CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-53258
5.3 MEDIUM

Autolab is a course management service that enables auto-graded programming assignments. From Autolab versions v.3.0.0 onward students can download all assignments from another student, as …

Nov 25, 2024
CVE-2024-53599
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in the /scroll.php endpoint of LafeLabs Chaos v0.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Nov 25, 2024
CVE-2024-53255
5.4 MEDIUM

BoidCMS is a free and open-source flat file CMS for building simple websites and blogs, developed using PHP and uses JSON as a database. In …

Nov 25, 2024
CVE-2024-52529
5.8 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For users with the following configuration: 1. An allow policy that selects a …

Nov 25, 2024
CVE-2024-51723
4.6 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability in the Management Console of BlackBerry AtHoc version 7.15 could allow an attacker to potentially execute actions in the …

Nov 25, 2024
CVE-2024-32468
5.4 MEDIUM

Deno is a runtime for JavaScript and TypeScript written in rust. Several cross-site scripting vulnerabilities existed in the `deno_doc` crate which lead to Self-XSS with …

Nov 25, 2024
CVE-2023-45181
6.1 MEDIUM

IBM Jazz Foundation 7.0.2 and below are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …

Nov 25, 2024
CVE-2023-26280
5.3 MEDIUM

IBM Jazz Foundation 7.0.2 and 7.0.3 could allow a user to change their dashboard using a specially crafted HTTP request due to improper access control.

Nov 25, 2024
CVE-2024-11672
4.3 MEDIUM

Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated malicious user to bypass the …

Nov 25, 2024
CVE-2024-11671
5.4 MEDIUM

Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an authenticated user to bypass the …

Nov 25, 2024
CVE-2024-11670
5.4 MEDIUM

Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows a malicious authenticated user to bypass the …

Nov 25, 2024
CVE-2022-33862
6.7 MEDIUM

IPP software prior to v1.71 is vulnerable to default credential vulnerability. This could lead attackers to identify and access vulnerable systems.

Nov 25, 2024
CVE-2022-33861
5.1 MEDIUM

IPP software versions prior to v1.71 do not sufficiently verify the authenticity of data, in a way that causes it to accept invalid data.

Nov 25, 2024
CVE-2021-23282
5.2 MEDIUM

Eaton Intelligent Power Manager (IPM) prior to 1.70 is vulnerable to stored Cross site scripting. The vulnerability exists due to insufficient validation of input from …

Nov 25, 2024
CVE-2024-9666
4.7 MEDIUM

A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack due to improper handling of …

Nov 25, 2024
CVE-2024-11662
6.3 MEDIUM

A vulnerability was found in welliamcao OpsManage 3.0.1/3.0.2/3.0.3/3.0.4/3.0.5. It has been rated as critical. This issue affects the function deploy_host_vars of the file /apps/api/views/deploy_api.py of …

Nov 25, 2024
CVE-2024-11661
4.3 MEDIUM

A vulnerability was found in Codezips Free Exam Hall Seating Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of …

Nov 25, 2024
CVE-2024-10451
5.9 MEDIUM

A flaw was found in Keycloak. This issue occurs because sensitive runtime values, such as passwords, may be captured during the Keycloak build process and …

Nov 25, 2024
CVE-2024-10270
6.5 MEDIUM

A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service …

Nov 25, 2024
CVE-2024-6538
5.3 MEDIUM

A flaw was found in OpenShift Console. A Server Side Request Forgery (SSRF) attack can happen if an attacker supplies all or part of a …

Nov 25, 2024
CVE-2024-11659
4.7 MEDIUM

A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Affected by this issue is some unknown functionality …

Nov 25, 2024
CVE-2024-6393
4.8 MEDIUM

The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.5 does not sanitise and escape some of its Images settings, which could allow high privilege …

Nov 25, 2024
CVE-2024-11658
4.7 MEDIUM

A vulnerability has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Affected by this vulnerability is an unknown …

Nov 25, 2024
CVE-2024-11657
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. Affected is an unknown function of the …

Nov 25, 2024
CVE-2024-10709
6.8 MEDIUM

The YaDisk Files WordPress plugin through 1.2.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Nov 25, 2024
CVE-2024-11656
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This issue affects some unknown processing …

