CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5400
8.8 HIGH

Openfind Mail2000 does not properly filter parameters of specific CGI. Remote attackers with regular privileges can exploit this vulnerability to execute arbitrary system commands on …

May 27, 2024
CVE-2024-4535
8.8 HIGH

The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

May 27, 2024
CVE-2024-4534
6.1 MEDIUM

The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

May 27, 2024
CVE-2024-4533
6.5 MEDIUM

The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admin users to …

May 27, 2024
CVE-2024-4532
6.4 MEDIUM

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

May 27, 2024
CVE-2024-4531
7.1 HIGH

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

May 27, 2024
CVE-2024-4530
6.3 MEDIUM

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

May 27, 2024
CVE-2024-4529
5.0 MEDIUM

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

May 27, 2024
CVE-2024-3939
5.4 MEDIUM

The Ditty WordPress plugin before 3.1.36 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 27, 2024
CVE-2024-3933
5.3 MEDIUM

In Eclipse OpenJ9 release versions prior to 0.44.0 and after 0.13.0, when running with JVM option -Xgc:concurrentScavenge, the sequence generated for System.arrayCopy on the IBM …

May 27, 2024
CVE-2024-35297
4.7 MEDIUM

Cross-site scripting vulnerability exists in WP Booking versions prior to 2.4.5. If this vulnerability is exploited, an arbitrary script may be executed on the web …

May 27, 2024
CVE-2024-35291
6.1 MEDIUM

Cross-site scripting vulnerability exists in Splunk Config Explorer versions prior to 1.7.16. If this vulnerability is exploited, an arbitrary script may be executed on the …

May 27, 2024
CVE-2024-5399
7.2 HIGH

Openfind Mail2000 does not properly filter parameters of specific API. Remote attackers with administrative privileges can exploit this vulnerability to execute arbitrary system commands on …

May 27, 2024
CVE-2024-36384
6.1 MEDIUM

Pointsharp Cryptshare Server before 7.0.0 has an XSS issue that is related to notification messages.

May 27, 2024
CVE-2024-5397
6.3 MEDIUM

A vulnerability classified as critical was found in itsourcecode Online Student Enrollment System 1.0. Affected by this vulnerability is an unknown functionality of the file …

May 27, 2024
CVE-2024-5396
6.3 MEDIUM

A vulnerability classified as critical has been found in itsourcecode Online Student Enrollment System 1.0. Affected is an unknown function of the file newfaculty.php. The …

May 27, 2024
CVE-2024-5395
6.3 MEDIUM

A vulnerability was found in itsourcecode Online Student Enrollment System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

May 27, 2024
CVE-2024-5394
6.3 MEDIUM

A vulnerability was found in itsourcecode Online Student Enrollment System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

May 27, 2024
CVE-2024-5393
6.3 MEDIUM

A vulnerability was found in itsourcecode Online Student Enrollment System 1.0. It has been classified as critical. This affects an unknown part of the file …

May 27, 2024
CVE-2024-5392
6.3 MEDIUM

A vulnerability was found in itsourcecode Online Student Enrollment System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

May 27, 2024
CVE-2024-5391
6.3 MEDIUM

A vulnerability has been found in itsourcecode Online Student Enrollment System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

May 27, 2024
CVE-2024-5390
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Online Student Enrollment System 1.0. Affected is an unknown function of the file listofstudent.php. …

May 27, 2024
CVE-2024-5385
2.4 LOW

A vulnerability, which was classified as problematic, has been found in oretnom23 Online Car Wash Booking System 1.0. This issue affects some unknown processing of …

May 27, 2024
CVE-2024-5384
7.3 HIGH

A vulnerability classified as critical was found in SourceCodester Facebook News Feed Like 1.0. This vulnerability affects unknown code of the file index.php. The manipulation …

May 27, 2024
CVE-2024-30658

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

May 27, 2024
CVE-2024-30657

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

May 27, 2024
CVE-2024-5383
3.5 LOW

A vulnerability classified as problematic has been found in lakernote EasyAdmin up to 20240324. This affects an unknown part of the file /sys/file/upload. The manipulation …

