CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-1798
5.3 MEDIUM

The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the tutor_lp_export_xml …

Jul 27, 2024
CVE-2024-37034
5.9 MEDIUM

An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with the Key-Value (KV) …

Jul 26, 2024
CVE-2024-42007
5.8 MEDIUM

SPX (aka php-spx) through 0.4.15 allows SPX_UI_URI Directory Traversal to read arbitrary files.

Jul 26, 2024
CVE-2024-41375
6.1 MEDIUM

ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/terminal-xhr.php

Jul 26, 2024
CVE-2024-41374
6.1 MEDIUM

ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/settings-screen.php

Jul 26, 2024
CVE-2024-41373
6.3 MEDIUM

ICEcoder 8.1 contains a Path Traversal vulnerability via lib/backup-versions-preview-loader.php.

Jul 26, 2024
CVE-2024-27357
5.8 MEDIUM

An issue was discovered in WithSecure Elements Agent through 23.x for macOS, WithSecure Elements Client Security through 23.x for macOS, and WithSecure MDR through 23.x …

Jul 26, 2024
CVE-2024-41356
4.7 MEDIUM

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\firewall-zones\zones-edit-network.php.

Jul 26, 2024
CVE-2024-41355
6.5 MEDIUM

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.php.

Jul 26, 2024
CVE-2024-41805
6.1 MEDIUM

Tracks, a Getting Things Done (GTD) web application, is vulnerable to reflected cross-site scripting in versions prior to 2.7.1. Reflected cross-site scripting enables execution of …

Jul 26, 2024
CVE-2024-7128
5.3 MEDIUM

A flaw was found in the OpenShift console. Several endpoints in the application use the authHandler() and authHandlerWithUser() middleware functions. When the default authentication provider …

Jul 26, 2024
CVE-2024-40689
6.0 MEDIUM

IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to …

Jul 26, 2024
CVE-2024-41691
4.6 MEDIUM

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of FTP credentials in plaintext within the SquashFS-root filesystem associated with the router's firmware. An …

Jul 26, 2024
CVE-2024-41690
4.6 MEDIUM

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of default username and password credentials in plaintext within the router's firmware/ database. An attacker …

Jul 26, 2024
CVE-2024-41689
4.6 MEDIUM

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials within the router's firmware/ database. An attacker with physical access …

Jul 26, 2024
CVE-2024-41688
4.6 MEDIUM

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due lack of encryption in storing of usernames and passwords within the router's firmware/ database. An attacker with …

Jul 26, 2024
CVE-2024-41684
5.3 MEDIUM

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing secure flag for the session cookies associated with the router's web management interface. An attacker …

Jul 26, 2024
CVE-2024-25090
5.4 MEDIUM

Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of Apache Roller on …

Jul 26, 2024
CVE-2024-6490
6.5 MEDIUM

During testing of the Master Slider WordPress plugin through 3.9.10, a CSRF vulnerability was found, which allows an unauthorized user to manipulate requests on behalf …

Jul 26, 2024
CVE-2024-40897
6.7 MEDIUM

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with …

Jul 26, 2024
CVE-2024-7120
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. This affects an unknown part of the file …

Jul 26, 2024
CVE-2024-7119
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. Affected by this issue is some unknown functionality of …

Jul 26, 2024
CVE-2023-49921
5.2 MEDIUM

An issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This could lead to raw contents …

Jul 26, 2024
CVE-2024-7118
6.3 MEDIUM

A vulnerability classified as critical was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. Affected by this vulnerability is an unknown functionality of the file /department_viewmore.php. …

Jul 26, 2024
CVE-2024-7117
6.3 MEDIUM

A vulnerability classified as critical has been found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. Affected is an unknown function of the file /shift_viewmore.php. The manipulation …

Jul 26, 2024
CVE-2024-7116
6.3 MEDIUM

A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. It has been rated as critical. This issue affects some unknown processing of the file …

Jul 26, 2024
CVE-2024-7115
6.3 MEDIUM

A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. It has been declared as critical. This vulnerability affects unknown code of the file /designation_viewmore.php. …

Jul 26, 2024
CVE-2024-7114
6.3 MEDIUM

A vulnerability was found in Tianchoy Blog up to 1.8.8. It has been classified as critical. This affects an unknown part of the file /so.php. …

Jul 26, 2024
CVE-2024-3938
5.4 MEDIUM

The "reset password" login page accepted an HTML injection via URL parameters. This has already been rectified via patch, and as such it cannot be …

Jul 25, 2024
CVE-2024-38103
5.9 MEDIUM

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Jul 25, 2024
CVE-2024-7106
4.3 MEDIUM

A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation …

Jul 25, 2024
CVE-2024-7105
6.3 MEDIUM

A vulnerability classified as critical has been found in ForIP Tecnologia Administração PABX 1.x. Affected is an unknown function of the file /detalheIdUra of the …

Jul 25, 2024
CVE-2024-6558
6.3 MEDIUM

HMS Industrial Networks Anybus-CompactCom 30 products are vulnerable to a XSS attack caused by the lack of input sanitation checks. As a consequence, it is …

Jul 25, 2024
CVE-2024-40324
5.4 MEDIUM

A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) characters into input fields, leading to HTTP …

Jul 25, 2024
CVE-2024-29069
4.8 MEDIUM

In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap. The snap format is a …

Jul 25, 2024
CVE-2024-29068
5.8 MEDIUM

In snapd versions prior to 2.62, snapd failed to properly check the file type when extracting a snap. The snap format is a squashfs file-system …

Jul 25, 2024
CVE-2024-1724
6.3 MEDIUM

In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. In Ubuntu, …

Jul 25, 2024
CVE-2024-40873
4.5 MEDIUM

There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.07. Attackers with system administrator permissions …

Jul 25, 2024
CVE-2024-28772
6.8 MEDIUM

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary …

Jul 25, 2024
CVE-2022-32759
5.3 MEDIUM

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses insufficient session expiration which could allow an unauthorized user to obtain sensitive …

Jul 25, 2024
CVE-2024-41801
4.7 MEDIUM

OpenProject is open source project management software. Prior to version 14.3.0, using a forged HOST header in the default configuration of packaged installations and using …

Jul 25, 2024
CVE-2024-41800
4.8 MEDIUM

Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able …

Jul 25, 2024
CVE-2024-41806
5.3 MEDIUM

The Open edX Platform is a learning management platform. Instructors can upload csv files containing learner information to create cohorts in the instructor dashboard. These …

Jul 25, 2024
CVE-2024-36111
6.3 MEDIUM

KubePi is a K8s panel. Starting in version 1.6.3 and prior to version 1.8.0, there is a defect in the KubePi JWT token verification. The …

Jul 25, 2024
CVE-2024-39674
6.2 MEDIUM

Plaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect availability.

Jul 25, 2024
CVE-2024-39673
6.8 MEDIUM

Vulnerability of serialisation/deserialisation mismatch in the iAware module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jul 25, 2024
CVE-2024-39670
6.2 MEDIUM

Privilege escalation vulnerability in the account synchronisation module. Impact: Successful exploitation of this vulnerability will affect availability.

Jul 25, 2024
CVE-2023-7271
5.5 MEDIUM

Privilege escalation vulnerability in the NMS module Impact: Successful exploitation of this vulnerability will affect availability.

Jul 25, 2024
CVE-2024-41707
4.8 MEDIUM

An issue was discovered in Archer Platform 6 before 2024.06. Authenticated users can achieve HTML content injection. A remote authenticated malicious Archer user could potentially …

Jul 25, 2024
CVE-2024-6972
6.5 MEDIUM

In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the task log in clear-text.

Jul 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.