Nov 25, 2024
CVE-2024-11655
4.7 MEDIUM

A vulnerability classified as critical was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This vulnerability affects unknown code of the file /admin/network/diag_pinginterface. …

Nov 25, 2024
CVE-2024-11654
4.7 MEDIUM

A vulnerability classified as critical has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This affects an unknown part of the file …

Nov 25, 2024
CVE-2024-11653
4.7 MEDIUM

A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been rated as critical. Affected by this issue is some …

Nov 25, 2024
CVE-2024-11483
5.0 MEDIUM

A vulnerability was found in the Ansible Automation Platform (AAP). This flaw allows attackers to escalate privileges by improperly leveraging read-scoped OAuth2 tokens to gain …

Nov 25, 2024
CVE-2024-53930
5.4 MEDIUM

WikiDocs before 1.0.65 allows stored XSS by authenticated users via data that comes after $$\\, which is mishandled by a KaTeX parser.

Nov 25, 2024
CVE-2024-11652
4.7 MEDIUM

A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been declared as critical. Affected by this vulnerability is an …

Nov 25, 2024
CVE-2024-11651
4.7 MEDIUM

A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been classified as critical. Affected is an unknown function of …

Nov 25, 2024
CVE-2024-11650
6.5 MEDIUM

A vulnerability was found in Tenda i9 1.0.0.8(3828) and classified as critical. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation leads …

Nov 25, 2024
CVE-2024-53901
5.5 MEDIUM

The Imager package before 1.025 for Perl has a heap-based buffer overflow leading to denial of service, or possibly unspecified other impact, when the trim() …

Nov 24, 2024
CVE-2024-11233
4.8 MEDIUM

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer …

Nov 24, 2024
CVE-2024-11234
4.8 MEDIUM

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy and "request_fulluri" option, the URI is not …

Nov 24, 2024
CVE-2024-35160
4.3 MEDIUM

IBM Watson Query on Cloud Pak for Data 1.8, 2.0, 2.1, 2.2 and IBM Db2 Big SQL on Cloud Pak for Data 7.3, 7.4, 7.5, …

Nov 23, 2024
CVE-2023-7299
6.3 MEDIUM

A vulnerability was found in DataGear up to 4.60. It has been declared as critical. This vulnerability affects unknown code of the file /dataSet/resolveSql. The …

Nov 23, 2024
CVE-2024-11631
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /expedit.php. The …

Nov 23, 2024
CVE-2024-11231
6.4 MEDIUM

The 우커머스 네이버페이 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mnp_purchase shortcode in all versions up to, and including, 3.3.7 …

Nov 23, 2024
CVE-2024-11229
6.4 MEDIUM

The 코드엠샵 소셜톡 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's add_plus_friends and add_plus_talk shortcodes in all versions up to, and …

Nov 23, 2024
CVE-2024-11228
6.4 MEDIUM

The 워드프레스 결제 심플페이 – 우커머스 결제 플러그인 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's pafw_instant_payment shortcode in all versions …

Nov 23, 2024
CVE-2024-11227
6.4 MEDIUM

The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's memberlite_accordion shortcode in all versions up to, and including, 1.3.9 …

Nov 23, 2024
CVE-2024-11199
6.4 MEDIUM

The Rescue Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rescue_progressbar shortcode in all versions up to, and including, 2.9 …

Nov 23, 2024
CVE-2024-10519
6.1 MEDIUM

The Wishlist for WooCommerce: Multi Wishlists Per Customer PRO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wtab' parameter in versions 3.0.8 …

Nov 23, 2024
CVE-2024-9635
6.1 MEDIUM

The Checkout with Cash App on WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_wp_http_referer' parameter in several files in all …

Nov 23, 2024
CVE-2024-11446
6.1 MEDIUM

The Chessgame Shizzle plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'cs_nonce' parameter in all versions up to, and including, 1.3.0 due …

Nov 23, 2024
CVE-2024-11330
6.1 MEDIUM

The Custom CSS, JS & PHP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate …

Nov 23, 2024
CVE-2024-11265
4.3 MEDIUM

The Increase Maximum Upload File Size | Increase Execution Time plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and …

Nov 23, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.