CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-1543
4.1 MEDIUM

The side-channel protected T-Table implementation in wolfSSL up to version 5.6.5 protects against a side-channel attacker with cache-line resolution. In a controlled environment such as …

Aug 29, 2024
CVE-2024-6672
8.8 HIGH

In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an authenticated low-privileged attacker to achieve privilege escalation by modifying a privileged user's …

Aug 29, 2024
CVE-2024-6671
9.8 CRITICAL

In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an unauthenticated attacker …

Aug 29, 2024
CVE-2024-6670
9.8 CRITICAL KEV

In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

Aug 29, 2024
CVE-2024-45302
6.1 MEDIUM

RestSharp is a Simple REST and HTTP API Client for .NET. The second argument to `RestRequest.AddHeader` (the header value) is vulnerable to CRLF injection. The …

Aug 29, 2024
CVE-2024-2502
2.0 LOW

An application can be configured to block boot attempts after consecutive tamper resets are detected, which may not occur as expected. This is possible because …

Aug 29, 2024
CVE-2024-41349
6.1 MEDIUM

unmark 1.9.2 is vulnerable to Cross Site Scripting (XSS) via application/views/marks/add_by_url.php.

Aug 29, 2024
CVE-2024-41372
9.8 CRITICAL

Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/settyping.php.

Aug 29, 2024
CVE-2024-41371
6.1 MEDIUM

Organizr v1.90 is vulnerable to Cross Site Scripting (XSS) via api.php.

Aug 29, 2024
CVE-2024-41370
9.8 CRITICAL

Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/setlike.php.

Aug 29, 2024
CVE-2024-41369
9.8 CRITICAL

RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWifi.php

Aug 29, 2024
CVE-2024-41368
9.8 CRITICAL

RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWlanIpMail.php

Aug 29, 2024
CVE-2024-41367
9.8 CRITICAL

RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\api\playlist\appendFileToPlaylist.php

Aug 29, 2024
CVE-2024-41366
9.8 CRITICAL

RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\userScripts.php

Aug 29, 2024
CVE-2024-41364
9.8 CRITICAL

RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\trackEdit.php

Aug 29, 2024
CVE-2024-41361
9.8 CRITICAL

RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\manageFilesFolders.php

Aug 29, 2024
CVE-2024-41358
6.1 MEDIUM

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.

Aug 29, 2024
CVE-2024-41351
6.1 MEDIUM

bjyadmin commit a560fd5 is vulnerable to Cross Site Scripting (XSS) via Public/statics/umeditor1_2_3/php/getContent.php

Aug 29, 2024
CVE-2024-41350
6.1 MEDIUM

bjyadmin commit a560fd5 is vulnerable to Cross Site Scripting (XSS) via Public/statics/umeditor1_2_3/php/imageUp.php

Aug 29, 2024
CVE-2024-41348
6.1 MEDIUM

openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/alsearch.php

Aug 29, 2024
CVE-2024-41347
6.1 MEDIUM

openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/settings.php

Aug 29, 2024
CVE-2024-41346
5.4 MEDIUM

openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/submit.php

Aug 29, 2024
CVE-2024-41345
5.4 MEDIUM

openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/trip.php

Aug 29, 2024
CVE-2024-34019
7.3 HIGH

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 4569.

Aug 29, 2024
CVE-2024-34018
5.5 MEDIUM

Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 4569.

Aug 29, 2024
CVE-2024-34017
7.3 HIGH

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 4569.

Aug 29, 2024
CVE-2024-43947
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Dinesh Karki WP Armour Extended.This issue affects WP Armour Extended: from n/a through 1.26.

Aug 29, 2024
CVE-2024-43921
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Magic Post Thumbnail allows Reflected XSS.This issue affects Magic Post Thumbnail: …

Aug 29, 2024
CVE-2024-43920
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jegstudio Gutenverse allows Stored XSS.This issue affects Gutenverse: from n/a through …

Aug 29, 2024
CVE-2024-44930
6.5 MEDIUM

Serilog before v2.1.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP …

Aug 29, 2024
CVE-2024-44779
9.6 CRITICAL

A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in …

Aug 29, 2024
CVE-2024-44778
9.6 CRITICAL

A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in …

Aug 29, 2024
CVE-2024-44777
9.6 CRITICAL

A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in …

Aug 29, 2024
CVE-2024-44776
6.1 MEDIUM

An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a crafted URL.

Aug 29, 2024
CVE-2024-44717
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in DedeBIZ v6.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Aug 29, 2024
CVE-2024-44716
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in DedeBIZ v6.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Aug 29, 2024
CVE-2024-43964
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Leithold DSGVO All in one for WP allows Stored XSS.This …

Aug 29, 2024
CVE-2024-43963
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WaspThemes YellowPencil Visual CSS Style Editor allows Reflected XSS.This issue affects …

Aug 29, 2024
CVE-2024-43961
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in azurecurve azurecurve Toggle Show/Hide allows Stored XSS.This issue affects azurecurve Toggle …

Aug 29, 2024
CVE-2024-43960
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Page Builder Addons Web and WooCommerce Addons for WPBakery Builder allows …

Aug 29, 2024
CVE-2024-43958
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gianni Porto IntoTheDark allows Reflected XSS.This issue affects IntoTheDark: from n/a …

Aug 29, 2024
CVE-2024-43953
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webcodingplace Classic Addons – WPBakery Page Builder classic-addons-wpbakery-page-builder-addons allows Stored XSS.This issue affects …

Aug 29, 2024
CVE-2024-43952
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Esotera allows Stored XSS.This issue affects Esotera: from n/a through …

Aug 29, 2024
CVE-2024-43951
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Tempera allows Stored XSS.This issue affects Tempera: from n/a through …

Aug 29, 2024
CVE-2024-43950
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Nextbricks Brickscore allows Stored XSS.This issue affects Brickscore: from n/a through …

Aug 29, 2024
CVE-2024-43949
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic GHActivity allows Stored XSS.This issue affects GHActivity: from n/a through …

Aug 29, 2024
CVE-2024-43948
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dinesh Karki WP Armour Extended.This issue affects WP Armour Extended: from …

Aug 29, 2024
CVE-2024-43946
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SKT Themes SKT Blocks – Gutenberg based Page Builder allows Stored …

Aug 29, 2024
CVE-2024-43936
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper EmbedPress allows Stored XSS.This issue affects EmbedPress: from n/a through …

Aug 29, 2024
CVE-2024-43935
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Delicious Delicious Recipes – WordPress Recipe Plugin allows Stored XSS.This …

Aug 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.