CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-1007
6.3 MEDIUM

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been classified as critical. Affected is an unknown function of the file edit_profile.php. …

Jan 29, 2024
CVE-2024-1005
5.3 MEDIUM

A vulnerability has been found in Shanxi Diankeyun Technology NODERP up to 6.0.2 and classified as critical. This vulnerability affects unknown code of the file …

Jan 29, 2024
CVE-2023-7200
6.1 MEDIUM

The EventON WordPress plugin before 4.4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jan 29, 2024
CVE-2023-7199
5.3 MEDIUM

The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthenticated user to read draft and private posts via a crafted …

Jan 29, 2024
CVE-2023-7089
5.4 MEDIUM

The Easy SVG Allow WordPress plugin through 1.0 does not sanitize uploaded SVG files, which could allow users with a role as low as Author …

Jan 29, 2024
CVE-2023-6633
4.3 MEDIUM

The Site Notes WordPress plugin through 2.0.0 does not have CSRF checks in some of its functionalities, which could allow attackers to make logged in …

Jan 29, 2024
CVE-2023-6530
5.4 MEDIUM

The TJ Shortcodes WordPress plugin through 0.1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Jan 29, 2024
CVE-2023-6503
5.4 MEDIUM

The WP Plugin Lister WordPress plugin through 2.1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which …

Jan 29, 2024
CVE-2023-6389
6.1 MEDIUM

The WordPress Toolbar WordPress plugin through 2.2.6 redirects to any URL via the "wptbto" parameter. This makes it possible for unauthenticated attackers to redirect users …

Jan 29, 2024
CVE-2023-6278
6.1 MEDIUM

The Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo WordPress plugin before 2.2.25 does not sanitise and escape the biteship_error and biteship_message parameters before outputting …

Jan 29, 2024
CVE-2023-6165
4.8 MEDIUM

The Restrict Usernames Emails Characters WordPress plugin before 3.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jan 29, 2024
CVE-2023-5956
4.8 MEDIUM

The Wp-Adv-Quiz WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jan 29, 2024
CVE-2023-5943
4.8 MEDIUM

The Wp-Adv-Quiz WordPress plugin before 1.0.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jan 29, 2024
CVE-2023-5124
4.8 MEDIUM

The Page Builder: Pagelayer WordPress plugin before 1.8.0 doesn't prevent attackers with administrator privileges from inserting malicious JavaScript inside a post's header or footer code, …

Jan 29, 2024
CVE-2024-22559
5.4 MEDIUM

LightCMS v2.0 is vulnerable to Cross Site Scripting (XSS) in the Content Management - Articles field.

Jan 29, 2024
CVE-2024-1014
6.2 MEDIUM

Uncontrolled resource consumption vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could interrupt the availability of the administration panel by sending …

Jan 29, 2024
CVE-2024-23792
5.3 MEDIUM

When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. The attack requires a logged-in other user to …

Jan 29, 2024
CVE-2024-23791
4.9 MEDIUM

Insertion of debug information into log file during building the elastic search index allows reading of sensitive information from articles.This issue affects OTRS: from 7.0.X …

Jan 29, 2024
CVE-2024-0989
5.4 MEDIUM

A vulnerability, which was classified as problematic, has been found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected by this issue is the function …

Jan 29, 2024
CVE-2024-0988
6.3 MEDIUM

A vulnerability classified as critical was found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected by this vulnerability is the function checklogin of the …

Jan 29, 2024
CVE-2024-0987
6.3 MEDIUM

A vulnerability classified as critical has been found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected is an unknown function of the file /runtime/log. …

Jan 29, 2024
CVE-2024-0986
4.7 MEDIUM

A vulnerability was found in Issabel PBX 4.0.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php?menu=asterisk_cli of …

Jan 29, 2024
CVE-2024-23782
5.4 MEDIUM

Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, …

Jan 28, 2024
CVE-2024-0841
6.6 MEDIUM

A null pointer dereference flaw was found in the hugetlbfs_fill_super function in the Linux kernel hugetlbfs (HugeTLB pages) functionality. This issue may allow a local …

Jan 28, 2024
CVE-2024-0962
6.3 MEDIUM

A vulnerability was found in obgm libcoap 4.3.4. It has been rated as critical. Affected by this issue is the function get_split_entry of the file …

Jan 27, 2024
CVE-2024-0960
5.0 MEDIUM

A vulnerability was found in flink-extended ai-flow 0.3.1. It has been declared as critical. Affected by this vulnerability is the function cloudpickle.loads of the file …

