CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-53269
4.5 MEDIUM

Envoy is a cloud-native high-performance edge/middle/service proxy. When additional address are not ip addresses, then the Happy Eyeballs sorting algorithm will crash in data plane. …

Dec 18, 2024
CVE-2024-52593
5.3 MEDIUM

Misskey is an open source, federated social media platform.In affected versions missing validation in `NoteCreateService.insertNote`, `ApPersonService.createPerson`, and `ApPersonService.updatePerson` allows an attacker to control the target …

Dec 18, 2024
CVE-2024-52592
5.3 MEDIUM

Misskey is an open source, federated social media platform. In affected versions missing validation in `ApInboxService.update` allows an attacker to modify the result of polls …

Dec 18, 2024
CVE-2024-52590
6.5 MEDIUM

Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService.signedGet` allows an attacker to create fake user profiles that …

Dec 18, 2024
CVE-2024-52579
6.4 MEDIUM

Misskey is an open source, federated social media platform. Some APIs using `HttpRequestService` do not properly check the target host. This vulnerability allows an attacker …

Dec 18, 2024
CVE-2024-51470
6.5 MEDIUM

IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD, IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and IBM …

Dec 18, 2024
CVE-2024-49201
4.3 MEDIUM

Keyfactor Remote File Orchestrator (aka remote-file-orchestrator) 2.8 before 2.8.1 allows Information Disclosure: sensitive information could be exposed at the debug logging level.

Dec 18, 2024
CVE-2024-47039
5.5 MEDIUM

In isSlotMarkedSuccessful of BootControl.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Dec 18, 2024
CVE-2024-55089
4.1 MEDIUM

Rhymix before 2.1.24 is vulnerable to Server-Side Request Forgery (SSRF) in the background import data function because XML documents may contain external entities.

Dec 18, 2024
CVE-2024-55492
6.1 MEDIUM

Winmail Server 4.4 is vulnerable to f_user=%22%3E%3Csvg%20onload Cross Site Scripting (XSS).

Dec 18, 2024
CVE-2024-45082
6.8 MEDIUM

IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By …

Dec 18, 2024
CVE-2024-41752
5.4 MEDIUM

IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when …

Dec 18, 2024
CVE-2024-25042
5.4 MEDIUM

IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is potentially vulnerable to Cross Site Scripting (XSS). A remote attacker could execute malicious commands …

Dec 18, 2024
CVE-2024-52361
5.7 MEDIUM

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 stores user credentials in plain text which can be read by an authenticated user with access …

Dec 18, 2024
CVE-2024-47119
5.9 MEDIUM

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 does not properly validate a certificate which could allow an attacker to spoof a trusted entity …

Dec 18, 2024
CVE-2023-50956
4.4 MEDIUM

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 could allow a privileged user to obtain highly sensitive user credentials from secret keys that are …

Dec 18, 2024
CVE-2024-56128
5.3 MEDIUM

Incorrect Implementation of Authentication Algorithm in Apache Kafka's SCRAM implementation. Issue Summary: Apache Kafka's implementation of the Salted Challenge Response Authentication Mechanism (SCRAM) did not …

Dec 18, 2024
CVE-2024-50570
5.0 MEDIUM

A Cleartext Storage of Sensitive Information vulnerability [CWE-312] in FortiClientWindows 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13 and FortiClientLinux 7.4.0 through 7.4.2, 7.2.0 …

Dec 18, 2024
CVE-2024-55997
6.5 MEDIUM

Missing Authorization vulnerability in webchunky Order Delivery & Pickup Location Date Time order-delivery-pickup-location-date-time-free-version allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Delivery …

Dec 18, 2024
CVE-2024-52485
6.5 MEDIUM

Missing Authorization vulnerability in Yudiz Solutions Ltd. WP Menu Image wp-menu-image allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Menu Image: from …

Dec 18, 2024
CVE-2024-11926
6.5 MEDIUM

The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '__stPartnerCreateServiceRental', 'st_delete_order_item', …

Dec 18, 2024
CVE-2024-11291
5.3 MEDIUM

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up …

Dec 18, 2024
CVE-2024-47104
6.8 MEDIUM

IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with authority to a view …

Dec 18, 2024
CVE-2024-12554
5.4 MEDIUM

The Peter’s Custom Anti-Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.3. This is due to …

