CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-6785
5.3 MEDIUM

The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, …

Mar 13, 2024
CVE-2024-25154
5.3 MEDIUM

Improper URL validation leads to path traversal in FileCatalyst Direct 3.8.8 and earlier allowing an encoded payload to cause the web server to return files …

Mar 13, 2024
CVE-2024-26629
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix RELEASE_LOCKOWNER The test on so_count in nfsd4_release_lockowner() is nonsense and harmful. Revert to …

Mar 13, 2024
CVE-2024-1508
6.4 MEDIUM

The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'settings['title_tags']' attribute of the Mercury widget in …

Mar 13, 2024
CVE-2024-1507
6.4 MEDIUM

The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tags' attribute of the Rubix widget in …

Mar 13, 2024
CVE-2023-52608
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Check mailbox/SMT channel for consistency On reception of a completion interrupt the shared …

Mar 13, 2024
CVE-2024-28668
6.1 MEDIUM

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/mychannel_add.php

Mar 13, 2024
CVE-2024-28667
6.1 MEDIUM

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/templets_one_edit.php

Mar 13, 2024
CVE-2024-28666
5.5 MEDIUM

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/media_add.php

Mar 13, 2024
CVE-2024-28430
6.1 MEDIUM

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_edit.php.

Mar 13, 2024
CVE-2024-28429
5.5 MEDIUM

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/archives_do.php

Mar 13, 2024
CVE-2024-2416
6.5 MEDIUM

Cross-Site Request Forgery vulnerability in Movistar's 4G router affecting version ES_WLD71-T1_v2.0.201820. This vulnerability allows an attacker to force an end user to execute unwanted actions …

Mar 13, 2024
CVE-2023-43043
5.1 MEDIUM

IBM Maximo Application Suite - Maximo Mobile for EAM 8.10 and 8.11 could disclose sensitive information to a local user. IBM X-Force ID: 266875.

Mar 13, 2024
CVE-2023-38723
6.4 MEDIUM

IBM Maximo Application Suite 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …

Mar 13, 2024
CVE-2023-28517
5.4 MEDIUM

IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …

Mar 13, 2024
CVE-2018-25090
5.4 MEDIUM

An unauthenticated remote attacker can use an XSS attack due to improper neutralization of input during web page generation. User interaction is required. This leads …

Mar 13, 2024
CVE-2024-28623
6.1 MEDIUM

RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section.

Mar 13, 2024
CVE-2024-27440
4.8 MEDIUM

The Toyoko Inn official App for iOS versions prior to 1.13.0 and Toyoko Inn official App for Android versions prior 1.3.14 don't properly verify server …

Mar 13, 2024
CVE-2024-2412
5.3 MEDIUM

The disabling function of the user registration page for Heimavista Rpage and Epage is not properly implemented, allowing remote attackers to complete user registration on …

Mar 13, 2024
CVE-2015-10130
5.3 MEDIUM

The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or …

Mar 13, 2024
CVE-2024-1582
6.4 MEDIUM

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpgmza' shortcode in all versions …

Mar 13, 2024
CVE-2023-4839
4.4 MEDIUM

The WP Go Maps for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 9.0.32 due to insufficient …

Mar 13, 2024
CVE-2024-1421
6.4 MEDIUM

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘border_type’ attribute of the Post Carousel …

Mar 12, 2024
CVE-2024-1397
6.4 MEDIUM

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up …

Mar 12, 2024
CVE-2024-2107
5.8 MEDIUM

The Blossom Spa theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.3 via generated source. This makes …

Mar 12, 2024
CVE-2023-43279
6.5 MEDIUM

Null Pointer Dereference in mask_cidr6 component at cidr.c in Tcpreplay 4.4.4 allows attackers to crash the application via crafted tcprewrite command.

Mar 12, 2024
CVE-2024-2406
5.4 MEDIUM

A vulnerability, which was classified as critical, was found in Gacjie Server up to 1.0. This affects the function index of the file /app/admin/controller/Upload.php. The …

Mar 12, 2024
CVE-2024-28239
5.4 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. The authentication API has a `redirect` parameter that can be exploited as …

Mar 12, 2024
CVE-2024-27305
5.3 MEDIUM

aiosmtpd is a reimplementation of the Python stdlib smtpd.py based on asyncio. aiosmtpd is vulnerable to inbound SMTP smuggling. SMTP smuggling is a novel vulnerability …

Mar 12, 2024
CVE-2024-24097
5.4 MEDIUM

Cross Site Scripting (XSS) vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via the News Feed.

Mar 12, 2024
CVE-2023-43292
6.1 MEDIUM

Cross Site Scripting vulnerability in My Food Recipe Using PHP with Source Code v.1.0 allows a local attacker to execute arbitrary code via a crafted …

Mar 12, 2024
CVE-2023-42308
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Manage Fastrack Subjects in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via the "Subject Name" …

Mar 12, 2024
CVE-2023-42307
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via "Subject Name" and "Subject Code" section.

Mar 12, 2024
CVE-2024-2130
6.4 MEDIUM

The CWW Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Module2 widget in all versions up to, and including, 1.2.7 due …

Mar 12, 2024
CVE-2024-2031
6.4 MEDIUM

The Video Conferencing with Zoom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zoom_recordings_by_meeting' shortcode in all versions up to, and …

Mar 12, 2024
CVE-2024-28112
6.1 MEDIUM

Peering Manager is a BGP session management tool. Affected versions of Peering Manager are subject to a potential stored Cross-Site Scripting (XSS) attack in the …

Mar 12, 2024
CVE-2023-30968
6.8 MEDIUM

One of Gotham Gaia services was found to be vulnerable to a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker to bypass …

Mar 12, 2024
CVE-2024-28098
6.4 MEDIUM

The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, such as retention, TTL, and offloading settings. These management operations …

Mar 12, 2024
CVE-2024-1765
5.9 MEDIUM

Cloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server …

Mar 12, 2024
CVE-2024-1137
4.3 MEDIUM

The Proxy and Client components of TIBCO Software Inc.'s TIBCO ActiveSpaces - Enterprise Edition contain a vulnerability that theoretically allows an Active Spaces client to …

Mar 12, 2024
CVE-2024-2182
6.5 MEDIUM

A flaw was found in the Open Virtual Network (OVN). In OVN clusters where BFD is used between hypervisors for high availability, an attacker can …

Mar 12, 2024
CVE-2024-28339
5.4 MEDIUM

An information leak in the debuginfo.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without …

Mar 12, 2024
CVE-2024-26201
6.6 MEDIUM

Microsoft Intune Linux Agent Elevation of Privilege Vulnerability

Mar 12, 2024
CVE-2024-26197
6.5 MEDIUM

Windows Standards-Based Storage Management Service Denial of Service Vulnerability

Mar 12, 2024
CVE-2024-26185
6.5 MEDIUM

Windows Compressed Folder Tampering Vulnerability

Mar 12, 2024
CVE-2024-26181
5.5 MEDIUM

Windows Kernel Denial of Service Vulnerability

Mar 12, 2024
CVE-2024-26177
5.5 MEDIUM

Windows Kernel Information Disclosure Vulnerability

Mar 12, 2024
CVE-2024-26174
5.5 MEDIUM

Windows Kernel Information Disclosure Vulnerability

Mar 12, 2024
CVE-2024-26160
5.5 MEDIUM

Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability

Mar 12, 2024
CVE-2024-21448
5.0 MEDIUM

Microsoft Teams for Android Information Disclosure Vulnerability

Mar 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.