Jan 27, 2024
CVE-2024-0959
5.0 MEDIUM

A vulnerability was found in StanfordVL GibsonEnv 0.3.1. It has been classified as critical. Affected is the function cloudpickle.load of the file gibson\utils\pposgd_fuse.py. The manipulation …

Jan 27, 2024
CVE-2024-0618
4.4 MEDIUM

The Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jan 27, 2024
CVE-2023-48202
5.4 MEDIUM

Cross-Site Scripting (XSS) vulnerability in Sunlight CMS 8.0.1 allows an authenticated low-privileged user to escalate privileges via a crafted SVG file in the File Manager …

Jan 27, 2024
CVE-2023-48201
5.4 MEDIUM

Cross Site Scripting (XSS) vulnerability in Sunlight CMS v.8.0.1, allows remote authenticated attackers to execute arbitrary code and escalate privileges via a crafted script to …

Jan 27, 2024
CVE-2024-0824
6.4 MEDIUM

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Anything functionality in all versions up to, and …

Jan 27, 2024
CVE-2024-0697
6.5 MEDIUM

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.3 via …

Jan 27, 2024
CVE-2024-0667
5.4 MEDIUM

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions …

Jan 27, 2024
CVE-2024-0664
4.4 MEDIUM

The Meks Smart Social Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Meks Smart Social Widget in all versions up to, …

Jan 27, 2024
CVE-2023-6497
4.4 MEDIUM

The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the automatic redirect URL setting in all versions up to …

Jan 27, 2024
CVE-2023-6482
5.2 MEDIUM

Use of encryption key derived from static information in Synaptics Fingerprint Driver allows an attacker to set up a TLS session with the fingerprint sensor …

Jan 27, 2024
CVE-2023-52187
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Thomas Maier Image Source Control Lite – Show Image Credits and Captions.This issue affects Image …

Jan 27, 2024
CVE-2023-29081
5.5 MEDIUM

A vulnerability has been reported in Suite Setups built with versions prior to InstallShield 2023 R2. This vulnerability may allow locally authenticated users to cause …

Jan 26, 2024
CVE-2024-0941
5.5 MEDIUM

A vulnerability was found in Novel-Plus 4.3.0-RC1 and classified as critical. This issue affects some unknown processing of the file /novel/bookComment/list. The manipulation of the …

Jan 26, 2024
CVE-2024-0939
6.3 MEDIUM

A vulnerability has been found in Byzoro Smart S210 Management Platform up to 20240117 and classified as critical. This vulnerability affects unknown code of the …

Jan 26, 2024
CVE-2024-20305
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against …

Jan 26, 2024
CVE-2024-20263
5.8 MEDIUM

A vulnerability with the access control list (ACL) management within a stacked switch configuration of Cisco Business 250 Series Smart Switches and Business 350 Series …

Jan 26, 2024
CVE-2024-0938
5.5 MEDIUM

A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.9. This affects an unknown part of the file /general/email/inbox/delete_webmail.php. …

Jan 26, 2024
CVE-2024-0937
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in van_der_Schaar LAB synthcity 0.2.9. Affected by this issue is the function load_from_file of the …

Jan 26, 2024
CVE-2024-23820
5.3 MEDIUM

OpenFGA, an authorization/permission engine, is vulnerable to a denial of service attack in versions prior to 1.4.3. In some scenarios that depend on the model …

Jan 26, 2024
CVE-2024-0936
6.3 MEDIUM

A vulnerability classified as critical was found in van_der_Schaar LAB TemporAI 0.0.3. Affected by this vulnerability is the function load_from_file of the component PKL File …

Jan 26, 2024
CVE-2024-0933
6.3 MEDIUM

A vulnerability was found in Niushop B2B2C V5 and classified as critical. Affected by this issue is some unknown functionality of the file \app\model\Upload.php. The …

Jan 26, 2024
CVE-2024-0932
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.49_multi_TDE01. This issue affects the function setSmartPowerManagement. The manipulation of the argument …

Jan 26, 2024
CVE-2024-0931
4.7 MEDIUM

A vulnerability classified as critical was found in Tenda AC10U 15.03.06.49_multi_TDE01. This vulnerability affects the function saveParentControlInfo. The manipulation of the argument deviceId/time/urls leads to …

Jan 26, 2024
CVE-2024-0930
4.7 MEDIUM

A vulnerability classified as critical has been found in Tenda AC10U 15.03.06.49_multi_TDE01. This affects the function fromSetWirelessRepeat. The manipulation of the argument wpapsk_crypto leads to …

Jan 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.