CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-52478
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Astoundify Jobify jobify allows Stored XSS.This issue affects Jobify: from n/a through < …

Dec 2, 2024
CVE-2024-51900
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in James Hunt What Would Seth Godin Do what-would-seth-godin-do allows Stored XSS.This issue affects …

Dec 2, 2024
CVE-2024-33053
6.7 MEDIUM

Memory corruption when multiple threads try to unregister the CVP buffer at the same time.

Dec 2, 2024
CVE-2024-33040
6.7 MEDIUM

Memory corruption while invoking redundant release command to release one buffer from user space as race condition can occur in kernel space between buffer release …

Dec 2, 2024
CVE-2024-33039
6.7 MEDIUM

Memory corruption when PAL client calls PAL service APIs by passing a random value as handle and the handle is not validated by the service.

Dec 2, 2024
CVE-2024-33037
6.1 MEDIUM

Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware.

Dec 2, 2024
CVE-2024-33036
6.7 MEDIUM

Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge …

Dec 2, 2024
CVE-2024-20139
6.5 MEDIUM

In Bluetooth firmware, there is a possible firmware asssert due to improper handling of exceptional conditions. This could lead to local denial of service with …

Dec 2, 2024
CVE-2024-20136
6.2 MEDIUM

In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no …

Dec 2, 2024
CVE-2024-20135
6.7 MEDIUM

In soundtrigger, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Dec 2, 2024
CVE-2024-20134
6.7 MEDIUM

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Dec 2, 2024
CVE-2024-20133
6.7 MEDIUM

In Modem, there is a possible escalation of privilege due to an incorrect bounds check. This could lead to local escalation of privilege with System …

Dec 2, 2024
CVE-2024-20132
6.7 MEDIUM

In Modem, there is a possible out of bonds write due to a mission bounds check. This could lead to local escalation of privilege with …

Dec 2, 2024
CVE-2024-20131
6.7 MEDIUM

In Modem, there is a possible escalation of privilege due to an incorrect bounds check. This could lead to local escalation of privilege with System …

Dec 2, 2024
CVE-2024-20130
6.7 MEDIUM

In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Dec 2, 2024
CVE-2024-20125
6.7 MEDIUM

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Dec 2, 2024
CVE-2024-20116
4.4 MEDIUM

In cmdq, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Dec 2, 2024
CVE-2024-12007
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Farmacia 1.0. This affects an unknown part of the file /visualizar-produto.php. The manipulation of …

Dec 1, 2024
CVE-2024-53752
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Berg Informatik Stripe Donation bin-stripe-donation allows Stored XSS.This issue affects Stripe Donation: from …

Dec 1, 2024
CVE-2024-53749
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plugin Devs Post Carousel Slider for Elementor post-carousel-slider-for-elementor allows Stored XSS.This issue affects …

Dec 1, 2024
CVE-2024-53748
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Terry L. WP Mermaid wp-mermaid allows Stored XSS.This issue affects WP Mermaid: from …

Dec 1, 2024
CVE-2024-53747
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nutttaro Video Player for WPBakery video-player-for-wpbakery allows Stored XSS.This issue affects Video Player …

Dec 1, 2024
CVE-2024-53746
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FlickDevs Elementor Button Plus fd-elementor-button-plus allows Stored XSS.This issue affects Elementor Button Plus: …

Dec 1, 2024
CVE-2024-53745
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 코스모스팜 – Cosmosfarm 소셜 공유 버튼 By 코스모스팜 cosmosfarm-share-buttons allows Stored XSS.This issue …

Dec 1, 2024
CVE-2024-53744
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SkyBootstrap Elementor Image Gallery Plugin skyboot-portfolio-gallery allows Stored XSS.This issue affects Elementor Image …

Dec 1, 2024
CVE-2024-53743
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aezaz Shaikh Countdown Timer for Elementor countdown-timer-for-elementor allows Stored XSS.This issue affects Countdown …

Dec 1, 2024
CVE-2024-53786
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codeless Cowidgets – Elementor Addons cowidgets-elementor-addons allows Stored XSS.This issue affects Cowidgets – …

