CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7470
6.3 MEDIUM

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been rated as critical. This issue affects the function sslvpn_config_mod of …

Aug 5, 2024
CVE-2024-7469
6.3 MEDIUM

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been declared as critical. This vulnerability affects the function sslvpn_config_mod of …

Aug 5, 2024
CVE-2024-7468
6.3 MEDIUM

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been classified as critical. This affects the function sslvpn_config_mod of the …

Aug 5, 2024
CVE-2024-7467
6.3 MEDIUM

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90 and classified as critical. Affected by this issue is the function sslvpn_config_mod of …

Aug 5, 2024
CVE-2024-7464
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in TOTOLINK CP900 6.3c.566. This issue affects the function setTelnetCfg of the component Telnet Service. …

Aug 5, 2024
CVE-2024-7460
4.3 MEDIUM

A vulnerability was found in OSWAPP Warehouse Inventory System 1.0/2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Aug 4, 2024
CVE-2024-7459
4.3 MEDIUM

A vulnerability was found in OSWAPP Warehouse Inventory System 1.0/2.0. It has been classified as problematic. Affected is an unknown function of the file /edit_account.php. …

Aug 4, 2024
CVE-2024-7458
5.5 MEDIUM

A vulnerability was found in elunez eladmin up to 2.7 and classified as critical. This issue affects some unknown processing of the file /api/deploy/upload /api/database/upload …

Aug 4, 2024
CVE-2024-35143
6.7 MEDIUM

IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it …

Aug 4, 2024
CVE-2024-7455
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System 1.0. This affects an unknown part of the file partedit.php. The …

Aug 4, 2024
CVE-2024-7454
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Clinics Patient Management System 1.0. Affected by this issue is the function patient_name …

Aug 4, 2024
CVE-2024-7452
6.3 MEDIUM

A vulnerability was found in itsourcecode Placement Management System 1.0. It has been classified as critical. This affects an unknown part of the file view_company.php. …

Aug 4, 2024
CVE-2024-7451
6.3 MEDIUM

A vulnerability was found in itsourcecode Placement Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Aug 4, 2024
CVE-2024-7450
6.3 MEDIUM

A vulnerability has been found in itsourcecode Placement Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Aug 4, 2024
CVE-2024-7446
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Ticket Reservation System 1.0. This affects an unknown part of the file list_tickets.php. The …

Aug 3, 2024
CVE-2024-7445
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in itsourcecode Ticket Reservation System 1.0. Affected by this issue is some unknown functionality of …

Aug 3, 2024
CVE-2024-7443
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Vivotek IB8367A VVTK-0100b. Affected is the function getenv of the file …

Aug 3, 2024
CVE-2024-7442
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek SD9364 VVTK-0103f. It has been rated as critical. This issue affects the function getenv …

Aug 3, 2024
CVE-2024-7440
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek CC8160 VVTK-0100d. It has been classified as critical. This affects the function getenv of …

Aug 3, 2024
CVE-2024-7438
4.3 MEDIUM

A vulnerability has been found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php?action=profile;u=2;area=showalerts;do=read …

Aug 3, 2024
CVE-2024-37286
5.7 MEDIUM

APM server logs contain document body from a partially failed bulk index request. For example, in case of unavailable_shards_exception for a specific document, since the …

Aug 3, 2024
CVE-2024-7437
5.4 MEDIUM

A vulnerability, which was classified as critical, was found in SimpleMachines SMF 2.1.4. Affected is an unknown function of the file /index.php?action=profile;u=2;area=showalerts;do=remove of the component …

Aug 3, 2024
CVE-2024-7436
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in D-Link DI-8100 16.07. This issue affects the function msp_info_htm of the file msp_info.htm. The …

Aug 3, 2024
CVE-2024-38321
5.3 MEDIUM

IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2, and 24.0.0 stores potentially sensitive information in log files under certain situations that could be read by an …

Aug 3, 2024
CVE-2024-6872
4.3 MEDIUM

The Build Your Dream Website Fast with 400+ Starter Templates and Landing Pages, No Coding Needed, One-Click Import for Elementor & Gutenberg Blocks! – TemplateSpare …

