CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-51512
6.2 MEDIUM

Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulnerability may affect availability.

Nov 5, 2024
CVE-2024-51511
6.2 MEDIUM

Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulnerability may affect availability.

Nov 5, 2024
CVE-2024-51510
7.6 HIGH

Out-of-bounds access vulnerability in the logo module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 5, 2024
CVE-2024-10711
8.8 HIGH

The WooCommerce Report plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.1. This is due to missing …

Nov 5, 2024
CVE-2024-10114
8.1 HIGH

The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.7.7. This is due to …

Nov 5, 2024
CVE-2024-47797
8.4 HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through out-of-bounds write.

Nov 5, 2024
CVE-2024-47404
8.4 HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through double free.

Nov 5, 2024
CVE-2024-47402
3.3 LOW

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through out-of-bounds read.

Nov 5, 2024
CVE-2024-47137
8.4 HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through out-of-bounds write.

Nov 5, 2024
CVE-2024-10097
8.1 HIGH

The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication bypass in all versions up to, and including, 1.9.2. This is due to …

Nov 5, 2024
CVE-2024-9883
4.8 MEDIUM

The Pods WordPress plugin before 3.2.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Nov 5, 2024
CVE-2024-9689
4.3 MEDIUM

The Post From Frontend WordPress plugin through 1.0.0 does not have CSRF check when deleting posts, which could allow attackers to make logged in admin …

Nov 5, 2024
CVE-2024-9459
8.3 HIGH

Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in reports module.

Nov 5, 2024
CVE-2024-7877
4.8 MEDIUM

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Notification settings, which …

Nov 5, 2024
CVE-2024-7876
4.8 MEDIUM

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Appointment Type settings, …

Nov 5, 2024
CVE-2024-5578
4.8 MEDIUM

The Table of Contents Plus WordPress plugin through 2408 does not sanitise and escape some of its settings, which could allow high privilege users such …

Nov 5, 2024
CVE-2024-10810
6.3 MEDIUM

A vulnerability was found in code-projects E-Health Care System 1.0. It has been classified as critical. Affected is an unknown function of the file Doctor/app_request.php. …

Nov 5, 2024
CVE-2024-10809
6.3 MEDIUM

A vulnerability was found in code-projects E-Health Care System 1.0 and classified as critical. This issue affects some unknown processing of the file /Doctor/chat.php. The …

Nov 5, 2024
CVE-2024-10808
6.3 MEDIUM

A vulnerability has been found in code-projects E-Health Care System 1.0 and classified as critical. This vulnerability affects unknown code of the file Admin/req_detail.php. The …

Nov 5, 2024
CVE-2024-10807
2.4 LOW

A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been rated as problematic. This issue affects some unknown processing of the file …

Nov 5, 2024
CVE-2024-10340
6.4 MEDIUM

The Shortcodes Blocks Creator Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'scu' shortcode in versions up to, and including, 2.1.3 due …

Nov 5, 2024
CVE-2024-10806
2.4 LOW

A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as problematic. This vulnerability affects unknown code of the file betweendates-detailsreports.php. …

Nov 5, 2024
CVE-2024-51498

cobalt is a media downloader that doesn't piss you off. A malicious cobalt instance could serve links with the `javascript:` protocol, resulting in Cross-site Scripting …

Nov 5, 2024
CVE-2024-50346

WebFeed is a lightweight web feed reader extension for Firefox/Chrome. Multiple HTML injection vulnerabilities in WebFeed can lead to CSRF and UI spoofing attacks. A …

Nov 5, 2024
CVE-2024-32870
5.8 MEDIUM

Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and parameters) can be read …

Nov 5, 2024
CVE-2024-31998
8.8 HIGH

Combodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV import simulation. This issue has been fixed …

Nov 5, 2024
CVE-2024-31448
8.8 HIGH

Combodo iTop is a simple, web based IT Service Management tool. By filling malicious code in a CSV content, an Cross-site Scripting (XSS) attack can …

