CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9477
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AirTies Air4443 Firmware allows Cross-Site Scripting (XSS).This issue affects Air4443 Firmware: …

Nov 13, 2024
CVE-2024-50854
8.8 HIGH

Tenda G3 v3.0 v15.11.0.20 was discovered to contain a stack overflow via the formSetPortMapping function.

Nov 13, 2024
CVE-2024-50853
8.8 HIGH

Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetDebugCfg function.

Nov 13, 2024
CVE-2024-50852
8.8 HIGH

Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetUSBPartitionUmount function.

Nov 13, 2024
CVE-2024-49506

Insecure creation of temporary files allows local users on systems with non-default configurations to cause denial of service or set the encryption key for a …

Nov 13, 2024
CVE-2024-49505
6.1 MEDIUM

A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in openSUSE Tumbleweed MirrorCache allows the execution of arbitrary JS via reflected XSS …

Nov 13, 2024
CVE-2024-49504

grub2 allowed attackers with access to the grub shell to access files on the encrypted disks.

Nov 13, 2024
CVE-2024-48900
4.3 MEDIUM

A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipients can only access lists of those …

Nov 13, 2024
CVE-2024-48510
9.8 CRITICAL

Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code via the src/Zip.Shared/ZipEntry.Extract.cs component NOTE: This vulnerability only affects …

Nov 13, 2024
CVE-2024-11165

An information disclosure vulnerability exists in the backup configuration process where the SAS token is not masked in the configuration response. This oversight results in …

Nov 13, 2024
CVE-2024-48989
7.5 HIGH

A vulnerability in the PROFINET stack implementation of the IndraDrive (all versions) of Bosch Rexroth allows an attacker to cause a denial of service, rendering …

Nov 13, 2024
CVE-2024-11159
4.3 MEDIUM

Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird < 128.4.3 and Thunderbird < 132.0.1.

Nov 13, 2024
CVE-2022-45157
9.1 CRITICAL

A vulnerability has been identified in the way that Rancher stores vSphere's CPI (Cloud Provider Interface) and CSI (Container Storage Interface) credentials used to deploy …

Nov 13, 2024
CVE-2024-47574
7.8 HIGH

A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0, and 6.4.10 through …

Nov 13, 2024
CVE-2024-4741
7.5 HIGH

Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously freed in some situations Impact summary: A use …

Nov 13, 2024
CVE-2024-8001
5.3 MEDIUM

A vulnerability was found in VIWIS LMS 9.11. It has been classified as critical. Affected is an unknown function of the component Print Handler. The …

Nov 13, 2024
CVE-2024-11028
9.8 CRITICAL

The MultiManager WP – Manage All Your WordPress Sites Easily plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, …

Nov 13, 2024
CVE-2024-9682
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Form Builder widget in all versions up …

Nov 13, 2024
CVE-2024-9668
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, …

Nov 13, 2024
CVE-2024-9059
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps widget in all versions up to, …

Nov 13, 2024
CVE-2024-10877
6.1 MEDIUM

The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without …

Nov 13, 2024
CVE-2024-52268
4.8 MEDIUM

Cross-site scripting vulnerability exists in VK All in One Expansion Unit versions prior to 9.100.1.0. If this vulnerability is exploited, an arbitrary script may be …

Nov 13, 2024
CVE-2024-9409
7.5 HIGH

CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive resulting in communication loss when a large amount of IGMP …

Nov 13, 2024
CVE-2024-8938
8.1 HIGH

CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a potential arbitrary code execution after a successful …

Nov 13, 2024
CVE-2024-8937
6.5 MEDIUM

CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a potential arbitrary code execution after a successful …

Nov 13, 2024
CVE-2024-8936
6.5 MEDIUM

CWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory after a successful Man-In-The-Middle attack followed by sending a …

Nov 13, 2024
CVE-2024-8935
7.5 HIGH

CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss of confidentiality and integrity of controllers when conducting a …

Nov 13, 2024
CVE-2024-21541
7.3 HIGH

Versions of the package dom-iterator before 1.0.1 are vulnerable to Arbitrary Code Execution due to use of the Function constructor without complete input sanitization. Function …

Nov 13, 2024
CVE-2024-21540

Rejected reason: This issue is not a vulnerability because no real attack scenario can happen.

Nov 13, 2024
CVE-2024-11150
9.8 CRITICAL

The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_tmp_uploaded_file() function in …

Nov 13, 2024
CVE-2024-10800
8.8 HIGH

The WordPress User Extra Fields plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the ajax_save_fields() function in all …

Nov 13, 2024
CVE-2024-10575
9.8 CRITICAL

CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connected devices.

Nov 13, 2024
CVE-2024-8933
7.5 HIGH

CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause retrieval of password hash that could lead to …

Nov 13, 2024
CVE-2024-10828
8.1 HIGH

The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.5 via deserialization …

Nov 13, 2024
CVE-2024-10820
9.8 CRITICAL

The WooCommerce Upload Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all …

Nov 13, 2024
CVE-2024-10816
7.5 HIGH

The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.24.01.24 via the js/fallback.php file. This …

Nov 13, 2024
CVE-2024-10802
5.3 MEDIUM

The Hash Elements plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hash_elements_get_posts_title_by_id() function in all …

Nov 13, 2024
CVE-2024-10794
4.3 MEDIUM

The Boostify Header Footer Builder for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.6 via the …

Nov 13, 2024
CVE-2024-10174
7.3 HIGH

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Insecure Direct …

Nov 13, 2024
CVE-2024-11143
4.3 MEDIUM

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.8. This is due …

Nov 13, 2024
CVE-2024-10882
6.1 MEDIUM

The Product Delivery Date for WooCommerce – Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg …

Nov 13, 2024
CVE-2024-10684
6.1 MEDIUM

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dir' parameter in all versions up to, and including, …

Nov 13, 2024
CVE-2024-10593
4.3 MEDIUM

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Cross-Site Request Forgery …

Nov 13, 2024
CVE-2024-10531
5.3 MEDIUM

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_assistant() function …

Nov 13, 2024
CVE-2024-10530
4.3 MEDIUM

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the add_new_assistant() function …

Nov 13, 2024
CVE-2024-10529
5.3 MEDIUM

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_assistant() function …

Nov 13, 2024
CVE-2024-9614
6.1 MEDIUM

The Constant Contact Forms by MailMunch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on …

Nov 13, 2024
CVE-2024-9578
5.3 MEDIUM

The Hide Links plugin for WordPress is vulnerable to unauthorized shortcode execution due to do_shortcode being hooked through the comment_text filter in all versions up …

Nov 13, 2024
CVE-2024-9426
6.4 MEDIUM

The Aqua SVG Sprite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.0.14 …

Nov 13, 2024
CVE-2024-8985
6.4 MEDIUM

The Social Proof (Testimonial) Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's spslider-block shortcode in all versions up to, and …

Nov 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.