CVE Database

53300+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-57682
6.5 MEDIUM

An information disclosure vulnerability in the component d_status.asp of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to access sensitive information via a crafted POST request.

Jan 16, 2025
CVE-2024-57681
5.3 MEDIUM

An access control issue in the component form2alg.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the agl service of the device via a crafted …

Jan 16, 2025
CVE-2024-57680
5.3 MEDIUM

An access control issue in the component form2PortriggerRule.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the port trigger of the device via a crafted …

Jan 16, 2025
CVE-2024-57679
6.5 MEDIUM

An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G repeater service of the device …

Jan 16, 2025
CVE-2024-57678
6.5 MEDIUM

An access control issue in the component form2WlAc.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G mac access control list of …

Jan 16, 2025
CVE-2024-57677
6.5 MEDIUM

An access control issue in the component form2Wan.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the wan service of the device via a crafted …

Jan 16, 2025
CVE-2024-57676
6.5 MEDIUM

An access control issue in the component form2WlanBasicSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G wlan service of the device …

Jan 16, 2025
CVE-2024-52594
4.3 MEDIUM

Gomatrixserverlib is a Go library for matrix federation. Gomatrixserverlib is vulnerable to server-side request forgery, serving content from a private network it can access, under …

Jan 16, 2025
CVE-2025-20072
6.5 MEDIUM

Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to …

Jan 16, 2025
CVE-2024-57776
4.6 MEDIUM

A cross-site scripting (XSS) vulnerability in the /apply/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Jan 16, 2025
CVE-2024-57774
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in the getBusinessUploadListPage?busid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Jan 16, 2025
CVE-2024-57773
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Jan 16, 2025
CVE-2024-57772
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Jan 16, 2025
CVE-2024-57771
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Jan 16, 2025
CVE-2025-0518
5.3 MEDIUM

Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive Constants Within an Executable. This vulnerability is associated with program files https://github.Com/FFmpeg/FFmpeg/blob/master/libavfilter/af_pan.C . This …

Jan 16, 2025
CVE-2024-57161
4.3 MEDIUM

07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit.html

Jan 16, 2025
CVE-2024-57160
4.3 MEDIUM

07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaTask/edit.html.

Jan 16, 2025
CVE-2025-0473
6.5 MEDIUM

Vulnerability in the PMB platform that allows an attacker to persist temporary files on the server, affecting versions 4.0.10 and above. This vulnerability exists in …

Jan 16, 2025
CVE-2024-13387
6.4 MEDIUM

The WP Responsive Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprtabs' shortcode in all versions up to, and including, …

Jan 16, 2025
CVE-2024-13355
5.4 MEDIUM

The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to limited file uploads due to insufficient file type validation …

Jan 16, 2025
CVE-2024-12615
6.5 MEDIUM

The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX actions in all versions up to, and …

Jan 16, 2025
CVE-2024-12427
5.3 MEDIUM

The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability check on the fw_upload_file AJAX action …

Jan 16, 2025
CVE-2024-48885
5.3 MEDIUM

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder 7.2.0 through 7.2.1, FortiRecorder 7.0.0 through 7.0.4, FortiVoice 7.0.0 …

Jan 16, 2025
CVE-2024-12226
6.5 MEDIUM

In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes script pod log in clear-text. This was …

Jan 16, 2025
CVE-2024-11452
6.4 MEDIUM

The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'business_categories' shortcode in all versions up to, and …

Jan 16, 2025
CVE-2024-10789
4.3 MEDIUM

The WP User Profile Avatar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5. This is due …

Jan 16, 2025
CVE-2025-0170
6.1 MEDIUM

The DWT - Directory & Listing WordPress Theme is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.3.3 due to insufficient input …

Jan 16, 2025
CVE-2024-10970
5.4 MEDIUM

The The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, …

Jan 16, 2025
CVE-2025-0476
4.3 MEDIUM

Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, which allows an attacker to crash the mobile app for any user …

Jan 16, 2025
CVE-2025-0215
6.1 MEDIUM

The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the showdata and initiate_restore parameters in all versions …

Jan 15, 2025
CVE-2024-41454
6.5 MEDIUM

An arbitrary file upload vulnerability in the UI login page logo upload function of Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitrary code via …

Jan 15, 2025
CVE-2024-41453
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Jan 15, 2025
CVE-2024-39967
6.5 MEDIUM

Insecure permissions in Aginode GigaSwitch v5 allows attackers to access sensitive information via using the SCP command.

Jan 15, 2025
CVE-2025-0491
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Fanli2012 native-php-cms 1.0. Affected is an unknown function of the file /fladmin/cat_dodel.php. The manipulation of …

Jan 15, 2025
CVE-2025-0490
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Fanli2012 native-php-cms 1.0. This issue affects some unknown processing of the file /fladmin/article_dodel.php. The …

Jan 15, 2025
CVE-2025-0489
6.3 MEDIUM

A vulnerability classified as critical was found in Fanli2012 native-php-cms 1.0. This vulnerability affects unknown code of the file /fladmin/friendlink_dodel.php. The manipulation of the argument …

Jan 15, 2025
CVE-2024-36751
6.5 MEDIUM

An issue in parse-uri v1.0.9 allows attackers to cause a Regular expression Denial of Service (ReDoS) via a crafted URL.

Jan 15, 2025
CVE-2025-0488
6.3 MEDIUM

A vulnerability classified as critical has been found in Fanli2012 native-php-cms 1.0. This affects an unknown part of the file product_list.php. The manipulation of the …

Jan 15, 2025
CVE-2025-0487
6.3 MEDIUM

A vulnerability was found in Fanli2012 native-php-cms 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file …

Jan 15, 2025
CVE-2024-48122
6.7 MEDIUM

Insecure default configurations in HI-SCAN 6040i Hitrax HX-03-19-I allow authenticated attackers with low-level privileges to escalate to root-level privileges.

Jan 15, 2025
CVE-2024-48121
6.5 MEDIUM

The HI-SCAN 6040i Hitrax HX-03-19-I was discovered to transmit user credentials in cleartext over the GIOP protocol. This allows attackers to possibly gain access to …

Jan 15, 2025
CVE-2024-54540
4.3 MEDIUM

The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Processing maliciously crafted web content may disclose …

Jan 15, 2025
CVE-2024-54535
4.3 MEDIUM

A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, visionOS 2.1, watchOS …

Jan 15, 2025
CVE-2024-54470
4.6 MEDIUM

A logic issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1. An attacker …

Jan 15, 2025
CVE-2024-44136
4.6 MEDIUM

This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to a …

Jan 15, 2025
CVE-2024-40854
5.5 MEDIUM

A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, …

Jan 15, 2025
CVE-2025-0481
5.3 MEDIUM

A vulnerability classified as problematic has been found in D-Link DIR-878 1.03. Affected is an unknown function of the file /dllog.cgi of the component HTTP …

Jan 15, 2025
CVE-2025-23040
6.6 MEDIUM

GitHub Desktop is an open-source Electron-based GitHub app designed for git development. An attacker convincing a user to clone a repository directly or through a …

Jan 15, 2025
CVE-2025-0480
4.3 MEDIUM

A vulnerability classified as problematic has been found in wuzhicms 4.1.0. This affects the function test of the file coreframe/app/search/admin/config.php. The manipulation of the argument …

Jan 15, 2025
CVE-2025-21083
6.5 MEDIUM

Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.

Jan 15, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.