CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7745
6.5 MEDIUM

In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to skip the second-factor …

Aug 28, 2024
CVE-2024-7744
6.5 MEDIUM

In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Web Transfer Module …

Aug 28, 2024
CVE-2024-6053
4.3 MEDIUM

Improper access control in the clipboard synchronization feature in TeamViewer Full Client prior version 15.57 and TeamViewer Meeting prior version 15.55.3 can lead to unintentional …

Aug 28, 2024
CVE-2024-41565
4.3 MEDIUM

JustEnoughItems (JEI) 19.5.0.33 and before contains an Improper Validation of Specified Index, Position, or Offset in Input vulnerability. The specific issue is a failure to …

Aug 28, 2024
CVE-2024-41564
4.3 MEDIUM

EMI v.1.1.10 and before, fixed in v.1.1.11, contains an Improper Validation of Specified Index, Position, or Offset in Input vulnerability. The specific issue is a …

Aug 28, 2024
CVE-2024-20478
6.5 MEDIUM

A vulnerability in the software upgrade component of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an …

Aug 28, 2024
CVE-2024-20413
6.7 MEDIUM

A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to elevate privileges to network-admin on …

Aug 28, 2024
CVE-2024-20411
6.7 MEDIUM

A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to execute arbitrary code as root on …

Aug 28, 2024
CVE-2024-20289
4.4 MEDIUM

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to execute arbitrary commands on the underlying operating system …

Aug 28, 2024
CVE-2024-20286
5.3 MEDIUM

A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized …

Aug 28, 2024
CVE-2024-20285
5.3 MEDIUM

A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized …

Aug 28, 2024
CVE-2024-20284
5.3 MEDIUM

A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized …

Aug 28, 2024
CVE-2024-20279
4.3 MEDIUM

A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to modify the behavior …

Aug 28, 2024
CVE-2024-42900
6.1 MEDIUM

Ruoyi v4.7.9 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the sql parameter of the createTable() function at /tool/gen/create.

Aug 28, 2024
CVE-2024-42698
4.3 MEDIUM

Roughly Enough Items (REI) v.16.0.729 and before contains an Improper Validation of Specified Index, Position, or Offset in Input vulnerability. The specific issue is a …

Aug 28, 2024
CVE-2024-8195
5.3 MEDIUM

The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'debug_data', 'debug_query', and …

Aug 28, 2024
CVE-2024-7447
5.3 MEDIUM

The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification …

Aug 28, 2024
CVE-2024-6450
6.1 MEDIUM

HyperView Geoportal Toolkit in versions lower than 8.5.0 is vulnerable to Reflected Cross-Site Scripting (XSS). An unauthenticated attacker might trick somebody into using a crafted …

Aug 28, 2024
CVE-2024-6449
6.5 MEDIUM

HyperView Geoportal Toolkit in versions lower than 8.5.0 does not restrict cross-domain requests when fetching remote content pointed by one of GET request parameters. An …

Aug 28, 2024
CVE-2024-7269
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation vulnerability in "Update of Personal Details" form in ConnX ESP HR Management allows Stored XSS attack. An …

Aug 28, 2024
CVE-2024-44943
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm: gup: stop abusing try_grab_folio A kernel warning was reported when pinning folio in CMA …

Aug 28, 2024
CVE-2023-26321
6.3 MEDIUM

A path traversal vulnerability exists in the Xiaomi File Manager application product(international version). The vulnerability is caused by unfiltered special characters and can be exploited …

Aug 28, 2024
CVE-2024-6312
6.5 MEDIUM

The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 3.7.3.2 via the 'af2DeleteFontFile' function. This …

Aug 28, 2024
CVE-2024-4556
5.7 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText NetIQ Access Manager allows access the sensitive information. This issue affects …

Aug 28, 2024
CVE-2021-38122
6.2 MEDIUM

A Cross-Site Scripting vulnerable identified in NetIQ Advance Authentication that impacts the server functionality and disclose sensitive information. This issue affects NetIQ Advance Authentication before …

