CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-27731
6.1 MEDIUM

Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the lack of file type filtering in the file …

Aug 15, 2024
CVE-2024-27729
6.1 MEDIUM

Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the location parameter of the calendar event feature.

Aug 15, 2024
CVE-2024-27728
6.1 MEDIUM

Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the text parameter of the babel debug feature.

Aug 15, 2024
CVE-2024-25633
5.4 MEDIUM

eLabFTW is an open source electronic lab notebook for research labs. In an eLabFTW system, one can configure who is allowed to create new user …

Aug 15, 2024
CVE-2024-32231
6.3 MEDIUM

Stash up to v0.25.1 was discovered to contain a SQL injection vulnerability via the sort parameter.

Aug 15, 2024
CVE-2024-22219
6.3 MEDIUM

XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows authenticated users to submit malicious XML via …

Aug 15, 2024
CVE-2024-22217
6.5 MEDIUM

A Server-Side Request Forgery (SSRF) vulnerability in Terminalfour before 8.3.19 allows authenticated users to use specific features to access internal services including sensitive information on …

Aug 15, 2024
CVE-2024-40705
6.5 MEDIUM

IBM InfoSphere Information Server could allow an authenticated user to consume file space resources due to unrestricted file uploads. IBM X-Force ID: 298279.

Aug 15, 2024
CVE-2024-40704
4.9 MEDIUM

IBM InfoSphere Information Server 11.7 could allow a privileged user to obtain sensitive information from authentication request headers. IBM X-Force ID: 298277.

Aug 15, 2024
CVE-2024-31905
5.9 MEDIUM

IBM QRadar Network Packet Capture 7.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport …

Aug 15, 2024
CVE-2024-31800
6.8 MEDIUM

Authentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privileged command shell via the UART Debugging …

Aug 15, 2024
CVE-2024-31799
4.6 MEDIUM

Information Disclosure in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to read the WiFi passphrase via the UART Debugging Port.

Aug 15, 2024
CVE-2024-31798
6.8 MEDIUM

Identical Hardcoded Root Password for All Devices in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to retrieve the root password …

Aug 15, 2024
CVE-2024-6347
6.5 MEDIUM

* Unprotected privileged mode access through UDS session in the Blind Spot Detection Sensor ECU firmware in Nissan Altima (2022) allows attackers to trigger denial-of-service …

Aug 15, 2024
CVE-2024-7833
6.3 MEDIUM

A vulnerability was found in D-Link DI-8100 16.07. It has been classified as critical. This affects the function upgrade_filter_asp of the file upgrade_filter.asp. The manipulation …

Aug 15, 2024
CVE-2024-42680
5.5 MEDIUM

An issue in Super easy enterprise management system v.1.0.0 and before allows a local attacker to obtain the server absolute path by entering a single …

Aug 15, 2024
CVE-2024-42678
6.1 MEDIUM

Cross Site Scripting vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker to execute arbitrary code via a crafted script …

Aug 15, 2024
CVE-2024-42677
5.5 MEDIUM

An issue in Huizhi enterprise resource management system v.1.0 and before allows a local attacker to obtain sensitive information via the /nssys/common/filehandle. Aspx component

Aug 15, 2024
CVE-2024-7411
5.3 MEDIUM

The Newsletters plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 4.9.9. This is due the plugin not …

Aug 15, 2024
CVE-2024-7064
6.4 MEDIUM

The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 3.6.5 due to …

Aug 15, 2024
CVE-2024-7063
4.3 MEDIUM

The ElementsKit Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.6 via the 'render_raw' function. This …

Aug 15, 2024
CVE-2024-6534
4.3 MEDIUM

Directus v10.13.0 allows an authenticated external attacker to modify presets created by the same user to assign them to another user. This is possible because …

Aug 15, 2024
CVE-2024-7813
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in SourceCodester Prison Management System 1.0. This issue affects some unknown processing of the file …

