CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10113
6.4 MEDIUM

The WP AdCenter – Ad Manager & Adsense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpadcenter_ad shortcode in all …

Nov 15, 2024
CVE-2024-9609
6.1 MEDIUM

The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'learnpress_import_form_server' parameter in all versions …

Nov 15, 2024
CVE-2024-10897
4.3 MEDIUM

The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the install_etlms_dependency_plugin() function in …

Nov 15, 2024
CVE-2024-10924
9.8 CRITICAL

The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due …

Nov 15, 2024
CVE-2024-11120
9.8 CRITICAL KEV

Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on …

Nov 15, 2024
CVE-2024-52613
5.5 MEDIUM

A heap-based buffer under-read in tsMuxer version nightly-2024-05-12-02-01-18 allows attackers to cause Denial of Service (DoS) via a crafted MOV video file.

Nov 14, 2024
CVE-2024-52308
8.0 HIGH

The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code execution through a malicious codespace SSH server when using `gh codespace ssh` or …

Nov 14, 2024
CVE-2024-49778
8.8 HIGH

A heap-based buffer overflow in tsMuxer version nightly-2024-05-12-02-01-18 allows attackers to cause Denial of Service (DoS) and Code Execution via a crafted MOV video file.

Nov 14, 2024
CVE-2024-49777
8.8 HIGH

A heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service (DoS), Information Disclosure and Code Execution via a crafted MKV …

Nov 14, 2024
CVE-2024-49776
6.5 MEDIUM

A negative-size-param in tsMuxer version nightly-2024-04-05-01-53-02 allows attackers to cause Denial of Service (DoS) via a crafted TS video file.

Nov 14, 2024
CVE-2024-41217
6.5 MEDIUM

A heap-based buffer overflow in tsMuxer version nightly-2024-05-10-02-00-45 allows attackers to cause Denial of Service (DoS) via a crafted MKV video file.

Nov 14, 2024
CVE-2024-41209
8.8 HIGH

A heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service (DoS) and Code Execution via a crafted MOV video file.

Nov 14, 2024
CVE-2024-41206
6.5 MEDIUM

A stack-based buffer over-read in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Information Disclosure via a crafted TS video file.

Nov 14, 2024
CVE-2017-13227
5.5 MEDIUM

In the autofill service, the package name that is provided by the app process is trusted inappropriately. This could lead to information disclosure with no …

Nov 14, 2024
CVE-2024-51679
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in gentlesource Appointmind appointmind allows Stored XSS.This issue affects Appointmind: from n/a through <= 4.0.0.

Nov 14, 2024
CVE-2024-51659
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in GeekRMX Twitter @Anywhere Plus twitter-anywhere-plus allows Stored XSS.This issue affects Twitter @Anywhere Plus: from n/a through <= 2.0.

Nov 14, 2024
CVE-2024-51658
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Henrik Hoff WP Course Manager wp-course-manager allows Stored XSS.This issue affects WP Course Manager: from n/a through <= 1.3.

Nov 14, 2024
CVE-2024-51156
4.7 MEDIUM

07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component 'erp.07fly.net:80/admin/SysNotifyUser/del.html?id=93'.

Nov 14, 2024
CVE-2024-50968
7.5 HIGH

A business logic vulnerability exists in the Add to Cart function of itsourcecode Agri-Trading Online Shopping System 1.0, which allows remote attackers to manipulate the …

Nov 14, 2024
CVE-2024-48974
9.3 CRITICAL

The ventilator does not perform proper file integrity checks when adopting firmware updates. This makes it possible for an attacker to force unauthorized changes to …

Nov 14, 2024
CVE-2024-48973
9.3 CRITICAL

The debug port on the ventilator's serial interface is enabled by default. This could allow an attacker to send and receive messages over the debug …

Nov 14, 2024
CVE-2024-48971
9.3 CRITICAL

The Clinician Password and Serial Number Clinician Password are hard-coded into the ventilator in plaintext form. This could allow an attacker to obtain the password …

Nov 14, 2024
CVE-2024-48970
9.3 CRITICAL

The ventilator's microcontroller lacks memory protection. An attacker could connect to the internal JTAG interface and read or write to flash memory using an off-the-shelf …

Nov 14, 2024
CVE-2024-48967
10.0 CRITICAL

The ventilator and the Service PC lack sufficient audit logging capabilities to allow for detection of malicious activity and subsequent forensic examination. An attacker with …

Nov 14, 2024
CVE-2024-48966
10.0 CRITICAL

The software tools used by service personnel to test & calibrate the ventilator do not support user authentication. An attacker with access to the Service …

Nov 14, 2024
CVE-2024-40579
5.4 MEDIUM

Cross Site Scripting vulnerability in Virtuozzo Hybrid Server for WHMCS Open Source v.1.7.1 allows a remote attacker to obtain sensitive information via modification of the …

Nov 14, 2024
CVE-2024-39707
5.3 MEDIUM

Insyde IHISI function 0x49 can restore factory defaults for certain UEFI variables without further authentication by default, which could lead to a possible roll-back attack …

Nov 14, 2024
CVE-2024-31695
9.8 CRITICAL

A misconfiguration in the fingerprint authentication mechanism of Binance: BTC, Crypto and NFTS v2.85.4, allows attackers to bypass authentication when adding a new fingerprint.

