CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-44057
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Nirvana allows Stored XSS.This issue affects Nirvana: from n/a through …

Sep 15, 2024
CVE-2024-44056
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Mantra allows Stored XSS.This issue affects Mantra: from n/a through …

Sep 15, 2024
CVE-2024-44054
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Fluida allows Stored XSS.This issue affects Fluida: from n/a through …

Sep 15, 2024
CVE-2024-44053
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mohammad Arif Opor Ayam allows Reflected XSS.This issue affects Opor Ayam: …

Sep 15, 2024
CVE-2024-45460
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in manu225 Flipping Cards flipping-cards allows Stored XSS.This issue affects Flipping Cards: from n/a …

Sep 15, 2024
CVE-2024-45459
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Product Slider for WooCommerce woocommerce-products-slider allows Reflected XSS.This issue affects Product Slider …

Sep 15, 2024
CVE-2024-45458
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows Reflected XSS.This issue affects Spiffy Calendar: from …

Sep 15, 2024
CVE-2024-45457
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows Stored XSS.This issue affects Spiffy Calendar: from …

Sep 15, 2024
CVE-2024-45456
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JoomUnited WP Meta SEO wp-meta-seo allows Stored XSS.This issue affects WP Meta SEO: …

Sep 15, 2024
CVE-2024-45455
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JoomUnited WP Meta SEO wp-meta-seo allows Stored XSS.This issue affects WP Meta SEO: …

Sep 15, 2024
CVE-2024-44063
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Happyforms allows Stored XSS.This issue affects Happyforms: from n/a through 1.26.0.

Sep 15, 2024
CVE-2024-44062
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hiroaki Miyashita Custom Field Template allows Stored XSS.This issue affects Custom …

Sep 15, 2024
CVE-2024-44060
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jennifer Hall Filmix allows Reflected XSS.This issue affects Filmix: from n/a …

Sep 15, 2024
CVE-2024-8868
7.3 HIGH

A vulnerability was found in code-projects Crud Operation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Sep 15, 2024
CVE-2024-8867
3.5 LOW

A vulnerability was found in Perfex CRM 3.1.6. It has been declared as problematic. This vulnerability affects unknown code of the file application/controllers/Clients.php of the …

Sep 15, 2024
CVE-2024-8866
4.3 MEDIUM

A vulnerability was found in AutoCMS 5.4. It has been classified as problematic. This affects an unknown part of the file /admin/robot.php. The manipulation of …

Sep 15, 2024
CVE-2024-8865
3.5 LOW

A vulnerability was found in composiohq composio up to 0.5.8 and classified as problematic. Affected by this issue is the function path of the file …

Sep 15, 2024
CVE-2024-8864
5.5 MEDIUM

A vulnerability has been found in composiohq composio up to 0.5.6 and classified as critical. Affected by this vulnerability is the function Calculator of the …

Sep 15, 2024
CVE-2024-8863
3.5 LOW

A vulnerability, which was classified as problematic, was found in aimhubio aim up to 3.24. Affected is the function dangerouslySetInnerHTML of the file textbox.tsx of …

Sep 14, 2024
CVE-2024-8862
7.3 HIGH

A vulnerability, which was classified as critical, has been found in h2oai h2o-3 3.46.0.4. This issue affects the function getConnectionSafe of the file /dtale/chart-data/1 of …

Sep 14, 2024
CVE-2024-6482
8.8 HIGH

The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.49. This is due to …

Sep 14, 2024
CVE-2023-3410
5.4 MEDIUM

The Bricks theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘customTag' attribute in versions up to, and including, 1.10.1 due to insufficient …

Sep 14, 2024
CVE-2024-8797
6.1 MEDIUM

The WP Booking System – Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without …

Sep 14, 2024
CVE-2024-8724
6.1 MEDIUM

The Waitlist Woocommerce ( Back in stock notifier ) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without …

