CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-56365
5.4 MEDIUM

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site …

Jan 3, 2025
CVE-2024-56408
5.4 MEDIUM

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have no sanitization in the `/vendor/phpoffice/phpspreadsheet/samples/Engineering/Convert-Online.php` …

Jan 3, 2025
CVE-2024-5591
4.3 MEDIUM

IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in …

Jan 3, 2025
CVE-2024-41780
4.2 MEDIUM

IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could could allow a physical user to obtain sensitive information due to not masking passwords during entry.

Jan 3, 2025
CVE-2024-12132
4.3 MEDIUM

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference …

Jan 3, 2025
CVE-2024-53839
5.5 MEDIUM

In GetCellInfoList() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Jan 3, 2025
CVE-2024-53836
6.7 MEDIUM

In wbrc_bt_dev_write of wb_regon_coordinator.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege …

Jan 3, 2025
CVE-2025-0176
6.3 MEDIUM

A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown …

Jan 3, 2025
CVE-2025-0174
6.3 MEDIUM

A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0. It has been classified as critical. This affects an unknown part …

Jan 3, 2025
CVE-2024-8447
5.9 MEDIUM

A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds …

Jan 2, 2025
CVE-2024-48197
4.7 MEDIUM

Cross Site Scripting vulnerability in Audiocodes MP-202b v.4.4.3 allows a remote attacker to escalate privileges via the login page of the web interface.

Jan 2, 2025
CVE-2025-0173
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jan 2, 2025
CVE-2024-56199
5.2 MEDIUM

phpMyFAQ is an open source FAQ web application. Starting no later than version 3.2.10 and prior to version 4.0.2, an attacker can inject malicious HTML …

Jan 2, 2025
CVE-2025-0172
6.3 MEDIUM

A vulnerability has been found in code-projects Chat System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file …

Jan 2, 2025
CVE-2024-56414
5.5 MEDIUM

Web installer integrity check used weak hash algorithm. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.

Jan 2, 2025
CVE-2024-56413
6.1 MEDIUM

Missing session invalidation after user deletion. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.

Jan 2, 2025
CVE-2024-55542
4.4 MEDIUM

Local privilege escalation due to excessive permissions assigned to Tray Monitor service. The following products are affected: Acronis Cyber Protect 16 (Linux, macOS, Windows) before …

Jan 2, 2025
CVE-2024-55541
6.1 MEDIUM

Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build …

Jan 2, 2025
CVE-2023-23672
5.4 MEDIUM

Missing Authorization vulnerability in Liquid Web / StellarWP GiveWP.This issue affects GiveWP: from n/a through 2.25.1.

Jan 2, 2025
CVE-2022-47601
5.3 MEDIUM

Missing Authorization vulnerability in JoomUnited WP Table Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Table Manager: from n/a through 3.5.2.

Jan 2, 2025
CVE-2022-45811
5.4 MEDIUM

Missing Authorization vulnerability in WeyHan Ng Post Teaser.This issue affects Post Teaser: from n/a through 4.1.5.

Jan 2, 2025
CVE-2025-0171
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Chat System 1.0. Affected is an unknown function of the file /admin/deleteuser.php. The manipulation …

Jan 2, 2025
CVE-2024-56137
6.8 MEDIUM

MaxKB, which stands for Max Knowledge Base, is an open source knowledge base question-answering system based on a large language model and retrieval-augmented generation (RAG). …

Jan 2, 2025
CVE-2024-55538
4.0 MEDIUM

Sensitive information disclosure due to missing authentication. The following products are affected: Acronis True Image (macOS) before build 41725, Acronis True Image (Windows) before build …

Jan 2, 2025
CVE-2024-49385
5.5 MEDIUM

Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis True Image (Windows) before build 41736, Acronis True Image OEM (Windows) …

Jan 2, 2025
CVE-2023-48739
5.3 MEDIUM

Missing Authorization vulnerability in Porto Theme Porto Theme - Functionality porto-functionality allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Porto Theme - Functionality: …

Jan 2, 2025
CVE-2023-47807
4.3 MEDIUM

Missing Authorization vulnerability in 10Web 10WebAnalytics wd-google-analytics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 10WebAnalytics: from n/a through <= 1.2.12.