Nov 14, 2024
CVE-2024-9834
9.3 CRITICAL

Improper data protection on the ventilator's serial interface could allow an attacker to send and receive messages that result in unauthorized disclosure of information and/or …

Nov 14, 2024
CVE-2024-9832
9.3 CRITICAL

There is no limit on the number of failed login attempts permitted with the Clinician Password or the Serial Number Clinician Password. An attacker could …

Nov 14, 2024
CVE-2024-51687
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Platform.ly Platform.ly Official platformly allows Stored XSS.This issue affects Platform.ly Official: from n/a through <= 1.1.3.

Nov 14, 2024
CVE-2024-51684
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu W3P SEO wp-perfect-plugin allows Stored XSS.This issue affects W3P SEO: from n/a through < 1.8.6.

Nov 14, 2024
CVE-2024-51688
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in fraudlabspro FraudLabs Pro SMS Verification fraudlabs-pro-sms-verification allows Stored XSS.This issue affects FraudLabs Pro SMS Verification: from n/a through <= …

Nov 14, 2024
CVE-2024-49025
5.4 MEDIUM

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Nov 14, 2024
CVE-2024-10397
7.8 HIGH

A malicious server can crash the OpenAFS cache manager and other client utilities, and possibly execute arbitrary code.

Nov 14, 2024
CVE-2024-10396
6.5 MEDIUM

An authenticated user can provide a malformed ACL to the fileserver's StoreACL RPC, causing the fileserver to crash, possibly expose uninitialized memory, and possibly store …

Nov 14, 2024
CVE-2024-10394
7.8 HIGH

A local user can bypass the OpenAFS PAG (Process Authentication Group) throttling mechanism in Unix clients, allowing the user to create a PAG using an …

Nov 14, 2024
CVE-2024-52370
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Hive Support Hive Support hive-support allows Upload a Web Shell to a Web Server.This issue affects …

Nov 14, 2024
CVE-2024-52369
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Optimal Access KBucket kbucket allows Upload a Web Shell to a Web Server.This issue affects KBucket: …

Nov 14, 2024
CVE-2024-3760
7.5 HIGH

In lunary-ai/lunary version 1.2.7, there is a lack of rate limiting on the forgot password page, leading to an email bombing vulnerability. Attackers can exploit …

Nov 14, 2024
CVE-2024-5125
7.3 HIGH

parisneo/lollms-webui version 9.6 is vulnerable to Cross-Site Scripting (XSS) and Open Redirect due to inadequate input validation and processing of SVG files during the upload …

Nov 14, 2024
CVE-2024-52524

Giskard is an evaluation and testing framework for AI systems. A Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security …

Nov 14, 2024
CVE-2024-52396
4.9 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-editor allows Path Traversal.This issue affects WOLF: from n/a through …

Nov 14, 2024
CVE-2024-52393
9.1 CRITICAL

Deserialization of Untrusted Data vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress.This issue affects Podlove Podcast Publisher: from n/a through <= 4.1.15.

Nov 14, 2024
CVE-2024-52384
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in wpmonks Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, Dalle-3 Image Generation ai-content-generator allows Upload a Web …

Nov 14, 2024
CVE-2024-52383
7.5 HIGH

Missing Authorization vulnerability in aitool Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One ai-auto-tool allows Exploiting Incorrectly Configured Access Control …

Nov 14, 2024
CVE-2024-52382
9.8 CRITICAL

Missing Authorization vulnerability in medmatech Matix Popup Builder medma-matix allows Privilege Escalation.This issue affects Matix Popup Builder: from n/a through <= 1.0.0.

Nov 14, 2024
CVE-2024-52381
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Shoaib Rehmat ZIJ KART zij-kart allows PHP Local File …

Nov 14, 2024
CVE-2024-52380
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in softpulseinfotech Picsmize picsmize allows Upload a Web Shell to a Web Server.This issue affects Picsmize: from …

Nov 14, 2024
CVE-2024-52379
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in faizalbahasan kineticPay for WooCommerce kineticpay-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects …

Nov 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.