CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6316
8.8 HIGH

The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and …

Jul 9, 2024
CVE-2024-6310
8.8 HIGH

The Advanced AJAX Page Loader plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 2.7.7. …

Jul 9, 2024
CVE-2024-6309
8.8 HIGH

The Attachment File Icons (AF Icons) plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, …

Jul 9, 2024
CVE-2024-6180
7.2 HIGH

The EventON plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'eventon_import_settings' ajax action in all …

Jul 9, 2024
CVE-2024-6161
8.8 HIGH

The Default Thumbnail Plus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'get_cache_image' function in all …

Jul 9, 2024
CVE-2024-6123
7.2 HIGH

The Bit Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'iconUpload' function in all versions …

Jul 9, 2024
CVE-2024-28750
7.2 HIGH

A remote attacker with high privileges may use a deleting file function to inject OS commands.

Jul 9, 2024
CVE-2024-28749
7.2 HIGH

A remote attacker with high privileges may use a writing file function to inject OS commands.

Jul 9, 2024
CVE-2024-28748
7.2 HIGH

A remote attacker with high privileges may use a reading file function to inject OS commands.

Jul 9, 2024
CVE-2024-5441
8.8 HIGH

The Modern Events Calendar plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_featured_image function in all …

Jul 9, 2024
CVE-2024-6166
8.8 HIGH

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘addons_order’ parameter in all versions …

Jul 9, 2024
CVE-2024-39597
7.2 HIGH

In SAP Commerce, a user can misuse the forgotten password functionality to gain access to a Composable Storefront B2B site for which early login and …

Jul 9, 2024
CVE-2024-39592
7.7 HIGH

Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This allows an attacker to read sensitive …

Jul 9, 2024
CVE-2024-5974
7.2 HIGH

A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges …

Jul 9, 2024
CVE-2024-4944
7.8 HIGH

A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated …

Jul 9, 2024
CVE-2024-5793
8.8 HIGH

The Houzez Theme - Functionality plugin for WordPress is vulnerable to SQL Injection via the ‘currency_code’ parameter in all versions up to, and including, 3.2.2 …

Jul 9, 2024
CVE-2024-5549
8.1 HIGH

A CORS misconfiguration in the stitionai/devika repository allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from …

Jul 9, 2024
CVE-2024-5971
7.5 HIGH

A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the …

Jul 8, 2024
CVE-2024-6227
7.5 HIGH

A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to cause an infinite loop by configuring the remote tracking server to point at itself. This …

Jul 8, 2024
CVE-2024-6409
7.0 HIGH

A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacker does not authenticate within a set …

Jul 8, 2024
CVE-2024-39896
7.5 HIGH

Directus is a real-time API and App dashboard for managing SQL database content. When relying on SSO providers in combination with local authentication it can …

Jul 8, 2024
CVE-2024-6563
7.5 HIGH

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Renesas arm-trusted-firmware allows Local Execution of Code. This vulnerability is associated with program …

Jul 8, 2024
CVE-2024-39202
8.8 HIGH

D-Link DIR-823X firmware - 240126 was discovered to contain a remote command execution (RCE) vulnerability via the dhcpd_startip parameter at /goform/set_lan_settings.

Jul 8, 2024
CVE-2024-31504
7.5 HIGH

Buffer Overflow vulnerability in SILA Embedded Solutions GmbH freemodbus v.2018-09-12 allows a remtoe attacker to cause a denial of service via the LINUXTCP server component.

Jul 8, 2024
CVE-2024-21778
7.2 HIGH

A heap-based buffer overflow vulnerability exists in the configuration file mib_init_value_array functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted .dat file can lead …

Jul 8, 2024
CVE-2023-50383
7.2 HIGH

Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-50382
7.2 HIGH

Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-50381
7.2 HIGH

Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-50330
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa getInfo functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-50244
7.2 HIGH

Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-50243
7.2 HIGH

Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-50240
7.2 HIGH

Two stack-based buffer overflow vulnerabilities exist in the boa set_RadvdInterfaceParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can …

Jul 8, 2024
CVE-2023-50239
7.2 HIGH

Two stack-based buffer overflow vulnerabilities exist in the boa set_RadvdInterfaceParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can …

Jul 8, 2024
CVE-2023-49867
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-49595
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa rollback_control_code functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can …

Jul 8, 2024
CVE-2023-49593
7.2 HIGH

Leftover debug code exists in the boa formSysCmd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A specially crafted network request can lead to arbitrary command execution.

Jul 8, 2024
CVE-2023-49073
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa formFilter functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-48270
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa formDnsv6 functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can …

Jul 8, 2024
CVE-2023-47856
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa set_RadvdPrefixParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can …

Jul 8, 2024
CVE-2023-47677
8.8 HIGH

A cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network request can …

Jul 8, 2024
CVE-2023-45742
7.2 HIGH

An integer overflow vulnerability exists in the boa updateConfigIntoFlash functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead …

Jul 8, 2024
CVE-2023-45215
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa setRepeaterSsid functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can …

Jul 8, 2024
CVE-2023-41251
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa formRoute functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-34435
7.2 HIGH

A firmware update vulnerability exists in the boa formUpload functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network packets can lead to arbitrary …

Jul 8, 2024
CVE-2024-39742
8.1 HIGH

IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configurations due to a partial string comparison …

Jul 8, 2024
CVE-2024-37999
7.8 HIGH

A vulnerability has been identified in Medicalis Workflow Orchestrator (All versions). The affected application executes as a trusted account with high privileges and network access. …

Jul 8, 2024
CVE-2024-27459
7.8 HIGH

The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary …

Jul 8, 2024
CVE-2024-24974
7.5 HIGH

The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with …

Jul 8, 2024
CVE-2024-38330
7.0 HIGH

IBM System Management for i 7.2, 7.3, and 7.4 could allow a local user to gain elevated privileges due to an unqualified library program call. …

Jul 8, 2024
CVE-2024-3651
7.5 HIGH

A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting version 3.6. The issue arises from the function's handling of crafted …

Jul 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.