CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-52702
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the component install\index.php of MyBB v1.8.38 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Nov 20, 2024
CVE-2024-52701
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Configuration page of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Nov 20, 2024
CVE-2024-48535
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into …

Nov 20, 2024
CVE-2024-48534
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability on the Camp Details module of eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary code in the context of …

Nov 20, 2024
CVE-2024-48533
5.3 MEDIUM

A discrepancy between responses for valid and invalid e-mail accounts in the Forgot your Login? module of eSoft Planner 3.24.08271-USA allows attackers to enumerate valid …

Nov 20, 2024
CVE-2024-48531
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability on the Rental Availability module of eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary code in the context of …

Nov 20, 2024
CVE-2024-52757
4.9 MEDIUM

D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the notify parameter in the arp_sys_asp function.

Nov 20, 2024
CVE-2024-52754
4.9 MEDIUM

D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the fn parameter in the tgfile_htm function.

Nov 20, 2024
CVE-2024-45510
5.4 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) through 10.0. Zimbra Webmail (Modern UI) is vulnerable to a stored Cross-Site Scripting (XSS) attack due to …

Nov 20, 2024
CVE-2024-45511
5.4 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A reflected Cross-Site Scripting (XSS) issue exists through the Briefcase module due to improper sanitization …

Nov 20, 2024
CVE-2018-9487
5.5 MEDIUM

In setVpnForcedLocked of Vpn.java, there is a possible blocking of internet traffic through vpn due to a bad uid check. This could lead to local …

Nov 20, 2024
CVE-2018-9486
6.5 MEDIUM

In hidh_l2cif_data_ind of hidh_conn.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Nov 20, 2024
CVE-2018-9485
6.5 MEDIUM

In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure …

Nov 20, 2024
CVE-2018-9483
6.5 MEDIUM

In bta_dm_remove_sec_dev_entry of bta_dm_act.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure …

Nov 20, 2024
CVE-2018-9482
6.5 MEDIUM

In intr_data_copy_cb of btif_hd.cc, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure in …

Nov 20, 2024
CVE-2018-9481
6.5 MEDIUM

In bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure in the Bluetooth …

Nov 20, 2024
CVE-2018-9480
6.5 MEDIUM

In bta_hd_get_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to improper input validation. This could lead to remote information disclosure in the Bluetooth …

Nov 20, 2024
CVE-2024-52796
5.3 MEDIUM

Password Pusher, an open source application to communicate sensitive information over the web, comes with a configurable rate limiter. In versions prior to v1.49.0, the …

Nov 20, 2024
CVE-2024-52725
4.9 MEDIUM

SemCms v4.8 was discovered to contain a SQL injection vulnerability. This allows an attacker to execute arbitrary code via the ldgid parameter in the SEMCMS_SeoAndTag.php …

Nov 20, 2024
CVE-2024-11487
6.3 MEDIUM

A vulnerability has been found in Code4Berry Decoration Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /decoration/admin/btndates_report.php of …

Nov 20, 2024
CVE-2024-11486
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Code4Berry Decoration Management System 1.0. This affects an unknown part of the file /decoration/admin/user_permission.php of …

Nov 20, 2024
CVE-2024-11485
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Code4Berry Decoration Management System 1.0. Affected by this issue is some unknown functionality of …

Nov 20, 2024
CVE-2024-11484
6.3 MEDIUM

A vulnerability classified as critical was found in Code4Berry Decoration Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /decoration/admin/update_image.php …

Nov 20, 2024
CVE-2024-51209
5.4 MEDIUM

Cross-Site Scripting (XSS) vulnerabilities in Anuj Kumar's Client Management System Version 1.2 allow local attackers to inject arbitrary web script or HTML via the search …

Nov 20, 2024
CVE-2024-52597
6.1 MEDIUM

2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Versions prior to 5.4.1 are vulnerable to stored cross-site …

Nov 20, 2024
CVE-2024-11154
4.3 MEDIUM

The PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, …

Nov 20, 2024
CVE-2024-11406
6.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django CMS Attributes Fields allows Stored XSS.This issue …

Nov 20, 2024
CVE-2024-11404
5.5 MEDIUM

Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in django CMS Association django …

Nov 20, 2024
CVE-2024-10520
5.3 MEDIUM

The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'check' method of …

Nov 20, 2024
CVE-2024-48899
4.3 MEDIUM

A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they …

Nov 20, 2024
CVE-2024-45691
5.4 MEDIUM

A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be bypassed or less secure due …

Nov 20, 2024
CVE-2024-45689
6.5 MEDIUM

A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they did …

Nov 20, 2024
CVE-2024-10872
6.4 MEDIUM

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `template-post-custom-field` block in all versions up to, and including, …

Nov 20, 2024
CVE-2024-11179
6.5 MEDIUM

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to SQL Injection via the 'status_type' parameter …

Nov 20, 2024
CVE-2024-10891
6.4 MEDIUM

The Save as PDF Plugin by Pdfcrowd plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'save_as_pdf_pdfcrowd' shortcode in all versions up …

Nov 20, 2024
CVE-2024-10665
5.4 MEDIUM

The Yaad Sarig Payment Gateway For WC plugin for WordPress is vulnerable to unauthorized modification & access of data due to a missing capability check …

Nov 20, 2024
CVE-2024-10126
4.3 MEDIUM

Local File Inclusion vulnerability in M-Files Server in versions before 24.11 (excluding 24.8 SR1, 24.2 SR3 and 23.8 SR7) allows an authenticated user to read …

Nov 20, 2024
CVE-2024-52033
5.3 MEDIUM

Exposure of sensitive system information to an unauthorized control sphere issue exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If this vulnerability is …

Nov 20, 2024
CVE-2024-47865
5.3 MEDIUM

Missing authentication for critical function vulnerability exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If this vulnerability is exploited, a remote unauthenticated attacker …

Nov 20, 2024
CVE-2024-9239
6.1 MEDIUM

The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on …

Nov 20, 2024
CVE-2024-8726
6.1 MEDIUM

The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …

Nov 20, 2024
CVE-2024-11277
6.1 MEDIUM

The 404 Solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 2.35.19 due to insufficient …

Nov 20, 2024
CVE-2024-10900
6.5 MEDIUM

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Nov 20, 2024
CVE-2024-10365
4.3 MEDIUM

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in …

Nov 20, 2024
CVE-2024-9653
6.1 MEDIUM

The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' parameter in all …

Nov 20, 2024
CVE-2024-52614
4.0 MEDIUM

Use of hard-coded cryptographic key issue exists in "Kura Sushi Official App Produced by EPARK" for Android versions prior to 3.8.5. If this vulnerability is …

Nov 20, 2024
CVE-2024-11278
6.1 MEDIUM

The GD bbPress Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Nov 20, 2024
CVE-2024-44309
6.3 MEDIUM KEV

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and …

Nov 20, 2024
CVE-2018-9440
6.5 MEDIUM

In parse of M3UParser.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial of service with no additional …

Nov 19, 2024
CVE-2024-52392
6.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in w3speedster W3SPEEDSTER w3speedster-wp.This issue affects W3SPEEDSTER: from n/a through <= 7.25.

Nov 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.