CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7882
6.5 MEDIUM

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Special Minds Design and Software e-Commerce allows SQL Injection.This issue affects …

Nov 22, 2024
CVE-2024-8929
5.8 MEDIUM

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of …

Nov 22, 2024
CVE-2024-9422
6.6 MEDIUM

The GEO my WP WordPress plugin before 4.5, gmw-premium-settings WordPress plugin before 3.1 does not sufficiently validate files to be uploaded, which could allow attackers …

Nov 22, 2024
CVE-2024-8735
6.1 MEDIUM

The MailMunch – Grow your Email List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping …

Nov 22, 2024
CVE-2024-11381
6.4 MEDIUM

The Control horas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ch_registro' shortcode in all versions up to, and including, 1.0.1 …

Nov 22, 2024
CVE-2024-11355
4.3 MEDIUM

The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check …

Nov 22, 2024
CVE-2024-11225
6.1 MEDIUM

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate …

Nov 22, 2024
CVE-2024-10666
4.3 MEDIUM

The Easy Twitter Feed – Twitter feeds plugin for WP plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, …

Nov 22, 2024
CVE-2024-10034
5.5 MEDIUM

The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery plugin for WordPress is vulnerable to …

Nov 22, 2024
CVE-2024-38296
6.7 MEDIUM

Dell Edge Gateway 3200, versions prior to 15.40.30.2879, and Edge Gateway 5200, versions prior to 12.0.94.2380, contain an Exposure of Sensitive Information in Shared Microarchitectural …

Nov 22, 2024
CVE-2024-47142
5.5 MEDIUM

AIPHONE IXG SYSTEM IXG-2C7 firmware Ver.2.03 and earlier and IXG-2C7-L firmware Ver.2.03 and earlier contain an issue with insufficiently protected credentials, which may allow a …

Nov 22, 2024
CVE-2024-45837
5.4 MEDIUM

Use of hard-coded cryptographic key issue exists in AIPHONE IX SYSTEM, IXG SYSTEM, and System Support Software. A network-adjacent unauthenticated attacker may log in to …

Nov 22, 2024
CVE-2024-39290
6.5 MEDIUM

Insufficiently protected credentials issue exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent unauthenticated attacker may obtain sensitive information such as a username and …

Nov 22, 2024
CVE-2024-52056
6.5 MEDIUM

Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to delete any directory on the file system if …

Nov 21, 2024
CVE-2024-52055
4.9 MEDIUM

Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to read any file on the file system if …

Nov 21, 2024
CVE-2024-52616
5.3 MEDIUM

A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable …

Nov 21, 2024
CVE-2024-52615
5.3 MEDIUM

A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are …

Nov 21, 2024
CVE-2024-49588
6.8 MEDIUM

Multiple endpoints in `oracle-sidecar` in versions 0.347.0 to 0.543.0 were found to be vulnerable to SQL injections.

Nov 21, 2024
CVE-2024-53094
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Add sendpage_ok() check to disable MSG_SPLICE_PAGES While running ISER over SIW, the initiator machine …

Nov 21, 2024
CVE-2024-53093
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvme-multipath: defer partition scanning We need to suppress the partition scan from occuring within the …

Nov 21, 2024
CVE-2024-53092
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: virtio_pci: Fix admin vq cleanup by using correct info pointer vp_modern_avq_cleanup() and vp_del_vqs() clean up …

Nov 21, 2024
CVE-2024-53091
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Add sk_is_inet and IS_ICSK check in tls_sw_has_ctx_tx/rx As the introduction of the support for …

Nov 21, 2024
CVE-2024-53090
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: afs: Fix lock recursion afs_wake_up_async_call() can incur lock recursion. The problem is that it is …

Nov 21, 2024
CVE-2024-53089
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Mark hrtimer to expire in hard interrupt context Like commit 2c0d278f3293f ("KVM: LAPIC: …

Nov 21, 2024
CVE-2024-53333
6.3 MEDIUM

TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function. This vulnerability allows an attacker to execute arbitrary commands via …

