CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-28418
6.5 MEDIUM

Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php

Mar 14, 2024
CVE-2024-28417
6.3 MEDIUM

Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.

Mar 14, 2024
CVE-2024-27986
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Livemesh Elementor Addons by Livemesh allows Stored XSS.This issue affects Elementor Addons by …

Mar 14, 2024
CVE-2024-0313
5.5 MEDIUM

A malicious insider exploiting this vulnerability can circumvent existing security controls put in place by the organization. On the contrary, if the victim is legitimately …

Mar 14, 2024
CVE-2024-0312
5.5 MEDIUM

A malicious insider can uninstall Skyhigh Client Proxy without a valid uninstall password.

Mar 14, 2024
CVE-2024-0311
5.5 MEDIUM

A malicious insider can bypass the existing policy of Skyhigh Client Proxy without a valid release code.

Mar 14, 2024
CVE-2024-22398
4.9 MEDIUM

An improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in SonicWall Email Security Appliance could allow a remote attacker with administrative …

Mar 14, 2024
CVE-2024-22396
5.3 MEDIUM

An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially …

Mar 14, 2024
CVE-2024-1884
6.5 MEDIUM

This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that allows an attacker to induce the server-side application to make …

Mar 14, 2024
CVE-2024-1883
6.3 MEDIUM

This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit this weakness by crafting a malicious URL …

Mar 14, 2024
CVE-2024-25653
4.3 MEDIUM

Broken Access Control in the Report functionality of Delinea PAM Secret Server 11.4 allows unprivileged users, when Unlimited Admin Mode is enabled, to view system …

Mar 14, 2024
CVE-2024-25651
5.3 MEDIUM

User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4. This allows a remote attacker to determine whether a user …

Mar 14, 2024
CVE-2024-25649
6.7 MEDIUM

In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machine) to read the following data …

Mar 14, 2024
CVE-2024-1223
4.8 MEDIUM

This vulnerability potentially allows unauthorized enumeration of information from the embedded device APIs. An attacker must already have existing knowledge of some combination of valid …

Mar 14, 2024
CVE-2024-25650
5.9 MEDIUM

Insecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM administrator to obtain the Symmetric Key (used to …

Mar 14, 2024
CVE-2024-28251
5.6 MEDIUM

Querybook is a Big Data Querying UI, combining collocated table metadata and a simple notebook interface. Querybook's datadocs functionality works by using a Websocket Server. …

Mar 14, 2024
CVE-2024-2242
6.1 MEDIUM

The Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘active-tab’ parameter in all versions up to, and including, 5.9 …

Mar 13, 2024
CVE-2024-2079
6.4 MEDIUM

The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'per_line_mobile' shortcode in all versions up …

Mar 13, 2024
CVE-2024-27703
5.4 MEDIUM

Cross Site Scripting vulnerability in Leantime 3.0.6 allows a remote attacker to execute arbitrary code via the to-do title parameter.

Mar 13, 2024
CVE-2023-38536
6.4 MEDIUM

HTML injection in OpenText™ Exceed Turbo X affecting version 12.5.1. The vulnerability could result in Cross site scripting.

Mar 13, 2024
CVE-2023-38535
4.7 MEDIUM

Use of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2. The vulnerability could compromise the cryptographic keys.

Mar 13, 2024
CVE-2024-28662
5.4 MEDIUM

A Cross Site Scripting vulnerability exists in Piwigo before 14.3.0 script because of missing sanitization in create_tag in admin/include/functions.php.

Mar 13, 2024
CVE-2024-28193
6.5 MEDIUM

your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version <1.8.0 allows users to create a public token in the settings, which can …

Mar 13, 2024
CVE-2024-28192
5.3 MEDIUM

your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version <1.8.0 is vulnerable to NoSQL injection in the public access token processing logic. …

Mar 13, 2024
CVE-2024-27097
4.3 MEDIUM

A user endpoint didn't perform filtering on an incoming parameter, which was added directly to the application log. This could lead to an attacker injecting …

Mar 13, 2024
CVE-2023-50726
6.4 MEDIUM

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. "Local sync" is an Argo CD feature that allows developers to temporarily override an …

Mar 13, 2024
CVE-2023-36238
6.5 MEDIUM

Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the invoice ID parameter.

