CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9378
6.1 MEDIUM

The YML for Yandex Market plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, …

Oct 2, 2024
CVE-2024-9344
6.1 MEDIUM

The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is vulnerable to Reflected …

Oct 2, 2024
CVE-2024-9218
6.1 MEDIUM

The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to Reflected …

Oct 2, 2024
CVE-2024-9225
6.1 MEDIUM

The SEOPress – On-site SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping …

Oct 2, 2024
CVE-2024-9222
6.1 MEDIUM

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use …

Oct 2, 2024
CVE-2024-9210
6.1 MEDIUM

The MC4WP: Mailchimp Top Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …

Oct 2, 2024
CVE-2024-9172
6.4 MEDIUM

The Demo Importer Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0.1 …

Oct 2, 2024
CVE-2024-8967
6.4 MEDIUM

The PWA — easy way to Progressive Web App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions …

Oct 2, 2024
CVE-2024-8800
6.1 MEDIUM

The RabbitLoader – Website Speed Optimization for improving Core Web Vital metrics with Cache, Image Optimization, and more plugin for WordPress is vulnerable to Reflected …

Oct 2, 2024
CVE-2024-8254
5.4 MEDIUM

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in …

Oct 2, 2024
CVE-2024-9333

Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited amount of documents via incorrect access control list calculation

Oct 2, 2024
CVE-2024-9174
5.4 MEDIUM

Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UI

Oct 2, 2024
CVE-2024-7315
7.5 HIGH

The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that is created when generating a backup, which could …

Oct 2, 2024
CVE-2024-7855
8.8 HIGH

The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function in all …

Oct 2, 2024
CVE-2024-45186
9.8 CRITICAL

FileSender before 2.49 allows server-side template injection (SSTI) for retrieving credentials.

Oct 2, 2024
CVE-2024-33662
7.5 HIGH

Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.

Oct 2, 2024
CVE-2024-21530
4.5 MEDIUM

Versions of the package cocoon before 0.4.0 are vulnerable to Reusing a Nonce, Key Pair in Encryption when the encrypt, wrap, and dump functions are …

Oct 2, 2024
CVE-2024-9407
4.7 MEDIUM

A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not properly validate the input passed to this option, …

Oct 1, 2024
CVE-2024-47609

Tonic is a native gRPC client & server implementation with async/await support. When using tonic::transport::Server there is a remote DoS attack that can cause the …

Oct 1, 2024
CVE-2024-47528
4.8 MEDIUM

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Stored Cross-Site Scripting (XSS) can be achieved by uploading a new Background for a Custom Map. Users …

Oct 1, 2024
CVE-2024-47527
7.5 HIGH

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Device Dependencies" feature allows authenticated users to inject arbitrary …

Oct 1, 2024
CVE-2024-47526
3.5 LOW

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Self Cross-Site Scripting (Self-XSS) vulnerability in the "Alert Templates" feature allows users to inject arbitrary JavaScript …

Oct 1, 2024
CVE-2024-47525
7.5 HIGH

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Alert Rules" feature allows authenticated users to inject arbitrary …

Oct 1, 2024
CVE-2024-47524
7.2 HIGH

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can create a Device Groups, the application did not properly sanitize the user …

Oct 1, 2024
CVE-2024-47523
7.5 HIGH

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Alert Transports" feature allows authenticated users to inject arbitrary …

Oct 1, 2024
CVE-2024-46084
8.0 HIGH

Scriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function.

Oct 1, 2024
CVE-2024-46082
5.4 MEDIUM

Scriptcase v.9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in nm_cor.php via the form and field parameters.

Oct 1, 2024
CVE-2024-46080
8.0 HIGH

Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function.

Oct 1, 2024
CVE-2024-9411
3.5 LOW

A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument …

Oct 1, 2024
CVE-2024-45999
9.8 CRITICAL

A SQL Injection vulnerability was discovered in Cloudlog 2.6.15, specifically within the get_station_info()function located in the file /application/models/Oqrs_model.php. The vulnerability is exploitable via the station_id …

Oct 1, 2024
CVE-2024-9355
6.5 MEDIUM

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed …

Oct 1, 2024
CVE-2024-9341
5.4 MEDIUM

A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper …

Oct 1, 2024
CVE-2024-46083
5.4 MEDIUM

Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads using the messages feature, which allows the …

Oct 1, 2024
CVE-2024-46081
5.4 MEDIUM

Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads in the To-Do List. The assigned user …

Oct 1, 2024
CVE-2024-46079
6.1 MEDIUM

Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in proj_new.php via the Descricao parameter.

Oct 1, 2024
CVE-2024-42514
8.1 HIGH

A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack …

Oct 1, 2024
CVE-2024-31835
4.8 MEDIUM

Cross Site Scripting vulnerability in flatpress CMS Flatpress v1.3 allows a remote attacker to execute arbitrary code via a crafted payload to the file name …

Oct 1, 2024
CVE-2024-47608
9.8 CRITICAL

Logicytics is designed to harvest and collect data for forensic analysis. Logicytics has a basic vuln affecting compromised devices from shell injections. This vulnerability is …

Oct 1, 2024
CVE-2024-9403
7.3 HIGH

Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of …

Oct 1, 2024
CVE-2024-9402
9.8 CRITICAL

Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume …

Oct 1, 2024
CVE-2024-9401
9.8 CRITICAL

Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption …

Oct 1, 2024
CVE-2024-9400
8.8 HIGH

A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a specific moment during JIT compilation. …

Oct 1, 2024
CVE-2024-9399
7.5 HIGH

A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulnerability affects …

Oct 1, 2024
CVE-2024-9398
5.3 MEDIUM

By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler …

Oct 1, 2024
CVE-2024-9397
6.1 MEDIUM

A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This …

Oct 1, 2024
CVE-2024-9396
8.8 HIGH

It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory …

Oct 1, 2024
CVE-2024-9395
5.3 MEDIUM

A specially crafted filename containing a large number of spaces could obscure the file's extension when displayed in the download dialog. *This bug only affects …

Oct 1, 2024
CVE-2024-9394
7.5 HIGH

An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. …

Oct 1, 2024
CVE-2024-9393
7.5 HIGH

An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. …

Oct 1, 2024
CVE-2024-9392
9.8 CRITICAL

A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox …

Oct 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.