CVE Database

39716+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-52469
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dhrubok Infotech Services Ltd. WooCommerce Price Alert price-alert-woocommerce allows Reflected XSS.This issue affects …

Dec 2, 2024
CVE-2024-52468
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LeadBoxer LeadBoxer leadboxer allows Reflected XSS.This issue affects LeadBoxer: from n/a through <= …

Dec 2, 2024
CVE-2024-52467
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in August Infotech AI Responsive Gallery Album ai-responsive-gallery-album allows Reflected XSS.This issue affects AI …

Dec 2, 2024
CVE-2024-52466
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Explara Explara Events explara-events allows Reflected XSS.This issue affects Explara Events: from n/a …

Dec 2, 2024
CVE-2024-52465
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Risk Mitigation, Inc. LGPD Framework lgpd-framework allows Reflected XSS.This issue affects LGPD …

Dec 2, 2024
CVE-2024-52464
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in anmari amr shortcodes amr-shortcodes allows Reflected XSS.This issue affects amr shortcodes: from n/a …

Dec 2, 2024
CVE-2024-52463
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Peter Westwood Post By Email post-by-email allows Reflected XSS.This issue affects Post By …

Dec 2, 2024
CVE-2024-52462
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jacob Schwartz WP e-Commerce Style Email wp-e-commerce-style-email allows Reflected XSS.This issue affects WP …

Dec 2, 2024
CVE-2024-52461
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kinsta Infinite Slider infinite-slider allows Reflected XSS.This issue affects Infinite Slider: from n/a …

Dec 2, 2024
CVE-2024-52460
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in atarapay AtaraPay WooCommerce Payment Gateway atarapay-woocommerce allows Reflected XSS.This issue affects AtaraPay WooCommerce …

Dec 2, 2024
CVE-2024-52459
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chameleoni Chameleoni Jobs chameleon-jobs allows Reflected XSS.This issue affects Chameleoni Jobs: from n/a …

Dec 2, 2024
CVE-2024-52458
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zaymund TM Islamic Helper tm-islamic-helper allows Reflected XSS.This issue affects TM Islamic Helper: …

Dec 2, 2024
CVE-2024-52457
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in youneeq Youneeq Recommendations youneeq-panel allows Reflected XSS.This issue affects Youneeq Recommendations: from n/a …

Dec 2, 2024
CVE-2024-52456
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpoets Awesome Studio awesome-studio allows Reflected XSS.This issue affects Awesome Studio: from n/a …

Dec 2, 2024
CVE-2024-52455
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in goqsystem GoQSmile goqsmile allows Reflected XSS.This issue affects GoQSmile: from n/a through <= …

Dec 2, 2024
CVE-2024-52454
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in goqsystem GoQMieruca goqmieruca allows Reflected XSS.This issue affects GoQMieruca: from n/a through <= …

Dec 2, 2024
CVE-2024-52453
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in photonicgnostic Library Bookshelves library-bookshelves allows Reflected XSS.This issue affects Library Bookshelves: from n/a …

Dec 2, 2024
CVE-2024-52452
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eduNEXT Open edX LMS allows Reflected XSS.This issue affects Open edX LMS: from …

Dec 2, 2024
CVE-2024-12015
7.7 HIGH

The 'Project Manager' WordPress Plugin is affected by an authenticated SQL injection vulnerability in the 'orderby' parameter in the '/pm/v2/activites' route.

Dec 2, 2024
CVE-2024-43053
7.8 HIGH

Memory corruption while invoking IOCTL calls from user space to read WLAN target diagnostic information.

Dec 2, 2024
CVE-2024-43052
7.8 HIGH

Memory corruption while processing API calls to NPU with invalid input.

Dec 2, 2024
CVE-2024-43050
7.8 HIGH

Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver.

Dec 2, 2024
CVE-2024-43049
7.8 HIGH

Memory corruption while invoking IOCTL calls from user space to set generic private command inside WLAN driver.

Dec 2, 2024
CVE-2024-43048
7.8 HIGH

Memory corruption when invalid input is passed to invoke GPU Headroom API call.

