132723+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.
HCL Hive is affected by a cryptographic primitive with a risky implementation which could allow an attacker unauthorized lateral compromise or widespread credential leakage if …
An authenticated attacker with Editor access or alert.instances.external:write can submit an external Alertmanager alert containing a controlled generatorURL. The attacker is authorized to create the …
HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker unauthorized access to resources.
Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 allows any authenticated user to read and modify …
A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=confirm_order. The manipulation of …
HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly. Although no sensitive information (e.g., credentials, PII) was discovered, …
HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to introduce unverified, malicious, or broken code …
A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present …
Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions.
Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form <= 1.4.0 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Fluent Support Pro <= 2.3.1 versions.
Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions.
Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions.
Subscriber Broken Access Control in Fluent Support Pro <= 2.3.1 versions.
Author SQL Injection in FluentCRM Pro <= 3.1.12 versions.
Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions.
Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions.
A vulnerability has been found in itsourcecode Online Clinic Management System 1.0. This vulnerability affects unknown code of the file success/login.php of the component Admin …
Firmware in KAON PG5298A and PG5298B routers allow an unauthenticated user to query a specific endpoint and acquire sensitive information such as a password to …
Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions.
Unauthenticated Local File Inclusion in Måne <= 1.7 versions.
Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions.
Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions.
Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions.
Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.
Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions.
Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.
Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.
Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.
Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions.
Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions.
Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions.
Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.
Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.
Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.
Unauthenticated Privilege Escalation in Digits <= 9.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions.
Unauthenticated Broken Access Control in Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More <= 1.7.1 versions.
Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.
Unauthenticated Local File Inclusion in Tonda < 2.6 versions.
Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform operations not possible via GUI, e.g. system …
Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the …
A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_uploaded_file of the file all_users/register.php of the component User Registration. …
A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this issue is some unknown functionality of the file search.php. Performing a …
fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the result, and …
Free website and port scanning — find vulnerabilities before attackers do.