CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-41019
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Validate ff offset This adds sanity checks for ff offset. There is a check …

Jul 29, 2024
CVE-2024-41018
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add a check for attr_names and oatbl Added out-of-bound checking for *ane (ATTR_NAME_ENTRY).

Jul 29, 2024
CVE-2024-41017
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: jfs: don't walk off the end of ealist Add a check before visiting the members …

Jul 29, 2024
CVE-2024-41016
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ocfs2: strict bound check before memcmp in ocfs2_xattr_find_entry() xattr in ocfs2 maybe 'non-indexed', which saved …

Jul 29, 2024
CVE-2024-41015
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ocfs2: add bounds checking to ocfs2_check_dir_entry() This adds sanity checks for ocfs2_dir_entry to make sure …

Jul 29, 2024
CVE-2024-6487
5.9 MEDIUM

The Inline Related Posts WordPress plugin before 3.8.0 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jul 29, 2024
CVE-2024-6362
4.6 MEDIUM

The Ultimate Blocks WordPress plugin before 3.2.0 does not validate and escape some of its post-grid block attributes before outputting them back in a page/post …

Jul 29, 2024
CVE-2024-5883
4.7 MEDIUM

The Ultimate Classified Listings WordPress plugin before 1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jul 29, 2024
CVE-2024-5285
5.5 MEDIUM

The wp-affiliate-platform WordPress plugin before 6.5.2 does not have CSRF check in place when deleting affiliates, which could allow attackers to make a logged in …

Jul 29, 2024
CVE-2024-4483
5.4 MEDIUM

The Email Encoder WordPress plugin before 2.2.2 does not escape the WP_Email_Encoder_Bundle_options[protection_text] parameter before outputting it back in an attribute in an admin page, leading …

Jul 29, 2024
CVE-2024-7181
6.3 MEDIUM

A vulnerability classified as critical was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. This vulnerability affects the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Jul 29, 2024
CVE-2024-7175
6.3 MEDIUM

A vulnerability has been found in TOTOLINK A3600R 4.1.2cu.5182_B20201102 and classified as critical. This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. The manipulation …

Jul 29, 2024
CVE-2024-7171
6.3 MEDIUM

A vulnerability classified as critical has been found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. Affected is the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Jul 28, 2024
CVE-2024-7169
4.3 MEDIUM

A vulnerability classified as problematic has been found in SourceCodester School Fees Payment System 1.0. This affects an unknown part of the file /ajax.php. The …

Jul 28, 2024
CVE-2024-7168
6.3 MEDIUM

A vulnerability was found in SourceCodester School Fees Payment System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Jul 28, 2024
CVE-2024-7167
6.3 MEDIUM

A vulnerability was found in SourceCodester School Fees Payment System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Jul 28, 2024
CVE-2024-7166
6.3 MEDIUM

A vulnerability was found in SourceCodester School Fees Payment System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Jul 28, 2024
CVE-2024-7165
6.3 MEDIUM

A vulnerability was found in SourceCodester School Fees Payment System 1.0 and classified as critical. This issue affects some unknown processing of the file /view_payment.php. …

Jul 28, 2024
CVE-2024-7161
4.3 MEDIUM

A vulnerability classified as problematic was found in SeaCMS 13.0. Affected by this vulnerability is an unknown functionality of the file /member.php?action=chgpwdsubmit of the component …

Jul 28, 2024
CVE-2024-7160
6.3 MEDIUM

A vulnerability classified as critical has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is the function setWanCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Jul 28, 2024
CVE-2024-7159
5.5 MEDIUM

A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. It has been rated as critical. This issue affects some unknown processing of the file /web_cste/cgi-bin/product.ini of …

Jul 28, 2024
CVE-2024-7158
6.3 MEDIUM

A vulnerability was found in TOTOLINK A3100R 4.1.2cu.5050_B20200504. It has been declared as critical. This vulnerability affects the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi of …

Jul 28, 2024
CVE-2024-7156
5.3 MEDIUM

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as problematic. Affected by this issue is some unknown functionality of the file /cgi-bin/ExportSettings.sh of …

Jul 28, 2024
CVE-2024-7154
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is an unknown function of the file /wizard.html of the component …

Jul 28, 2024
CVE-2024-42055
5.4 MEDIUM

Cervantes through 0.5-alpha allows stored XSS.

