CVE Database

46795+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8941
7.5 HIGH

Path traversal vulnerability in Scriptcase version 9.4.019, in /scriptcase/devel/compat/nm_edit_php_edit.php (in the “subpage” parameter), which allows unauthenticated remote users to bypass SecurityManager's intended restrictions and list …

Sep 25, 2024
CVE-2024-8914
7.2 HIGH

The Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam plugin for WordPress is vulnerable to …

Sep 25, 2024
CVE-2024-8497
7.5 HIGH

Franklin Fueling Systems TS-550 EVO versions prior to 2.26.4.8967 possess a file that can be read arbitrarily that could allow an attacker obtain administrator credentials.

Sep 25, 2024
CVE-2024-46936
7.5 HIGH

Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and before is vulnerable to a message forgery / impersonation issue. Attackers can abuse the UpdateOTRAck method to …

Sep 25, 2024
CVE-2024-46935
7.5 HIGH

Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers who craft messages with specific characters may crash …

Sep 25, 2024
CVE-2024-46610
7.5 HIGH

An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request …

Sep 25, 2024
CVE-2024-46609
7.5 HIGH

An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and returns all user information, …

Sep 25, 2024
CVE-2024-46607
7.6 HIGH

Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin …

Sep 25, 2024
CVE-2024-45373
8.8 HIGH

Once logged in to ProGauge MAGLINK LX4 CONSOLE, a valid user can change their privileges to administrator.

Sep 25, 2024
CVE-2024-41725
8.8 HIGH

ProGauge MAGLINK LX CONSOLE does not have sufficient filtering on input fields that are used to render pages which may allow cross site scripting.

Sep 25, 2024
CVE-2024-39928
7.5 HIGH

In Apache Linkis <= 1.5.0, a Random string security vulnerability in Spark EngineConn, random string generated by the Token when starting Py4j uses the Commons …

Sep 25, 2024
CVE-2024-21545
8.2 HIGH

Proxmox Virtual Environment is an open-source server management platform for enterprise virtualization. Insufficient safeguards against malicious API response values allow authenticated attackers with 'Sys.Audit' or …

Sep 25, 2024
CVE-2023-26691
7.2 HIGH

Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via crafted zip file when installing a new add-on.

Sep 25, 2024
CVE-2023-26690
8.8 HIGH

File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/Editor component in the vendor or admin menu.

Sep 25, 2024
CVE-2023-26687
8.8 HIGH

Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive information via the product_data parameter in the PDF Add-on.

Sep 25, 2024
CVE-2021-38963
8.0 HIGH

IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. …

Sep 25, 2024
CVE-2024-8623
7.3 HIGH

The The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, …

Sep 24, 2024
CVE-2022-2439
7.2 HIGH

The Easy Digital Downloads – Simple eCommerce for Selling Digital Files plugin for WordPress is vulnerable to deserialization of untrusted input via the 'upload[file]' parameter …

Sep 24, 2024
CVE-2024-8795
8.8 HIGH

The BA Book Everything plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.20. This is due to …

Sep 24, 2024
CVE-2024-7023
8.8 HIGH

Insufficient data validation in Updater in Google Chrome prior to 128.0.6537.0 allowed a remote attacker to perform privilege escalation via a malicious file. (Chromium security …

Sep 23, 2024
CVE-2024-7018
7.8 HIGH

Heap buffer overflow in PDF in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. …

Sep 23, 2024
CVE-2021-38023
8.8 HIGH

Use after free in Extensions in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Sep 23, 2024
CVE-2018-20072
7.8 HIGH

Insufficient data validation in PDF in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform out of bounds memory access via a crafted …

Sep 23, 2024
CVE-2024-42861
7.5 HIGH

An issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted Pdelay_Req message to …

Sep 23, 2024
CVE-2024-46639
7.6 HIGH

A cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Sep 23, 2024
CVE-2024-43201
8.8 HIGH

The Planet Fitness Workouts iOS and Android mobile apps fail to properly validate TLS certificates, allowing an attacker with appropriate network access to obtain session …

Sep 23, 2024
CVE-2024-37779
8.8 HIGH

WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script functionality.