Nov 21, 2024
CVE-2024-52307
5.6 MEDIUM

authentik is an open-source identity provider. Due to the usage of a non-constant time comparison for the /-/metrics/ endpoint it was possible to brute-force the …

Nov 21, 2024
CVE-2024-49529
5.5 MEDIUM

InDesign Desktop versions 19.0, 20.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Nov 21, 2024
CVE-2024-45517
5.4 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability in the /h/rest endpoint of the Zimbra webmail and admin …

Nov 21, 2024
CVE-2024-45513
4.8 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A stored Cross-Site Scripting (XSS) vulnerability exists in the /modern/contacts/print endpoint of Zimbra webmail. This …

Nov 21, 2024
CVE-2024-45194
4.8 MEDIUM

In Zimbra Collaboration (ZCS) 9.0 and 10.0, a vulnerability in the Webmail Modern UI allows execution of stored Cross-Site Scripting (XSS) payloads. An attacker with …

Nov 21, 2024
CVE-2024-45514
5.4 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) through v10.1. A Cross-Site Scripting (XSS) vulnerability exists in one of the endpoints of Zimbra Webmail due …

Nov 21, 2024
CVE-2024-45512
5.4 MEDIUM

An issue was discovered in webmail in Zimbra Collaboration (ZCS) through 10.1. An attacker can exploit this vulnerability by creating a folder in the Briefcase …

Nov 21, 2024
CVE-2024-48747
6.8 MEDIUM

An issue in alist-tvbox v1.7.1 allows a remote attacker to execute arbitrary code via the /atv-cli file.

Nov 21, 2024
CVE-2024-7130
5.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kion Computer KION Exchange Programs Software allows Reflected XSS.This issue affects …

Nov 21, 2024
CVE-2024-53426
6.2 MEDIUM

A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.

Nov 21, 2024
CVE-2024-53425
6.2 MEDIUM

A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue occurs when processing certain malformed MD5 model files, leading to an …

Nov 21, 2024
CVE-2024-11089
5.3 MEDIUM

The Anonymous Restricted Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.5 via the WordPress core …

Nov 21, 2024
CVE-2024-11088
5.3 MEDIUM

The Simple Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.5 via the WordPress core search …

Nov 21, 2024
CVE-2024-7016
4.8 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Smarttek Informatics Smart Doctor's allows Stored XSS required admin privileges.This issue …

Nov 21, 2024
CVE-2024-11589
6.3 MEDIUM

A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /expcatedit.php. …

Nov 21, 2024
CVE-2024-9851
6.4 MEDIUM

The LSX Tour Operator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.4.9 …

Nov 21, 2024
CVE-2024-9828
4.1 MEDIUM

The Taskbuilder WordPress plugin before 3.0.5 does not sanitize user input into the 'load_orders' parameter and uses it in a SQL statement, allowing high privilege …

Nov 21, 2024
CVE-2024-9768
4.8 MEDIUM

The Formidable Forms WordPress plugin before 6.14.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Nov 21, 2024
CVE-2024-9600
4.8 MEDIUM

The Ditty WordPress plugin before 3.1.47 does not sanitise and escape some of its settings, which could allow high privilege users such as author to …

Nov 21, 2024
CVE-2024-9542
4.3 MEDIUM

The Sky Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.1 via the render …

Nov 21, 2024
CVE-2024-9442
6.4 MEDIUM

The F4 Improvements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.9.0 due …

Nov 21, 2024
CVE-2024-9371
6.1 MEDIUM

The Branda – White Label & Branding, Custom Login Page Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of …

Nov 21, 2024
CVE-2024-9111
6.4 MEDIUM

The Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.36 due …

Nov 21, 2024
CVE-2024-8157
4.3 MEDIUM

The Alphabetical List WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Nov 21, 2024
CVE-2024-5029
4.8 MEDIUM

The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is missing sanitisation as well as …

Nov 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.