CVE Database

39885+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6989
8.8 HIGH

Use after free in Loader in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Aug 6, 2024
CVE-2024-6988
8.8 HIGH

Use after free in Downloads in Google Chrome on iOS prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Aug 6, 2024
CVE-2024-6720
8.8 HIGH

The Light Poll WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

Aug 6, 2024
CVE-2024-23483
7.0 HIGH

An Improper Input Validation vulnerability in Zscaler Client Connector on MacOS allows OS Command Injection. This issue affects Zscaler Client Connector on MacOS <4.2.

Aug 6, 2024
CVE-2024-23464
7.2 HIGH

In certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Zscaler Client Connector on Windows <4.2.1

Aug 6, 2024
CVE-2024-23458
7.3 HIGH

While copying individual autoupdater log files, reparse point check was missing which could result into crafted attacks, potentially leading to a local privilege escalation. This …

Aug 6, 2024
CVE-2024-23456
7.8 HIGH

Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connector <4.2.0.190 with anti-tampering enabled.

Aug 6, 2024
CVE-2024-41913
8.8 HIGH

A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly sanitize User input.

Aug 6, 2024
CVE-2024-41226
7.8 HIGH

A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary code via a crafted payload. NOTE: Automation Anywhere disputes …

Aug 6, 2024
CVE-2024-7530
8.8 HIGH

Incorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129.

Aug 6, 2024
CVE-2024-7528
8.8 HIGH

Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < …

Aug 6, 2024
CVE-2024-7527
8.8 HIGH

Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox …

Aug 6, 2024
CVE-2024-7525
8.1 HIGH

It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body …

Aug 6, 2024
CVE-2024-7523
8.1 HIGH

A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. *This issue …

Aug 6, 2024
CVE-2024-7522
8.8 HIGH

Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < …

Aug 6, 2024
CVE-2024-7521
8.8 HIGH

Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird …

Aug 6, 2024
CVE-2024-7520
8.8 HIGH

A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129, Firefox ESR …

Aug 6, 2024
CVE-2024-43114
7.5 HIGH

In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions

Aug 6, 2024
CVE-2024-33994
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a …

Aug 6, 2024
CVE-2024-33993
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a …

Aug 6, 2024
CVE-2024-33992
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to …

Aug 6, 2024
CVE-2024-33991
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to …

Aug 6, 2024
CVE-2024-33990
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload …

Aug 6, 2024
CVE-2024-33989
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload …

Aug 6, 2024
CVE-2024-33988
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL …

Aug 6, 2024
CVE-2024-33987
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL …

Aug 6, 2024
CVE-2024-33986
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL …

Aug 6, 2024
CVE-2024-33985
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL …

Aug 6, 2024
CVE-2024-33984
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL …

Aug 6, 2024
CVE-2024-33983
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL …

Aug 6, 2024
CVE-2024-33982
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL …

Aug 6, 2024
CVE-2024-33981
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send …

Aug 6, 2024
CVE-2024-33980
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send …

Aug 6, 2024
CVE-2024-33979
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send …

Aug 6, 2024
CVE-2024-33978
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to …

Aug 6, 2024
CVE-2024-33977
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to …

Aug 6, 2024
CVE-2024-33976
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an …

Aug 6, 2024
CVE-2024-33975
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an …

Aug 6, 2024
CVE-2024-41995
7.5 HIGH

Initialization of a resource with an insecure default vulnerability exists in JavaTM Platform Ver.12.89 and earlier. If this vulnerability is exploited, the product may be …

Aug 6, 2024
CVE-2024-6203
8.3 HIGH

HaloITSM versions up to 2.146.1 are affected by a Password Reset Poisoning vulnerability. Poisoned password reset links can be sent to existing HaloITSM users (given …

Aug 6, 2024
CVE-2024-6200
8.0 HIGH

HaloITSM versions up to 2.146.1 are affected by a Stored Cross-Site Scripting (XSS) vulnerability. The injected JavaScript code can execute arbitrary action on behalf of …

Aug 6, 2024
CVE-2024-5709
8.8 HIGH

The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.7 via the 'layout_name' parameter. …

Aug 6, 2024
CVE-2024-7505
7.3 HIGH

A vulnerability, which was classified as critical, was found in itsourcecode Bike Delivery System 1.0. Affected is an unknown function of the file contact_us_action.php. The …

Aug 6, 2024
CVE-2024-6781
7.5 HIGH

Path traversal in Calibre <= 7.14.0 allow unauthenticated attackers to achieve arbitrary file read.

Aug 6, 2024
CVE-2024-7498
7.3 HIGH

A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been classified as critical. Affected is the function login/login2 of the file /admin/login.php …

Aug 6, 2024
CVE-2024-5828
8.6 HIGH

Expression Language Injection vulnerability in Hitachi Tuning Manager on Windows, Linux, Solaris allows Code Injection.This issue affects Hitachi Tuning Manager: before 8.8.7-00.

Aug 6, 2024
CVE-2024-7485
7.2 HIGH

The Traffic Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page' parameter in the 'UserWebStat' AJAX function in all versions up …

Aug 6, 2024
CVE-2024-7484
7.2 HIGH

The CRM Perks Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'handle_uploaded_files' function in versions up …

Aug 6, 2024
CVE-2024-6315
8.8 HIGH

The Blox Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handleUploadFile' function in all …

Aug 6, 2024
CVE-2023-5000
8.8 HIGH

The Horizontal scrolling announcements plugin for WordPress is vulnerable to SQL Injection via the plugin's 'hsas-shortcode' shortcode in versions up to, and including, 2.4 due …

Aug 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.