CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-36615
5.9 MEDIUM

FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, …

Nov 29, 2024
CVE-2024-36624
5.4 MEDIUM

Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the construct_copy_div function in copy_and_paste.js.

Nov 29, 2024
CVE-2024-36621
6.5 MEDIUM

moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting …

Nov 29, 2024
CVE-2024-36620
6.5 MEDIUM

moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.

Nov 29, 2024
CVE-2024-36618
6.2 MEDIUM

FFmpeg n6.1.1 has a vulnerability in the AVI demuxer of the libavformat library which allows for an integer overflow, potentially resulting in a denial-of-service (DoS) …

Nov 29, 2024
CVE-2024-36617
6.2 MEDIUM

FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.

Nov 29, 2024
CVE-2024-47193
5.5 MEDIUM

WithSecure Elements Agent for Mac before 24.3, MDR before 24.3, and Elements Client Security for Mac before 16.10 allow a remote Denial of Service.

Nov 29, 2024
CVE-2024-36626
5.3 MEDIUM

In prestashop 8.1.4, a NULL pointer dereference was identified in the math_round function within Tools.php.

Nov 29, 2024
CVE-2024-36625
5.4 MEDIUM

Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the replace_emoji_with_text function in ui_util.ts.

Nov 29, 2024
CVE-2024-36619
5.3 MEDIUM

FFmpeg n6.1.1 has a vulnerability in the WAVARC decoder of the libavcodec library which allows for an integer overflow when handling certain block types, leading …

Nov 29, 2024
CVE-2024-35369
5.5 MEDIUM

In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a potential security vulnerability exists due to insufficient validation of certain parameters when parsing Speex codec …

Nov 29, 2024
CVE-2024-11990
4.6 MEDIUM

A Cross-Site Scripting (XSS) vulnerability in SurgeMail v78c2 could allow an attacker to execute arbitrary JavaScript code via an elaborate payload injected into vulnerable parameters.

Nov 29, 2024
CVE-2024-47094
5.5 MEDIUM

Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p22, <2.2.0p37, <2.1.0p50 (EOL) causes remote site secrets to be written to web …

Nov 29, 2024
CVE-2024-11014
4.3 MEDIUM

Cross-site request forgery (CSRF) vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27 and for Ver10.9 up to Ver10.9.14 …

Nov 29, 2024
CVE-2024-39162
6.1 MEDIUM

pyspider through 0.3.10 allows /update XSS. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

Nov 29, 2024
CVE-2024-10980
5.4 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some …

Nov 29, 2024
CVE-2024-10704
4.8 MEDIUM

The Photo Gallery by 10Web WordPress plugin before 1.8.31 does not sanitise and escape some of its settings, which could allow high privilege users such …

Nov 29, 2024
CVE-2024-45495
4.3 MEDIUM

MSA FieldServer Gateway 5.0.0 through 6.5.2 allows cross-origin WebSocket hijacking.

Nov 29, 2024
CVE-2024-35451
4.8 MEDIUM

LinkStack 2.7.9 through 4.7.7 allows resources\views\components\favicon.blade.php link SSRF.

Nov 29, 2024
CVE-2024-54123
6.1 MEDIUM

Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text format.

Nov 29, 2024
CVE-2024-11968
6.3 MEDIUM

A vulnerability was found in code-projects Farmacia up to 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Nov 28, 2024
CVE-2024-11963
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Responsive Hotel Site 1.0. Affected by this issue is some unknown functionality of …

Nov 28, 2024
CVE-2024-11961
5.3 MEDIUM

A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms 3.7. It has been rated as problematic. This issue affects the function preHandle of the …

Nov 28, 2024
CVE-2024-7747
6.5 MEDIUM

The Wallet for WooCommerce plugin for WordPress is vulnerable to incorrect conversion between numeric types in all versions up to, and including, 1.5.6. This is …

Nov 28, 2024
CVE-2024-53731
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fintelligence Fintelligence Calculator fintelligence-calculator allows Stored XSS.This issue affects Fintelligence Calculator: from n/a …

Nov 28, 2024
CVE-2024-8308
6.5 MEDIUM

A low privileged remote attacker can insert a SQL injection in the web application due to improper handling of HTTP request input data which allows …

