CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-41968
5.4 MEDIUM

A low privileged remote attacker may modify the docker settings setup of the device, leading to a limited DoS.

Nov 18, 2024
CVE-2024-22067
6.8 MEDIUM

ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web module interface, an authenticated attacker may exploit the …

Nov 18, 2024
CVE-2024-52947
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.20.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter of the …

Nov 18, 2024
CVE-2024-52944
5.4 MEDIUM

An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP …

Nov 18, 2024
CVE-2024-52943
5.4 MEDIUM

An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24697. It allows an authenticated remote attacker to inject a parameter into an HTTP …

Nov 18, 2024
CVE-2024-52942
5.4 MEDIUM

An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24696. It allows an authenticated remote attacker to inject a parameter into an HTTP …

Nov 18, 2024
CVE-2024-52941
5.4 MEDIUM

An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24695. It allows an authenticated remote attacker to inject a parameter into an HTTP …

Nov 18, 2024
CVE-2024-11308
6.2 MEDIUM

The DVC from TRCore encrypts files using a hardcoded key. Attackers can use this key to decrypt the files and restore the original content.

Nov 18, 2024
CVE-2024-52926
6.5 MEDIUM

Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.

Nov 18, 2024
CVE-2024-52922
6.5 MEDIUM

In Bitcoin Core before 25.1, an attacker can cause a node to not download the latest block, because there can be minutes of delay when …

Nov 18, 2024
CVE-2024-52921
5.3 MEDIUM

In Bitcoin Core before 25.0, a peer can affect the download state of other peers by sending a mutated block.

Nov 18, 2024
CVE-2024-52919
6.5 MEDIUM

Bitcoin Core before 22.0 has a CAddrMan nIdCount integer overflow and resultant assertion failure (and daemon exit) via a flood of addr messages.

Nov 18, 2024
CVE-2024-52918
6.5 MEDIUM

Bitcoin-Qt in Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption and application crash) via a BIP21 r parameter …

Nov 18, 2024
CVE-2024-52917
6.5 MEDIUM

Bitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis of random data received over the network, e.g., …

Nov 18, 2024
CVE-2024-52913
5.3 MEDIUM

In Bitcoin Core before 0.21.0, an attacker could prevent a node from seeing a specific unconfirmed transaction, because transaction re-requests are mishandled.

Nov 18, 2024
CVE-2024-38828
5.3 MEDIUM

Spring MVC controller methods with an @RequestBody byte[] method parameter are vulnerable to a DoS attack.

Nov 18, 2024
CVE-2024-11306
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Altenergy Power Control Software up to 20241108. This issue affects some unknown processing of …

Nov 18, 2024
CVE-2024-11305
6.3 MEDIUM

A vulnerability classified as critical was found in Altenergy Power Control Software up to 20241108. This vulnerability affects the function get_status_zigbee of the file /index.php/display/status_zigbee. …

Nov 18, 2024
CVE-2023-6110
5.5 MEDIUM

A flaw was found in OpenStack. When a user tries to delete a non-existing access rule in it's scope, it deletes other existing access rules …

Nov 17, 2024
CVE-2023-1419
5.9 MEDIUM

A script injection vulnerability was found in the Debezium database connector, where it does not properly sanitize some parameters. This flaw allows an attacker to …

Nov 17, 2024
CVE-2024-52386
5.3 MEDIUM

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Classified Listing classified-listing allows PHP Local File Inclusion.This …

Nov 16, 2024
CVE-2024-11094
5.3 MEDIUM

The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.35.17 via the export feature. This …

Nov 16, 2024
CVE-2024-10592
6.4 MEDIUM

The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the popup class parameter in all versions up to, and including, …

Nov 16, 2024
CVE-2024-10614
4.3 MEDIUM

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cancel_import() function in all …

Nov 16, 2024
CVE-2024-9938
6.1 MEDIUM

The Bounce Handler MailPoet 3 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, …

Nov 16, 2024
CVE-2024-9850
6.4 MEDIUM

The SVG Case Study plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0 …

Nov 16, 2024
CVE-2024-9615
6.1 MEDIUM

The BulkPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all …

Nov 16, 2024
CVE-2024-9386
6.4 MEDIUM

The Exclusive Divi – Divi Preloader, Modules for Divi & Extra Theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads …

Nov 16, 2024
CVE-2024-8873
6.1 MEDIUM

The PeproDev WooCommerce Receipt Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …

Nov 16, 2024
CVE-2024-6628
4.3 MEDIUM

The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up …

Nov 16, 2024
CVE-2024-11118
5.3 MEDIUM

The 404 Error Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to …

Nov 16, 2024
CVE-2024-11092
6.4 MEDIUM

The SVGPlus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.1.0 …

Nov 16, 2024
CVE-2024-11085
5.4 MEDIUM

The WP Log Viewer plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on several AJAX actions in …

Nov 16, 2024
CVE-2024-10884
6.1 MEDIUM

The SimpleForm Contact Form Submissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping …

Nov 16, 2024
CVE-2024-10883
6.1 MEDIUM

The SimpleForm – Contact form made simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without …

Nov 16, 2024
CVE-2024-10875
6.1 MEDIUM

The Gallery Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_Query_Arg without appropriate escaping on the URL in …

Nov 16, 2024
CVE-2024-10533
4.3 MEDIUM

The WP Chat App plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the ajax_install_plugin() function in all …

Nov 16, 2024
CVE-2024-10262
6.3 MEDIUM

The The Drop Shadow Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.7.14. This is due …

Nov 16, 2024
CVE-2024-10147
6.4 MEDIUM

The Steel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn shortcode in all versions up to, and including, 1.3.0 due …

Nov 16, 2024
CVE-2024-10017
6.4 MEDIUM

The PJW Mime Config plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0 …

Nov 16, 2024
CVE-2024-10015
6.4 MEDIUM

The ConvertCalculator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'type' parameters in all versions up to, and …

Nov 16, 2024
CVE-2024-10861
5.3 MEDIUM

The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Nov 16, 2024
CVE-2024-10795
4.3 MEDIUM

The Popularis Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.7 via the 'elementor-template' shortcode due to …

Nov 16, 2024
CVE-2024-10786
4.3 MEDIUM

The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the sla_clear_user_cache function in all …

Nov 16, 2024
CVE-2024-11262
5.3 MEDIUM

A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as critical. Affected by this vulnerability is the function main of …

Nov 15, 2024
CVE-2024-51765
5.5 MEDIUM

A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.

Nov 15, 2024
CVE-2024-51764
5.5 MEDIUM

A security vulnerability has been identified in HPE Data Management Framework (DMF) Suite (CXFS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.

Nov 15, 2024
CVE-2024-50983
5.4 MEDIUM

FlightPath 7.5 contains a Cross Site Scripting (XSS) vulnerability, which allows authenticated remote attackers with administrative rights to inject arbitrary JavaScript in the web browser …

Nov 15, 2024
CVE-2024-38370
5.3 MEDIUM

GLPI is a free asset and IT management software package. Starting in 9.2.0 and prior to 11.0.0, it is possible to download a document from …

Nov 15, 2024
CVE-2024-11261
5.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Student Record Management System 1.0. Affected is an unknown function of the file StudentRecordManagementSystem.cpp …

Nov 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.