critical. Affected is the function pageList of the file /pageList. …

May 25, 2024
CVE-2024-5340
4.7 MEDIUM

A vulnerability was found in Ruijie RG-UAC up to 20240516. It has been rated as critical. Affected by this issue is some unknown functionality of …

May 25, 2024
CVE-2024-30056
7.1 HIGH

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

May 25, 2024
CVE-2024-5339
4.7 MEDIUM

A vulnerability was found in Ruijie RG-UAC up to 20240516. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

May 25, 2024
CVE-2024-5338
4.7 MEDIUM

A vulnerability was found in Ruijie RG-UAC up to 20240516. It has been classified as critical. Affected is an unknown function of the file /view/vpn/autovpn/online.php. …

May 25, 2024
CVE-2024-5337
4.7 MEDIUM

A vulnerability was found in Ruijie RG-UAC up to 20240516 and classified as critical. This issue affects some unknown processing of the file /view/systemConfig/sys_user/user_commit.php. The …

May 25, 2024
CVE-2024-5336
4.7 MEDIUM

A vulnerability has been found in Ruijie RG-UAC up to 20240516 and classified as critical. This vulnerability affects the function addVlan of the file /view/networkConfig/vlan/vlan_add_commit.php. …

May 25, 2024
CVE-2024-4045
6.4 MEDIUM

The Popup Builder by OptinMonster – WordPress Popups for Optins, Email Newsletters and Lead Generation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

May 25, 2024
CVE-2024-5218
6.4 MEDIUM

The Reviews and Rating – Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feature in all versions …

May 25, 2024
CVE-2024-5229
6.4 MEDIUM

The Primary Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table widget in all versions up to, …

May 25, 2024
CVE-2024-4858
5.3 MEDIUM

The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_testimonials_option_callback' function …

May 25, 2024
CVE-2024-5220
6.4 MEDIUM

The ND Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's upload feature in all versions up to, and including, 7.5 …

May 25, 2024
CVE-2024-36079
6.5 MEDIUM

An issue was discovered in Vaultize 21.07.27. When uploading files, there is no check that the filename parameter is correct. As a result, a temporary …

May 24, 2024
CVE-2024-35374
9.8 CRITICAL

Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing remote attackers to execute arbitrary commands and potentially …

May 24, 2024
CVE-2024-35373
9.8 CRITICAL

Mocodo Mocodo Online 4.2.6 and below is vulnerable to Remote Code Execution via /web/rewrite.php.

May 24, 2024
CVE-2024-35232
3.7 LOW

github.com/huandu/facebook is a Go package that fully supports the Facebook Graph API with file upload, batch request and marketing API. access_token can be exposed in …

May 24, 2024
CVE-2024-35388
8.8 HIGH

TOTOLINK NR1800X v9.1.0u.6681_B20230703 was discovered to contain a stack overflow via the password parameter in the function urldecode

May 24, 2024
CVE-2024-33471
7.2 HIGH

An issue in the Sensor Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to SMTP credentials in plaintext via a crafted …

May 24, 2024
CVE-2024-35387
9.8 CRITICAL

TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.

May 24, 2024
CVE-2024-36049
6.5 MEDIUM

Aptos Wisal payroll accounting before 7.1.6 uses hardcoded credentials in the Windows client to fetch the complete list of usernames and passwords from the database …

May 24, 2024
CVE-2023-46442
4.3 MEDIUM

An infinite loop in the retrieveActiveBody function of Soot before v4.4.1 under Java 8 allows attackers to cause a Denial of Service (DoS).

May 24, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.