CVE Database

59714+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-1908
6.3 MEDIUM

An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use the Enterprise Actions GitHub Connect download token to …

Mar 21, 2024
CVE-2024-1503
4.3 MEDIUM

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Mar 21, 2024
CVE-2024-1502
5.4 MEDIUM

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check …

Mar 21, 2024
CVE-2024-1450
6.4 MEDIUM

The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortcode in all versions up to, and including, 4.6.10 …

Mar 21, 2024
CVE-2024-1326
6.4 MEDIUM

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML Tag attributes in all versions up to, and including, 2.6.2 …

Mar 21, 2024
CVE-2024-1278
6.4 MEDIUM

The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Mar 21, 2024
CVE-2024-1214
4.3 MEDIUM

The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all …

Mar 21, 2024
CVE-2024-1213
5.4 MEDIUM

The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all …

Mar 21, 2024
CVE-2024-1142
5.4 MEDIUM

Path Traversal in Sonatype IQ Server from version 143 allows remote authenticated attackers to overwrite or delete files via a specially crafted request. Version 171 …

Mar 21, 2024
CVE-2024-0966
6.4 MEDIUM

The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortcode in all versions up to, and including, 4.6.9 …

Mar 21, 2024
CVE-2023-6500
6.4 MEDIUM

The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortcode in all versions up to, and including, 4.6.9 …

Mar 21, 2024
CVE-2023-49985
6.5 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via …

Mar 21, 2024
CVE-2023-49984
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /management/settings of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via …

Mar 21, 2024
CVE-2023-49983
6.8 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via …

Mar 21, 2024
CVE-2023-38825
6.5 MEDIUM

SQL injection vulnerability in Vanderbilt REDCap before v.13.8.0 allows a remote attacker to obtain sensitive information via the password reset mechanism in MyCapMobileApp/update.php.

Mar 21, 2024
CVE-2022-4963
5.5 MEDIUM

A vulnerability was found in Folio Spring Module Core up to 1.1.5. It has been rated as critical. Affected by this issue is the function …

Mar 21, 2024
CVE-2024-2748
4.3 MEDIUM

A Cross Site Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker to execute unauthorized actions on behalf of an unsuspecting …

Mar 21, 2024
CVE-2024-24050
4.7 MEDIUM

Cross Site Scripting (XSS) vulnerability in Sourcecodester Workout Journal App 1.0 allows attackers to run arbitrary code via parameters firstname and lastname in /add-user.php.

Mar 20, 2024
CVE-2024-29474
5.4 MEDIUM

OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the User Management module.

Mar 20, 2024
CVE-2024-29473
6.1 MEDIUM

OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Role Management module.

Mar 20, 2024
CVE-2024-29472
5.4 MEDIUM

OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Privilege Management module.

Mar 20, 2024
CVE-2024-29471
5.4 MEDIUM

OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Notice Manage module.

Mar 20, 2024
CVE-2024-29470
6.1 MEDIUM

OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component {{rootpath}}/links.

Mar 20, 2024
CVE-2024-29469
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in OneBlog v2.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

Mar 20, 2024
CVE-2024-29036
4.3 MEDIUM

Saleor Storefront is software for building e-commerce experiences. Prior to commit 579241e75a5eb332ccf26e0bcdd54befa33f4783, when any user authenticates in the storefront, anonymous users are able to access …

Mar 20, 2024
CVE-2024-29032
5.3 MEDIUM

Qiskit IBM Runtime is an environment that streamlines quantum computations and provides optimal implementations of the Qiskit quantum computing SDK. Starting in version 0.1.0 and …

Mar 20, 2024
CVE-2024-29018
5.9 MEDIUM

Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. …

Mar 20, 2024
CVE-2024-2714
6.3 MEDIUM

A vulnerability has been found in Campcodes Complete Online DJ Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality …

Mar 20, 2024
CVE-2024-27286
6.5 MEDIUM

Zulip is an open-source team collaboration tool. When a user moves a Zulip message, they have the option to move all messages in the topic, …

Mar 20, 2024
CVE-2024-23821
4.8 MEDIUM

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A stored cross-site scripting (XSS) vulnerability …

Mar 20, 2024
CVE-2024-23819
4.8 MEDIUM

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A stored cross-site scripting (XSS) vulnerability …

Mar 20, 2024
CVE-2024-23818
4.8 MEDIUM

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A stored cross-site scripting (XSS) vulnerability …

Mar 20, 2024
CVE-2024-23643
4.8 MEDIUM

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A stored cross-site scripting (XSS) vulnerability …

Mar 20, 2024
CVE-2024-23642
4.8 MEDIUM

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A stored cross-site scripting (XSS) vulnerability …

Mar 20, 2024
CVE-2023-45177
5.3 MEDIUM

IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD is vulnerable to a denial-of-service attack due to an error within the …

Mar 20, 2024
CVE-2024-2707
6.3 MEDIUM

A vulnerability has been found in Tenda AC10U 15.03.06.49 and classified as critical. This vulnerability affects the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation …

Mar 20, 2024
CVE-2024-2631
4.3 MEDIUM

Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Mar 20, 2024
CVE-2024-2630
6.5 MEDIUM

Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security …

Mar 20, 2024
CVE-2024-2629
4.3 MEDIUM

Incorrect security UI in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium …

Mar 20, 2024
CVE-2024-2628
4.3 MEDIUM

Inappropriate implementation in Downloads in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted URL. (Chromium security severity: …

Mar 20, 2024
CVE-2024-2626
6.5 MEDIUM

Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a …

Mar 20, 2024
CVE-2024-23640
4.8 MEDIUM

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A stored cross-site scripting (XSS) vulnerability …

Mar 20, 2024
CVE-2024-23634
6.0 MEDIUM

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. An arbitrary file renaming vulnerability exists …

Mar 20, 2024
CVE-2023-51445
4.8 MEDIUM

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A stored cross-site scripting (XSS) vulnerability …

Mar 20, 2024
CVE-2024-2291
4.3 MEDIUM

In Progress MOVEit Transfer versions released before 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4), a logging bypass vulnerability has been discovered. An authenticated user …

Mar 20, 2024
CVE-2024-29419
5.4 MEDIUM

There is a Cross-site scripting (XSS) vulnerability in the Wireless settings under the Easy Setup Page of TOTOLINK X2000R before v1.0.0-B20231213.1013.

Mar 20, 2024
CVE-2023-35888
5.9 MEDIUM

IBM Security Verify Governance 10.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. …

Mar 20, 2024
CVE-2023-52229
6.5 MEDIUM

Missing Authorization vulnerability in Save as PDF plugin by Pdfcrowd Word Replacer Pro.This issue affects Word Replacer Pro: from n/a through 1.0.

Mar 20, 2024
CVE-2023-46841
6.5 MEDIUM

Recent x86 CPUs offer functionality named Control-flow Enforcement Technology (CET). A sub-feature of this are Shadow Stacks (CET-SS). CET-SS is a hardware feature designed to …

Mar 20, 2024
CVE-2023-46840
4.1 MEDIUM

Incorrect placement of a preprocessor directive in source code results in logic that doesn't operate as intended when support for HVM guests is compiled out …

Mar 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.