CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2020-26067
5.4 MEDIUM

A vulnerability in the web-based interface of Cisco Webex Teams could allow an authenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to …

Nov 18, 2024
CVE-2020-26066
6.5 MEDIUM

A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that …

Nov 18, 2024
CVE-2024-52426
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Linear Oy Linear linear allows DOM-Based XSS.This issue affects Linear: from n/a through …

Nov 18, 2024
CVE-2024-52425
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vladislav Urchenko Drozd – Addons for Elementor drozd-addons-for-elementor allows Stored XSS.This issue affects …

Nov 18, 2024
CVE-2024-52423
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Builder themify-builder allows Stored XSS.This issue affects Themify Builder: from n/a …

Nov 18, 2024
CVE-2024-52422
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Terry L. WP Githuber MD wp-githuber-md allows Stored XSS.This issue affects WP Githuber …

Nov 18, 2024
CVE-2024-52419
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Clipboard Agency Copy Anything to Clipboard copy-the-code allows Stored XSS.This issue affects Copy …

Nov 18, 2024
CVE-2021-1465
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a directory traversal attack and …

Nov 18, 2024
CVE-2021-1462
6.7 MEDIUM

A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to elevate privileges on an affected system. To exploit this …

Nov 18, 2024
CVE-2021-1461
4.9 MEDIUM

A vulnerability in the Image Signature Verification feature of Cisco SD-WAN Software could allow an authenticated, remote attacker with Administrator-level credentials to install a malicious software …

Nov 18, 2024
CVE-2021-1444
6.1 MEDIUM

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker …

Nov 18, 2024
CVE-2021-1440
6.8 MEDIUM

A vulnerability in the implementation of the Resource Public Key Infrastructure (RPKI) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause …

Nov 18, 2024
CVE-2021-1425
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to access sensitive …

Nov 18, 2024
CVE-2021-1424
5.3 MEDIUM

A vulnerability in the ipsecmgr process of Cisco ASR 5000 Series Software (StarOS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) …

Nov 18, 2024
CVE-2021-1410
4.3 MEDIUM

A vulnerability in the distribution list feature of Cisco Webex Meetings could allow an authenticated, remote attacker to modify a distribution list that belongs to another …

Nov 18, 2024
CVE-2021-1379
6.5 MEDIUM

Multiple vulnerabilities in the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) implementations for Cisco IP Phone Series 68xx/78xx/88xx could allow an unauthenticated, adjacent attacker to …

Nov 18, 2024
CVE-2021-1234
5.3 MEDIUM

A vulnerability in the cluster management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. …

Nov 18, 2024
CVE-2021-1232
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying filesystem …

Nov 18, 2024
CVE-2021-1132
5.3 MEDIUM

A vulnerability in the API subsystem and in the web-management interface of Cisco Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to access sensitive …

Nov 18, 2024
CVE-2020-3548
5.3 MEDIUM

A vulnerability in the Transport Layer Security (TLS) protocol implementation of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to …

Nov 18, 2024
CVE-2020-3539
6.3 MEDIUM

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete …

Nov 18, 2024
CVE-2020-3538
4.6 MEDIUM

A vulnerability in a certain REST API endpoint of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to perform a path …

Nov 18, 2024
CVE-2020-3532
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and …

Nov 18, 2024
CVE-2020-3525
4.3 MEDIUM

A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to recover service account passwords that are saved …

Nov 18, 2024
CVE-2020-3431
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco Small Business RV042 Dual WAN VPN Routers and Cisco Small Business RV042G Dual Gigabit WAN VPN Routers could …

Nov 18, 2024
CVE-2020-3420
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) …

Nov 18, 2024
CVE-2020-26063
5.4 MEDIUM

A vulnerability in the API endpoints of Cisco Integrated Management Controller could allow an authenticated, remote attacker to bypass authorization and take actions on a vulnerable …

Nov 18, 2024
CVE-2020-26062
5.3 MEDIUM

A vulnerability in Cisco Integrated Management Controller could allow an unauthenticated, remote attacker to enumerate valid usernames within the vulnerable application. The vulnerability is due to …

Nov 18, 2024
CVE-2024-37155
6.5 MEDIUM

OpenCTI is an open source platform allowing organizations to manage their cyber threat intelligence knowledge and observables. Prior to version 6.1.9, the regex validation used …

Nov 18, 2024
CVE-2024-9526
5.4 MEDIUM

There exists a stored XSS Vulnerability in Kubeflow Pipeline View web UI. The Kubeflow Web UI allows to create new pipelines. When creating a new …

Nov 18, 2024
CVE-2024-52318
6.1 MEDIUM

Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommended to upgrade to version 11.0.1, …

Nov 18, 2024
CVE-2024-52317
6.5 MEDIUM

Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or …

Nov 18, 2024
CVE-2024-48901
4.3 MEDIUM

A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a report if they have permission …

Nov 18, 2024
CVE-2024-48898
4.3 MEDIUM

A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have …

Nov 18, 2024
CVE-2024-48897
4.3 MEDIUM

A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to …

Nov 18, 2024
CVE-2024-48896
4.3 MEDIUM

A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not …

Nov 18, 2024
CVE-2024-11319
4.8 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django-cms allows Cross-Site Scripting (XSS).This issue affects django-cms: …

Nov 18, 2024
CVE-2024-11023
6.1 MEDIUM

Firebase JavaScript SDK utilizes a "FIREBASE_DEFAULTS" cookie to store configuration data, including an "_authTokenSyncURL" field used for session synchronization. If this cookie field is preset …

Nov 18, 2024
CVE-2024-42392
4.0 MEDIUM

Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters.

Nov 18, 2024
CVE-2024-42391
4.3 MEDIUM

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application …

Nov 18, 2024
CVE-2024-42390
4.3 MEDIUM

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application …

Nov 18, 2024
CVE-2024-42389
5.3 MEDIUM

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application …

Nov 18, 2024
CVE-2024-42388
5.3 MEDIUM

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application …

Nov 18, 2024
CVE-2024-42387
5.3 MEDIUM

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application …

Nov 18, 2024
CVE-2024-42385
4.0 MEDIUM

Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters.

Nov 18, 2024
CVE-2024-42383
4.2 MEDIUM

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value beyond the memory space dedicated for …

Nov 18, 2024
CVE-2024-41972
6.5 MEDIUM

A low privileged remote attacker can overwrite an arbitrary file on the filesystem which may lead to an arbitrary file read with root privileges.

Nov 18, 2024
CVE-2024-41970
5.7 MEDIUM

A low privileged remote attacker may gain access to forbidden diagnostic data due to incorrect permission assignment for critical resources.

Nov 18, 2024
CVE-2023-39180
4.0 MEDIUM

A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releasing memory after its effective …

Nov 18, 2024
CVE-2023-39176
5.8 MEDIUM

A flaw was found within the parsing of SMB2 requests that have a transform header in the kernel ksmbd module. The issue results from the …

Nov 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.