CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-11703
5.7 MEDIUM

On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication. This vulnerability affects Firefox < 133.

Nov 26, 2024
CVE-2024-11701
4.3 MEDIUM

The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible …

Nov 26, 2024
CVE-2024-11696
5.4 MEDIUM

The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupported extension …

Nov 26, 2024
CVE-2024-11695
5.4 MEDIUM

A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This …

Nov 26, 2024
CVE-2024-11694
6.1 MEDIUM

Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility …

Nov 26, 2024
CVE-2024-11692
4.3 MEDIUM

An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This …

Nov 26, 2024
CVE-2024-47250
5.0 MEDIUM

Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI advertising report could lead to out-of-bound access when parsing HCI event and thus bogus …

Nov 26, 2024
CVE-2024-47249
5.0 MEDIUM

Improper Validation of Array Index vulnerability in Apache NimBLE. Lack of input validation for HCI events from controller could result in out-of-bound memory corruption and …

Nov 26, 2024
CVE-2024-47248
6.3 MEDIUM

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. Specially crafted MESH message could result in memory corruption when non-default …

Nov 26, 2024
CVE-2024-38834
6.5 MEDIUM

VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to cloud provider might be able to inject malicious script …

Nov 26, 2024
CVE-2024-38833
6.8 MEDIUM

VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to email templates might inject malicious script leading to stored …

Nov 26, 2024
CVE-2023-2142
6.1 MEDIUM

In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two …

Nov 26, 2024
CVE-2024-8899
4.3 MEDIUM

The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.9 via the render_content function …

Nov 26, 2024
CVE-2024-50377
6.5 MEDIUM

A CWE-798 "Use of Hard-coded Credentials" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). …

Nov 26, 2024
CVE-2024-10579
4.3 MEDIUM

The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check …

Nov 26, 2024
CVE-2024-10308
6.4 MEDIUM

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's JKit - Countdown widget in all versions up to, …

Nov 26, 2024
CVE-2024-11032
6.1 MEDIUM

The Parsi Date plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in …

Nov 26, 2024
CVE-2024-9170
5.5 MEDIUM

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wcj_product_meta shortcode in all versions up to, and including, …

Nov 26, 2024
CVE-2024-11192
6.4 MEDIUM

The Spotify Play Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's spotifyplaybutton shortcode in all versions up to, …

Nov 26, 2024
CVE-2024-11119
6.4 MEDIUM

The BNE Gallery Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' shortcode in all versions up to, and including, …

Nov 26, 2024
CVE-2024-11091
6.4 MEDIUM

The Support SVG – Upload svg files in wordpress without hassle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File …

Nov 26, 2024
CVE-2024-8772
4.3 MEDIUM

51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API managedoverlayimages.cgi was vulnerable to a race condition attack allowing for …

Nov 26, 2024
CVE-2024-6831
4.4 MEDIUM

Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program has found that it is possible to edit and/or remove views without the necessary …

Nov 26, 2024
CVE-2024-34162
5.3 MEDIUM

The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users. But configuring LDAP authentication to "SIMPLE", the …

Nov 26, 2024
CVE-2024-33616
5.3 MEDIUM

Admin authentication can be bypassed with some specific invalid credentials, which allows logging in with an administrative privilege. Sharp Corporation states the telnet feature is …

Nov 26, 2024
CVE-2024-32151
5.9 MEDIUM

User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for …

Nov 26, 2024
CVE-2024-29978
5.9 MEDIUM

User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for …

Nov 26, 2024
CVE-2024-29146
5.9 MEDIUM

User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for …

Nov 26, 2024
CVE-2024-28955
5.9 MEDIUM

Affected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the device can examine the coredump files, and research …

Nov 26, 2024
CVE-2024-11202
6.1 MEDIUM

Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in various versions due to insufficient input sanitization and output escaping. …

Nov 26, 2024
CVE-2024-6749
6.3 MEDIUM

Seth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may expose sensitive credentials on the …

Nov 26, 2024
CVE-2024-6476
4.2 MEDIUM

Gee-netics, member of the AXIS Camera Station Pro Bug Bounty Program has found that it is possible for a non-admin user to gain system privileges …

Nov 26, 2024
CVE-2024-11002
6.3 MEDIUM

The The InPost Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution via the inpost_gallery_get_shortcode_template AJAX action in all versions up to, and including, …

Nov 26, 2024
CVE-2024-10857
6.5 MEDIUM

The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9 via the handle_downloads() …

Nov 26, 2024
CVE-2024-10471
4.8 MEDIUM

The Everest Forms WordPress plugin before 3.0.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Nov 26, 2024
CVE-2024-53278
4.8 MEDIUM

Cross-site scripting vulnerability exists in WP Admin UI Customize versions prior to ver 1.5.14. If a malicious admin user customizes the admin screen with some …

Nov 26, 2024
CVE-2024-49351
5.5 MEDIUM

IBM Workload Scheduler 9.5, 10.1, and 10.2 stores user credentials in plain text which can be read by a local user.

Nov 26, 2024
CVE-2024-11418
6.1 MEDIUM

The Additional Order Filters for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shipping_method_filter' parameter in all versions up to, and …

Nov 26, 2024
CVE-2024-11342
6.1 MEDIUM

The Skt NURCaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.5.0. This is due to missing …

Nov 26, 2024
CVE-2024-49596
5.9 MEDIUM

Dell Wyse Management Suite, version WMS 4.4 and prior, contain a Missing Authorization vulnerability. A high privileged attacker with remote access could potentially exploit this …

Nov 26, 2024
CVE-2024-11674
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in CodeAstro Hospital Management System 1.0. Affected is an unknown function of the file /backend/doc/his_doc_update-account.php. The …

Nov 26, 2024
CVE-2024-11673
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in 1000 Projects Bookstore Management System 1.0. This issue affects some unknown processing. The manipulation …

Nov 25, 2024
CVE-2024-53597
6.3 MEDIUM

masterstack_imgcap v0.0.1 was discovered to contain a SQL injection vulnerability via the endpoint /submit.

Nov 25, 2024
CVE-2024-53101
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs: Fix uninitialized value issue in from_kuid and from_kgid ocfs2_setattr() uses attr->ia_mode, attr->ia_uid and attr->ia_gid …

Nov 25, 2024
CVE-2024-53100
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvme: tcp: avoid race between queue_lock lock and destroy Commit 76d54bf20cdc ("nvme-tcp: don't access released …

Nov 25, 2024
CVE-2024-53097
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm: krealloc: Fix MTE false alarm in __do_krealloc This patch addresses an issue introduced by …

Nov 25, 2024
CVE-2024-53556
6.1 MEDIUM

An Open Redirect vulnerability in Taiga v6.8.1 allows attackers to redirect users to arbitrary websites via appending a crafted link to /login?next= in the login …

Nov 25, 2024
CVE-2024-50671
4.3 MEDIUM

Incorrect access control in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows attackers with Authenticated User roles to obtain email addresses via the "Get users" …

Nov 25, 2024
CVE-2024-53262
5.4 MEDIUM

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. The static error.html template for errors contains placeholders that are replaced without …

Nov 25, 2024
CVE-2024-53261
5.4 MEDIUM

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. "Unsanitized input from *the request URL* flows into `end`, where it is …

Nov 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.