Nov 30, 2024
CVE-2024-53774
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jakub Glos Sparkle Elementor Kit sparkle-elementor-kit allows DOM-Based XSS.This issue affects Sparkle Elementor …

Nov 30, 2024
CVE-2024-53773
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pracapl Znajdź Pracę z Praca.pl znajdz-prace-z-pracapl allows DOM-Based XSS.This issue affects Znajdź Pracę …

Nov 30, 2024
CVE-2024-53772
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Mail Picker mail-picker allows DOM-Based XSS.This issue affects Mail Picker: from n/a …

Nov 30, 2024
CVE-2024-53771
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sergiomico SimpleSchema simpleschema-free allows DOM-Based XSS.This issue affects SimpleSchema: from n/a through <= …

Nov 30, 2024
CVE-2024-53767
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixobe Pixobe Cartography pixobe-cartography allows DOM-Based XSS.This issue affects Pixobe Cartography: from n/a …

Nov 30, 2024
CVE-2024-53766
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devnex Devnex Addons For Elementor devnex-addons-for-elementor allows DOM-Based XSS.This issue affects Devnex Addons …

Nov 30, 2024
CVE-2024-53764
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SoftHopper Softtemplates For Elementor softtemplates-for-elementor allows DOM-Based XSS.This issue affects Softtemplates For Elementor: …

Nov 30, 2024
CVE-2024-53763
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rejuan Ahamed Best Addons for Elementor allows Stored XSS.This issue affects Best Addons …

Nov 30, 2024
CVE-2024-53760
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Capitalize My Title Capitalize My Title capitalize-my-title allows Stored XSS.This issue affects Capitalize …

Nov 30, 2024
CVE-2024-53758
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Terry L. WP MathJax wp-mathjax-plus allows Stored XSS.This issue affects WP MathJax: from …

Nov 30, 2024
CVE-2024-53757
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SocialEvolution WP Find Your Nearest wp-find-your-nearest allows Stored XSS.This issue affects WP Find …

Nov 30, 2024
CVE-2024-53756
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aftab Husain Vertical Carousel vertical-carousel-slider allows Stored XSS.This issue affects Vertical Carousel: from …

Nov 30, 2024
CVE-2024-53788
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in portfoliohub WordPress Portfolio Builder – Portfolio Gallery uber-grid allows Stored XSS.This issue affects …

Nov 30, 2024
CVE-2024-53787
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar Random Banner random-banner allows Stored XSS.This issue affects Random …

Nov 30, 2024
CVE-2024-53768
5.3 MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ideinteractive Content Audit Exporter content-audit-exporter allows Retrieve Embedded Sensitive Data.This issue affects Content …

Nov 30, 2024
CVE-2024-53738
4.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Gabe Livan Asset CleanUp: Page Speed Booster wp-asset-clean-up allows Server Side Request Forgery.This issue affects Asset CleanUp: Page Speed …

Nov 30, 2024
CVE-2024-12002
4.3 MEDIUM

A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to 20241129. Affected by this vulnerability is the function websReadEvent …

Nov 30, 2024
CVE-2024-11998
6.3 MEDIUM

A vulnerability was found in code-projects Farmacia 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /visualizer-forneccedor.chp. The manipulation …

Nov 30, 2024
CVE-2024-11252
6.1 MEDIUM

The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up …

Nov 30, 2024
CVE-2024-54159
4.1 MEDIUM

stalld through 1.19.7 allows local users to cause a denial of service (file overwrite) via a /tmp/rtthrottle symlink attack.

Nov 29, 2024
CVE-2024-53983
5.4 MEDIUM

The Backstage Scaffolder plugin Houses types and utilities for building scaffolder-related modules. A vulnerability is identified in Backstage Scaffolder template functionality where Server-Side Template Injection …

Nov 29, 2024
CVE-2024-52003
6.1 MEDIUM

Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. There is a vulnerability in Traefik that allows the client to provide the X-Forwarded-Prefix …

Nov 29, 2024
CVE-2024-36616
6.5 MEDIUM

An integer overflow in the component /libavformat/westwood_vqa.c of FFmpeg n6.1.1 allows attackers to cause a denial of service in the application via a crafted VQA …

Nov 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.