Aug 15, 2024
CVE-2024-7811
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Daily Expenses Monitoring App 1.0. This affects an unknown part of the file /endpoint/delete-expense.php. The …

Aug 15, 2024
CVE-2024-7420
5.8 MEDIUM

The Insert PHP Code Snippet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.6. This is due …

Aug 15, 2024
CVE-2024-6533
5.4 MEDIUM

Directus v10.13.0 allows an authenticated external attacker to execute arbitrary JavaScript on the client. This is possible because the application injects an attacker-controlled parameter that …

Aug 15, 2024
CVE-2024-25024
5.5 MEDIUM

IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores user credentials in plain clear text which can …

Aug 15, 2024
CVE-2024-7810
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Aug 15, 2024
CVE-2024-7809
5.3 MEDIUM

A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality …

Aug 15, 2024
CVE-2024-7800
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Simple Online Bidding System 1.0. This affects an unknown part of the file /simple-online-bidding-system/bidding/admin/ajax.php?action=delete_product. The …

Aug 15, 2024
CVE-2024-7799
5.3 MEDIUM

A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Aug 15, 2024
CVE-2024-7625
5.8 MEDIUM

In HashiCorp Nomad and Nomad Enterprise from 0.6.1 up to 1.6.13, 1.7.10, and 1.8.2, the archive unpacking process is vulnerable to writes outside the allocation …

Aug 15, 2024
CVE-2024-43368
6.5 MEDIUM

The Trix editor, versions prior to 2.1.4, is vulnerable to XSS when pasting malicious code. This vulnerability is a bypass of the fix put in …

Aug 14, 2024
CVE-2024-7794
6.3 MEDIUM

A vulnerability was found in itsourcecode Vehicle Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Aug 14, 2024
CVE-2024-42353
6.1 MEDIUM

WebOb provides objects for HTTP requests and responses. When WebOb normalizes the HTTP Location header to include the request hostname, it does so by parsing …

Aug 14, 2024
CVE-2024-7507
6.5 MEDIUM

CVE-2024-7507 IMPACT A denial-of-service vulnerability exists in the affected products. This vulnerability occurs when a malformed PCCC message is received, causing a fault in the …

Aug 14, 2024
CVE-2024-7792
6.3 MEDIUM

A vulnerability was found in SourceCodester Task Progress Tracker 1.0. It has been classified as critical. Affected is an unknown function of the file /endpoint/delete-task.php. …

Aug 14, 2024
CVE-2024-37529
6.5 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 could allow an authenticated user to cause a denial of service …

Aug 14, 2024
CVE-2024-35152
6.5 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to cause a denial of service with a …

Aug 14, 2024
CVE-2024-35136
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) federated server 10.5, 11.1, and 11.5 is vulnerable to denial of service with a …

Aug 14, 2024
CVE-2024-31882
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service, under specific non default …

Aug 14, 2024
CVE-2023-50314
5.3 MEDIUM

IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.8 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit …

Aug 14, 2024
CVE-2024-5916
4.4 MEDIUM

An information exposure vulnerability in Palo Alto Networks PAN-OS software enables a local system administrator to unintentionally disclose secrets, passwords, and tokens of external systems. …

Aug 14, 2024
CVE-2024-42441
6.2 MEDIUM

Incorrect privilege assignment in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before …

Aug 14, 2024
CVE-2024-42440
6.2 MEDIUM

Improper privilege management in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before …

Aug 14, 2024
CVE-2024-42439
6.5 MEDIUM

Untrusted search path in the installer for Zoom Workplace Desktop App for macOS and Zoom Meeting SDK for macOS before 6.1.0 may allow a privileged …

Aug 14, 2024
CVE-2024-42438
6.5 MEDIUM

Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via …

Aug 14, 2024
CVE-2024-42437
6.5 MEDIUM

Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via …

Aug 14, 2024
CVE-2024-42436
6.5 MEDIUM

Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via …

Aug 14, 2024
CVE-2024-42435
4.9 MEDIUM

Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via …

Aug 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.