Nov 28, 2024
CVE-2024-53737
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mailster wp-mailster allows Stored XSS.This issue affects WP Mailster: from n/a …

Nov 28, 2024
CVE-2024-52283
5.7 MEDIUM

Missing sanitation of inputs allowed arbitrary users to conduct a stored XSS attack that triggers for users that view a certain project

Nov 28, 2024
CVE-2024-22037
5.5 MEDIUM

The uyuni-server-attestation systemd service needs a database_password environment variable. This file has 640 permission, and cannot be shown users, but the environment is still exposed …

Nov 28, 2024
CVE-2024-10798
4.3 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1003 via the 'wpr-template' …

Nov 28, 2024
CVE-2024-10780
4.3 MEDIUM

The Restaurant & Cafe Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.9 via the …

Nov 28, 2024
CVE-2024-10670
4.3 MEDIUM

The Primary Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.6.2 via the [prim_elementor_template] shortcode …

Nov 28, 2024
CVE-2024-11788
6.4 MEDIUM

The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sw-youtube-embed' shortcode in all versions up to, and including, …

Nov 28, 2024
CVE-2024-11786
6.4 MEDIUM

The Login with Vipps and MobilePay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'continue-with-vipps' shortcode in all versions up to, …

Nov 28, 2024
CVE-2024-11761
6.4 MEDIUM

The LegalWeb Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'legalweb-popup' shortcode in all versions up to, and including, 1.1.2 …

Nov 28, 2024
CVE-2024-11685
6.1 MEDIUM

The `Kudos Donations – Easy donations and payments with Mollie` plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of `add_query_arg` …

Nov 28, 2024
CVE-2024-11684
6.1 MEDIUM

The Kudos Donations – Easy donations and payments with Mollie plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all …

Nov 28, 2024
CVE-2024-11458
6.1 MEDIUM

The FAQ Builder AYS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ays_faq_tab' parameter in all versions up to, and including, 1.7.1 …

Nov 28, 2024
CVE-2024-11431
6.4 MEDIUM

The Ragic Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ragic' shortcode in all versions up to, and including, 1.2 …

Nov 28, 2024
CVE-2024-11366
6.1 MEDIUM

The SEO Landing Page Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …

Nov 28, 2024
CVE-2024-11333
6.4 MEDIUM

The HLS Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hls_player' shortcode in all versions up to, and including, 1.0.10 …

Nov 28, 2024
CVE-2024-11203
6.4 MEDIUM

The EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor plugin for …

Nov 28, 2024
CVE-2024-11918
4.3 MEDIUM

The Image Alt Text plugin for WordPress is vulnerable to unauthorized modification of data| due to a missing capability check on the iat_add_alt_txt_action and iat_update_alt_txt_action …

Nov 28, 2024
CVE-2024-10896
5.4 MEDIUM

The Logo Slider WordPress plugin before 4.5.0 does not sanitise and escape some of its Logo and Slider settings, which could allow high privilege users …

Nov 28, 2024
CVE-2024-10510
4.8 MEDIUM

The adBuddy+ (AdBlocker Detection) by NetfunkDesign WordPress plugin through 1.1.3 does not sanitise and escape some of its settings, which could allow high privilege users …

Nov 28, 2024
CVE-2024-10493
5.4 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some …

Nov 28, 2024
CVE-2024-10473
5.4 MEDIUM

The Logo Slider WordPress plugin before 4.5.0 does not sanitise and escape some of its Logo Settings when outputing them in pages where the Logo …

Nov 28, 2024
CVE-2024-53008
5.3 MEDIUM

Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulnerability is exploited, a remote attacker may access a path that …

Nov 28, 2024
CVE-2018-9377
5.5 MEDIUM

In getIntentForIntentSender of ActivityManagerService.java, there is a possible way to access user metadata due to a pending intent. This could lead to local escalation of …

Nov 28, 2024
CVE-2018-9354
6.5 MEDIUM

In VideoFrameScheduler.cpp of VideoFrameScheduler::PLL::fit, there is a possible remote denial of service due to divide by 0. This could lead to remote denial of service …

Nov 27, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.