CVE Database

39885+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-42578
8.0 HIGH

A Cross-Site Request Forgery (CSRF) in the component edit_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42577
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component add_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42576
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component edit_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42564
7.6 HIGH

ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/inventory/delete?action=delete.

Aug 20, 2024
CVE-2024-42561
8.8 HIGH

Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at sales_report.php.

Aug 20, 2024
CVE-2024-42557
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component admin_modify_room.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42555
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component admin_room_removed.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42554
8.8 HIGH

Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_added.php.

Aug 20, 2024
CVE-2024-42553
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component admin_room_added.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42552
8.6 HIGH

Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_room_history.php.

Aug 20, 2024
CVE-2024-42336
8.2 HIGH

Servision - CWE-287: Improper Authentication

Aug 20, 2024
CVE-2024-41700
7.5 HIGH

Barix – CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Aug 20, 2024
CVE-2024-28829
7.8 HIGH

Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0p12, 2.2.0p32, 2.1.0p47 and 2.0.0 (EOL) allows local users …

Aug 20, 2024
CVE-2024-21689
8.0 HIGH

This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689 was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0 of Bamboo Data Center and …

Aug 20, 2024
CVE-2024-43688
7.3 HIGH

cron/entry.c in vixie cron before 9cc8ab1, as used in OpenBSD 7.4 and 7.5, allows a heap-based buffer underflow and memory corruption. NOTE: this issue was …

Aug 20, 2024
CVE-2024-7782
8.7 HIGH

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable …

Aug 20, 2024
CVE-2024-7780
7.2 HIGH

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable …

Aug 20, 2024
CVE-2024-7702
7.2 HIGH

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable …

Aug 20, 2024
CVE-2022-1206
7.2 HIGH

The AdRotate Banner Manager – The only ad manager you'll need plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension …

Aug 20, 2024
CVE-2024-7947
7.3 HIGH

A vulnerability classified as critical has been found in SourceCodester Point of Sales and Inventory Management System 1.0. This affects an unknown part of the …

Aug 20, 2024
CVE-2024-7946
7.3 HIGH

A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0. It has been rated as critical. Affected by this issue is some unknown …

Aug 20, 2024
CVE-2024-7827
8.8 HIGH

The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to boolean-based SQL Injection via the ‘model_number’ parameter in all versions up to, and …

Aug 20, 2024
CVE-2024-7305
7.8 HIGH

A maliciously crafted DWF file, when parsed in AdDwfPdk.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability …

Aug 20, 2024
CVE-2024-7933
7.3 HIGH

A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Aug 19, 2024
CVE-2024-4785
7.6 HIGH

BT: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Division by Zero

Aug 19, 2024
CVE-2024-7927
7.3 HIGH

A vulnerability classified as critical was found in ZZCMS 2023. Affected by this vulnerability is an unknown functionality of the file /admin/class.php?dowhat=modifyclass. The manipulation of …

Aug 19, 2024
CVE-2024-7926
7.3 HIGH

A vulnerability classified as critical has been found in ZZCMS 2023. Affected is an unknown function of the file /admin/about_edit.php?action=modify. The manipulation of the argument …

Aug 19, 2024
CVE-2024-43345
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PluginOps Landing Page Builder allows PHP Local File Inclusion.This issue affects Landing …

Aug 19, 2024
CVE-2024-43328
8.3 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper EmbedPress allows PHP Local File Inclusion.This issue affects EmbedPress: from n/a …

Aug 19, 2024
CVE-2024-7592
7.5 HIGH

There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contained backslashes for quoted characters in the …

Aug 19, 2024
CVE-2024-43271
8.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themelocation Woo Products Widgets For Elementor allows PHP Local File Inclusion.This issue …

Aug 19, 2024
CVE-2024-43256
7.1 HIGH

Missing Authorization vulnerability in nouthemes Leopard - WordPress offload media allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Leopard - WordPress offload media: …

Aug 19, 2024
CVE-2024-43250
7.1 HIGH

Incorrect Authorization vulnerability in Bit Apps Bit Form Pro bitformpro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bit Form Pro: from n/a …

Aug 19, 2024
CVE-2024-43248
8.6 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bit Apps Bit Form Pro allows File Manipulation.This issue affects Bit Form …

Aug 19, 2024
CVE-2024-43247
8.8 HIGH

Missing Authorization vulnerability in creativeon WHMpress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WHMpress: from n/a through 6.2-revision-5.

Aug 19, 2024
CVE-2024-43232
8.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP OnlineSupport, Essential Plugin Timeline and History slider allows PHP Local File …

Aug 19, 2024
CVE-2024-43221
8.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetGridBuilder allows PHP Local File Inclusion.This issue affects JetGridBuilder: from n/a …

Aug 19, 2024
CVE-2024-42657
7.5 HIGH

An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of encryption during login process

Aug 19, 2024
CVE-2024-32927
7.8 HIGH

In sendDeviceState_1_6 of RadioExt.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no …

Aug 19, 2024
CVE-2024-6348
7.5 HIGH

Predictable seed generation in the security access mechanism of UDS in the Blind Spot Protection Sensor ECU in Nissan Altima (2022) allows attackers to predict …

Aug 19, 2024
CVE-2024-42633
8.8 HIGH

A Command Injection vulnerability exists in the do_upgrade_post function of the httpd binary in Linksys E1500 v1.0.06.001. As a result, an authenticated attacker can execute …

Aug 19, 2024
CVE-2024-43399
8.0 HIGH

Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Before 4.0.7, there is a …

Aug 19, 2024
CVE-2024-6451
7.2 HIGH

AI Engine < 2.4.3 is susceptible to remote-code-execution (RCE) via Log Poisoning. The AI Engine WordPress plugin before 2.5.1 fails to validate the file extension …

Aug 19, 2024
CVE-2024-44083
7.5 HIGH

ida64.dll in Hex-Rays IDA Pro through 8.4 crashes when there is a section that has many jumps linked, and the final jump corresponds to the …

Aug 19, 2024
CVE-2024-44073
7.5 HIGH

The Miniscript (aka rust-miniscript) library before 12.2.0 for Rust allows stack consumption because it does not properly track tree depth.

Aug 19, 2024
CVE-2024-44070
7.5 HIGH

An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value.

Aug 19, 2024
CVE-2024-44069
7.5 HIGH

Pi-hole before 6 allows unauthenticated admin/api.php?setTempUnit= calls to change the temperature units of the web dashboard. NOTE: the supplier reportedly does "not consider the bug …

Aug 19, 2024
CVE-2024-44067
8.4 HIGH

The T-Head XuanTie C910 CPU in the TH1520 SoC and the T-Head XuanTie C920 CPU in the SOPHON SG2042 have instructions that allow unprivileged attackers …

Aug 19, 2024
CVE-2024-7913
7.3 HIGH

A vulnerability was found in itsourcecode Billing System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /addclient1.php. …

Aug 18, 2024
CVE-2024-43315
7.5 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in Checkout Plugins Stripe Payments For WooCommerce by Checkout.This issue affects Stripe Payments For WooCommerce by Checkout: from n/a …

Aug 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.