CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-28436
6.1 MEDIUM

Cross Site Scripting vulnerability in D-Link DAP products DAP-2230, DAP-2310, DAP-2330, DAP-2360, DAP-2553, DAP-2590, DAP-2690, DAP-2695, DAP-3520, DAP-3662 allows a remote attacker to execute arbitrary …

Apr 22, 2024
CVE-2024-28699
7.8 HIGH

A buffer overflow vulnerability in pdf2json v0.70 allows a local attacker to execute arbitrary code via the GString::copy() and ImgOutputDev::ImgOutputDev function.

Apr 22, 2024
CVE-2023-38302
4.3 MEDIUM

A certain software build for the Sharp Rouvo V device (SHARP/VZW_STTM21VAPP/STTM21VAPP:12/SP1A.210812.016/1KN0_0_530:user/release-keys) leaks the Wi-Fi MAC address and the Bluetooth MAC address to system properties that …

Apr 22, 2024
CVE-2023-38301
3.4 LOW

An issue was discovered in a third-party component related to vendor.gsm.serial, shipped on devices from multiple device manufacturers. Various software builds for the BLU View …

Apr 22, 2024
CVE-2023-38300
6.2 MEDIUM

A certain software build for the Orbic Maui device (Orbic/RC545L/RC545L:10/ORB545L_V1.4.2_BVZPP/230106:user/release-keys) leaks the IMEI and the ICCID to system properties that can be accessed by any …

Apr 22, 2024
CVE-2023-38299
5.5 MEDIUM

Various software builds for the AT&T Calypso, Nokia C100, Nokia C200, and BLU View 3 devices leak the device IMEI to a system property that …

Apr 22, 2024
CVE-2023-38298
8.8 HIGH

Various software builds for the following TCL devices (30Z, A3X, 20XE, 10L) leak the device IMEI to a system property that can be accessed by …

Apr 22, 2024
CVE-2023-38297
8.4 HIGH

An issue was discovered in a third-party com.factory.mmigroup component, shipped on devices from multiple device manufacturers. Certain software builds for various Android devices contain a …

Apr 22, 2024
CVE-2023-38296
8.0 HIGH

Various software builds for the following TCL 30Z and TCL A3X devices leak the ICCID to a system property that can be accessed by any …

Apr 22, 2024
CVE-2023-38295
7.8 HIGH

Certain software builds for the TCL 30Z and TCL 10 Android devices contain a vulnerable, pre-installed app that relies on a missing permission that provides …

Apr 22, 2024
CVE-2023-38294
6.1 MEDIUM

Certain software builds for the Itel Vision 3 Turbo Android device contain a vulnerable pre-installed app with a package name of com.transsion.autotest.factory (versionCode='7', versionName='1.8.0(220310_1027)') that …

Apr 22, 2024
CVE-2023-38293
7.3 HIGH

Certain software builds for the Nokia C200 and Nokia C100 Android devices contain a vulnerable, pre-installed app with a package name of com.tracfone.tfstatus (versionCode='31', versionName='12') …

Apr 22, 2024
CVE-2023-38292
8.7 HIGH

Certain software builds for the TCL 20XE Android device contain a vulnerable, pre-installed app with a package name of com.tct.gcs.hiddenmenuproxy (versionCode='2', versionName='v11.0.1.0.0201.0') that allows local …

Apr 22, 2024
CVE-2023-38291
7.1 HIGH

An issue was discovered in a third-party component related to ro.boot.wifimacaddr, shipped on devices from multiple device manufacturers. Various software builds for the following TCL …

Apr 22, 2024
CVE-2023-38290
7.8 HIGH

Certain software builds for the BLU View 2 and Sharp Rouvo V Android devices contain a vulnerable pre-installed app with a package name of com.evenwell.fqc …

Apr 22, 2024
CVE-2022-35503
7.5 HIGH

Improper verification of a user input in Open Source MANO v7-v12 allows an authenticated attacker to execute arbitrary code within the LCM module container via …

Apr 22, 2024
CVE-2022-34562
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in PHPFox v4.8.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the status …

Apr 22, 2024
CVE-2022-34561
4.3 MEDIUM

A cross-site scripting (XSS) vulnerability in PHPFox v4.8.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the video …

Apr 22, 2024
CVE-2022-34560
7.1 HIGH

A cross-site scripting (XSS) vulnerability in PHPFox v4.8.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the History …

Apr 22, 2024
CVE-2024-3645
6.4 MEDIUM

The Essential Addons for Elementor Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Counter widget in all versions up to, …

Apr 22, 2024
CVE-2024-32368
7.3 HIGH

Insecure Permission vulnerability in Agasta Sanketlife 2.0 Pocket 12-Lead ECG Monitor FW Version 3.0 allows a local attacker to cause a denial of service via …