Sep 14, 2024
CVE-2024-8669
9.1 CRITICAL

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter passed to the backuply_wp_clone_sql() function …

Sep 14, 2024
CVE-2024-8479
7.3 HIGH

The The Simple Spoiler plugin for WordPress is vulnerable to arbitrary shortcode execution in versions 1.2 to 1.3. This is due to the plugin adding …

Sep 14, 2024
CVE-2024-8246
8.8 HIGH

The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable …

Sep 14, 2024
CVE-2024-8039
9.8 CRITICAL

Improper permission configurationDomain configuration vulnerability of the mobile application (com.afmobi.boomplayer) can lead to account takeover risks.

Sep 14, 2024
CVE-2024-8775
5.5 MEDIUM

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. …

Sep 14, 2024
CVE-2024-8271
7.3 HIGH

The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, …

Sep 14, 2024
CVE-2022-3459
5.3 MEDIUM

The WooCommerce Multiple Free Gift plugin for WordPress is vulnerable to gift manipulation in all versions up to, and including, 1.2.3. This is due to …

Sep 14, 2024
CVE-2024-6259
7.6 HIGH

BT: HCI: adv_ext_report Improper discarding in adv_ext_report

Sep 13, 2024
CVE-2024-44096
4.4 MEDIUM

there is a possible arbitrary read due to an insecure default value. This could lead to local information disclosure with System execution privileges needed. User …

Sep 13, 2024
CVE-2024-44095
7.8 HIGH

In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible corrupt memory due to a logic error in the code. This could lead to local escalation of …

Sep 13, 2024
CVE-2024-44094
7.8 HIGH

In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with no …

Sep 13, 2024
CVE-2024-44093
7.8 HIGH

In ppmp_unprotect_buf of drm/code/drm_fw.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of …

Sep 13, 2024
CVE-2024-44092
7.8 HIGH

There is a possible LCS signing enforcement missing due to test/debugging code left in a production build. This could lead to local escalation of privilege …

Sep 13, 2024
CVE-2024-29779
7.8 HIGH

there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privilege with no additional execution …

Sep 13, 2024
CVE-2024-6137
7.6 HIGH

BT: Classic: SDP OOB access in get_att_search_list

Sep 13, 2024
CVE-2024-6135
7.6 HIGH

BT:Classic: Multiple missing buf length checks

Sep 13, 2024
CVE-2024-5931
6.3 MEDIUM

BT: Unchecked user input in bap_broadcast_assistant

Sep 13, 2024
CVE-2024-44430
9.8 CRITICAL

SQL Injection vulnerability in Best Free Law Office Management Software-v1.0 allows an attacker to execute arbitrary code and obtain sensitive information via a crafted payload …

Sep 13, 2024
CVE-2024-8784
6.3 MEDIUM

A vulnerability classified as critical was found in QDocs Smart School Management System 7.0.0. Affected by this vulnerability is an unknown functionality of the file …

Sep 13, 2024
CVE-2024-8783
3.5 LOW

A vulnerability classified as problematic has been found in OpenTibiaBR MyAAC up to 0.8.16. Affected is an unknown function of the file system/pages/forum/new_post.php of the …

Sep 13, 2024
CVE-2024-6258
6.8 MEDIUM

BT: Missing length checks of net_buf in rfcomm_handle_data

Sep 13, 2024
CVE-2024-5754
8.2 HIGH

BT: Encryption procedure host vulnerability

Sep 13, 2024
CVE-2024-8782
6.3 MEDIUM

A vulnerability was found in JFinalCMS up to 1.0. It has been rated as critical. This issue affects the function delete of the file /admin/template/edit. …

Sep 13, 2024
CVE-2024-8281
7.2 HIGH

An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection through specially …

Sep 13, 2024
CVE-2024-8280
7.2 HIGH

An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection or cause …

Sep 13, 2024
CVE-2024-8279
7.2 HIGH

A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially …

Sep 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.