CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8874
6.1 MEDIUM

The AJAX Login and Registration modal popup + inline form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg …

Nov 13, 2024
CVE-2024-39712
9.1 CRITICAL

Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin …

Nov 13, 2024
CVE-2024-39711
9.1 CRITICAL

Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin …

Nov 13, 2024
CVE-2024-39710
9.1 CRITICAL

Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin …

Nov 13, 2024
CVE-2024-39709
7.8 HIGH

Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1 (Not Applicable to 9.1Rx) …

Nov 13, 2024
CVE-2024-38656
9.1 CRITICAL

Argument injection in Ivanti Connect Secure before version 22.7R2.2 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin …

Nov 13, 2024
CVE-2024-38655
7.2 HIGH

Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.1 and 9.1R18.9 allows a remote authenticated attacker …

Nov 13, 2024
CVE-2024-38654
4.4 MEDIUM

Improper bounds checking in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker with admin privileges to cause a denial of service.

Nov 13, 2024
CVE-2024-38649
7.5 HIGH

An out-of-bounds write in IPsec of Ivanti Connect Secure before version 22.7R2.1(Not Applicable to 9.1Rx) allows a remote unauthenticated attacker to cause a denial of …

Nov 13, 2024
CVE-2024-37400
7.5 HIGH

An out of bounds read in Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to trigger an infinite loop, causing a denial …

Nov 13, 2024
CVE-2024-37398
7.8 HIGH

Insufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.

Nov 13, 2024
CVE-2024-37376
7.2 HIGH

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges …

Nov 13, 2024
CVE-2024-34787
7.8 HIGH

Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code …

Nov 13, 2024
CVE-2024-34784
7.2 HIGH

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges …

Nov 13, 2024
CVE-2024-34782
7.2 HIGH

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges …

Nov 13, 2024
CVE-2024-34781
7.2 HIGH

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges …

Nov 13, 2024
CVE-2024-34780
7.2 HIGH

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges …

Nov 13, 2024
CVE-2024-32847
7.2 HIGH

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges …

Nov 13, 2024
CVE-2024-32844
7.2 HIGH

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges …

Nov 13, 2024
CVE-2024-32841
7.2 HIGH

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges …

Nov 13, 2024
CVE-2024-32839
7.2 HIGH

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges …

Nov 13, 2024
CVE-2024-29211
4.7 MEDIUM

A race condition in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to modify sensitive configuration files.

Nov 13, 2024
CVE-2024-10887
6.4 MEDIUM

The NiceJob plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes (nicejob-lead, nicejob-review, nicejob-engage, nicejob-badge, nicejob-stories) in all versions …

Nov 13, 2024
CVE-2024-10854
4.3 MEDIUM

The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the buy_one_click_import_options AJAX …

Nov 13, 2024
CVE-2024-10853
4.3 MEDIUM

The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the removeorder AJAX …

Nov 13, 2024
CVE-2024-10852
4.3 MEDIUM

The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the buy_one_click_export_options AJAX …

Nov 13, 2024
CVE-2024-10851
6.1 MEDIUM

The Razorpay Payment Button Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping …

Nov 13, 2024
CVE-2024-10850
6.1 MEDIUM

The Razorpay Payment Button Elementor Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate …

Nov 13, 2024
CVE-2024-10778
4.3 MEDIUM

The BuddyPress Builder for Elementor – BuddyBuilder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.4 via the …

Nov 13, 2024
CVE-2024-10717
6.5 MEDIUM

The Styler for Ninja Forms plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to …

Nov 13, 2024
CVE-2024-10629
8.8 HIGH

The GPX Viewer plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check and file type validation in the gpxv_file_upload() …

Nov 13, 2024
CVE-2024-10577
6.1 MEDIUM

The 胖鼠采集(Fat Rat Collect) 微信知乎简书腾讯新闻列表分页采集, 还有自动采集、自动发布、自动标签、等多项功能。开源插件 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to missing escaping on a URL in all versions …

Nov 13, 2024
CVE-2024-10038
6.1 MEDIUM

The WP-Strava plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.12.1 due to insufficient …

Nov 13, 2024
CVE-2024-28731
4.3 MEDIUM

Cross Site Request Forgery vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker …

Nov 12, 2024
CVE-2024-28730
5.4 MEDIUM

Cross Site Scripting vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to …

Nov 12, 2024
CVE-2024-28729
9.8 CRITICAL

An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to execute arbitrary …

Nov 12, 2024
CVE-2024-28728
6.6 MEDIUM

Cross Site Scripting vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to …

Nov 12, 2024
CVE-2024-28726
8.0 HIGH

An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to execute arbitrary …

Nov 12, 2024
CVE-2021-27704
6.5 MEDIUM

Appspace 6.2.4 is affected by Incorrect Access Control via the Appspace Web Portal password reset page.

Nov 12, 2024
CVE-2021-27703
5.4 MEDIUM

Sercomm Model Etisalat Model S3- AC2100 is affected by Cross Site Scripting (XSS) via the firmware update page.

Nov 12, 2024
CVE-2021-27702
7.3 HIGH

Sercomm Router Etisalat Model S3- AC2100 is affected by Incorrect Access Control via the diagnostic utility in the router dashboard.

Nov 12, 2024
CVE-2021-27701
4.7 MEDIUM

SOCIFI Socifi Guest wifi as SAAS is affected by Cross Site Request Forgery (CSRF) via the Socifi wifi portal. The application does not contain a …

Nov 12, 2024
CVE-2021-27700
7.6 HIGH

SOCIFI Socifi Guest wifi as SAAS wifi portal is affected by Insecure Permissions. Any authorized customer with partner mode can switch to another customer dashboard …

Nov 12, 2024
CVE-2024-51179
7.5 HIGH

An issue in Open 5GS v.2.7.1 allows a remote attacker to cause a denial of service via the Network Function Virtualizations (NFVs) such as the …

Nov 12, 2024
CVE-2024-48075
5.3 MEDIUM

A Heap buffer overflow in the server-site handshake implementation in Real Time Logic SharkSSL from 09/09/24 and earlier allows a remote attacker to trigger a …

Nov 12, 2024
CVE-2024-11168
3.7 LOW

The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 …

Nov 12, 2024
CVE-2024-51094
8.0 HIGH

An issue in Snipe-IT v.7.0.13 build 15514 allows a low-privileged attacker to modify their profile name and inject a malicious payload into the "Name" field. …

Nov 12, 2024
CVE-2024-51093
8.7 HIGH

Stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT - v7.0.13 allows an attacker to upload a malicious XML file containing JavaScript code. This can lead to …

Nov 12, 2024
CVE-2024-49512
5.5 MEDIUM

InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Nov 12, 2024
CVE-2024-49511
5.5 MEDIUM

InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Nov 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.