Aug 28, 2024
CVE-2021-38120
5.1 MEDIUM

A vulnerability identified in Advance Authentication that allows bash command Injection in administrative controlled functionality of backup due to improper handling in provided command parameters. …

Aug 28, 2024
CVE-2021-22529
6.3 MEDIUM

A vulnerability identified in NetIQ Advance Authentication that leaks sensitive server information. This issue affects NetIQ Advance Authentication version before 6.3.5.1

Aug 28, 2024
CVE-2024-39771
6.8 MEDIUM

QBiC CLOUD CC-2L v1.1.30 and earlier and Safie One v1.8.2 and earlier do not properly validate certificates, which may allow a network-adjacent unauthenticated attacker to …

Aug 28, 2024
CVE-2023-43078
6.7 MEDIUM

Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege …

Aug 28, 2024
CVE-2024-6448
5.3 MEDIUM

The Mollie Payments for WooCommerce plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 7.7.0. This is due to …

Aug 28, 2024
CVE-2024-7573
5.3 MEDIUM

The Relevanssi Live Ajax Search plugin for WordPress is vulnerable to argument injection in all versions up to, and including, 2.4. This is due to …

Aug 28, 2024
CVE-2024-8223
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Music Gallery Site 1.0. This vulnerability affects unknown code of the file /classes/Master.php?f=delete_category. The manipulation of …

Aug 27, 2024
CVE-2024-8222
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Music Gallery Site 1.0. This affects an unknown part of the file /admin/?page=musics/manage_music. The manipulation …

Aug 27, 2024
CVE-2024-8221
6.3 MEDIUM

A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Aug 27, 2024
CVE-2024-8220
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Aug 27, 2024
CVE-2024-8216
5.4 MEDIUM

A vulnerability, which was classified as critical, has been found in nafisulbari/itsourcecode Insurance Management System 1.0. Affected by this issue is some unknown functionality of …

Aug 27, 2024
CVE-2024-8214
6.3 MEDIUM

A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, …

Aug 27, 2024
CVE-2024-8213
6.3 MEDIUM

A vulnerability classified as critical has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, …

Aug 27, 2024
CVE-2024-8212
6.3 MEDIUM

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 …

Aug 27, 2024
CVE-2024-8211
6.3 MEDIUM

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 …

Aug 27, 2024
CVE-2024-8210
6.3 MEDIUM

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 …

Aug 27, 2024
CVE-2024-5814
5.3 MEDIUM

A malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ciphersuite that it did not agree to and achieve a …

Aug 27, 2024
CVE-2024-5288
5.1 MEDIUM

An issue was discovered in wolfSSL before 5.7.0. A safe-error attack via Rowhammer, namely FAULT+PROBE, leads to ECDSA key disclosure. When WOLFSSL_CHECK_SIG_FAULTS is used in …

Aug 27, 2024
CVE-2024-45037
6.4 MEDIUM

The AWS Cloud Development Kit (CDK) is an open-source framework for defining cloud infrastructure using code. Customers use it to create their own applications which …

Aug 27, 2024
CVE-2024-1544
4.1 MEDIUM

Generating the ECDSA nonce k samples a random number r and then truncates this randomness with a modular reduction mod n where n is the …

Aug 27, 2024
CVE-2022-39996
4.8 MEDIUM

Cross Site Scripting vulnerability in Teldats Router RS123, RS123w allows attacker to execute arbitrary code via the cmdcookie parameter to the upgrade/query.php page.

Aug 27, 2024
CVE-2024-43788
6.4 MEDIUM

Webpack is a module bundler. Its main purpose is to bundle JavaScript files for usage in a browser, yet it is also capable of transforming, …

Aug 27, 2024
CVE-2024-8200
4.3 MEDIUM

The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to Cross-Site Request Forgery …

Aug 27, 2024
CVE-2024-8199
4.3 MEDIUM

The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to unauthorized modification of …

Aug 27, 2024
CVE-2024-40395
6.5 MEDIUM

An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, including PII, regardless of access level.

Aug 27, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.