Jan 2, 2025
CVE-2023-47778
4.3 MEDIUM

Missing Authorization vulnerability in LuckyWP LuckyWP Scripts Control luckywp-scripts-control allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LuckyWP Scripts Control: from n/a through …

Jan 2, 2025
CVE-2023-45633
6.5 MEDIUM

Missing Authorization vulnerability in IDX IMPress Listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IMPress Listings: from n/a through 2.6.2.

Jan 2, 2025
CVE-2023-45272
5.4 MEDIUM

Missing Authorization vulnerability in 10Web 10Web Map Builder for Google Maps allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 10Web Map Builder for …

Jan 2, 2025
CVE-2023-40327
6.5 MEDIUM

Missing Authorization vulnerability in Putler / Storeapps Putler Connector for WooCommerce.This issue affects Putler Connector for WooCommerce: from n/a through 2.12.0.

Jan 2, 2025
CVE-2023-39994
4.3 MEDIUM

Missing Authorization vulnerability in Repute InfoSystems ARMember Premium allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ARMember Premium: from n/a through 5.9.2.

Jan 2, 2025
CVE-2023-32240
5.4 MEDIUM

Missing Authorization vulnerability in Xtemos WoodMart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WoodMart: from n/a through 7.2.1.

Jan 2, 2025
CVE-2022-49035
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: s5p_cec: limit msg.len to CEC_MAX_MSG_SIZE I expect that the hardware will have limited this …

Jan 2, 2025
CVE-2022-45830
6.5 MEDIUM

Missing Authorization vulnerability in Analytify.This issue affects Analytify: from n/a through 4.2.3.

Jan 2, 2025
CVE-2022-43476
4.3 MEDIUM

Missing Authorization vulnerability in Daniel Söderström / Sidney van de Stouwe Subscribe to Category allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscribe …

Jan 2, 2025
CVE-2022-41995
4.3 MEDIUM

Missing Authorization vulnerability in Galleryape Gallery Images Ape allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gallery Images Ape: from n/a through 2.2.8.

Jan 2, 2025
CVE-2024-38732
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in VolThemes Patricia Blog allows Cross Site Request Forgery.This issue affects Patricia Blog: from n/a through 1.2.

Jan 2, 2025
CVE-2024-38731
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Marsian i-amaze allows Cross Site Request Forgery.This issue affects i-amaze: from n/a through 1.3.7.

Jan 2, 2025
CVE-2024-37931
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Creativthemes Point allows Cross Site Request Forgery.This issue affects Point: from n/a through 1.1.

Jan 2, 2025
CVE-2024-37925
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in BUDDYBOSS LLC BuddyBoss Theme allows Cross Site Request Forgery.This issue affects BuddyBoss Theme: from n/a through 2.4.61.

Jan 2, 2025
CVE-2024-37452
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in MyThemeShop Schema Lite allows Cross Site Request Forgery.This issue affects Schema Lite: from n/a through 1.2.2.

Jan 2, 2025
CVE-2024-37438
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Toolkit Pro for LearnDash allows Cross Site Request Forgery.This issue affects Uncanny Toolkit Pro for LearnDash: …

Jan 2, 2025
CVE-2024-37241
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Automattic WP Job Manager - Resume Manager allows Cross Site Request Forgery.This issue affects WP Job Manager - Resume …

Jan 2, 2025
CVE-2024-37237
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in fs-code FS Poster fs-poster allows Cross Site Request Forgery.This issue affects FS Poster: from n/a through <= 6.5.8.

Jan 2, 2025
CVE-2024-13111
5.6 MEDIUM

A vulnerability classified as critical was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected by this vulnerability is an unknown functionality …

Jan 2, 2025
CVE-2024-13110
4.3 MEDIUM

A vulnerability classified as problematic has been found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected is an unknown function of the …

Jan 2, 2025
CVE-2024-56268
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hookandhook Post Grid Elementor Addon post-grid-elementor-addon.This issue affects Post Grid Elementor Addon: from …

Jan 2, 2025
CVE-2024-56257
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CoolPlugins Coins MarketCap coins-marketcap allows DOM-Based XSS.This issue affects Coins MarketCap: from n/a …

Jan 2, 2025
CVE-2024-38778
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search fulltext-search.This issue affects WP Fast Total Search: from n/a through <= 1.69.234.

Jan 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.