CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-55056
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability was identified in Phpgurukul Online Birth Certificate System 1.0 in /user/certificate-form.php via the full name field.

Dec 17, 2024
CVE-2024-12539
6.5 MEDIUM

An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and …

Dec 17, 2024
CVE-2024-11993
6.1 MEDIUM

Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38 allows remote attackers to execute arbitrary …

Dec 17, 2024
CVE-2024-55514
6.3 MEDIUM

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_sfmig.php on the web interface. By …

Dec 17, 2024
CVE-2024-49819
4.1 MEDIUM

IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information in cleartext in a communication …

Dec 17, 2024
CVE-2024-49818
4.3 MEDIUM

IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information when a detailed technical error …

Dec 17, 2024
CVE-2024-49817
4.4 MEDIUM

IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in configuration files which can be read by a local privileged …

Dec 17, 2024
CVE-2024-49816
4.9 MEDIUM

IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitive information in log files that could be read by a local …

Dec 17, 2024
CVE-2024-53144
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Align BR/EDR JUST_WORKS paring with LE This aligned BR/EDR JUST_WORKS method with LE …

Dec 17, 2024
CVE-2024-37607
6.5 MEDIUM

A Buffer overflow vulnerability in D-Link DAP-2555 REVA_FIRMWARE_1.20 allows remote attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

Dec 17, 2024
CVE-2024-37606
6.5 MEDIUM

A Stack overflow vulnerability in D-Link DCS-932L REVB_FIRMWARE_2.18.01 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

Dec 17, 2024
CVE-2024-37605
6.5 MEDIUM

A NULL pointer dereference in D-Link DIR-860L REVB_FIRMWARE_2.04.B04_ic5b allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

Dec 17, 2024
CVE-2024-36831
5.3 MEDIUM

A NULL pointer dereference in the plugins_call_handle_uri_clean function of D-Link DAP-1520 REVA_FIRMWARE_1.10B04_BETA02_HOTFIX allows attackers to cause a Denial of Service (DoS) via a crafted HTTP …

Dec 17, 2024
CVE-2024-9819
6.5 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in NextGeography NG Analyser allows Functionality Misuse.This issue affects NG Analyser: before 2.2.711.

Dec 17, 2024
CVE-2024-54677
5.3 MEDIUM

Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 …

Dec 17, 2024
CVE-2024-10356
4.3 MEDIUM

The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.4.8 in inc/Widgets/accordion/output/content.php. This …

Dec 17, 2024
CVE-2024-8475
6.5 MEDIUM

Authentication Bypass by Assumed-Immutable Data vulnerability in Digital Operation Services WiFiBurada allows Manipulating User-Controlled Variables.This issue affects WiFiBurada: before 1.0.5.

Dec 17, 2024
CVE-2024-8429
4.3 MEDIUM

Improper Restriction of Excessive Authentication Attempts vulnerability in Digital Operation Services WiFiBurada allows Use of Known Domain Credentials.This issue affects WiFiBurada: before 1.0.5.

Dec 17, 2024
CVE-2024-52542
4.4 MEDIUM

Dell AppSync, version 4.6.0.x, contain a Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to …

Dec 17, 2024
CVE-2024-12601
5.3 MEDIUM

The Calculated Fields Form plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 5.2.63. This is due to …

Dec 17, 2024
CVE-2024-12395
6.1 MEDIUM

The WooCommerce Additional Fees On Checkout (Free) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘number’ parameter in all versions up to, …

Dec 17, 2024
CVE-2024-11280
5.3 MEDIUM

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.5 via the …

Dec 17, 2024
CVE-2024-12469
6.1 MEDIUM

The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘status’ parameter in all versions …

Dec 17, 2024
CVE-2024-12127
6.1 MEDIUM

The Learning Management System, eLearning, Course Builder, WordPress LMS Plugin – Sikshya LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ …

Dec 17, 2024
CVE-2024-11294
5.3 MEDIUM

The Memberful plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.73.9 via the WordPress core search feature. …

Dec 17, 2024
CVE-2024-12220
6.1 MEDIUM

The SMS for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.1. This is due to …

Dec 17, 2024
CVE-2024-12219
6.1 MEDIUM

The Stop Registration Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.23. This is due to …

Dec 17, 2024
CVE-2021-26281
5.5 MEDIUM

Some parameters of the alarm clock module are improperly stored, leaking some sensitive information.

