CVE Database

46624+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9598
8.8 HIGH

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.99.1. …

Oct 25, 2024
CVE-2024-45785
7.5 HIGH

MUSASI version 3 contains an issue with use of client-side authentication. If this vulnerability is exploited, other users' credential and sensitive information may be retrieved.

Oct 25, 2024
CVE-2024-9302
8.1 HIGH

The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to privilege escalation via account takeover in …

Oct 25, 2024
CVE-2024-9235
8.8 HIGH

The Mapster WP Maps plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to an insufficient capability …

Oct 25, 2024
CVE-2024-47801
7.4 HIGH

Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scripting vulnerability. Accessing a crafted URL which points …

Oct 25, 2024
CVE-2024-47549
7.4 HIGH

Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of unintended data to HTTP response headers. Accessing a …

Oct 25, 2024
CVE-2024-47005
8.1 HIGH

Sharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users only, but insufficiently restricted. A non-administrative user …

Oct 25, 2024
CVE-2024-43424
7.5 HIGH

Sharp and Toshiba Tec MFPs improperly process HTTP request headers, resulting in an Out-of-bounds Read vulnerability. Crafted HTTP requests may cause affected products crashed.

Oct 25, 2024
CVE-2024-42420
7.5 HIGH

Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword search input and improper processing of SOAP messages. Crafted …

Oct 25, 2024
CVE-2024-10011
8.1 HIGH

The BuddyPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 14.1.0 via the id parameter. This makes it …

Oct 25, 2024
CVE-2024-10370
7.3 HIGH

A vulnerability was found in Codezips Sales Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Oct 25, 2024
CVE-2024-10369
7.3 HIGH

A vulnerability was found in Codezips Sales Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Oct 25, 2024
CVE-2024-10368
7.3 HIGH

A vulnerability was found in Codezips Sales Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /addstock.php. …

Oct 25, 2024
CVE-2024-10351
8.8 HIGH

A vulnerability was found in Tenda RX9 Pro 22.03.02.20. It has been rated as critical. This issue affects the function sub_424CE0 of the file /goform/setMacFilterCfg …

Oct 25, 2024
CVE-2024-49760
7.1 HIGH

OpenRefine is a free, open source tool for working with messy data. The load-language command expects a `lang` parameter from which it constructs the path …

Oct 24, 2024
CVE-2024-49359
7.5 HIGH

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the …

Oct 24, 2024
CVE-2024-49357
7.5 HIGH

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the …

Oct 24, 2024
CVE-2024-48931
7.5 HIGH

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the …

Oct 24, 2024
CVE-2024-48423
7.8 HIGH

An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp library.

Oct 24, 2024
CVE-2024-48208
8.6 HIGH

pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file.

Oct 24, 2024
CVE-2024-47881
8.1 HIGH

OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extension, …

Oct 24, 2024
CVE-2024-47880
8.1 HIGH

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `export-rows` command can be used in such a …

Oct 24, 2024
CVE-2024-47879
7.6 HIGH

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, lack of cross-site request forgery protection on the `preview-expression` …

Oct 24, 2024
CVE-2024-47878
8.1 HIGH

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `/extension/gdata/authorized` endpoint includes the `state` GET parameter verbatim …

Oct 24, 2024
CVE-2024-45263
8.8 HIGH

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upload interface allows the uploading of arbitrary files …

Oct 24, 2024
CVE-2024-45262
8.8 HIGH

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call method of the …

Oct 24, 2024
CVE-2024-45261
8.0 HIGH

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific user is not …

Oct 24, 2024
CVE-2024-45260
8.0 HIGH

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users who belong to unauthorized groups can invoke any …

Oct 24, 2024
CVE-2024-10327
8.1 HIGH

A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOS ContextExtension feature allowing the …

Oct 24, 2024
CVE-2024-45242
7.8 HIGH

EnGenius ENH1350EXT A8J-ENH1350EXT devices through 3.9.3.2_c1.9.51 allow (blind) OS Command Injection via shell metacharacters to the Ping or Speed Test utility. During the time of …

Oct 24, 2024
CVE-2024-48454
7.2 HIGH

An issue in SourceCodester Purchase Order Management System v1.0 allows a remote attacker to execute arbitrary code via the /admin?page=user component

Oct 24, 2024
CVE-2024-48427
8.8 HIGH

A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter …

Oct 24, 2024
CVE-2024-48142
7.5 HIGH

A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access and exfiltrate all previous and …

Oct 24, 2024
CVE-2024-48141
7.5 HIGH

A prompt injection vulnerability in the chatbox of Zhipu AI CodeGeeX v2.17.0 allows attackers to access and exfiltrate all previous and subsequent chat data between …

Oct 24, 2024
CVE-2024-48140
7.5 HIGH

A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v6.3.0 allows attackers to access and exfiltrate …

Oct 24, 2024
CVE-2024-48139
7.5 HIGH

A prompt injection vulnerability in the chatbox of Blackbox AI v1.3.95 allows attackers to access and exfiltrate all previous and subsequent chat data between the …

Oct 24, 2024
CVE-2024-46998
7.1 HIGH

baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Edit Email Form Settings Feature. Version 5.1.2 fixes …

Oct 24, 2024
CVE-2024-48441
8.8 HIGH

Wuhan Tianyu Information Industry Co., Ltd Tianyu CPE Router CommonCPExCPETS_v3.2.468.11.04_P4 was discovered to contain a command injection vulnerability via the component at_command.asp.

Oct 24, 2024
CVE-2024-48440
8.8 HIGH

Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 was discovered to contain a command injection vulnerability via the component at_command.asp.

Oct 24, 2024
CVE-2024-10313
8.0 HIGH

iniNet Solutions SpiderControl SCADA PC HMI Editor has a path traversal vulnerability. When the software loads a malicious ‘ems' project template file constructed by an …

Oct 24, 2024
CVE-2024-10295
7.5 HIGH

A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A malformed basic …

Oct 24, 2024
CVE-2024-48547
8.4 HIGH

Incorrect access control in the firmware update and download processes of DreamCatcher Life v1.8.7 allows attackers to access sensitive information by analyzing the code and …

Oct 24, 2024
CVE-2024-48546
8.4 HIGH

Incorrect access control in the firmware update and download processes of Wear Sync v1.2.0 allows attackers to access sensitive information by analyzing the code and …

Oct 24, 2024
CVE-2024-48545
8.4 HIGH

Incorrect access control in the firmware update and download processes of IVY Smart v4.5.0 allows attackers to access sensitive information by analyzing the code and …

Oct 24, 2024
CVE-2024-48544
8.4 HIGH

Incorrect access control in the firmware update and download processes of Sylvania Smart Home v3.0.3 allows attackers to access sensitive information by analyzing the code …

Oct 24, 2024
CVE-2024-48542
8.4 HIGH

Incorrect access control in the firmware update and download processes of Yamaha Headphones Controller v1.6.7 allows attackers to access sensitive information by analyzing the code …

Oct 24, 2024
CVE-2024-48541
8.4 HIGH

Incorrect access control in the firmware update and download processes of Ruochan Smart v4.4.7 allows attackers to access sensitive information by analyzing the code and …

Oct 24, 2024
CVE-2024-10336
7.3 HIGH

A vulnerability was found in SourceCodeHero Clothes Recommendation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Oct 24, 2024
CVE-2024-10335
7.3 HIGH

A vulnerability was found in SourceCodester Garbage Collection Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Oct 24, 2024
CVE-2024-5608
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in the technician reports feature.

Oct 24, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.