CVE Database

39885+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7258
8.8 HIGH

The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'wppfm_removeFeedFile' function …

Aug 23, 2024
CVE-2024-7559
8.8 HIGH

The File Manager Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in the mk_file_folder_manager …

Aug 23, 2024
CVE-2024-43477
7.5 HIGH

Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable ID's on another tenant.

Aug 23, 2024
CVE-2024-8086
7.3 HIGH

A vulnerability has been found in SourceCodester E-Commerce System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ecommerce/admin/login.php of the …

Aug 22, 2024
CVE-2024-38210
7.8 HIGH

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Aug 22, 2024
CVE-2024-38209
7.8 HIGH

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Aug 22, 2024
CVE-2024-8081
7.3 HIGH

A vulnerability classified as critical was found in itsourcecode Payroll Management System 1.0. Affected by this vulnerability is an unknown functionality of the file login.php. …

Aug 22, 2024
CVE-2024-8079
8.8 HIGH

A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been rated as critical. This issue affects the function exportOvpn. The manipulation leads to …

Aug 22, 2024
CVE-2024-8078
8.8 HIGH

A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been declared as critical. This vulnerability affects the function setTracerouteCfg. The manipulation leads to …

Aug 22, 2024
CVE-2023-7260
7.5 HIGH

Path Traversal vulnerability discovered in OpenText™ CX-E Voice, affecting all version through 22.4. The vulnerability could allow arbitrarily access files on the system.

Aug 22, 2024
CVE-2024-8076
8.8 HIGH

A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228 and classified as critical. Affected by this issue is the function setDiagnosisCfg. The manipulation leads to …

Aug 22, 2024
CVE-2024-45201
8.8 HIGH

An issue was discovered in llama_index before 0.10.38. download/integration.py includes an exec call for import {cls_name}.

Aug 22, 2024
CVE-2024-42599
8.8 HIGH

SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_files.php imposes restrictions on edited files, attackers can still …

Aug 22, 2024
CVE-2024-42418
7.5 HIGH

Avtec Outpost uses a default cryptographic key that can be used to decrypt sensitive information.

Aug 22, 2024
CVE-2024-39776
7.5 HIGH

Avtec Outpost stores sensitive information in an insecure location without proper access controls in place.

Aug 22, 2024
CVE-2024-39717
7.2 HIGH KEV

The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user …

Aug 22, 2024
CVE-2024-42767
7.2 HIGH

Kashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php.

Aug 22, 2024
CVE-2024-42776
7.2 HIGH

Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php.

Aug 22, 2024
CVE-2024-42774
7.5 HIGH

An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to delete valid hotel room …

Aug 22, 2024
CVE-2024-42772
7.5 HIGH

An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to view valid hotel room …

Aug 22, 2024
CVE-2024-42490
7.5 HIGH

authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. The main API endpoints affected by this are …

Aug 22, 2024
CVE-2024-36444
8.1 HIGH

cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an unauthenticated attacker to gain access to device logs.

Aug 22, 2024
CVE-2024-36442
8.8 HIGH

cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an authenticated attacker to gain access to arbitrary files on the device's file system.

Aug 22, 2024
CVE-2024-36443
7.6 HIGH

Swissphone DiCal-RED 4009 devices allow a remote attacker to gain read access to almost the whole file system via anonymous FTP.

Aug 22, 2024
CVE-2022-48943
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: make apf token non-zero to fix bug In current async pagefault logic, when …

Aug 22, 2024
CVE-2022-48927
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: adc: tsc2046: fix memory corruption by preventing array overflow On one side we have …

Aug 22, 2024
CVE-2022-48926
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: rndis: add spinlock for rndis response list There's no lock for rndis response …

Aug 22, 2024
CVE-2024-7384
7.5 HIGH

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing …

Aug 22, 2024
CVE-2024-39576
8.8 HIGH

Dell Power Manager (DPM), versions 3.15.0 and prior, contains an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this …

Aug 22, 2024
CVE-2022-48925
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: RDMA/cma: Do not change route.addr.src_addr outside state checks If the state is not idle then …

Aug 22, 2024
CVE-2022-48919
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: cifs: fix double free race when mount fails in cifs_get_root() When cifs_get_root() fails during cifs_smb3_do_mount() …

Aug 22, 2024
CVE-2022-48913
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: blktrace: fix use after free for struct blk_trace When tracing the whole disk, 'dropped' and …

Aug 22, 2024
CVE-2022-48912
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfilter: fix use-after-free in __nf_register_net_hook() We must not dereference @new_hooks after nf_hook_mutex has been released, …

Aug 22, 2024
CVE-2024-43033
8.8 HIGH

JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to AttachmentController, such as a .jsp::$DATA …

Aug 22, 2024
CVE-2024-7980
7.8 HIGH

Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic …

Aug 21, 2024
CVE-2024-7979
7.8 HIGH

Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic …

Aug 21, 2024
CVE-2024-7977
7.8 HIGH

Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a malicious file. …

Aug 21, 2024
CVE-2024-7974
8.8 HIGH

Insufficient data validation in V8 API in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome …

Aug 21, 2024
CVE-2024-7973
8.8 HIGH

Heap buffer overflow in PDFium in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform an out of bounds memory read via a …

Aug 21, 2024
CVE-2024-7972
8.8 HIGH

Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially perform out of bounds memory access via a crafted …

Aug 21, 2024
CVE-2024-7969
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Aug 21, 2024
CVE-2024-7968
8.8 HIGH

Use after free in Autofill in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had convinced the user to engage in specific UI …

Aug 21, 2024
CVE-2024-7967
8.8 HIGH

Heap buffer overflow in Fonts in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Aug 21, 2024
CVE-2024-7966
8.8 HIGH

Out of bounds memory access in Skia in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had compromised the renderer process to perform …

Aug 21, 2024
CVE-2024-7965
8.8 HIGH KEV

Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Aug 21, 2024
CVE-2024-7964
8.8 HIGH

Use after free in Passwords in Google Chrome on Android prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Aug 21, 2024
CVE-2024-42786
8.8 HIGH

A SQL injection vulnerability in "/music/view_user.php" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter of …

Aug 21, 2024
CVE-2024-42785
8.8 HIGH

A SQL injection vulnerability in /music/index.php?page=view_playlist in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.

Aug 21, 2024
CVE-2024-42780
8.8 HIGH

An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_genre" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a …

Aug 21, 2024
CVE-2024-42779
8.8 HIGH

An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a …

Aug 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.