CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-41844
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Aug 23, 2024
CVE-2024-41843
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Aug 23, 2024
CVE-2024-41842
4.8 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Aug 23, 2024
CVE-2024-41841
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim …

Aug 23, 2024
CVE-2024-43032
4.3 MEDIUM

autMan v2.9.6 allows attackers to bypass authentication via a crafted web request.

Aug 23, 2024
CVE-2024-43031
4.3 MEDIUM

autMan v2.9.6 was discovered to contain an access control issue.

Aug 23, 2024
CVE-2024-42364
6.5 MEDIUM

Homepage is a highly customizable homepage with Docker and service API integrations. The default setup of homepage 0.9.1 is vulnerable to DNS rebinding. Homepage is …

Aug 23, 2024
CVE-2024-8113
5.4 MEDIUM

Stored XSS in organizer and event settings of pretix up to 2024.7.0 allows malicious event organizers to inject HTML tags into e-mail previews on settings …

Aug 23, 2024
CVE-2024-8112
4.3 MEDIUM

A vulnerability was found in thinkgem JeeSite 5.3. It has been rated as problematic. This issue affects some unknown processing of the file /js/a/login of …

Aug 23, 2024
CVE-2024-42766
5.4 MEDIUM

Kashipara Bus Ticket Reservation System v1.0 0 is vulnerable to Incorrect Access Control via /deleteTicket.php.

Aug 23, 2024
CVE-2024-41150
6.3 MEDIUM

An Stored Cross-site Scripting vulnerability in request module affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus.This issue affects ServiceDesk Plus versions: through …

Aug 23, 2024
CVE-2024-5502
6.4 MEDIUM

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion, Dual Heading, and Vertical Timeline widgets …

Aug 23, 2024
CVE-2024-38807
6.3 MEDIUM

Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where …

Aug 23, 2024
CVE-2024-43105
4.3 MEDIUM

Mattermost Plugin Channel Export versions <=1.0.0 fail to restrict concurrent runs of the /export command which allows a user to consume excessive resource by running …

Aug 23, 2024
CVE-2024-6715
6.1 MEDIUM

The Ditty WordPress plugin before 3.1.46 re-introduced a previously fixed security issue (https://wpscan.com/vulnerability/80a9eb3a-2cb1-4844-9004-ba2554b2d46c/) in v3.1.39

Aug 23, 2024
CVE-2024-3282
4.8 MEDIUM

The WP Table Builder WordPress plugin through 1.5.0 does not sanitise and escape some of its Table data, which could allow high privilege users such …

Aug 23, 2024
CVE-2024-8089
6.3 MEDIUM

A vulnerability was found in SourceCodester E-Commerce System 1.0. It has been classified as critical. Affected is an unknown function of the file /ecommerce/admin/products/controller.php. The …

Aug 23, 2024
CVE-2024-8087
6.3 MEDIUM

A vulnerability was found in SourceCodester E-Commerce System 1.0 and classified as critical. This issue affects some unknown processing of the file /ecommerce/popup_Item.php. The manipulation …

Aug 22, 2024
CVE-2024-38208
6.1 MEDIUM

Microsoft Edge for Android Spoofing Vulnerability

Aug 22, 2024
CVE-2024-8083
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this issue is some unknown …

Aug 22, 2024
CVE-2024-43790
4.5 MEDIUM

Vim is an open source command line text editor. When performing a search and displaying the search-count message is disabled (:set shm+=S), the search pattern …

Aug 22, 2024
CVE-2024-8080
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Online Health Care System 1.0. Affected is an unknown function of the file search.php. The …

Aug 22, 2024
CVE-2024-42763
5.4 MEDIUM

A Reflected Cross Site Scripting (XSS) vulnerability was found in the "/schedule.php" page of the Kashipara Bus Ticket Reservation System v1.0, which allows remote attackers …

Aug 22, 2024
CVE-2024-42762
5.4 MEDIUM

A Stored Cross Site Scripting (XSS) vulnerability was found in "/history.php" in Kashipara Bus Ticket Reservation System v1.0, which allows remote attackers to execute arbitrary …