Sep 23, 2024
CVE-2024-39842
7.2 HIGH

A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via user massive changes inputs.

Sep 23, 2024
CVE-2024-40442
7.2 HIGH

An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 …

Sep 23, 2024
CVE-2024-46985
7.5 HIGH

DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, there is an XML external entity injection vulnerability in the static resource …

Sep 23, 2024
CVE-2024-41228
7.6 HIGH

A symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to escalate privileges and write arbitrary files.

Sep 23, 2024
CVE-2024-23934
8.8 HIGH

Sony XAV-AX5500 WMV/ASF Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sony …

Sep 23, 2024
CVE-2024-8606
8.8 HIGH

Bypass of two factor authentication in RestAPI in Checkmk < 2.3.0p16 and < 2.2.0p34 allows authenticated users to bypass two factor authentication

Sep 23, 2024
CVE-2024-9091
7.3 HIGH

A vulnerability was found in code-projects Student Record System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Sep 23, 2024
CVE-2024-43989
7.5 HIGH

Server-Side Request Forgery (SSRF) vulnerability in Firsh Justified Image Grid justified-image-grid.This issue affects Justified Image Grid: from n/a through <= 4.6.1.

Sep 23, 2024
CVE-2024-9087
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Vehicle Management 1.0. This affects an unknown part of the file /edit1.php. The manipulation …

Sep 22, 2024
CVE-2024-9085
7.3 HIGH

A vulnerability was found in code-projects Restaurant Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Sep 22, 2024
CVE-2024-9080
7.3 HIGH

A vulnerability was found in code-projects Student Record System 1.0. It has been classified as critical. Affected is an unknown function of the file /pincode-verification.php. …

Sep 22, 2024
CVE-2024-9079
7.3 HIGH

A vulnerability was found in code-projects Student Record System 1.0 and classified as critical. This issue affects some unknown processing of the file /marks.php. The …

Sep 22, 2024
CVE-2024-9078
7.3 HIGH

A vulnerability has been found in code-projects Student Record System 1.0 and classified as critical. This vulnerability affects unknown code of the file /course.php. The …

Sep 22, 2024
CVE-2024-47221
7.5 HIGH

CheckUser in ScadaServerEngine/MainLogic.cs in Rapid SCADA through 5.8.4 allows an empty password.

Sep 22, 2024
CVE-2024-47210
8.8 HIGH

Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be used in updateMySelf in server/api/controllers/user.controller.js.

Sep 21, 2024
CVE-2024-42323
8.8 HIGH

SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating). This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat …

Sep 21, 2024
CVE-2024-46649
7.5 HIGH

eNMS up to 4.7.1 is vulnerable to Directory Traversal via download/folder.

Sep 20, 2024
CVE-2024-46648
7.5 HIGH

eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via scan_folder.

Sep 20, 2024
CVE-2024-46645
7.5 HIGH

eNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files.

Sep 20, 2024
CVE-2024-47062
8.8 HIGH

Navidrome is an open source web-based music collection server and streamer. Navidrome automatically adds parameters in the URL to SQL queries. This can be exploited …

Sep 20, 2024
CVE-2024-47061
8.3 HIGH

Plate is a javascript toolkit that makes it easier for you to develop with Slate, a popular framework for building text editors. One longstanding feature …

Sep 20, 2024
CVE-2024-42346
7.6 HIGH

Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. The editor visualization, /visualizations endpoint, …

Sep 20, 2024
CVE-2023-47480
8.4 HIGH

An issue in Pure Data 0.54-0 and fixed in 0.54-1 allows a local attacker to escalate privileges via the set*id () function.

Sep 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.