Aug 3, 2024
CVE-2024-6709
4.3 MEDIUM

The Sync Post With Other Site plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sps_add_update_post' …

Aug 3, 2024
CVE-2024-7356
6.4 MEDIUM

The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘filename’ parameter in all versions up to, and including, 3.3.100 …

Aug 3, 2024
CVE-2024-6390
5.9 MEDIUM

The Quiz and Survey Master (QSM) WordPress plugin before 9.1.0 does not properly sanitise and escape some of its Quizz settings, which could allow high …

Aug 3, 2024
CVE-2024-7319
5.0 MEDIUM

An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature …

Aug 2, 2024
CVE-2024-42349
5.3 MEDIUM

FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.4 and earlier can leak authorized and rejected logins via logs stored directly on the root …

Aug 2, 2024
CVE-2024-38888
6.8 MEDIUM

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform a Password Brute Forcing …

Aug 2, 2024
CVE-2024-33895
6.6 MEDIUM

Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parameters. This is …

Aug 2, 2024
CVE-2024-33893
6.1 MEDIUM

Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to XSS when displaying the logs due to improper …

Aug 2, 2024
CVE-2024-41519
5.4 MEDIUM

Feripro <= v2.2.3 is vulnerable to Cross Site Scripting (XSS) via "/admin/programm/<program_id>/zuordnung/veranstaltungen/<event_id>" through the "school" input field.

Aug 2, 2024
CVE-2024-41517
5.3 MEDIUM

An Incorrect Access Control vulnerability in "/admin/benutzer/institution/rechteverwaltung/uebersicht" in Feripro <= v2.2.3 allows remote attackers to get a list of all users and their corresponding privileges.

Aug 2, 2024
CVE-2024-7323
6.5 MEDIUM

Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input. A remote attacker with regular privilege …

Aug 2, 2024
CVE-2024-7204
6.1 MEDIUM

Ai3 QbiBot does not properly filter user input, allowing unauthenticated remote attackers to insert JavaScript code into the chat box. Once the recipient views the …

Aug 2, 2024
CVE-2024-6704
5.3 MEDIUM

The Comments – wpDiscuz plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 7.6.21. This is due to a …

Aug 2, 2024
CVE-2024-40723
4.3 MEDIUM

The specific API in HWATAIServiSign Windows Version from CHANGING Information Technology does not properly validate the length of server-side inputs. When a user visits a …

Aug 2, 2024
CVE-2024-40722
4.3 MEDIUM

The specific API in TCBServiSign Windows Version from CHANGING Information Technology does does not properly validate the length of server-side input. When a user visits …

Aug 2, 2024
CVE-2024-4643
6.4 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Aug 2, 2024
CVE-2024-40719
6.5 MEDIUM

The encryption strength of the authorization keys in CHANGING Information Technology TCBServiSign Windows Version is insufficient. When a remote attacker tricks a victim into visiting …

Aug 2, 2024
CVE-2024-27182
4.9 MEDIUM

In Apache Linkis <= 1.5.0, Arbitrary file deletion in Basic management services on A user with an administrator account could delete any file accessible by …

Aug 2, 2024
CVE-2024-42460
5.3 MEDIUM

In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because there is a missing check for whether the leading bit of r and …

Aug 2, 2024
CVE-2024-42459
5.3 MEDIUM

In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-valued bytes can be …

Aug 2, 2024
CVE-2024-39396
5.5 MEDIUM

InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Aug 2, 2024
CVE-2024-5595
5.4 MEDIUM

The Essential Blocks WordPress plugin before 4.7.0 does not validate and escape some of its block options before outputting them back in a page/post where …

Aug 2, 2024
CVE-2024-3827
6.4 MEDIUM

The Spectra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block ids in all versions up to, and including, 1.1.4 due to …

Aug 2, 2024
CVE-2024-38482
6.6 MEDIUM

CloudLink, versions 7.1.x and 8.x, contain an Improper check or handling of Exceptional Conditions Vulnerability in Cluster Component. A highly privileged malicious user with remote …

Aug 2, 2024
CVE-2024-7378
6.3 MEDIUM

A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Aug 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.