May 26, 2024
CVE-2024-5381
6.3 MEDIUM

A vulnerability classified as critical was found in itsourcecode Student Information Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …

May 26, 2024
CVE-2024-5380
3.5 LOW

A vulnerability classified as problematic has been found in jsy-1 short-url 1.0.0. Affected is an unknown function of the file admin.php. The manipulation of the …

May 26, 2024
CVE-2024-4286
4.9 MEDIUM

Mintplex-Labs' anything-llm application is vulnerable to improper neutralization of special elements used in an expression language statement, identified in the commit id `57984fa85c31988b2eff429adfc654c46e0c342a`. The vulnerability …

May 26, 2024
CVE-2024-36056
5.4 MEDIUM

Hw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily map physical memory via IOCTL 0x9c406490 (for IoAllocateMdl, MmBuildMdlForNonPagedPool, and MmMapLockedPages), leading …

May 26, 2024
CVE-2024-36055
5.5 MEDIUM

Hw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily map physical memory with read/write access via the MmMapIoSpace API (IOCTL 0x9c40a4f8, …

May 26, 2024
CVE-2024-36054
7.4 HIGH

Hw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily read kernel memory (and consequently gain all privileges) via IOCTL 0x9c4064b8 (via …

May 26, 2024
CVE-2024-5379
3.5 LOW

A vulnerability was found in JFinalCMS up to 20240111. It has been rated as problematic. This issue affects some unknown processing of the file /admin/template. …

May 26, 2024
CVE-2024-5378
6.3 MEDIUM

A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of …

May 26, 2024
CVE-2024-34454
7.4 HIGH

Nintendo Wii U OS 5.5.5 allows man-in-the-middle attackers to forge SSL certificates as though they came from a Root CA, because there is a secondary …

May 26, 2024
CVE-2024-5377
7.3 HIGH

A vulnerability was found in SourceCodester Vehicle Management System 1.0. It has been classified as critical. This affects an unknown part of the file /newvehicle.php. …

May 26, 2024
CVE-2024-5376
3.5 LOW

A vulnerability was found in Kashipara College Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file …

May 26, 2024
CVE-2024-5375
3.5 LOW

A vulnerability has been found in Kashipara College Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

May 26, 2024
CVE-2024-5374
3.5 LOW

A vulnerability, which was classified as problematic, was found in Kashipara College Management System 1.0. Affected is an unknown function of the file submit_new_faculty.php. The …

May 26, 2024
CVE-2024-5373
3.5 LOW

A vulnerability, which was classified as problematic, has been found in Kashipara College Management System 1.0. This issue affects some unknown processing of the file …

May 26, 2024
CVE-2024-5372
3.5 LOW

A vulnerability classified as problematic was found in Kashipara College Management System 1.0. This vulnerability affects unknown code of the file submit_extracurricular_activity.php. The manipulation of …

May 26, 2024
CVE-2024-5371
3.5 LOW

A vulnerability classified as problematic has been found in Kashipara College Management System 1.0. This affects an unknown part of the file submit_enroll_student.php. The manipulation …

May 26, 2024
CVE-2024-5370
3.5 LOW

A vulnerability was found in Kashipara College Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of …

May 26, 2024
CVE-2024-5369
3.5 LOW

A vulnerability was found in Kashipara College Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

May 26, 2024
CVE-2024-5368
3.5 LOW

A vulnerability was found in Kashipara College Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file delete_faculty.php. …

May 26, 2024
CVE-2024-5367
3.5 LOW

A vulnerability was found in Kashipara College Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file each_extracurricula_activities.php. The …

May 26, 2024
CVE-2024-5366
6.3 MEDIUM

A vulnerability has been found in SourceCodester Best House Rental Management System up to 1.0 and classified as critical. This vulnerability affects unknown code of …

May 26, 2024
CVE-2024-5272
4.3 MEDIUM

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to restrict the audience of the "custom_playbooks_playbook_run_updated" webhook event, which allows a guest …

May 26, 2024
CVE-2024-5270
4.3 MEDIUM

Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to check if the email signup configuration option is …

May 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.