CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-2358
9.8 CRITICAL

A path traversal vulnerability in the '/apply_settings' endpoint of parisneo/lollms-webui allows attackers to execute arbitrary code. The vulnerability arises due to insufficient sanitization of user-supplied …

May 16, 2024
CVE-2024-20793
5.5 MEDIUM

Illustrator versions 28.4, 27.9.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

May 16, 2024
CVE-2024-20792
7.8 HIGH

Illustrator versions 28.4, 27.9.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of …

May 16, 2024
CVE-2024-20791
7.8 HIGH

Illustrator versions 28.4, 27.9.3 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past …

May 16, 2024
CVE-2024-4966
7.3 HIGH

A vulnerability was found in SourceCodester SchoolWebTech 1.0. It has been classified as critical. Affected is an unknown function of the file /improve/home.php. The manipulation …

May 16, 2024
CVE-2024-4965
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000-40 V31R02B1413C and classified as critical. This issue affects some unknown processing of the …

May 16, 2024
CVE-2024-4964
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DAR-7000-40 V31R02B1413C and classified as critical. This vulnerability affects unknown code of the …

May 16, 2024
CVE-2024-4546
6.4 MEDIUM

The Custom Post Type Attachment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pdf_attachment' shortcode in all versions up to, and …

May 16, 2024
CVE-2024-4478
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Group widget in all versions up to, …

May 16, 2024
CVE-2024-4963
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DAR-7000-40 V31R02B1413C. This affects an unknown part of the …

May 16, 2024
CVE-2024-4962
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-7000-40 V31R02B1413C. Affected by this issue is some …

May 16, 2024
CVE-2024-4844
7.5 HIGH

Hardcoded credentials vulnerability in Trellix ePolicy Orchestrator (ePO) on Premise prior to 5.10 Service Pack 1 Update 2 allows an attacker with admin privileges on …

May 16, 2024
CVE-2024-4961
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in D-Link DAR-7000-40 V31R02B1413C. Affected by this vulnerability is an unknown functionality of …

May 16, 2024
CVE-2024-4960
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in D-Link DAR-7000-40 V31R02B1413C. Affected is an unknown function of the file …

May 16, 2024
CVE-2024-4946
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Art Gallery Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown …

May 16, 2024
CVE-2024-4843
4.3 MEDIUM

ePO doesn't allow a regular privileged user to delete tasks or assignments. Insecure direct object references that allow a least privileged user to manipulate the …

May 16, 2024
CVE-2024-4635
6.4 MEDIUM

The Menu Icons by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘add_mime_type’ function in versions up to, and including, 0.13.13 …

May 16, 2024
CVE-2024-4318
8.8 HIGH

The Tutor LMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘question_id’ parameter in versions up to, and including, 2.7.0 due to …

May 16, 2024
CVE-2024-4279
6.5 MEDIUM

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference to Arbitrary Course Deletion in versions …

May 16, 2024
CVE-2024-3644
4.8 MEDIUM

The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 16, 2024
CVE-2024-3643
8.8 HIGH

The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting list, which could allow attackers to make logged in admins perform …

May 16, 2024
CVE-2024-3642
6.9 MEDIUM

The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting subscriber, which could allow attackers to make logged in admins perform …

May 16, 2024
CVE-2024-3641
6.1 MEDIUM

The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some parameters, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks against …

May 16, 2024
CVE-2024-4945
4.3 MEDIUM

A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file …

May 16, 2024
CVE-2024-4933
6.3 MEDIUM

A vulnerability has been found in SourceCodester Simple Online Bidding System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

May 16, 2024
CVE-2024-4932
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Simple Online Bidding System 1.0. Affected is an unknown function of the file /simple-online-bidding-system/admin/index.php?page=manage_user. …

May 16, 2024
CVE-2024-4931
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Simple Online Bidding System 1.0. This issue affects some unknown processing of the …

May 16, 2024
CVE-2024-4930
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Simple Online Bidding System 1.0. This vulnerability affects unknown code of the file /simple-online-bidding-system/index.php?page=view_prod. The manipulation …

May 16, 2024
CVE-2024-4929
4.3 MEDIUM

A vulnerability classified as problematic has been found in SourceCodester Simple Online Bidding System 1.0. This affects an unknown part of the file /simple-online-bidding-system/admin/ajax.php?action=save_user. The …

May 16, 2024
CVE-2024-4928
6.3 MEDIUM

A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

May 16, 2024
CVE-2024-4927
7.3 HIGH

A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

May 16, 2024
CVE-2024-3750
8.8 HIGH

The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to unauthorized modification and retrieval of data due to a missing capability …

May 16, 2024
CVE-2024-4984
6.4 MEDIUM

The Yoast SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ author meta in all versions up to, and including, 22.6 …

May 16, 2024
CVE-2024-4926
6.3 MEDIUM

A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0. It has been classified as critical. Affected is an unknown function of …

May 16, 2024
CVE-2024-4925
6.3 MEDIUM

A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0 and classified as critical. This issue affects some unknown processing of the …

May 16, 2024
CVE-2024-4923
6.3 MEDIUM

A vulnerability has been found in Codezips E-Commerce Site 1.0 and classified as critical. This vulnerability affects unknown code of the file admin/addproduct.php. The manipulation …

May 16, 2024
CVE-2024-4922
3.5 LOW

A vulnerability, which was classified as problematic, was found in SourceCodester Simple Image Stack Website 1.0. This affects an unknown part. The manipulation of the …

May 16, 2024
CVE-2024-4921
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. Affected is an unknown function of the …

May 16, 2024
CVE-2024-4920
7.3 HIGH

A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. It has been rated as critical. This issue affects some unknown processing of the …

May 16, 2024
CVE-2024-4919
6.3 MEDIUM

A vulnerability was found in Campcodes Online Examination System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /adminpanel/admin/query/addCourseExe.php. …

May 16, 2024
CVE-2024-4918
6.3 MEDIUM

A vulnerability was found in Campcodes Online Examination System 1.0. It has been classified as critical. This affects an unknown part of the file updateQuestion.php. …

May 15, 2024
CVE-2024-4917
6.3 MEDIUM

A vulnerability was found in Campcodes Online Examination System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

May 15, 2024
CVE-2024-4916
6.3 MEDIUM

A vulnerability has been found in Campcodes Online Examination System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

May 15, 2024
CVE-2024-4915
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Campcodes Online Examination System 1.0. Affected is an unknown function of the file result.php. The …

May 15, 2024
CVE-2024-4914
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Campcodes Online Examination System 1.0. This issue affects some unknown processing of the file …

May 15, 2024
CVE-2024-35184
5.5 MEDIUM

Paperless-ngx is a document management system that transforms physical documents into a searchable online archive. Starting in version 2.5.0 and prior to version 2.8.6, remote …

May 15, 2024
CVE-2024-35183
4.4 MEDIUM

wolfictl is a command line tool for working with Wolfi. A git authentication issue in versions prior to 0.16.10 allows a local user’s GitHub token …

May 15, 2024
CVE-2024-4976
5.5 MEDIUM

Out-of-bounds array write in Xpdf 4.05 and earlier, due to missing object type check in AcroForm field reference.

May 15, 2024
CVE-2024-4950
6.5 MEDIUM

Inappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

May 15, 2024
CVE-2024-4949
6.5 MEDIUM

Use after free in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

May 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.