CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-34537
4.9 MEDIUM

TYPO3 before 13.3.1 allows denial of service (interface error) in the Bookmark Toolbar (ext:backend), exploitable by an administrator-level backend user account via manipulated data saved …

Oct 28, 2024
CVE-2024-10455
7.5 HIGH

Reachable Assertion in BPv7 parser in µD3TN v0.14.0 allows attacker to disrupt service via malformed Extension Block

Oct 28, 2024
CVE-2024-10448
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank Management System 1.0. Affected by this issue is some unknown functionality …

Oct 28, 2024
CVE-2024-8013
2.2 LOW

A bug in query analysis of certain complex self-referential $lookup subpipelines may result in literal values in expressions for encrypted fields to be sent to …

Oct 28, 2024
CVE-2024-50582
4.6 MEDIUM

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements

Oct 28, 2024
CVE-2024-50581
4.6 MEDIUM

In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag

Oct 28, 2024
CVE-2024-50580
4.6 MEDIUM

In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule

Oct 28, 2024
CVE-2024-50579
4.6 MEDIUM

In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible

Oct 28, 2024
CVE-2024-50578
4.6 MEDIUM

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page

Oct 28, 2024
CVE-2024-50577
4.6 MEDIUM

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings

Oct 28, 2024
CVE-2024-50576
4.6 MEDIUM

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest

Oct 28, 2024
CVE-2024-50575
5.4 MEDIUM

In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API

Oct 28, 2024
CVE-2024-50574
5.3 MEDIUM

In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality

Oct 28, 2024
CVE-2024-50573
4.3 MEDIUM

In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized services

Oct 28, 2024
CVE-2024-50502
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CozyThemes Cozy Blocks cozy-addons allows DOM-Based XSS.This issue affects Cozy Blocks: from n/a …

Oct 28, 2024
CVE-2024-50501
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Climax Themes Kata Plus kata-plus allows DOM-Based XSS.This issue affects Kata Plus: from …

Oct 28, 2024
CVE-2024-50497
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wdesco Advanced Online Ordering and Delivery Platform advanced-online-ordering-and-delivery-platform allows …

Oct 28, 2024
CVE-2024-50491
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MicahBlu RSVP ME rsvp-me allows SQL Injection.This issue affects RSVP ME: …

Oct 28, 2024
CVE-2024-50488
8.8 HIGH

Authentication Bypass Using an Alternate Path or Channel vulnerability in yespbs Token Login token-login allows Authentication Bypass.This issue affects Token Login: from n/a through <= …

Oct 28, 2024
CVE-2024-50483
9.8 CRITICAL

Authorization Bypass Through User-Controlled Key vulnerability in Tareq Hasan Meetup meetup allows Privilege Escalation.This issue affects Meetup: from n/a through <= 0.1.

Oct 28, 2024
CVE-2024-50479
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chenyenming Woocommerce Quote Calculator woo-quote-calculator-order allows Blind SQL Injection.This issue affects …

Oct 28, 2024
CVE-2024-50478
9.8 CRITICAL

Authentication Bypass by Primary Weakness vulnerability in Swoop 1-Click Login: Passwordless Authentication allows Authentication Bypass.This issue affects 1-Click Login: Passwordless Authentication: 1.4.5.

Oct 28, 2024
CVE-2024-50472
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in martindrapeau Amilia Store amilia-store allows Stored XSS.This issue affects Amilia Store: from n/a …

Oct 28, 2024
CVE-2024-50471
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in checklistcom Trip Plan tripplan allows DOM-Based XSS.This issue affects Trip Plan: from n/a …

Oct 28, 2024
CVE-2024-50470
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themes4WP Themes4WP YouTube External Subtitles themes4wp-youtube-external-subtitles allows DOM-Based XSS.This issue affects Themes4WP YouTube …

Oct 28, 2024
CVE-2024-50465
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP SEO – Calin Vingan Premium SEO Pack allows SQL Injection.This …

Oct 28, 2024
CVE-2024-50463
4.7 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.9.

