CVE Database

59714+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-2131
6.4 MEDIUM

The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's infobox and button widget in all versions up …

Mar 23, 2024
CVE-2024-1697
6.4 MEDIUM

The Custom WooCommerce Checkout Fields Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the save_wcfe_options function in all versions up to, and …

Mar 23, 2024
CVE-2024-29057
4.3 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Mar 22, 2024
CVE-2024-26247
4.7 MEDIUM

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Mar 22, 2024
CVE-2024-2828
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in lakernote EasyAdmin up to 20240315. Affected is the function thumbnail of the file src/main/java/com/laker/admin/module/sys/controller/IndexController.java. The …

Mar 22, 2024
CVE-2024-2827
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in lakernote EasyAdmin up to 20240315. This issue affects some unknown processing of the file …

Mar 22, 2024
CVE-2024-2826
6.3 MEDIUM

A vulnerability classified as problematic was found in lakernote EasyAdmin up to 20240315. This vulnerability affects unknown code of the file /ureport/designer/saveReportFile. The manipulation leads …

Mar 22, 2024
CVE-2024-2825
6.3 MEDIUM

A vulnerability classified as critical has been found in lakernote EasyAdmin up to 20240315. This affects an unknown part of the file /ureport/designer/saveReportFile. The manipulation …

Mar 22, 2024
CVE-2024-2824
6.3 MEDIUM

A vulnerability was found in Matthias-Wandel jhead 3.08 and classified as critical. This issue affects the function PrintFormatNumber of the file exif.c. The manipulation leads …

Mar 22, 2024
CVE-2023-4063
5.3 MEDIUM

Certain HP OfficeJet Pro printers are potentially vulnerable to a Denial of Service when using an improper eSCL URL GET request.

Mar 22, 2024
CVE-2024-2823
4.3 MEDIUM

A vulnerability has been found in DedeCMS 5.7 and classified as problematic. This vulnerability affects unknown code of the file /src/dede/mda_main.php. The manipulation leads to …

Mar 22, 2024
CVE-2024-2822
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in DedeCMS 5.7. This affects an unknown part of the file /src/dede/vote_edit.php. The manipulation of the …

Mar 22, 2024
CVE-2024-29186
5.3 MEDIUM

Bref is an open-source project that helps users go serverless on Amazon Web Services with PHP. When Bref prior to version 2.1.17 is used with …

Mar 22, 2024
CVE-2024-29042
5.3 MEDIUM

Translate is a package that allows users to convert text to different languages on Node.js and the browser. Prior to version 3.0.0, an attacker controlling …

Mar 22, 2024
CVE-2024-2821
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7. Affected by this issue is some unknown functionality of the file /src/dede/friendlink_edit.php. …

Mar 22, 2024
CVE-2024-2820
4.3 MEDIUM

A vulnerability classified as problematic was found in DedeCMS 5.7. Affected by this vulnerability is an unknown functionality of the file /src/dede/baidunews.php. The manipulation of …

Mar 22, 2024
CVE-2022-32754
4.8 MEDIUM

IBM Security Verify Directory 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …

Mar 22, 2024
CVE-2022-32753
4.5 MEDIUM

IBM Security Verify Directory 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 228444.

Mar 22, 2024
CVE-2022-32751
5.3 MEDIUM

IBM Security Verify Directory 10.0.0 could disclose sensitive server information that could be used in further attacks against the system. IBM X-Force ID: 228437.

Mar 22, 2024
CVE-2024-29865
5.4 MEDIUM

Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form.

Mar 22, 2024
CVE-2024-28593
5.4 MEDIUM

The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to …

Mar 22, 2024
CVE-2024-2728
4.1 MEDIUM

Information exposure vulnerability in the CIGESv2 system. This vulnerability could allow a local attacker to intercept traffic due to the lack of proper implementation of …

Mar 22, 2024
CVE-2024-2727
6.1 MEDIUM

HTML injection vulnerability affecting the CIGESv2 system, which allows an attacker to inject arbitrary code and modify elements of the website and email confirmation message.

Mar 22, 2024
CVE-2024-2726
6.1 MEDIUM

Stored Cross-Site Scripting (Stored-XSS) vulnerability affecting the CIGESv2 system, allowing an attacker to execute and store malicious javascript code in the application form without prior …

Mar 22, 2024
CVE-2024-28560
5.4 MEDIUM

SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the deleteArea() function of the Address.php component.

