CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-50997
5.7 MEDIUM

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at pptp.cgi. This …

Nov 5, 2024
CVE-2024-50996
5.7 MEDIUM

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the bpa_server parameter at genie_bpa.cgi. This …

Nov 5, 2024
CVE-2024-50995
5.7 MEDIUM

Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the share_name parameter at usb_remote_smb_conf.cgi. This vulnerability allows attackers to cause a Denial of …

Nov 5, 2024
CVE-2024-50994
5.7 MEDIUM

Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component ipv6_fix.cgi via the ipv6_wan_ipaddr, ipv6_lan_ipaddr, ipv6_wan_length, and ipv6_lan_length parameters. These vulnerabilities …

Nov 5, 2024
CVE-2023-29115
6.5 MEDIUM

In certain conditions a request directed to the Waybox Enel X Web management application could cause a denial-of-service (e.g. reboot).

Nov 5, 2024
CVE-2023-29114
5.7 MEDIUM

System logs could be accessed through web management application due to a lack of access control. An attacker can obtain the following sensitive information: • …

Nov 5, 2024
CVE-2024-10841
5.5 MEDIUM

A vulnerability classified as critical was found in romadebrian WEB-Sekolah 1.0. Affected by this vulnerability is an unknown functionality of the file /Proses_Kirim.php of the …

Nov 5, 2024
CVE-2024-10329
4.3 MEDIUM

The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6 via the …

Nov 5, 2024
CVE-2024-9867
5.4 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Nov 5, 2024
CVE-2024-9657
6.5 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Nov 5, 2024
CVE-2024-51530
6.6 MEDIUM

LaunchAnywhere vulnerability in the account module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 5, 2024
CVE-2024-51529
5.5 MEDIUM

Data verification vulnerability in the battery module Impact: Successful exploitation of this vulnerability may affect function stability.

Nov 5, 2024
CVE-2024-9178
6.4 MEDIUM

The XT Floating Cart for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and …

Nov 5, 2024
CVE-2024-10319
4.3 MEDIUM

The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and …

Nov 5, 2024
CVE-2024-9878
4.4 MEDIUM

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up …

Nov 5, 2024
CVE-2024-7429
4.3 MEDIUM

The Zotpress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Zotpress_process_accounts_AJAX function in all versions …

Nov 5, 2024
CVE-2024-51528
4.0 MEDIUM

Vulnerability of improper log printing in the Super Home Screen module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 5, 2024
CVE-2024-51527
5.1 MEDIUM

Permission control vulnerability in the Gallery app Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 5, 2024
CVE-2024-51525
6.2 MEDIUM

Permission control vulnerability in the clipboard module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 5, 2024
CVE-2024-51524
4.0 MEDIUM

Permission control vulnerability in the Wi-Fi module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 5, 2024
CVE-2024-51522
6.2 MEDIUM

Vulnerability of improper device information processing in the device management module Impact: Successful exploitation of this vulnerability may affect availability.

Nov 5, 2024
CVE-2024-51521
5.7 MEDIUM

Input parameter verification vulnerability in the background service module Impact: Successful exploitation of this vulnerability may affect availability.

Nov 5, 2024
CVE-2024-51520
5.5 MEDIUM

Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect availability.

Nov 5, 2024
CVE-2024-51519
5.0 MEDIUM

Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect availability.

Nov 5, 2024
CVE-2024-51518
5.3 MEDIUM

Vulnerability of message types not being verified in the advanced messaging modul Impact: Successful exploitation of this vulnerability may affect availability.

Nov 5, 2024
CVE-2024-51517
5.1 MEDIUM

Vulnerability of improper memory access in the phone service module Impact: Successful exploitation of this vulnerability may affect availability.

