CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-20099
6.7 MEDIUM

In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Oct 7, 2024
CVE-2024-20098
6.7 MEDIUM

In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Oct 7, 2024
CVE-2024-20097
4.4 MEDIUM

In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Oct 7, 2024
CVE-2024-20096
4.4 MEDIUM

In m4u, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Oct 7, 2024
CVE-2024-20095
4.4 MEDIUM

In m4u, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Oct 7, 2024
CVE-2024-20094
7.5 HIGH

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional …

Oct 7, 2024
CVE-2024-20093
4.4 MEDIUM

In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Oct 7, 2024
CVE-2024-20092
7.8 HIGH

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Oct 7, 2024
CVE-2024-20091
4.4 MEDIUM

In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Oct 7, 2024
CVE-2024-20090
6.7 MEDIUM

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Oct 7, 2024
CVE-2024-9565
8.8 HIGH

A vulnerability has been found in D-Link DIR-605L 2.13B01 BETA and classified as critical. Affected by this vulnerability is the function formSetPassword of the file …

Oct 7, 2024
CVE-2024-9564
8.8 HIGH

A vulnerability, which was classified as critical, was found in D-Link DIR-605L 2.13B01 BETA. Affected is the function formWlanWizardSetup of the file /goform/formWlanWizardSetup. The manipulation …

Oct 7, 2024
CVE-2024-9563
8.8 HIGH

A vulnerability, which was classified as critical, has been found in D-Link DIR-605L 2.13B01 BETA. This issue affects the function formWlanSetup_Wizard of the file /goform/formWlanSetup_Wizard. …

Oct 7, 2024
CVE-2024-9562
8.8 HIGH

A vulnerability classified as critical was found in D-Link DIR-605L 2.13B01 BETA. This vulnerability affects the function formSetWizard1/formSetWizard2. The manipulation of the argument curTime leads …

Oct 6, 2024
CVE-2024-9561
8.8 HIGH

A vulnerability classified as critical has been found in D-Link DIR-605L 2.13B01 BETA. This affects the function formSetWAN_Wizard51/formSetWAN_Wizard52. The manipulation of the argument curTime leads …

Oct 6, 2024
CVE-2024-9560
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG V5. It has been rated as critical. Affected by this issue is the function delCatelogs of the file …

Oct 6, 2024
CVE-2024-9559
8.8 HIGH

A vulnerability was found in D-Link DIR-605L 2.13B01 BETA. It has been classified as critical. Affected is the function formWlanSetup of the file /goform/formWlanSetup. The …

Oct 6, 2024
CVE-2024-9558
8.8 HIGH

A vulnerability was found in D-Link DIR-605L 2.13B01 BETA and classified as critical. This issue affects the function formSetWanPPTP of the file /goform/formSetWanPPTP. The manipulation …

Oct 6, 2024
CVE-2024-9557
8.8 HIGH

A vulnerability has been found in D-Link DIR-605L 2.13B01 BETA and classified as critical. This vulnerability affects the function formSetWanPPPoE of the file /goform/formSetWanPPPoE. The …

Oct 6, 2024
CVE-2024-9556
8.8 HIGH

A vulnerability, which was classified as critical, was found in D-Link DIR-605L 2.13B01 BETA. This affects the function formSetEnableWizard of the file /goform/formSetEnableWizard. The manipulation …

Oct 6, 2024
CVE-2024-9555
8.8 HIGH

A vulnerability, which was classified as critical, has been found in D-Link DIR-605L 2.13B01 BETA. Affected by this issue is the function formSetEasy_Wizard of the …

Oct 6, 2024
CVE-2024-47650
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Axton WP-WebAuthn wp-webauthn allows Stored XSS.This issue affects WP-WebAuthn: from n/a through <= …

Oct 6, 2024
CVE-2024-47350
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITHEMES YITH WooCommerce Ajax Search yith-woocommerce-ajax-search.This issue affects YITH WooCommerce Ajax …

Oct 6, 2024
CVE-2024-47338
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal WPExperts Square For GiveWP wpexperts-square-for-give allows SQL Injection.This issue …