Mar 22, 2024
CVE-2024-25168
6.3 MEDIUM

SQL injection vulnerability in snow snow v.2.0.0 allows a remote attacker to execute arbitrary code via the dataScope parameter of the system/role/list interface.

Mar 22, 2024
CVE-2024-2817
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Tenda AC15 15.03.05.18. Affected by this issue is the function fromSysToolRestoreSet of the file …

Mar 22, 2024
CVE-2024-2816
4.3 MEDIUM

A vulnerability classified as problematic was found in Tenda AC15 15.03.05.18. Affected by this vulnerability is the function fromSysToolReboot of the file /goform/SysToolReboot. The manipulation …

Mar 22, 2024
CVE-2024-2812
6.3 MEDIUM

A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. It has been classified as critical. This affects the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation …

Mar 22, 2024
CVE-2024-29273
6.1 MEDIUM

There is Stored Cross-Site Scripting (XSS) in dzzoffice 2.02.1 SC UTF8 in uploadfile to index.php, with the XSS payload in an SVG document.

Mar 22, 2024
CVE-2024-29272
6.5 MEDIUM

Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and obtain sensitive information via the sanitizeFileName parameter …

Mar 22, 2024
CVE-2024-29271
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) vulnerability in VvvebJs before version 1.7.7, allows remote attackers to execute arbitrary code and obtain sensitive information via the action parameter …

Mar 22, 2024
CVE-2024-26557
5.4 MEDIUM

Codiad v2.8.4 allows reflected XSS via the components/market/dialog.php type parameter.

Mar 22, 2024
CVE-2024-25807
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Lychee 3.1.6, allows remote attackers to execute arbitrary code and obtain sensitive information via the title parameter when creating …

Mar 22, 2024
CVE-2024-2500
6.4 MEDIUM

The ColorMag theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.1.6 due …

Mar 22, 2024
CVE-2024-2392
6.4 MEDIUM

The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Newsletter widget in all versions up to, and including, 2.0.31 …

Mar 22, 2024
CVE-2024-2080
4.3 MEDIUM

The LiquidPoll – Polls, Surveys, NPS and Feedback Reviews plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, …

Mar 22, 2024
CVE-2024-0957
6.1 MEDIUM

The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Customer Notes field …

Mar 22, 2024
CVE-2024-2777
6.3 MEDIUM

A vulnerability has been found in Campcodes/PHPGurukul Online Marriage Registration System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Mar 22, 2024
CVE-2024-2776
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Campcodes Online Marriage Registration System 1.0. Affected is an unknown function of the file /admin/search.php. …

Mar 22, 2024
CVE-2024-2774
6.3 MEDIUM

A vulnerability classified as critical was found in Campcodes Online Marriage Registration System 1.0. This vulnerability affects unknown code of the file /user/search.php. The manipulation …

Mar 21, 2024
CVE-2024-2770
6.3 MEDIUM

A vulnerability was found in Campcodes Complete Online Beauty Parlor Management System 1.0. It has been rated as critical. Affected by this issue is some …

Mar 21, 2024
CVE-2024-2453
6.4 MEDIUM

There is an SQL injection vulnerability in Advantech WebAccess/SCADA software that allows an authenticated attacker to remotely inject SQL code in the database. Successful exploitation …

Mar 21, 2024
CVE-2024-28863
6.5 MEDIUM

node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. …

Mar 21, 2024
CVE-2024-28045
4.6 MEDIUM

Improper neutralization of input within the affected product could lead to cross-site scripting.

Mar 21, 2024
CVE-2023-42954
4.9 MEDIUM

A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in to the Admin Console with an administrator …

Mar 21, 2024
CVE-2024-2769
6.3 MEDIUM

A vulnerability was detected in Campcodes Complete Online Beauty Parlor Management System 1.0. The affected element is an unknown function of the file /admin/admin-profile.php. The …

Mar 21, 2024
CVE-2024-2768
6.3 MEDIUM

A vulnerability was found in Campcodes Complete Online Beauty Parlor Management System 1.0. It has been classified as critical. Affected is an unknown function of …

Mar 21, 2024
CVE-2024-2767
6.3 MEDIUM

A vulnerability was found in Campcodes Complete Online Beauty Parlor Management System 1.0 and classified as critical. This issue affects some unknown processing of the …

Mar 21, 2024
CVE-2024-2766
6.3 MEDIUM

A vulnerability has been found in Campcodes Complete Online Beauty Parlor Management System 1.0 and classified as critical. This vulnerability affects unknown code of the …

Mar 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.