122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_update
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_save.
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/score/del.
FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the email settings of the website settings section.
FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the system website settings website name section.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Macroturk Software and Internet Technologies Macro-Bel allows Reflected XSS.This issue affects Macro-Bel: before …
This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0 …
This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0. …
Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow.This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3, from …
NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation. This vulnerability is associated with program files net/sched/sch_cbs.C. This issue affects …
IBM App Connect Enterprise 11.0.0.1 through 11.0.0.24 and 12.0.1.0 through 12.0.11.0 could allow a remote attacker to obtain sensitive information or cause a denial of …
A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could store a malicious URL to be opened by …
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mergen Software Quality Management System allows SQL Injection.This issue affects Quality …
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to …
Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a …
Omission of user-controlled key authorization in the IDMSistemas platform, affecting the QSige product. This vulnerability allows an attacker to extract sensitive information from the API …
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of the 'tag' attribute in the wprm-recipe-name, wprm-recipe-date, and …
The WP Recipe Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Referer' header in all versions up to, and including, 9.1.0 …
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 9.1.0 …
A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be …
A vulnerability has been found in Novel-Plus 4.3.0-RC1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /novel/bookSetting/list. The …
In autotest driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with …
In drm driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …
In vsp driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …
In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …
In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …
In telephone service, there is a possible improper input validation. This could lead to local information disclosure with no additional execution privileges needed
In vsp driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System …
In phasecheckserver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with …
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …
In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with …
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with …
In video decoder, there is a possible improper input validation. This could lead to local denial of service with no additional execution privileges needed
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with …
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with …
In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with …
In media service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with …
In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with …
In jpg driver, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed
A vulnerability, which was classified as problematic, was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22. Affected is an unknown function of the file mainscripts/Util.py. The manipulation leads …
A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality …
A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …
Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting
A vulnerability was found in Karjasoft Sami HTTP Server 2.0. It has been classified as problematic. Affected is an unknown function of the component HTTP …
The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.
pyLoad is a free and open-source Download Manager written in pure Python. The `pyload` API allows any API call to be made using GET requests. …
A vulnerability was found in Project Worlds Visitor Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file …
Free website and port scanning — find vulnerabilities before attackers do.