CVE Database

53300+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-13204
5.5 MEDIUM

A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file …

Jan 9, 2025
CVE-2024-13203
4.3 MEDIUM

A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request …

Jan 9, 2025
CVE-2024-13201
4.7 MEDIUM

A vulnerability has been found in wander-chu SpringBoot-Blog 1.0 and classified as critical. This vulnerability affects the function upload of the file src/main/java/com/my/blog/website/controller/admin/AttachtController.java of the …

Jan 9, 2025
CVE-2023-38037
5.5 MEDIUM

ActiveSupport::EncryptedFile writes contents that will be encrypted to a temporary file. The temporary file's permissions are defaulted to the user's current `umask` settings, meaning that …

Jan 9, 2025
CVE-2023-28362
4.0 MEDIUM

The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential …

Jan 9, 2025
CVE-2023-28120
5.3 MEDIUM

There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.

Jan 9, 2025
CVE-2023-27539
5.3 MEDIUM

There is a denial of service vulnerability in the header parsing component of Rack.

Jan 9, 2025
CVE-2023-27531
5.3 MEDIUM

There is a deserialization of untrusted data vulnerability in the Kredis JSON deserialization code

Jan 9, 2025
CVE-2023-23913
6.3 MEDIUM

There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable …

Jan 9, 2025
CVE-2024-13195
6.3 MEDIUM

A vulnerability was found in donglight bookstore电商书城系统说明 1.0.0. It has been classified as critical. This affects the function getHtml of the file src/main/java/org/zdd/bookstore/rawl/HttpUtil.java. The manipulation …

Jan 9, 2025
CVE-2024-13194
6.3 MEDIUM

A vulnerability was found in Sucms 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/admin_members.php?ac=search. The manipulation …

Jan 9, 2025
CVE-2024-13193
6.3 MEDIUM

A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file …

Jan 8, 2025
CVE-2024-13191
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in ZeroWdd myblog 1.0. This issue affects the function upload of the file src/main/java/com/wdd/myblog/controller/admin/uploadController.java. The …

Jan 8, 2025
CVE-2024-52869
6.0 MEDIUM

Certain Teradata account-handling code through 2024-11-04, used with SUSE Enterprise Linux Server, mismanages groups. Specifically, when there is an operating system move from SUSE Enterprise …

Jan 8, 2025
CVE-2024-13190
6.3 MEDIUM

A vulnerability classified as critical was found in ZeroWdd myblog 1.0. This vulnerability affects unknown code of the file src/main/resources/mapper/BlogMapper.xml. The manipulation of the argument …

Jan 8, 2025
CVE-2024-12431
4.3 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.5 before 17.5.5, 17.6 before 17.6.3, and 17.7 before 17.7.1, in which unauthorized …

Jan 8, 2025
CVE-2025-22143
6.1 MEDIUM

WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the listar_permissoes.php endpoint of the WeGIA application. This …

Jan 8, 2025
CVE-2025-0194
6.5 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from …

Jan 8, 2025
CVE-2025-22139
6.1 MEDIUM

WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the configuracao_geral.php endpoint of the WeGIA application. This …

Jan 8, 2025
CVE-2024-53526
6.4 MEDIUM

composio >=0.5.40 is vulnerable to Command Execution in composio_openai, composio_claude, and composio_julep via the handle_tool_calls function.

Jan 8, 2025
CVE-2024-13188
5.3 MEDIUM

A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. Affected by this issue is some unknown functionality …

Jan 8, 2025
CVE-2024-6350
6.5 MEDIUM

A malformed 802.15.4 packet causes a buffer overflow to occur leading to an assert and a denial of service. A watchdog reset clears the error …

Jan 8, 2025
CVE-2024-56787
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: soc: imx8m: Probe the SoC driver as platform driver With driver_async_probe=* on kernel command line, …

Jan 8, 2025
CVE-2024-56785
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: MIPS: Loongson64: DTS: Really fix PCIe port nodes for ls7a Fix the dtc warnings: arch/mips/boot/dts/loongson/ls7a-pch.dtsi:68.16-416.5: …

