CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-54001
5.5 MEDIUM

Kanboard is project management software that focuses on the Kanban methodology. HTML can be injected and stored into the application settings section. The fields application_language, …

Dec 5, 2024
CVE-2024-53471
6.1 MEDIUM

Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/meio_pagamento.php of WeGIA v3.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Dec 5, 2024
CVE-2024-53470
6.1 MEDIUM

Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/gateway_pagamento.php of WeGIA v3.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Dec 5, 2024
CVE-2024-12247
4.6 MEDIUM

Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate permission scheme updates across cluster nodes which allows a …

Dec 5, 2024
CVE-2024-10716
5.9 MEDIUM

Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search.

Dec 5, 2024
CVE-2024-11942
5.9 MEDIUM

A vulnerability in Drupal Core allows File Manipulation.This issue affects Drupal Core: from 10.0.0 before 10.2.10.

Dec 5, 2024
CVE-2024-54679
4.3 MEDIUM

CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.

Dec 5, 2024
CVE-2024-53702
5.3 MEDIUM

Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certain cases, can be predicted by …

Dec 5, 2024
CVE-2024-45319
6.3 MEDIUM

A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions allows a remote authenticated attacker can circumvent the certificate requirement during authentication.

Dec 5, 2024
CVE-2024-12227
5.5 MEDIUM

A vulnerability, which was classified as problematic, was found in MSI Dragon Center up to 2.0.146.0. This affects the function MmUnMapIoSpace in the library NTIOLib_X64.sys …

Dec 5, 2024
CVE-2024-45841
6.5 MEDIUM

Incorrect permission assignment for critical resource issue exists in UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier. If an attacker with the …

Dec 5, 2024
CVE-2024-11779
6.4 MEDIUM

The WIP WooCarousel Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wip_woocarousel_products_carousel' shortcode in all versions up to, and including, …

Dec 5, 2024
CVE-2024-11420
6.4 MEDIUM

The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Contact Info Block link parameter in all versions up to, and including, …

Dec 5, 2024
CVE-2024-11341
4.3 MEDIUM

The Simple Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing …

Dec 5, 2024
CVE-2024-11324
6.1 MEDIUM

The Accounting for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Dec 5, 2024
CVE-2024-10848
6.4 MEDIUM

The NewsMunch theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all versions up to, and including, 1.0.35 due …

Dec 5, 2024
CVE-2024-10777
4.3 MEDIUM

The AnyWhere Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.11 via the 'INSERT_ELEMENTOR' shortcode due to …

Dec 5, 2024
CVE-2024-10056
6.4 MEDIUM

The Contact Form Builder by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's livesite-pay shortcode in all versions up to, …

Dec 5, 2024
CVE-2024-10937
5.3 MEDIUM

The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions …

Dec 5, 2024
CVE-2024-10178
6.4 MEDIUM

The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget …

Dec 5, 2024
CVE-2024-10881
6.4 MEDIUM

The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lunaradio' shortcode in versions up to, and including, 6.24.11.07 due …

Dec 5, 2024
CVE-2024-12186
5.3 MEDIUM

A vulnerability was found in code-projects Hotel Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file hotelnew.c of …

Dec 5, 2024
CVE-2024-12185
5.3 MEDIUM

A vulnerability has been found in code-projects Hotel Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the component Administrator Login …

Dec 5, 2024
CVE-2018-9463
6.7 MEDIUM

In sw49408_irq_runtime_engine_debug of touch_sw49408.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Dec 5, 2024
CVE-2018-9462
6.7 MEDIUM

In store_cmd of ftm4_pdc.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Dec 5, 2024
CVE-2018-9439
6.7 MEDIUM

In __unregister_prot_hook and packet_release of af_packet.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the …

Dec 5, 2024
CVE-2018-9416
6.7 MEDIUM

In sg_remove_scat of scsi/sg.c, there is a possible memory corruption due to an unusual root cause. This could lead to local escalation of privilege with …

Dec 5, 2024
CVE-2018-9408
4.4 MEDIUM

In m3326_gps_write and m3326_gps_read of gps.s, there is a possible Out Of Bounds Read due to a missing bounds check. This could lead to a …

Dec 5, 2024
CVE-2018-9407
5.5 MEDIUM

In emmc_rpmb_ioctl of emmc_rpmb.c, there is an Information Disclosure due to a Missing Bounds Check. This could lead to Information Disclosure of kernel data.

