CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9391
6.5 MEDIUM

A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing …

Oct 1, 2024
CVE-2024-47604
8.2 HIGH

NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handling of HTML element attributes, which allows an …

Oct 1, 2024
CVE-2024-47534

go-tuf is a Go implementation of The Update Framework (TUF). The go-tuf client inconsistently traces the delegations. For example, if targets delegate to "A", and …

Oct 1, 2024
CVE-2024-47071
6.8 MEDIUM

OSS Endpoint Manager is an endpoint manager module for FreePBX. OSS Endpoint Manager module activation can allow authenticated web users unauthorized access to read system …

Oct 1, 2024
CVE-2024-25660
9.0 CRITICAL

The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized file operations, because of execution with …

Oct 1, 2024
CVE-2024-25659
7.2 HIGH

In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP server on Linux servers allows remote attacker to access …

Oct 1, 2024
CVE-2024-45967
4.7 MEDIUM

Pagekit 1.0.18 is vulnerable to Cross Site Scripting (XSS) in index.php/admin/site/widget.

Oct 1, 2024
CVE-2024-45408
7.5 HIGH

eLabFTW is an open source electronic lab notebook for research labs. An incorrect permission check has been found that could allow an authenticated user to …

Oct 1, 2024
CVE-2024-44610
5.6 MEDIUM

PCAN-Ethernet Gateway FD before 1.3.0 and PCAN-Ethernet Gateway before 2.11.0 are vulnerable to Command injection via shell metacharacters in a Software Update to processing.php.

Oct 1, 2024
CVE-2024-41673
7.1 HIGH

Decidim is a participatory democracy framework. The version control feature used in resources is subject to potential XSS attack through a malformed URL. This vulnerability …

Oct 1, 2024
CVE-2024-25661
7.7 HIGH

In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of the desktop application TNMS Client allows guest OS administrators …

Oct 1, 2024
CVE-2024-25658
6.5 MEDIUM

Cleartext storage of passwords in Infinera TNMS (Transcend Network Management System) Server 19.10.3 allows attackers (with access to the database or exported configuration files) to …

Oct 1, 2024
CVE-2024-25632
8.6 HIGH

eLabFTW is an open source electronic lab notebook for research labs. In the context of eLabFTW, an administrator is a user account with certain privileges …

Oct 1, 2024
CVE-2021-37577
6.8 MEDIUM

Bluetooth LE and BR/EDR Secure Connections pairing and Secure Simple Pairing using the Passkey entry protocol in Bluetooth Core Specifications 2.1 through 5.3 may permit …

Oct 1, 2024
CVE-2024-46276
7.8 HIGH

cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_chunk() function at cute_png.h.

Oct 1, 2024
CVE-2024-46274
7.8 HIGH

cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_stored() function at cute_png.h.

Oct 1, 2024
CVE-2024-46267
7.8 HIGH

cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_block() function at cute_png.h.

Oct 1, 2024
CVE-2024-46264
7.8 HIGH

cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_find() function at cute_png.h.

Oct 1, 2024
CVE-2024-46263
7.8 HIGH

cute_png v1.05 was discovered to contain a stack overflow via the cp_dynamic() function at cute_png.h.

Oct 1, 2024
CVE-2024-46261
7.8 HIGH

cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_make32() function at cute_png.h.

Oct 1, 2024
CVE-2024-46259
7.8 HIGH

cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_unfilter() function at cute_png.h.

Oct 1, 2024
CVE-2024-46258
7.8 HIGH

cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_load_png_mem() function at cute_png.h.

Oct 1, 2024
CVE-2024-44744
5.7 MEDIUM

An issue in Malwarebytes Premium Security v5.0.0.883 allows attackers to execute arbitrary code via placing crafted binaries into unspecified directories. NOTE: Malwarebytes argues that this …

Oct 1, 2024
CVE-2024-41276
9.8 CRITICAL

A vulnerability in Kaiten version 57.131.12 and earlier allows attackers to bypass the PIN code authentication mechanism. The application requires users to input a 6-digit …

Oct 1, 2024
CVE-2023-7273
6.8 MEDIUM

Cross site request forgery in Kiteworks OwnCloud allows an unauthenticated attacker to forge requests. If a request has no Authorization header, it is created with …

Oct 1, 2024
CVE-2024-9405
5.3 MEDIUM

An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting version 4.7.18. An unauthenticated attacker could …

Oct 1, 2024
CVE-2024-30132
3.7 LOW

HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to obtain sensitive information via unspecified …

Oct 1, 2024
CVE-2024-9118
6.4 MEDIUM

The QS Dark Mode Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Oct 1, 2024
CVE-2024-9060
6.4 MEDIUM

The AVIF & SVG Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in version 1.1.0 due to insufficient input …

Oct 1, 2024
CVE-2023-3441
6.6 MEDIUM

An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4. The product did not sufficiently warn about security implications …

Oct 1, 2024
CVE-2024-9289
9.8 CRITICAL

The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 8.4.1. This is due …

Oct 1, 2024
CVE-2024-9265
9.8 CRITICAL

The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.4.6. This is due …

Oct 1, 2024
CVE-2024-9241
6.1 MEDIUM

The PDF Image Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Oct 1, 2024
CVE-2024-9228
6.1 MEDIUM

The Loggedin – Limit Active Logins plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on …

Oct 1, 2024
CVE-2024-9224
6.5 MEDIUM

The Hello World plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 2.1.1 via the hello_world_lyric() function. This …

Oct 1, 2024
CVE-2024-9220
6.1 MEDIUM

The LH Copy Media File plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …

Oct 1, 2024
CVE-2024-9209
6.1 MEDIUM

The WP Search Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Oct 1, 2024
CVE-2024-9018
8.8 HIGH

The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘key’ parameter in all versions up …

Oct 1, 2024
CVE-2024-8799
6.1 MEDIUM

The Custom Banners plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in …

Oct 1, 2024
CVE-2024-8793
6.1 MEDIUM

The Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to …

Oct 1, 2024
CVE-2024-8786
6.1 MEDIUM

The Auto Featured Image from Title plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on …

Oct 1, 2024
CVE-2024-8430
5.3 MEDIUM

The Spice Starter Sites plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the spice_starter_sites_importer_creater function in …

Oct 1, 2024
CVE-2024-8324
6.4 MEDIUM

The XO Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘get_slider’ function in all versions up to, and including, 3.8.6 due …

Oct 1, 2024
CVE-2024-8288
6.4 MEDIUM

The Guten Post Layout – An Advanced Post Grid Collection for WordPress Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ …

Oct 1, 2024
CVE-2024-9304
6.4 MEDIUM

The LocateAndFilter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.14 due to …

Oct 1, 2024
CVE-2024-9274
6.4 MEDIUM

The Elastik Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.27.4 …

Oct 1, 2024
CVE-2024-9272
6.4 MEDIUM

The R Animated Icon Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Oct 1, 2024
CVE-2024-9269
6.4 MEDIUM

The Relogo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.4.2 due to …

Oct 1, 2024
CVE-2024-9267
6.1 MEDIUM

The Easy WordPress Subscribe – Optin Hound plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping …

Oct 1, 2024
CVE-2024-9145

Wiz Code Visual Studio Code extension in versions 1.0.0 up to 1.5.3 and Wiz (legacy) Visual Studio Code extension in versions 0.13.0 up to 0.17.8 …

Oct 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.