Oct 6, 2024
CVE-2024-45252
9.8 CRITICAL

Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Oct 6, 2024
CVE-2024-45251
9.8 CRITICAL

Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Oct 6, 2024
CVE-2024-45250
4.3 MEDIUM

ZKteco – CWE 200 Exposure of Sensitive Information to an Unauthorized Actor

Oct 6, 2024
CVE-2024-45249
9.8 CRITICAL

Cavok – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Oct 6, 2024
CVE-2024-45248
7.5 HIGH

Multi-DNC – CWE-35: Path Traversal: '.../...//'

Oct 6, 2024
CVE-2024-44040
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in plainware ShiftController Employee Shift Scheduling shiftcontroller allows Stored XSS.This issue affects ShiftController Employee …

Oct 6, 2024
CVE-2024-44039
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Travel WP Travel wp-travel allows Stored XSS.This issue affects WP Travel: from …

Oct 6, 2024
CVE-2024-44037
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magepeopleteam Multipurpose Ticket Booking Manager bus-booking-manager allows Stored XSS.This issue affects Multipurpose Ticket …

Oct 6, 2024
CVE-2024-44036
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pierre Lebedel Kodex Posts likes kodex-posts-likes allows Stored XSS.This issue affects Kodex Posts …

Oct 6, 2024
CVE-2024-44035
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atawai Gum Elementor Addon gum-elementor-addon allows Stored XSS.This issue affects Gum Elementor Addon: …

Oct 6, 2024
CVE-2024-44033
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Primary Addon for Elementor primary-addon-for-elementor allows Stored XSS.This issue affects Primary Addon …

Oct 6, 2024
CVE-2024-44032
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Restaurant & Cafe Addon for Elementor restaurant-cafe-addon-for-elementor allows Stored XSS.This issue affects …

Oct 6, 2024
CVE-2024-44029
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in David Garlitz viala allows Reflected XSS.This issue affects viala: from n/a …

Oct 6, 2024
CVE-2024-44028
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in nicejob NiceJob nicejob allows Stored XSS.This issue affects NiceJob: from n/a through < 3.6.5.

Oct 6, 2024
CVE-2024-44027
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atawai Gum Elementor Addon gum-elementor-addon allows Stored XSS.This issue affects Gum Elementor Addon: …

Oct 6, 2024
CVE-2024-44026
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Charity Addon for Elementor charity-addon-for-elementor allows Stored XSS.This issue affects Charity Addon …

Oct 6, 2024
CVE-2024-44025
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicejob NiceJob nicejob allows Stored XSS.This issue affects NiceJob: from n/a through < …

Oct 6, 2024
CVE-2024-44024
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Medical Addon for Elementor medical-addon-for-elementor allows Stored XSS.This issue affects Medical Addon …

Oct 6, 2024
CVE-2024-44022
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Trustmary Review & testimonial widgets trustmary allows Stored XSS.This issue affects Review & …

Oct 6, 2024
CVE-2024-44010
5.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catchthemes Full frame full-frame allows Stored XSS.This issue affects Full frame: from n/a …

Oct 6, 2024
CVE-2024-9554
3.7 LOW

A vulnerability classified as problematic was found in Sovell Smart Canteen System up to 3.0.7303.30513. Affected by this vulnerability is the function Check_ET_CheckPwdz201 of the …

Oct 6, 2024
CVE-2024-47322
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ex-Themes WP Timeline – Vertical and Horizontal timeline plugin wp-timelines allows Reflected XSS.This …

Oct 6, 2024
CVE-2024-47320
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark Westguard WS Form LITE ws-form allows Stored XSS.This issue affects WS Form …

Oct 6, 2024
CVE-2024-47313
5.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catchthemes Catch Base catch-base allows Stored XSS.This issue affects Catch Base: from n/a …

Oct 6, 2024
CVE-2024-47310
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arisoft ARI Fancy Lightbox ari-fancy-lightbox allows Stored XSS.This issue affects ARI Fancy Lightbox: …

Oct 6, 2024
CVE-2024-47307
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Essential Plugin Meta slider and carousel with lightbox meta-slider-and-carousel-with-lightbox allows Stored XSS.This issue …

Oct 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.