Dec 5, 2024
CVE-2018-9404
6.7 MEDIUM

In oemCallback of ril.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege …

Dec 5, 2024
CVE-2018-9403
6.7 MEDIUM

In the MTK_FLP_MSG_HAL_DIAG_REPORT_DATA_NTF handler of flp2hal_- interface.c, there is a possible stack buffer overflow due to a missing bounds check. This could lead to local …

Dec 5, 2024
CVE-2018-9400
6.7 MEDIUM

In gt1x_debug_write_proc and gt1x_tool_write of drivers/input/touchscreen/mediatek/GT1151/gt1x_generic.c and gt1x_tools.c, there is a possible out of bounds write due to a missing bounds check. This could lead …

Dec 5, 2024
CVE-2018-9399
6.7 MEDIUM

In /proc/driver/wmt_dbg driver, there are several possible out of bounds writes. These could lead to local escalation of privilege with System execution privileges needed. User …

Dec 5, 2024
CVE-2018-9398
6.7 MEDIUM

In fm_set_stat of mediatek FM radio driver, there is a possible OOB write due to improper input validation. This could lead to local escalation of …

Dec 5, 2024
CVE-2018-9397
6.7 MEDIUM

In WMT_unlocked_ioctl of MTK WMT device driver, there is a possible OOB write due to a missing bounds check. This could lead to local escalation …

Dec 5, 2024
CVE-2018-9396
6.7 MEDIUM

In rpc_msg_handler and related handlers of drivers/misc/mediatek/eccci/port_rpc.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to …

Dec 4, 2024
CVE-2024-54675
6.1 MEDIUM

app/webroot/js/workflows-editor/workflows-editor.js in MISP through 2.5.2 has stored XSS in the editor interface for an ad-hoc workflow.

Dec 4, 2024
CVE-2024-54674
6.1 MEDIUM

app/View/GalaxyClusters/cluster_export_misp_galaxy.ctp in MISP through 2.5.2 has stored XSS when exporting custom clusters into the misp-galaxy format.

Dec 4, 2024
CVE-2024-51210
5.3 MEDIUM

Firepad through 1.5.11 allows remote attackers, who have knowledge of a pad ID, to retrieve both the current text of a document and all content …

Dec 4, 2024
CVE-2024-12196
6.5 MEDIUM

Incorrect authorization in the permission component in Devolutions Server 2024.3.7.0 and earlier allows an authenticated user to view the password history of an entry without …

Dec 4, 2024
CVE-2024-12151
5.0 MEDIUM

Incorrect permission assignment in the user migration feature in Devolutions Server 2024.3.8.0 and earlier allows users to retain their old permission sets.

Dec 4, 2024
CVE-2024-12148
4.3 MEDIUM

Incorrect authorization in permission validation component in Devolutions Server 2024.3.6.0 and earlier allows an authenticated user to access some reporting endpoints.

Dec 4, 2024
CVE-2024-12147
6.5 MEDIUM

A vulnerability was found in Netgear R6900 1.0.1.26_1.0.20. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file …

Dec 4, 2024
CVE-2018-9395
6.7 MEDIUM

In mtk_cfg80211_vendor_packet_keep_alive_start and mtk_cfg80211_vendor_set_config of drivers/misc/mediatek/connectivity/wlan/gen2/os/linux/gl_vendor.c, there is a possible OOB write due to a missing bounds check. This could lead to local escalation of …

Dec 4, 2024
CVE-2018-9394
6.7 MEDIUM

In mtk_p2p_wext_set_key of drivers/misc/mediatek/connectivity/wlan/gen2/os/linux/gl_p2p.c, there is a possible OOB write due to improper input validation. This could lead to local escalation of privilege with System …

Dec 4, 2024
CVE-2018-9393
6.7 MEDIUM

In procfile_write of drivers/misc/mediatek/connectivity/wlan/gen2/os/linux/gl_proc.c, there is a possible OOB write due to a missing bounds check. This could lead to local escalation of privilege with …

Dec 4, 2024
CVE-2018-9392
6.7 MEDIUM

In get_binary of vendor/mediatek/proprietary/hardware/connectivity/gps/gps_hal/src/data_coder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Dec 4, 2024
CVE-2024-52676
5.4 MEDIUM

Itsourcecode Online Discussion Forum Project v.1.0.0 is vulnerable to Cross Site Scripting (XSS) via /bcc_forum/members/home.php.

Dec 4, 2024
CVE-2024-20397
5.2 MEDIUM

A vulnerability in the bootloader of Cisco NX-OS Software could allow an unauthenticated attacker with physical access to an affected device, or an authenticated, local …

Dec 4, 2024
CVE-2024-54002
5.3 MEDIUM

Dependency-Track is a Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Performing a login request against the …

Dec 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.