Jul 28, 2024
CVE-2024-42054
5.4 MEDIUM

Cervantes through 0.5-alpha accepts insecure file uploads.

Jul 28, 2024
CVE-2024-7153
5.3 MEDIUM

A vulnerability classified as problematic has been found in Netgear WN604 up to 20240719. Affected is an unknown function of the file siteSurvey.php. The manipulation …

Jul 27, 2024
CVE-2024-6703
4.9 MEDIUM

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site …

Jul 27, 2024
CVE-2024-6897
6.4 MEDIUM

The aThemes Starter Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.53 …

Jul 27, 2024
CVE-2024-6627
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's PDF View widget in all versions up to, …

Jul 27, 2024
CVE-2024-6521
4.4 MEDIUM

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site …

Jul 27, 2024
CVE-2024-6520
4.4 MEDIUM

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site …

Jul 27, 2024
CVE-2024-6518
4.4 MEDIUM

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site …

Jul 27, 2024
CVE-2024-5614
5.3 MEDIUM

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.29 via the 'pafe_posts_list' …

Jul 27, 2024
CVE-2024-6569
5.3 MEDIUM

The Campaign Monitor for WordPress plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.8.15. This is due …

Jul 27, 2024
CVE-2024-6458
6.4 MEDIUM

The WooCommerce Product Table Lite plugin for WordPress is vulnerable to unauthorized post title modification due to a missing capability check on the wcpt_presets__duplicate_preset_to_table function …

Jul 27, 2024
CVE-2024-5969
5.8 MEDIUM

The AIomatic - Automatic AI Content Writer for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 2.0.5. This is …

Jul 27, 2024
CVE-2024-42029
6.3 MEDIUM

xdg-desktop-portal-hyprland (aka an XDG Desktop Portal backend for Hyprland) before 1.3.3 allows OS command execution, e.g., because single quotes are not used when sending a …

Jul 27, 2024
CVE-2024-6661
4.4 MEDIUM

The ParityPress – Parity Pricing with Discount Rules plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Discount Text' in all versions up to, …

Jul 27, 2024
CVE-2024-6634
6.4 MEDIUM

The Master Currency WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's currencyconverterform shortcode in all versions up to, and including, …

Jul 27, 2024
CVE-2024-6591
5.8 MEDIUM

The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized email creation and sending due to a missing capability check on the 'send_auction_email_callback' …

Jul 27, 2024
CVE-2024-6573
5.3 MEDIUM

The Intelligence plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.0. This is due the plugin not …

Jul 27, 2024
CVE-2024-6566
5.3 MEDIUM

The Aramex Shipping WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.1.21. This is due the …

Jul 27, 2024
CVE-2024-6549
5.3 MEDIUM

The Admin Post Navigation plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.1. This is due to …

Jul 27, 2024
CVE-2024-6548
5.3 MEDIUM

The Add Admin JavaScript plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0. This is due to …

Jul 27, 2024
CVE-2024-6547
5.3 MEDIUM

The Add Admin CSS plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1. This is due to …

Jul 27, 2024
CVE-2024-6546
5.3 MEDIUM

The One Click Close Comments plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.7.1. This is due …

Jul 27, 2024
CVE-2024-6545
5.3 MEDIUM

The Admin Trim Interface plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.5.1. This is due to …

Jul 27, 2024
CVE-2024-4410
5.4 MEDIUM

The IgnitionDeck Crowdfunding Platform plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.9.8. This is due to missing capability …

Jul 27, 2024
CVE-2024-1804
4.3 MEDIUM

The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tutor_import_from_xml …

Jul 27, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.