Dec 18, 2024
CVE-2024-12454
6.1 MEDIUM

The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.23. This …

Dec 18, 2024
CVE-2024-12340
4.3 MEDIUM

The Animation Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.6 via the 'render' …

Dec 18, 2024
CVE-2024-11295
5.3 MEDIUM

The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.29 via the WordPress …

Dec 18, 2024
CVE-2024-56175
6.1 MEDIUM

In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from client-side template injection …

Dec 18, 2024
CVE-2024-56173
4.7 MEDIUM

In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from JavaScript in an …

Dec 18, 2024
CVE-2024-10892
5.4 MEDIUM

The Cost Calculator Builder WordPress plugin before 3.2.43 does not have CSRF checks in some AJAX actions, which could allow attackers to make logged in …

Dec 18, 2024
CVE-2024-56170
5.3 MEDIUM

A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI manifests are listings of relevant files that clients are supposed to verify. …

Dec 18, 2024
CVE-2024-56169
5.3 MEDIUM

A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI Relying Parties (such as Fort) are supposed to maintain a backup cache …

Dec 18, 2024
CVE-2024-12698
6.5 MEDIUM

An incomplete fix for ose-olm-catalogd-container was issued for the Rapid Reset Vulnerability (CVE-2023-39325/CVE-2023-44487) where only unauthenticated streams were protected, not streams created by authenticated sources.

Dec 18, 2024
CVE-2024-12596
4.3 MEDIUM

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to arbitrary post deletion due to a missing capability …

Dec 18, 2024
CVE-2024-12449
6.4 MEDIUM

The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_player_html' shortcode in …

Dec 18, 2024
CVE-2024-12250
5.3 MEDIUM

The Accept Authorize.NET Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2 via …

Dec 18, 2024
CVE-2024-12061
4.3 MEDIUM

The Events Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.3 via the naevents_elementor_template shortcode …

Dec 18, 2024
CVE-2024-11254
6.1 MEDIUM

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the disqus_name parameter in all versions up …

Dec 18, 2024
CVE-2024-12513
6.4 MEDIUM

The Contests by Rewards Fuel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'RF_CONTEST' shortcode in all versions up to, and …

Dec 18, 2024
CVE-2024-12500
6.4 MEDIUM

The Philantro – Donations and Donor Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes like 'donate' in all versions …

Dec 18, 2024
CVE-2024-11881
6.4 MEDIUM

The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easywaveformplayer' shortcode in all versions up to, and including, …

Dec 18, 2024
CVE-2024-11748
6.4 MEDIUM

The Taeggie Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'taeggie-feed' shortcode in all versions up to, and including, 0.1.9 …

Dec 18, 2024
CVE-2024-11439
6.4 MEDIUM

The ScanCircle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'scancircle' shortcode in all versions up to, and including, 2.9.2 due …

Dec 18, 2024
CVE-2024-10973
5.7 MEDIUM

A vulnerability was found in Keycloak. The environment option `KC_CACHE_EMBEDDED_MTLS_ENABLED` does not work and the JGroups replication configuration is always used in plain text which …

Dec 17, 2024
CVE-2024-56142
6.5 MEDIUM

pghoard is a PostgreSQL backup daemon and restore tooling that stores backup data in cloud object stores. A vulnerability has been discovered that could allow …

Dec 17, 2024
CVE-2024-52792
6.5 MEDIUM

LDAP Account Manager (LAM) is a php webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In affected versions LAM …

Dec 17, 2024
CVE-2023-37940
4.8 MEDIUM

Cross-site scripting (XSS) vulnerability in the edit Service Access Policy page in Liferay Portal 7.0.0 through 7.4.3.87, and Liferay DXP 7.4 GA through update 87, …

Dec 17, 2024
CVE-2024-55059
6.1 MEDIUM

A stored HTML Injection vulnerability was identified in PHPGurukul Online Birth Certificate System v1.0 in /user/certificate-form.php.

Dec 17, 2024
CVE-2024-55058
4.3 MEDIUM

An insecure direct object reference (IDOR) vulnerability was discovered in PHPGurukul Online Birth Certificate System v1.0. This vulnerability resides in the viewid parameter of /user/view-application-detail.php. …

Dec 17, 2024
CVE-2024-55057
5.4 MEDIUM

Phpgurukul Online Birth Certificate System 1.0 suffers from insufficient password requirements which can lead to unauthorized access to user accounts.

Dec 17, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.