CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-30868
9.8 CRITICAL

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/add_getlogin.php.

Apr 1, 2024
CVE-2022-4966
3.5 LOW

A vulnerability was found in sequentech admin-console up to 6.1.7 and classified as problematic. Affected by this issue is some unknown functionality of the component …

Apr 1, 2024
CVE-2023-6154
7.8 HIGH

A configuration setting issue in seccenter.exe as used in Bitdefender Total Security, Bitdefender Internet Security, Bitdefender Antivirus Plus, Bitdefender Antivirus Free allows an attacker to …

Apr 1, 2024
CVE-2024-3130
5.7 MEDIUM

Hard-coded Credentials in CoolKit eWeLlink app are before 5.4.x on Android and IOS allows local attacker to unauthorized access to sensitive data via Decryption algorithm …

Apr 1, 2024
CVE-2024-26654
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: ALSA: sh: aica: reorder cleanup operations to avoid UAF bugs The dreamcastcard->timer could schedule the …

Apr 1, 2024
CVE-2024-26653
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: usb: misc: ljca: Fix double free in error handling path When auxiliary_device_add() returns error and …

Apr 1, 2024
CVE-2024-25080
4.7 MEDIUM

WebMail in Axigen 10.x before 10.3.3.62 allows XSS via the image attachment viewer.

Apr 1, 2024
CVE-2016-15038
6.5 MEDIUM

A vulnerability, which was classified as critical, was found in NUUO NVRmini 2 up to 3.0.8. Affected is an unknown function of the file /deletefile.php. …

Apr 1, 2024
CVE-2024-2278
6.1 MEDIUM

Themify WordPress plugin before 1.4.4 does not sanitise and escape some of its Filters settings, which could allow high privilege users such as admin to …

Apr 1, 2024
CVE-2024-2263
4.8 MEDIUM

Themify WordPress plugin before 1.4.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting …

Apr 1, 2024
CVE-2024-2262
4.7 MEDIUM

Themify WordPress plugin before 1.4.4 does not have CSRF check in its bulk action, which could allow attackers to make logged in users delete arbitrary …

Apr 1, 2024
CVE-2024-1526
5.3 MEDIUM

The Hubbub Lite WordPress plugin before 1.33.1 does not ensure that user have access to password protected post before displaying its content in a meta …

Apr 1, 2024
CVE-2024-20055
6.3 MEDIUM

In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges …

Apr 1, 2024
CVE-2024-20054
6.6 MEDIUM

In gnss, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System …

Apr 1, 2024
CVE-2024-20053
8.4 HIGH

In flashc, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege with System …

Apr 1, 2024
CVE-2024-20052
4.4 MEDIUM

In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. …

Apr 1, 2024
CVE-2024-20051
2.3 LOW

In flashc, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with System execution privileges …

Apr 1, 2024
CVE-2024-20050
4.4 MEDIUM

In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. …

Apr 1, 2024
CVE-2024-20049
4.4 MEDIUM

In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. …

Apr 1, 2024
CVE-2024-20048
6.2 MEDIUM

In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. …

Apr 1, 2024
CVE-2024-20047
5.4 MEDIUM

In battery, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution …

Apr 1, 2024
CVE-2024-20046
6.6 MEDIUM

In battery, there is a possible escalation of privilege due to an integer overflow. This could lead to local escalation of privilege with System execution …

Apr 1, 2024
CVE-2024-20045
2.3 LOW

In audio, there is a possible out of bounds read due to an incorrect calculation of buffer size. This could lead to local information disclosure …

Apr 1, 2024
CVE-2024-20044
6.6 MEDIUM

In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Apr 1, 2024
CVE-2024-20043
6.6 MEDIUM

In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Apr 1, 2024
CVE-2024-20042
6.6 MEDIUM

In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Apr 1, 2024
CVE-2024-20041
4.4 MEDIUM

In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Apr 1, 2024
CVE-2024-20040
8.8 HIGH