Apr 22, 2024
CVE-2024-27349
9.1 CRITICAL

Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0. Users are recommended to upgrade to version 1.3.0, which …

Apr 22, 2024
CVE-2024-27348
9.8 CRITICAL KEV

RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to …

Apr 22, 2024
CVE-2024-27347
5.3 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Apache HugeGraph-Hubble.This issue affects Apache HugeGraph-Hubble: from 1.0.0 before 1.3.0. Users are recommended to upgrade to version 1.3.0, which …

Apr 22, 2024
CVE-2024-4026
4.6 MEDIUM

Cross-Site Scripting (XSS) vulnerability in the Holded application. This vulnerability could allow an attacker to store a JavaScript payload within all editable parameters within the …

Apr 22, 2024
CVE-2024-29661
9.8 CRITICAL

A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload.

Apr 22, 2024
CVE-2024-28717
4.9 MEDIUM

An issue in OpenStack Storlets yoga-eom allows a remote attacker to execute arbitrary code via the gateway.py component.

Apr 22, 2024
CVE-2024-22856
5.4 MEDIUM

A SQL injection vulnerability via the Save Favorite Search function in Axefinance Axe Credit Portal >= v.3.0 allows authenticated attackers to execute unintended queries and …

Apr 22, 2024
CVE-2024-22815
5.3 MEDIUM

An issue in the communication protocol of Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) via crafted …

Apr 22, 2024
CVE-2024-22813
4.4 MEDIUM

An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to overwrite the hardcoded IP address in the device memory, disrupting network connectivity …

Apr 22, 2024
CVE-2024-22811
8.2 HIGH

An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) by disrupting the communication between the …

Apr 22, 2024
CVE-2024-22809
6.5 MEDIUM

Incorrect access control in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to access the G code's shared folder and view sensitive information.

Apr 22, 2024
CVE-2024-22808
7.5 HIGH

An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) by disrupting the communication between the …

Apr 22, 2024
CVE-2024-22807
6.5 MEDIUM

An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to erase a critical sector of the flash memory, causing the machine to …

Apr 22, 2024
CVE-2024-32691
5.3 MEDIUM

Missing Authorization vulnerability in realmag777 Active Products Tables for WooCommerce.This issue affects Active Products Tables for WooCommerce: from n/a through 1.0.6.2.

Apr 22, 2024
CVE-2024-32688
6.5 MEDIUM

Missing Authorization vulnerability in Long Watch Studio MyRewards.This issue affects MyRewards: from n/a through 5.3.0.

Apr 22, 2024
CVE-2024-32687
4.3 MEDIUM

Missing Authorization vulnerability in WPClever WPC Frequently Bought Together for WooCommerce.This issue affects WPC Frequently Bought Together for WooCommerce: from n/a through 7.0.3.

Apr 22, 2024
CVE-2024-32684
5.3 MEDIUM

Missing Authorization vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through 2.2.5.

Apr 22, 2024
CVE-2024-32682
7.1 HIGH

Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Addons For Elementor: from n/a through 3.13.2.

Apr 22, 2024
CVE-2024-32681
4.3 MEDIUM

Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Addons For Elementor: from n/a through 3.13.2.

Apr 22, 2024
CVE-2024-32698
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons.This issue affects Happy Addons for Elementor: from …

Apr 22, 2024
CVE-2024-32697
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HelloAsso allows Stored XSS.This issue affects HelloAsso: from n/a through 1.1.5.

Apr 22, 2024
CVE-2024-32696
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Infographic Maker – iList allows Stored XSS.This issue affects Infographic Maker – …

Apr 22, 2024
CVE-2024-32695
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marco Gasi Language Switcher for Transposh allows Reflected XSS.This issue affects Language Switcher …

Apr 22, 2024
CVE-2024-32694
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Creative interactive media 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook …

Apr 22, 2024
CVE-2024-32693
7.6 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in ValvePress Automatic.This issue affects Automatic: from n/a before 3.93.0.

Apr 22, 2024
CVE-2024-32690
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood RSS Feed Widget allows Stored XSS.This issue affects RSS Feed Widget: …

Apr 22, 2024
CVE-2023-7252
5.3 MEDIUM

The Tickera WordPress plugin before 3.5.2.5 does not prevent users from leaking other users' tickets.

Apr 22, 2024
CVE-2018-25101
3.5 LOW

A vulnerability, which was classified as problematic, has been found in l2c2technologies Koha up to 20180108. This issue affects some unknown processing of the file …

Apr 22, 2024
CVE-2024-32418
9.8 CRITICAL

An issue in flusity CMS v2.33 allows a remote attacker to execute arbitrary code via the add_addon.php component.

Apr 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.