Dec 2, 2024
CVE-2024-33063
7.5 HIGH

Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which …

Dec 2, 2024
CVE-2024-33056
8.4 HIGH

Memory corruption when allocating and accessing an entry in an SMEM partition continuously.

Dec 2, 2024
CVE-2024-33044
8.4 HIGH

Memory corruption while Configuring the SMR/S2CR register in Bypass mode.

Dec 2, 2024
CVE-2024-53104
7.8 HIGH KEV

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out …

Dec 2, 2024
CVE-2024-53103
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: hv_sock: Initializing vsk->trans to NULL to prevent a dangling pointer When hvs is released, there …

Dec 2, 2024
CVE-2024-20138
7.5 HIGH

In wlan driver, there is a possible out of bound read due to improper input validation. This could lead to remote information disclosure with no …

Dec 2, 2024
CVE-2024-20137
7.5 HIGH

In wlan driver, there is a possible client disconnection due to improper handling of exceptional conditions. This could lead to remote denial of service with …

Dec 2, 2024
CVE-2024-20129
7.5 HIGH

In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with …

Dec 2, 2024
CVE-2024-20128
7.5 HIGH

In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with …

Dec 2, 2024
CVE-2024-20127
7.5 HIGH

In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with …

Dec 2, 2024
CVE-2024-53605
7.5 HIGH

Incorrect access control in the component content://com.handcent.messaging.provider.MessageProvider/ of Handcent NextSMS v10.9.9.7 allows attackers to access sensitive data.

Dec 2, 2024
CVE-2024-53750
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Maeve Lander PayPal Responder allows Stored XSS.This issue affects PayPal Responder: from n/a through 1.2.

Dec 1, 2024
CVE-2024-53742
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prism I.T. Systems Multilevel Referral Affiliate Plugin for WooCommerce multilevel-referral-plugin-for-woocommerce allows Reflected XSS.This …

Dec 1, 2024
CVE-2024-45520
7.5 HIGH

WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1 allows a remote Denial of Service because of memory corruption during scanning of a PE32 file.

Dec 1, 2024
CVE-2024-53778
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Essential Marketer Essential Breadcrumbs essential-breadcrumbs allows Stored XSS.This issue affects Essential Breadcrumbs: from n/a through <= 1.1.1.

Nov 30, 2024
CVE-2024-53783
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Anzar Ahmed Ni WooCommerce Cost Of Goods ni-woocommerce-cost-of-goods.This issue affects Ni …

Nov 30, 2024
CVE-2024-53739
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cool Plugins Cryptocurrency Widgets For Elementor cryptocurrency-widgets-for-elementor allows PHP …

Nov 30, 2024
CVE-2024-43703
8.1 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to achieve unauthorised reads and writes of physical memory from the …

Nov 30, 2024
CVE-2024-43702
8.1 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to allow unprivileged access to arbitrary physical memory page.

Nov 30, 2024
CVE-2024-53623
7.5 HIGH

Incorrect access control in the component l_0_0.xml of TP-Link ARCHER-C7 v5 allows attackers to access sensitive information.

Nov 29, 2024
CVE-2024-36612
7.5 HIGH

Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers.

Nov 29, 2024
CVE-2024-35371
7.5 HIGH

Ant-Media-Serverv2.8.2 is affected by Improper Output Neutralization for Logs. The vulnerability stems from insufficient input sanitization in the logging mechanism. Without proper filtering or validation, …

Nov 29, 2024
CVE-2024-53980
7.5 HIGH

RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded devices. A malicious actor …

Nov 29, 2024
CVE-2024-53979
8.2 HIGH

ibm.ibm_zhmc is an Ansible collection for the IBM Z HMC. The Ansible collection "ibm.ibm_zhmc" writes password-like properties in clear text into its log file and …

Nov 29, 2024
CVE-2024-53865
8.2 HIGH

zhmcclient is a pure Python client library for the IBM Z HMC Web Services API. In affected versions the Python package "zhmcclient" writes password-like properties …

Nov 29, 2024
CVE-2024-53848
7.1 HIGH

check-jsonschema is a CLI and set of pre-commit hooks for jsonschema validation. The default cache strategy uses the basename of a remote schema as the …

Nov 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.