In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege with …

Apr 1, 2024
CVE-2024-20039
8.8 HIGH

In modem protocol, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with …

Apr 1, 2024
CVE-2024-31033
6.8 MEDIUM

JJWT (aka Java JWT) through 0.12.5 ignores certain characters and thus a user might falsely conclude that they have a strong key. The impacted code …

Apr 1, 2024
CVE-2024-28895
6.1 MEDIUM

'Yahoo! JAPAN' App for Android v2.3.1 to v3.161.1 and 'Yahoo! JAPAN' App for iOS v3.2.2 to v4.109.0 contain a cross-site scripting vulnerability. If this vulnerability …

Apr 1, 2024
CVE-2024-27609
6.5 MEDIUM

Bonita before 2023.2-u2 allows stored XSS via a UI screen in the administration panel.

Apr 1, 2024
CVE-2023-51803
9.8 CRITICAL

LinuxServer.io Heimdall before 2.5.7 does not prevent use of icons that have non-image data such as the "<?php ?>" substring.

Apr 1, 2024
CVE-2014-125110
3.5 LOW

A vulnerability has been found in wp-file-upload Plugin up to 2.4.3 on WordPress and classified as problematic. Affected by this vulnerability is the function wfu_ajax_action_callback …

Apr 1, 2024
CVE-2024-31104
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GetResponse GetResponse for WordPress allows Stored XSS.This issue affects GetResponse for WordPress: from …

Mar 31, 2024
CVE-2024-31103
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kanban for WordPress Kanban Boards for WordPress allows Reflected XSS.This issue affects Kanban …

Mar 31, 2024
CVE-2024-31102
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scimone Ignazio Prenotazioni allows Stored XSS.This issue affects Prenotazioni: from n/a through 1.7.4.

Mar 31, 2024
CVE-2024-31101
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in August Infotech AI Twitter Feeds (Twitter widget & shortcode) allows Stored XSS.This issue …

Mar 31, 2024
CVE-2024-31097
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stephan Spencer SEO Title Tag allows Reflected XSS.This issue affects SEO Title Tag: …

Mar 31, 2024
CVE-2024-31092
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Philip M. Hofer (Frumph) Comic Easel allows Reflected XSS.This issue affects Comic Easel: …

Mar 31, 2024
CVE-2024-31091
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SparkWeb Interactive, Inc. Custom Field Bulk Editor allows Reflected XSS.This issue affects Custom …

Mar 31, 2024
CVE-2024-31090
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 荒野无灯 Hacklog Down As PDF allows Reflected XSS.This issue affects Hacklog Down As …

Mar 31, 2024
CVE-2024-31089
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Techblissonline.Com (Rajesh) Platinum SEO allows Stored XSS.This issue affects Platinum SEO: from n/a …

Mar 31, 2024
CVE-2024-31087
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joel Starnes pageMash > Page Management allows Reflected XSS.This issue affects pageMash > …

Mar 31, 2024
CVE-2024-31085
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rob Marsh, SJ Post-Plugin Library allows Reflected XSS.This issue affects Post-Plugin Library: from …

Mar 31, 2024
CVE-2024-31084
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pulsar Web Design Weekly Class Schedule allows Reflected XSS.This issue affects Weekly Class …

Mar 31, 2024
CVE-2024-30561
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scientech It Solution Appointment Calendar allows Reflected XSS.This issue affects Appointment Calendar: from …

Mar 31, 2024
CVE-2024-30559
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maurice Spin 360 deg and 3D Model Viewer allows Stored XSS.This issue affects …

Mar 31, 2024
CVE-2024-30558
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Simpson Add Shortcodes Actions And Filters allows Reflected XSS.This issue affects Add …

Mar 31, 2024
CVE-2024-30557
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aesopinteractive Aesop Story Engine allows Stored XSS.This issue affects Aesop Story Engine: from …

Mar 31, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.