Mar 13, 2024
CVE-2024-24692
5.3 MEDIUM

Race condition in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authenticated user to conduct a denial of service …

Mar 13, 2024
CVE-2024-2433
4.3 MEDIUM

An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authenticated read-only administrator to upload files using the web interface and completely fill …

Mar 13, 2024
CVE-2024-2432
4.5 MEDIUM

A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. …

Mar 13, 2024
CVE-2024-2431
5.5 MEDIUM

An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a user to …

Mar 13, 2024
CVE-2024-2418
6.3 MEDIUM

A vulnerability was found in SourceCodester Best POS Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Mar 13, 2024
CVE-2024-2403
5.9 MEDIUM

Improper cleanup in temporary file handling component in Devolutions Remote Desktop Manager 2024.1.12 and earlier on Windows allows an attacker that compromised a user endpoint, …

Mar 13, 2024
CVE-2024-28196
6.5 MEDIUM

your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version < 1.9.0 does not prevent other pages from displaying it in an iframe …

Mar 13, 2024
CVE-2024-27953
4.7 MEDIUM

Missing Authorization vulnerability in Cool Plugins Cryptocurrency Widgets – Price Ticker & Coins List.This issue affects Cryptocurrency Widgets – Price Ticker & Coins List: from …

Mar 13, 2024
CVE-2024-20322
5.8 MEDIUM

A vulnerability in the access control list (ACL) processing on Pseudowire interfaces in the ingress direction of Cisco IOS XR Software could allow an unauthenticated, …

Mar 13, 2024
CVE-2024-20319
4.3 MEDIUM

A vulnerability in the UDP forwarding code of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to bypass configured management plane protection policies …

Mar 13, 2024
CVE-2024-20315
5.8 MEDIUM

A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR Software could allow an unauthenticated, …

Mar 13, 2024
CVE-2024-20266
5.3 MEDIUM

A vulnerability in the DHCP version 4 (DHCPv4) server feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to trigger a crash …

Mar 13, 2024
CVE-2024-20262
6.5 MEDIUM

A vulnerability in the Secure Copy Protocol (SCP) and SFTP feature of Cisco IOS XR Software could allow an authenticated, local attacker to create or …

Mar 13, 2024
CVE-2024-0163
5.3 MEDIUM

Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain a TOCTOU race condition vulnerability. A local low privileged attacker could potentially exploit this vulnerability …

Mar 13, 2024
CVE-2024-0162
5.3 MEDIUM

Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit …

Mar 13, 2024
CVE-2024-2293
6.4 MEDIUM

The Site Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user display name in all versions up to, and including, 6.11.4 …

Mar 13, 2024
CVE-2024-2286
6.4 MEDIUM

The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart) plugin for WordPress is vulnerable to Stored …

Mar 13, 2024
CVE-2024-2252
5.4 MEDIUM

The Droit Elementor Addons – Widgets, Blocks, Templates Library For Elementor Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets …

Mar 13, 2024
CVE-2024-2239
6.4 MEDIUM

The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Premium Magic Scroll module in all versions up to, and …

Mar 13, 2024
CVE-2024-2238
6.4 MEDIUM

The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Mouse Cursor module in all versions up to, and …

Mar 13, 2024
CVE-2024-2237
6.4 MEDIUM

The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Global Badge module in all versions up to, and including, …

Mar 13, 2024
CVE-2024-2126
6.4 MEDIUM

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Registration Form widget in all versions up to, and …

Mar 13, 2024
CVE-2024-2106
5.3 MEDIUM

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, …

Mar 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.