CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-55546
5.4 MEDIUM

Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.

Dec 10, 2024
CVE-2024-55545
6.1 MEDIUM

Missing input validation in the ORing IAP-420 web-interface allows Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.

Dec 10, 2024
CVE-2024-46657
5.5 MEDIUM

Artifex Software mupdf v1.24.9 was discovered to contain a segmentation fault via the component /tools/pdfextract.c. This vulnerability allows attackers to cause a Denial of Service …

Dec 10, 2024
CVE-2024-12323
6.1 MEDIUM

The turboSMTP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all versions up to, and including, 4.6 due to …

Dec 10, 2024
CVE-2024-12236
5.5 MEDIUM

A security issue exists in Vertex Gemini API for customers using VPC-SC. By utilizing a custom crafted file URI for image input, data exfiltration is …

Dec 10, 2024
CVE-2024-54005
5.1 MEDIUM

A vulnerability has been identified in COMOS V10.3 (All versions < V10.3.3.5.8), COMOS V10.4.0 (All versions), COMOS V10.4.1 (All versions), COMOS V10.4.2 (All versions), COMOS …

Dec 10, 2024
CVE-2024-53832
4.6 MEDIUM

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V05.30). The affected devices contain a secure element which is connected via an …

Dec 10, 2024
CVE-2024-49704
5.5 MEDIUM

A vulnerability has been identified in COMOS V10.3 (All versions < V10.3.3.5.8), COMOS V10.4.0 (All versions), COMOS V10.4.1 (All versions), COMOS V10.4.2 (All versions), COMOS …

Dec 10, 2024
CVE-2024-47117
5.4 MEDIUM

IBM Carbon Design System (Carbon Charts 0.4.0 through 1.13.16) is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code …

Dec 10, 2024
CVE-2024-11868
5.3 MEDIUM

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.7.3 via class-lp-rest-material-controller.php. …

Dec 10, 2024
CVE-2024-11928
6.4 MEDIUM

The iChart – Easy Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions up to, …

Dec 10, 2024
CVE-2024-11106
5.3 MEDIUM

The Simple Restrict plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.7 via the WordPress core search …

Dec 10, 2024
CVE-2024-11973
6.1 MEDIUM

The Quran multilanguage Text & Audio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sourate' and 'lang' parameter in all versions up …

Dec 10, 2024
CVE-2024-11945
6.4 MEDIUM

The Email Reminders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 2.0.4 due …

Dec 10, 2024
CVE-2024-45709
5.3 MEDIUM

SolarWinds Web Help Desk was susceptible to a local file read vulnerability. This vulnerability requires the software be installed on Linux and configured to use …

Dec 10, 2024
CVE-2024-11940
6.4 MEDIUM

The Property Hive Mortgage Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘price’ parameter in all versions up to, and including, …

Dec 10, 2024
CVE-2024-11107
6.1 MEDIUM

The System Dashboard WordPress plugin before 2.8.15 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users …

Dec 10, 2024
CVE-2024-10708
4.9 MEDIUM

The System Dashboard WordPress plugin before 2.8.15 does not validate user input used in a path, which could allow high privilege users such as admin …

Dec 10, 2024
CVE-2024-47585
4.3 MEDIUM

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to gain higher access levels than they should have by exploiting improper …

Dec 10, 2024
CVE-2024-47582
5.3 MEDIUM

Due to missing validation of XML input, an unauthenticated attacker could send malicious input to an endpoint which leads to XML Entity Expansion attack. This …

Dec 10, 2024
CVE-2024-47581
4.3 MEDIUM

SAP HCM Approve Timesheets Version 4 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.There is low impact …

Dec 10, 2024
CVE-2024-47580
6.8 MEDIUM

An attacker authenticated as an administrator can use an exposed webservice to create a PDF with an embedded attachment. By specifying the file to be …

Dec 10, 2024
CVE-2024-47579
6.8 MEDIUM

An attacker authenticated as an administrator can use an exposed webservice to upload or download a custom PDF font file on the system server. Using …

Dec 10, 2024
CVE-2024-32732
5.3 MEDIUM

Under certain conditions SAP BusinessObjects Business Intelligence platform allows an attacker to access information which would otherwise be restricted.This has low impact on Confidentiality with …