Oct 28, 2024
CVE-2024-10447
6.3 MEDIUM

A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. Affected by this vulnerability is an unknown functionality of the …

Oct 28, 2024
CVE-2024-50498
10.0 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Ajit Bohra WP Query Console wp-query-console allows Code Injection.This issue affects WP Query Console: from …

Oct 28, 2024
CVE-2024-50492
8.3 HIGH

Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson ScottCart scottcart allows Code Injection.This issue affects ScottCart: from n/a through <= 1.1.

Oct 28, 2024
CVE-2024-50489
9.8 CRITICAL

Authentication Bypass Using an Alternate Path or Channel vulnerability in realtyworkstation Realty Workstation realty-workstation allows Authentication Bypass.This issue affects Realty Workstation: from n/a through <= …

Oct 28, 2024
CVE-2024-50487
9.8 CRITICAL

Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo MaanStore API maanstore-api allows Authentication Bypass.This issue affects MaanStore API: from n/a through <= …

Oct 28, 2024
CVE-2024-50486
9.8 CRITICAL

Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo Acnoo Flutter API acnoo-flutter-api allows Authentication Bypass.This issue affects Acnoo Flutter API: from n/a …

Oct 28, 2024
CVE-2024-50477
9.8 CRITICAL

Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentication Bypass.This issue affects Stacks Mobile App Builder: …

Oct 28, 2024
CVE-2024-50450
7.3 HIGH

Improper Control of Generation of Code ('Code Injection') vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Code Injection.This issue affects MDTF: from n/a through <= 1.3.3.4.

Oct 28, 2024
CVE-2024-50442
6.5 MEDIUM

Improper Restriction of XML External Entity Reference vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows XML Injection.This issue affects Royal Elementor Addons: from n/a …

Oct 28, 2024
CVE-2024-50416
8.8 HIGH

Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce wpc-shop-as-customer allows Object Injection.This issue affects WPC Shop as a Customer …

Oct 28, 2024
CVE-2024-50408
8.8 HIGH

Deserialization of Untrusted Data vulnerability in Bob Namaste! LMS namaste-lms allows Object Injection.This issue affects Namaste! LMS: from n/a through <= 2.6.3.

Oct 28, 2024
CVE-2024-48074
8.0 HIGH

An authorized RCE vulnerability exists in the DrayTek Vigor2960 router version 1.4.4, where an attacker can place a malicious command into the table parameter of …

Oct 28, 2024
CVE-2024-10446
6.3 MEDIUM

A vulnerability classified as critical has been found in Project Worlds Online Time Table Generator 1.0. Affected is an unknown function of the file /timetable/admin/admindashboard.php?info=add_course. …

Oct 28, 2024
CVE-2024-38821
9.1 CRITICAL

Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances. For this to impact an application, all …

Oct 28, 2024
CVE-2024-9162
7.2 HIGH

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing file type validation during the export …

Oct 28, 2024
CVE-2024-50307
5.5 MEDIUM

Use of potentially dangerous function issue exists in Chatwork Desktop Application (Windows) versions prior to 2.9.2. If a user clicks a specially crafted link in …

Oct 28, 2024
CVE-2024-48936
5.0 MEDIUM

SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. …

Oct 28, 2024
CVE-2024-10440
9.8 CRITICAL

The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL command to read, modify, and delete database …

Oct 28, 2024
CVE-2024-10439
5.3 MEDIUM

The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to access arbitrary …

Oct 28, 2024
CVE-2024-10438
7.5 HIGH

The eHRD CTMS from Sunnet has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to bypass authentication by satisfying specific conditions in order to access …

Oct 28, 2024
CVE-2024-23843
2.2 LOW

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Genians Genian NAC V5.0, Genians Genian NAC LTS V5.0.This issue affects …

Oct 28, 2024
CVE-2024-50067
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: uprobe: avoid out-of-bounds memory access of fetching args Uprobe needs to fetch args into a …

Oct 28, 2024
CVE-2024-10435
6.3 MEDIUM

A vulnerability was found in didi Super-Jacoco 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /cov/triggerEnvCov. The manipulation …

Oct 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.