Aug 22, 2024
CVE-2024-42761
6.1 MEDIUM

A Stored Cross Site Scripting (XSS) vulnerability was found in "/admin_schedule.php" in Kashipara Bus Ticket Reservation System v1.0, which allows remote attackers to execute arbitrary …

Aug 22, 2024
CVE-2024-8077
6.3 MEDIUM

A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been classified as critical. This affects the function setTracerouteCfg. The manipulation leads to os …

Aug 22, 2024
CVE-2024-8075
6.3 MEDIUM

A vulnerability has been found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228 and classified as critical. Affected by this vulnerability is the function setDiagnosisCfg. The manipulation leads …

Aug 22, 2024
CVE-2024-7634
4.9 MEDIUM

NGINX Agent's "config_dirs" restriction feature allows a highly privileged attacker to gain the ability to write/overwrite files outside of the designated secure directory.

Aug 22, 2024
CVE-2024-42768
6.8 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Hotel Management System v1.0 via /admin/delete_room.php.

Aug 22, 2024
CVE-2024-8041
6.5 MEDIUM

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior …

Aug 22, 2024
CVE-2024-7110
6.4 MEDIUM

An issue was discovered in GitLab EE affecting all versions starting 17.0 to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1 allows an …

Aug 22, 2024
CVE-2024-6502
5.7 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.2 prior to 17.1.6 starting from 17.2 prior to 17.2.4, and starting from …

Aug 22, 2024
CVE-2024-45193
4.3 MEDIUM

An issue was discovered in Matrix libolm through 3.2.16. There is Ed25519 signature malleability due to lack of validation criteria (does not ensure that S …

Aug 22, 2024
CVE-2024-45192
5.3 MEDIUM

An issue was discovered in Matrix libolm through 3.2.16. Cache-timing attacks can occur due to use of base64 when decoding group session keys. This refers …

Aug 22, 2024
CVE-2024-45191
5.3 MEDIUM

An issue was discovered in Matrix libolm through 3.2.16. The AES implementation is vulnerable to cache-timing attacks due to use of S-boxes. This is related …

Aug 22, 2024
CVE-2024-43780
4.3 MEDIUM

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissions which allows a guest user with read access to …

Aug 22, 2024
CVE-2024-42771
4.8 MEDIUM

A Stored Cross Site Scripting (XSS) vulnerability was found in " /admin/edit_room_controller.php" of the Kashipara Hotel Management System v1.0, which allows remote attackers to execute …

Aug 22, 2024
CVE-2024-42770
4.7 MEDIUM

A Stored Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php" of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code …

Aug 22, 2024
CVE-2024-42769
6.1 MEDIUM

A Reflected Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php " of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary …

Aug 22, 2024
CVE-2024-42497
6.0 MEDIUM

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to properly enforce permissions which allows a user with systems …

Aug 22, 2024
CVE-2024-3127
4.3 MEDIUM

An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting from 17.2 before 17.2.4, all versions …

Aug 22, 2024
CVE-2024-36441
5.4 MEDIUM

Swissphone DiCal-RED 4009 devices allow an unauthenticated attacker use a port-2101 TCP connection to gain access to operation messages that are received by the device.

Aug 22, 2024
CVE-2024-43787
5.0 MEDIUM

Hono is a Web application framework that provides support for any JavaScript runtime. Hono CSRF middleware can be bypassed using crafted Content-Type header. MIME types …

Aug 22, 2024
CVE-2024-43398
5.9 MEDIUM

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep …

Aug 22, 2024
CVE-2024-36440
6.8 MEDIUM

An issue was discovered on Swissphone DiCal-RED 4009 devices. An attacker with access to the file /etc/deviceconfig may recover the administrative device password via password-cracking …

Aug 22, 2024
CVE-2024-43331
5.3 MEDIUM

Missing Authorization vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.9.3.

Aug 22, 2024
CVE-2024-7848
4.3 MEDIUM

The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and …

Aug 22, 2024
CVE-2024-39746
5.9 MEDIUM

IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly …

Aug 22, 2024
CVE-2024-39745
5.9 MEDIUM

IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive …

Aug 22, 2024
CVE-2024-39744
4.3 MEDIUM

IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and …

Aug 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.