CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-48052
6.5 MEDIUM

In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no …

Nov 4, 2024
CVE-2024-10805
6.3 MEDIUM

A vulnerability was found in code-projects University Event Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Nov 4, 2024
CVE-2024-48463
6.5 MEDIUM

Bruno before 1.29.1 uses Electron shell.openExternal without validation (of http or https) for opening windows within the Markdown docs viewer.

Nov 4, 2024
CVE-2024-45185
5.1 MEDIUM

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, …

Nov 4, 2024
CVE-2024-45086
5.5 MEDIUM

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could …

Nov 4, 2024
CVE-2024-34891
6.8 MEDIUM

Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read Exchange account passwords via HTTP GET request.

Nov 4, 2024
CVE-2024-34885
6.8 MEDIUM

Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read SMTP accounts passwords via HTTP GET request.

Nov 4, 2024
CVE-2024-30618
6.1 MEDIUM

A Stored Cross-Site Scripting (XSS) Vulnerability in Chamilo LMS 1.11.26 allows a remote attacker to execute arbitrary JavaScript in a web browser by including a …

Nov 4, 2024
CVE-2024-30617
5.4 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 "/main/social/home.php," allows attackers to initiate a request that posts a fake post onto the user's …

Nov 4, 2024
CVE-2024-51328
6.1 MEDIUM

Cross Site Scripting vulnerability in addcategory.php in projectworld's Travel Management System v1.0 allows remote attacker to inject arbitrary code via the t2 parameter.

Nov 4, 2024
CVE-2024-34887
4.9 MEDIUM

Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send AD/LDAP administrators account passwords to an arbitrary server via …

Nov 4, 2024
CVE-2024-34883
4.9 MEDIUM

Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allow remote administrators to read proxy-server accounts passwords via HTTP GET request.

Nov 4, 2024
CVE-2024-34882
4.9 MEDIUM

Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send SMTP account passwords to an arbitrary server via HTTP …

Nov 4, 2024
CVE-2024-10766
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Codezips Free Exam Hall Seating Management System 1.0. This issue affects some unknown processing …

Nov 4, 2024
CVE-2024-10765
6.3 MEDIUM

A vulnerability classified as critical was found in Codezips Online Institute Management System up to 1.0. This vulnerability affects unknown code of the file /profile.php. …

Nov 4, 2024
CVE-2024-10764
6.3 MEDIUM

A vulnerability classified as critical has been found in Codezips Online Institute Management System 1.0. This affects an unknown part of the file /pages/save_user.php. The …

Nov 4, 2024
CVE-2024-51685
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Gangolf Accordion title for Elementor allows Stored XSS.This issue affects …

Nov 4, 2024
CVE-2024-51683
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Custom post type templates for Elementor custom-post-type-templates-for-elementor allows Stored XSS.This issue affects …

Nov 4, 2024
CVE-2024-51682
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Builder – WordPress Theme Builder for Elementor ht-builder allows Stored XSS.This …

Nov 4, 2024
CVE-2024-51681
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeRevolution WP Pocket URLs wp-pocket-urls allows Stored XSS.This issue affects WP Pocket URLs: …

Nov 4, 2024
CVE-2024-51680
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrestaProject Cresta Addons for Elementor cresta-addons-for-elementor allows Stored XSS.This issue affects Cresta Addons …

Nov 4, 2024
CVE-2024-51678
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcel Pol Elo Rating Shortcode elo-rating-shortcode allows Stored XSS.This issue affects Elo Rating …

Nov 4, 2024
CVE-2024-51677
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Knowledge Base knowledgebase allows Stored XSS.This issue affects Knowledge Base: from n/a …

Nov 4, 2024
CVE-2024-51665
4.9 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Noor Alam Magical Addons For Elementor magical-addons-for-elementor allows Server Side Request Forgery.This issue affects Magical Addons For Elementor: from …

Nov 4, 2024
CVE-2024-9147
6.1 MEDIUM

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Bna Informatics PosPratik allows XSS Through HTTP Query Strings.This issue affects …

Nov 4, 2024
CVE-2024-51560
4.3 MEDIUM

This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API endpoint. An authenticated remote attacker could exploit …

Nov 4, 2024
CVE-2024-51559
6.5 MEDIUM

This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by …

Nov 4, 2024
CVE-2024-51557
6.5 MEDIUM

This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit …

Nov 4, 2024
CVE-2024-51556
6.5 MEDIUM

This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API response. An authenticated remote attacker could exploit …

Nov 4, 2024
CVE-2024-10523
4.6 MEDIUM

This vulnerability exists in TP-Link IoT Smart Hub due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical …

Nov 4, 2024
CVE-2024-33033
6.7 MEDIUM

Memory corruption while processing IOCTL calls to unmap the buffers.

Nov 4, 2024
CVE-2024-33032
6.7 MEDIUM

Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.

Nov 4, 2024
CVE-2024-33031
6.7 MEDIUM

Memory corruption while processing the update SIM PB records request.

Nov 4, 2024
CVE-2024-33030
6.7 MEDIUM

Memory corruption while parsing IPC frequency table parameters for LPLH that has size greater than expected size.

Nov 4, 2024
CVE-2024-33029
6.7 MEDIUM

Memory corruption while handling the PDR in driver for getting the remote heap maps.

Nov 4, 2024
CVE-2024-23386
6.7 MEDIUM

memory corruption when WiFi display APIs are invoked with large random inputs.

Nov 4, 2024
CVE-2024-23377
6.7 MEDIUM

Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already …

Nov 4, 2024
CVE-2024-10761
4.3 MEDIUM

A vulnerability was found in Umbraco CMS up to 10.7.7/12.3.6/13.5.2/14.3.1/15.1.1. It has been classified as problematic. Affected is an unknown function of the file /Umbraco/preview/frame?id{} …

Nov 4, 2024
CVE-2024-10760
6.3 MEDIUM

A vulnerability was found in code-projects University Event Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dodelete.php. …

Nov 4, 2024
CVE-2024-10759
6.3 MEDIUM

A vulnerability has been found in itsourcecode Farm Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /edit-pig.php. The …

Nov 4, 2024
CVE-2024-20124
4.4 MEDIUM

In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution …

Nov 4, 2024
CVE-2024-20123
4.4 MEDIUM

In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution …

Nov 4, 2024
CVE-2024-20122
4.4 MEDIUM

In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution …

Nov 4, 2024
CVE-2024-20121
6.7 MEDIUM

In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Nov 4, 2024
CVE-2024-20120
6.7 MEDIUM

In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Nov 4, 2024
CVE-2024-20119
6.7 MEDIUM

In mms, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with …

Nov 4, 2024
CVE-2024-20118
6.7 MEDIUM

In mms, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with …

Nov 4, 2024
CVE-2024-20117
4.4 MEDIUM

In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution …

Nov 4, 2024
CVE-2024-20115
6.7 MEDIUM

In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Nov 4, 2024
CVE-2024-20114
6.7 MEDIUM

In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Nov 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.