Dec 17, 2024
CVE-2024-55864
4.8 MEDIUM

Cross-site scripting vulnerability exists in My WP Customize Admin/Frontend versions prior to ver 1.24.1. If a malicious administrative user customizes the administrative page with some …

Dec 17, 2024
CVE-2021-26279
5.9 MEDIUM

Some parameters of the weather module are improperly stored, leaking some sensitive information.

Dec 17, 2024
CVE-2024-12239
6.1 MEDIUM

The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the navigate parameter in all versions up to, and …

Dec 17, 2024
CVE-2021-26278
6.3 MEDIUM

The wifi module exposes the interface and has improper permission control, leaking sensitive information about the device.

Dec 17, 2024
CVE-2020-12484
6.4 MEDIUM

When using special mode to connect to enterprise wifi, certain options are not properly configured and attackers can pretend to be enterprise wifi through a …

Dec 17, 2024
CVE-2024-11906
6.4 MEDIUM

The TPG Get Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tpg_get_posts' shortcode in all versions up to, and including, …

Dec 17, 2024
CVE-2024-11905
6.4 MEDIUM

The Animated Counters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'animatedcounte' shortcode in all versions up to, and including, 2.0 …

Dec 17, 2024
CVE-2024-11902
6.4 MEDIUM

The Slope Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slope-reservations' shortcode in all versions up to, and including, 4.2.12 …

Dec 17, 2024
CVE-2024-11900
6.4 MEDIUM

The Portfolio – Filterable Masonry Portfolio Gallery for Professionals plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'portfolio-pro' shortcode in all …

Dec 17, 2024
CVE-2024-55452
5.4 MEDIUM

A URL redirection vulnerability exists in UJCMS 9.6.3 due to improper validation of URLs in the upload and rendering of new block / carousel items. …

Dec 16, 2024
CVE-2024-55451
4.8 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability exists in authenticated SVG file upload and viewing functionality in UJCMS 9.6.3. The vulnerability arises from insufficient sanitization of …

Dec 16, 2024
CVE-2024-35230
5.3 MEDIUM

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. In affected versions the welcome and …

Dec 16, 2024
CVE-2024-12443
6.4 MEDIUM

The CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'crm-perks-tickets' shortcode …

Dec 16, 2024
CVE-2024-55554
5.4 MEDIUM

Intrexx Portal Server before 12.0.2 allows XSS via a user-defined portlet.

Dec 16, 2024
CVE-2024-37776
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in Sunbird DCIM dcTrack v9.1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in some …

Dec 16, 2024
CVE-2024-37773
4.8 MEDIUM

An HTML injection vulnerability in Sunbird DCIM dcTrack 9.1.2 allows attackers authenticated as administrators to inject arbitrary HTML code in an admin screen.

Dec 16, 2024
CVE-2024-55100
4.8 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Online Nurse Hiring System v1.0 allows attackers to execute arbitrary web scripts or HTML …

Dec 16, 2024
CVE-2024-12666
4.7 MEDIUM

A vulnerability has been found in ClassCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file …

Dec 16, 2024
CVE-2024-12662
5.5 MEDIUM

A vulnerability classified as problematic has been found in IObit Advanced SystemCare Utimate up to 17.0.0. This affects the function 0x8001E040 in the library AscRegistryFilter.sys …

Dec 16, 2024
CVE-2024-12661
5.5 MEDIUM

A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0. It has been rated as problematic. Affected by this issue is the function …

Dec 16, 2024
CVE-2024-12660
5.5 MEDIUM

A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0. It has been declared as problematic. Affected by this vulnerability is the function …

Dec 16, 2024
CVE-2024-12659
5.5 MEDIUM

A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0. It has been classified as problematic. Affected is the function 0x8001E004 in the …

Dec 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.