CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10695
4.3 MEDIUM

The Futurio Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.0.13 via the 'elementor-template' shortcode due to …

Nov 12, 2024
CVE-2024-10685
6.1 MEDIUM

The Contact Form 7 Redirect & Thank You Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions …

Nov 12, 2024
CVE-2024-10538
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the before_label parameter in the Image Comparison widget in all …

Nov 12, 2024
CVE-2024-49395
5.3 MEDIUM

In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients …

Nov 12, 2024
CVE-2024-49394
5.3 MEDIUM

In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed …

Nov 12, 2024
CVE-2024-8882
4.5 MEDIUM

A buffer overflow vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker with …

Nov 12, 2024
CVE-2024-8881
6.8 MEDIUM

A post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker …

Nov 12, 2024
CVE-2024-49393
6.5 MEDIUM

In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to …

Nov 12, 2024
CVE-2024-47595
6.3 MEDIUM

An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access. On successful exploitation the attacker could cause …

Nov 12, 2024
CVE-2024-47593
4.3 MEDIUM

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the server, which otherwise would be restricted.This attack is …

Nov 12, 2024
CVE-2024-47592
5.3 MEDIUM

SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality in order to identify the legitimate user IDs. This has an …

Nov 12, 2024
CVE-2024-47588
4.7 MEDIUM

In SAP NetWeaver Java (Software Update Manager 1.1), under certain conditions when a software upgrade encounters errors, credentials are written in plaintext to a log …

Nov 12, 2024
CVE-2024-47586
5.3 MEDIUM

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously crafted http request which could cause a null …

Nov 12, 2024
CVE-2024-42372
6.5 MEDIUM

Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthorized user can read and modify some restricted global SLD configurations …

Nov 12, 2024
CVE-2024-11096
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Task Manager 1.0. This affects an unknown part of the file /newProject.php. The manipulation …

Nov 12, 2024
CVE-2024-11079
5.5 MEDIUM

A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. …

Nov 12, 2024
CVE-2024-51213
6.1 MEDIUM

Cross Site Scripting vulnerability in Online Shop Store v.1.0 allows a remote attacker to execute arbitrary code via the login.php component.

Nov 11, 2024
CVE-2024-50601
6.1 MEDIUM

Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to version 10.5.28 allow attackers to execute …

Nov 11, 2024
CVE-2024-51026
5.4 MEDIUM

The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is possible to inject a malicious …

Nov 11, 2024
CVE-2024-52531
6.5 MEDIUM

GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this …

Nov 11, 2024
CVE-2024-52288
5.1 MEDIUM

libosdp is an implementation of IEC 60839-11-5 OSDP (Open Supervised Device Protocol) and provides a C library with support for C++, Rust and Python3. In …

Nov 11, 2024
CVE-2024-51992
4.1 MEDIUM

Orchid is a @laravel package that allows for rapid application development of back-office applications, admin/user panels, and dashboards. This vulnerability is a method exposure issue …

Nov 11, 2024
CVE-2024-51490
5.5 MEDIUM

Ampache is a web based audio/video streaming application and file manager. This vulnerability exists in the interface section of the Ampache menu, where users can …

Nov 11, 2024
CVE-2024-51489
5.4 MEDIUM

Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate CSRF tokens when users …

Nov 11, 2024
CVE-2024-51488
5.4 MEDIUM

Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate CSRF tokens when users …

Nov 11, 2024
CVE-2024-51486
5.5 MEDIUM

Ampache is a web based audio/video streaming application and file manager. The vulnerability exists in the interface section of the Ampache menu, where users can …

Nov 11, 2024
CVE-2024-51190
4.8 MEDIUM

TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the ptRule_ApplicationName_1.1.6.0.0 parameter on the /special_ap.htm page.

Nov 11, 2024
CVE-2024-51189
4.8 MEDIUM

TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the macList_Name_1.1.1.0.0 parameter on the /filters.htm page.

Nov 11, 2024
CVE-2024-51188
4.8 MEDIUM

TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the vsRule_VirtualServerName_1.1.10.0.0 parameter on the /virtual_server.htm page.

Nov 11, 2024
CVE-2024-51187
4.8 MEDIUM

TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the firewallRule_Name_1.1.1.0.0 parameter on the /firewall_setting.htm page.

Nov 11, 2024
CVE-2024-46965
5.4 MEDIUM

The DS allvideo.downloader.browser (aka Fast Video Downloader: Browser) application through 1.6-RC1 for Android allows an attacker to execute arbitrary JavaScript code via the allvideo.downloader.browser.DefaultBrowserActivity component.

Nov 11, 2024
CVE-2024-11076
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Job Recruitment 1.0. This issue affects some unknown processing of the file /activation.php. …

Nov 11, 2024
CVE-2024-11074
6.3 MEDIUM

A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. This vulnerability affects unknown code of the file /incadd.php. The manipulation of …

Nov 11, 2024
CVE-2024-45087
4.8 MEDIUM

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the …

Nov 11, 2024
CVE-2024-11073
4.3 MEDIUM

A vulnerability classified as problematic has been found in SourceCodester Hospital Management System 1.0. This affects an unknown part of the file /vm/patient/delete-account.php. The manipulation …

Nov 11, 2024
CVE-2024-45088
6.4 MEDIUM

IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI …

Nov 11, 2024
CVE-2024-43439
5.4 MEDIUM

A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk.

Nov 11, 2024
CVE-2024-51054
4.8 MEDIUM

A Cross Site Scriptng (XSS) vulnerability was found in /omrs/admin/search.php in PHPGurukul Online Marriage Registration System 1.0, which allows remote attackers to execute arbitrary code …

Nov 11, 2024
CVE-2024-50991
4.8 MEDIUM

A Cross Site Scripting (XSS) vulnerability was found in /ums-sp/admin/registered-users.php in PHPGurukul User Management System v1.0, which allows remote attackers to execute arbitrary code via …

Nov 11, 2024
CVE-2024-50990
6.1 MEDIUM

A Reflected Cross Site Scriptng (XSS) vulnerability was found in /omrs/user/search.php in PHPGurukul Online Marriage Registration System v1.0, which allows remote attackers to execute arbitrary …

Nov 11, 2024
CVE-2024-50263
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fork: only invoke khugepaged, ksm hooks if no error There is no reason to invoke …

Nov 11, 2024
CVE-2024-34014
5.5 MEDIUM

Arbitrary file overwrite during recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before …

Nov 11, 2024
CVE-2024-43437
5.4 MEDIUM

A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup …

Nov 11, 2024
CVE-2024-43435
5.3 MEDIUM

A flaw was found in moodle. Insufficient capability checks make it possible for users with access to restore glossaries in courses to restore them into …

Nov 11, 2024
CVE-2024-43433
5.3 MEDIUM

A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users.

Nov 11, 2024
CVE-2024-43432
5.3 MEDIUM

A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, …

Nov 11, 2024
CVE-2024-43430
5.3 MEDIUM

A flaw was found in moodle. External API access to Quiz can override contained insufficient access control.

Nov 11, 2024
CVE-2024-43429
5.3 MEDIUM

A flaw was found in moodle. Some hidden user profile fields are visible in gradebook reports, which could result in users without the "view hidden …

Nov 11, 2024
CVE-2024-11021
5.4 MEDIUM

Webopac from Grand Vice info has Stored Cross-site Scripting vulnerability. Remote attackers with regular privileges can inject arbitrary JavaScript code into the server. When users …

Nov 11, 2024
CVE-2024-52355
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MiKa OSM osm.This issue affects OSM: from n/a through <= 6.1.2.

Nov 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.