Nov 5, 2024
CVE-2023-34445
8.8 HIGH

Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.render.php XSS are possible for scripts outside of script tags. This issue …

Nov 5, 2024
CVE-2023-34444
8.8 HIGH

Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.searchform.php XSS are possible for scripts outside of script tags. This issue …

Nov 5, 2024
CVE-2023-34443
8.8 HIGH

Combodo iTop is a simple, web based IT Service Management tool. When displaying page Run queries Cross-site Scripting (XSS) are possible for scripts outside of …

Nov 5, 2024
CVE-2024-51734

Zope AccessControl provides a general security framework for use in Zope. In affected versions anonymous users can delete the user data maintained by an `AccessControl.userfolder.UserFolder` …

Nov 4, 2024
CVE-2024-51502

loona is an experimental, HTTP/1.1 and HTTP/2 implementation in Rust on top of io-uring. `loona-hpack` suffers from the same vulnerability as the original `hpack` as …

Nov 4, 2024
CVE-2024-51501

Refit is an automatic type-safe REST library for .NET Core, Xamarin and .NET The various header-related Refit attributes (Header, HeaderCollection and Authorize) are vulnerable to …

Nov 4, 2024
CVE-2024-51500
5.3 MEDIUM

Meshtastic firmware is a device firmware for the Meshtastic project. The Meshtastic firmware does not check for packets claiming to be from the special broadcast …

Nov 4, 2024
CVE-2024-48061
9.8 CRITICAL

langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the components run on the local machine rather …

Nov 4, 2024
CVE-2024-48059
6.1 MEDIUM

gaizhenbiao/chuanhuchatgpt project, version <=20240802 is vulnerable to stored Cross-Site Scripting (XSS) in WebSocket session transmission. An attacker can inject malicious content into a WebSocket message. …

Nov 4, 2024
CVE-2024-48057
6.1 MEDIUM

localai <=2.20.1 is vulnerable to Cross Site Scripting (XSS). When calling the delete model API and passing inappropriate parameters, it can cause a one-time storage …

Nov 4, 2024
CVE-2024-48052
6.5 MEDIUM

In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no …

Nov 4, 2024
CVE-2024-48050
9.8 CRITICAL

In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this function, the line result = eval(s) poses a security risk as it can …

Nov 4, 2024
CVE-2024-10805
6.3 MEDIUM

A vulnerability was found in code-projects University Event Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Nov 4, 2024
CVE-2024-51744
3.1 LOW

golang-jwt is a Go implementation of JSON Web Tokens. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are potentially …

Nov 4, 2024
CVE-2024-48463
6.5 MEDIUM

Bruno before 1.29.1 uses Electron shell.openExternal without validation (of http or https) for opening windows within the Markdown docs viewer.

Nov 4, 2024
CVE-2024-45185
5.1 MEDIUM

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, …

Nov 4, 2024
CVE-2024-45086
5.5 MEDIUM

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could …

Nov 4, 2024
CVE-2024-10791
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Codezips Hospital Appointment System 1.0. This issue affects some unknown processing of the file …

Nov 4, 2024
CVE-2024-34891
6.8 MEDIUM

Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read Exchange account passwords via HTTP GET request.

Nov 4, 2024
CVE-2024-34885
6.8 MEDIUM

Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read SMTP accounts passwords via HTTP GET request.

Nov 4, 2024
CVE-2024-30619
7.5 HIGH

Chamilo LMS Version 1.11.26 is vulnerable to Incorrect Access Control. A non-authenticated attacker can request the number of messages and the number of online users …

Nov 4, 2024
CVE-2024-30618
6.1 MEDIUM

A Stored Cross-Site Scripting (XSS) Vulnerability in Chamilo LMS 1.11.26 allows a remote attacker to execute arbitrary JavaScript in a web browser by including a …

Nov 4, 2024
CVE-2024-30617
5.4 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 "/main/social/home.php," allows attackers to initiate a request that posts a fake post onto the user's …

Nov 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.