Jan 8, 2025
CVE-2024-56783
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_socket: remove WARN_ON_ONCE on maximum cgroup level cgroup maximum depth is INT_MAX by default, …

Jan 8, 2025
CVE-2024-56782
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ACPI: x86: Add adev NULL check to acpi_quirk_skip_serdev_enumeration() acpi_dev_hid_match() does not check for adev == …

Jan 8, 2025
CVE-2024-56780
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: quota: flush quota_release_work upon quota writeback One of the paths quota writeback is called from …

Jan 8, 2025
CVE-2024-56779
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix nfs4_openowner leak when concurrent nfsd4_open occur The action force umount(umount -f) will attempt …

Jan 8, 2025
CVE-2024-56778
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/sti: avoid potential dereference of error pointers in sti_hqvdp_atomic_check The return value of drm_atomic_get_crtc_state() needs …

Jan 8, 2025
CVE-2024-56777
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/sti: avoid potential dereference of error pointers in sti_gdp_atomic_check The return value of drm_atomic_get_crtc_state() needs …

Jan 8, 2025
CVE-2024-56776
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/sti: avoid potential dereference of error pointers The return value of drm_atomic_get_crtc_state() needs to be …

Jan 8, 2025
CVE-2024-56774
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: add a sanity check for btrfs root in btrfs_search_slot() Syzbot reports a null-ptr-deref in …

Jan 8, 2025
CVE-2024-56773
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: kunit: Fix potential null dereference in kunit_device_driver_test() kunit_kzalloc() may return a NULL pointer, dereferencing it …

Jan 8, 2025
CVE-2024-56771
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mtd: spinand: winbond: Fix 512GW, 01GW, 01JW and 02JW ECC information These four chips: * …

Jan 8, 2025
CVE-2025-20168
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) …

Jan 8, 2025
CVE-2025-20167
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) …

Jan 8, 2025
CVE-2025-20166
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) …

Jan 8, 2025
CVE-2024-56770
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/sched: netem: account for backlog updates from child qdisc In general, 'qlen' of any classful …

Jan 8, 2025
CVE-2024-55459
6.5 MEDIUM

An issue in keras 3.7.0 allows attackers to write arbitrary files to the user's machine via downloading a crafted tar file through the get_file function.

Jan 8, 2025
CVE-2024-13187
5.3 MEDIUM

A vulnerability was found in Kingsoft WPS Office 6.14.0 on macOS. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Jan 8, 2025
CVE-2025-20126
4.8 MEDIUM

A vulnerability in certification validation routines of Cisco ThousandEyes Endpoint Agent for macOS and RoomOS could allow an unauthenticated, remote attacker to intercept or manipulate …

Jan 8, 2025
CVE-2025-20123
4.8 MEDIUM

Multiple vulnerabilities in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against …

Jan 8, 2025
CVE-2024-12337
6.1 MEDIUM

The Shipping via Planzer for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘processed-ids’ parameter in all versions up to, and …

Jan 8, 2025
CVE-2024-11830
6.4 MEDIUM

The PDF Flipbook, 3D Flipbook—DearFlip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via outline settings in all versions up to 2.3.52 due to …

Jan 8, 2025
CVE-2024-12712
5.3 MEDIUM

The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the webhook …

Jan 8, 2025
CVE-2024-12855
4.3 MEDIUM

The AdForest theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions like 'sb_remove_ad' in …

Jan 8, 2025
CVE-2024-12328
6.4 MEDIUM

The MAS Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.7 due …

Jan 8, 2025
CVE-2024-12045
4.4 MEDIUM

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the maker title value …

Jan 8, 2025
CVE-2025-22215
4.3 MEDIUM

VMware Aria Automation contains a server-side request forgery (SSRF) vulnerability. A malicious actor with "Organization Member" access to Aria Automation may exploit this vulnerability enumerate …

Jan 8, 2025
CVE-2024-8002
4.3 MEDIUM

A vulnerability has been found in VIWIS LMS 9.11 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component File …

Jan 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.