Dec 10, 2024
CVE-2024-9672
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in PaperCut NG/MF. This issue can be used to execute specially created JavaScript payloads in the browser. A …

Dec 10, 2024
CVE-2024-55635
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from …

Dec 10, 2024
CVE-2024-12393
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from …

Dec 10, 2024
CVE-2024-12369
4.2 MEDIUM

A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, …

Dec 9, 2024
CVE-2024-54147
6.8 MEDIUM

Altair is a GraphQL client for all platforms. Prior to version 8.0.5, Altair GraphQL Client's desktop app does not validate HTTPS certificates allowing a man-in-the-middle …

Dec 9, 2024
CVE-2024-52599
5.4 MEDIUM

Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edition prior to version 16.1.99.50 and Tuleap Enterprise …

Dec 9, 2024
CVE-2024-52586
5.4 MEDIUM

eLabFTW is an open source electronic lab notebook for research labs. A vulnerability has been found starting in version 4.6.0 and prior to version 5.1.0 …

Dec 9, 2024
CVE-2022-29974
4.3 MEDIUM

AMI (aka American Megatrends) NTFS driver 1.0.0 (fixed in late 2021 or early 2022) has a buffer overflow. This driver is, for example, used in …

Dec 9, 2024
CVE-2024-54935
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts …

Dec 9, 2024
CVE-2024-11268
5.5 MEDIUM

A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a …

Dec 9, 2024
CVE-2024-45761
5.4 MEDIUM

Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input validation vulnerability. A remote low-privileged malicious user could potentially exploit this vulnerability to …

Dec 9, 2024
CVE-2024-45760
4.3 MEDIUM

Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper access control vulnerability. A remote low privileged user could potentially exploit this vulnerability via …

Dec 9, 2024
CVE-2023-43962
4.8 MEDIUM

Cross Site Scripting vulnerability in Xunrui CMS Public Edition v.4.6.1 allows a remote attacker to execute arbitrary code via the project name function in the …

Dec 9, 2024
CVE-2024-54919
5.4 MEDIUM

A Stored Cross Site Scripting (XSS ) was found in /teacher_avatar.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary …

Dec 9, 2024
CVE-2024-49603
4.3 MEDIUM

Dell PowerScale OneFS Versions 8.2.2.x through 9.9.0.x contain an incorrect specified argument vulnerability. A remote low privileged legitimate user could potentially exploit this vulnerability, leading …

Dec 9, 2024
CVE-2024-49602
6.5 MEDIUM

Dell PowerScale OneFS Versions 8.2.2.x through 9.8.0.x contain an improper resource unlocking vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to …

Dec 9, 2024
CVE-2024-42426
4.3 MEDIUM

Dell PowerScale OneFS Versions 9.5.0.x through 9.8.0.x contain an uncontrolled resource consumption vulnerability. A low privilege remote attacker could potentially exploit this vulnerability, leading to …

Dec 9, 2024
CVE-2024-38485
4.3 MEDIUM

Dell ECS, versions prior to 3.8.0, contain(s) a Host Header Injection Vulnerability. A remote low-privileged attacker could potentially exploit this vulnerability to trigger redirections that …

Dec 9, 2024
CVE-2024-11991
5.6 MEDIUM

Motoko's incremental garbage collector is impacted by an uninitialized memory access bug, caused by incorrect use of write barriers in a few locations. This vulnerability …

Dec 9, 2024
CVE-2023-7298
4.4 MEDIUM

A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to …

Dec 9, 2024
CVE-2024-54937
5.3 MEDIUM

A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/assets.

Dec 9, 2024
CVE-2024-54936
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message.php of Kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts …

Dec 9, 2024
CVE-2024-54218
6.5 MEDIUM

Missing Authorization vulnerability in thehp AIO Contact aio-contact.This issue affects AIO Contact: from n/a through <= 2.8.1.

Dec 9, 2024
CVE-2024-53949
6.5 MEDIUM

Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users to use this API. issue affects Apache …

Dec 9, 2024
CVE-2024-53948
5.3 MEDIUM

Generation of Error Message Containing analytics metadata Information in Apache Superset. This issue affects Apache Superset: before 4.1.0. Users are recommended to upgrade to version …

Dec 9, 2024
CVE-2024-53814
6.5 MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Adnan Analytify wp-analytify.This issue affects Analytify: from n/a through <= 5.4.3.

Dec 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.