Nov 5, 2024
CVE-2024-47255
4.7 MEDIUM

In 2N Access Commander versions 3.1.1.2 and prior, a local attacker can escalate their privileges in the system which could allow for arbitrary code execution …

Nov 5, 2024
CVE-2024-47254
6.3 MEDIUM

In 2N Access Commander versions 3.1.1.2 and prior, an Insufficient Verification of Data Authenticity vulnerability could allow an attacker to escalate their privileges and gain …

Nov 5, 2024
CVE-2023-52920
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: support non-r10 register spill/fill to/from stack in precision tracking Use instruction (jump) history to …

Nov 5, 2024
CVE-2024-9667
6.1 MEDIUM

The Seriously Simple Podcasting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Nov 5, 2024
CVE-2024-9443
6.4 MEDIUM

The Basticom Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.5.0 due …

Nov 5, 2024
CVE-2024-51516
6.2 MEDIUM

Permission control vulnerability in the ability module Impact: Successful exploitation of this vulnerability may cause features to function abnormally.

Nov 5, 2024
CVE-2024-51515
6.2 MEDIUM

Race condition vulnerability in the kernel network module Impact:Successful exploitation of this vulnerability may affect availability.

Nov 5, 2024
CVE-2024-51514
5.3 MEDIUM

Vulnerability of pop-up windows belonging to no app in the VPN module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 5, 2024
CVE-2024-51513
5.5 MEDIUM

Vulnerability of processes not being fully terminated in the VPN module Impact: Successful exploitation of this vulnerability will affect power consumption.

Nov 5, 2024
CVE-2024-51512
6.2 MEDIUM

Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulnerability may affect availability.

Nov 5, 2024
CVE-2024-51511
6.2 MEDIUM

Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulnerability may affect availability.

Nov 5, 2024
CVE-2024-9883
4.8 MEDIUM

The Pods WordPress plugin before 3.2.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Nov 5, 2024
CVE-2024-9689
4.3 MEDIUM

The Post From Frontend WordPress plugin through 1.0.0 does not have CSRF check when deleting posts, which could allow attackers to make logged in admin …

Nov 5, 2024
CVE-2024-7877
4.8 MEDIUM

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Notification settings, which …

Nov 5, 2024
CVE-2024-7876
4.8 MEDIUM

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Appointment Type settings, …

Nov 5, 2024
CVE-2024-5578
4.8 MEDIUM

The Table of Contents Plus WordPress plugin through 2408 does not sanitise and escape some of its settings, which could allow high privilege users such …

Nov 5, 2024
CVE-2024-10810
6.3 MEDIUM

A vulnerability was found in code-projects E-Health Care System 1.0. It has been classified as critical. Affected is an unknown function of the file Doctor/app_request.php. …

Nov 5, 2024
CVE-2024-10809
6.3 MEDIUM

A vulnerability was found in code-projects E-Health Care System 1.0 and classified as critical. This issue affects some unknown processing of the file /Doctor/chat.php. The …

Nov 5, 2024
CVE-2024-10808
6.3 MEDIUM

A vulnerability has been found in code-projects E-Health Care System 1.0 and classified as critical. This vulnerability affects unknown code of the file Admin/req_detail.php. The …

Nov 5, 2024
CVE-2024-10340
6.4 MEDIUM

The Shortcodes Blocks Creator Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'scu' shortcode in versions up to, and including, 2.1.3 due …

Nov 5, 2024
CVE-2024-32870
5.8 MEDIUM

Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and parameters) can be read …

Nov 5, 2024
CVE-2024-51500
5.3 MEDIUM

Meshtastic firmware is a device firmware for the Meshtastic project. The Meshtastic firmware does not check for packets claiming to be from the special broadcast …

Nov 4, 2024
CVE-2024-48059
6.1 MEDIUM

gaizhenbiao/chuanhuchatgpt project, version <=20240802 is vulnerable to stored Cross-Site Scripting (XSS) in WebSocket session transmission. An attacker can inject malicious content into a WebSocket message. …

Nov 4, 2024
CVE-2024-48057
6.1 MEDIUM

localai <=2.20.1 is vulnerable to Cross Site Scripting (XSS). When calling the delete model API and passing inappropriate parameters, it can cause a one-time storage …

Nov 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.