CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10651
4.9 MEDIUM

IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrator privileges to exploit this …

Nov 1, 2024
CVE-2024-10232
6.4 MEDIUM

The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's atomchat shortcode in all versions …

Nov 1, 2024
CVE-2024-9655
6.4 MEDIUM

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon …

Nov 1, 2024
CVE-2024-7424
5.4 MEDIUM

The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to unauthorized modification of and access to data due to a missing capability …

Nov 1, 2024
CVE-2024-49501
5.7 MEDIUM

Sysmac Studio provided by OMRON Corporation contains an incorrect authorization vulnerability. If this vulnerability is exploited, an attacker may access the program which is protected …

Nov 1, 2024
CVE-2024-21510
5.4 MEDIUM

Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making …

Nov 1, 2024
CVE-2024-10620
5.3 MEDIUM

A vulnerability was found in knightliao Disconf 2.6.36. It has been classified as critical. This affects an unknown part of the file /api/config/list of the …

Nov 1, 2024
CVE-2024-10619
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.10. Affected is an unknown function of the file /pda/reportshop/next_detail.php. …

Nov 1, 2024
CVE-2024-10618
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Tongda OA 2017 up to 11.10. This issue affects some unknown processing of the …

Nov 1, 2024
CVE-2024-10617
6.3 MEDIUM

A vulnerability classified as critical was found in Tongda OA up to 11.10. This vulnerability affects unknown code of the file /pda/workflow/check_seal.php. The manipulation of …

Nov 1, 2024
CVE-2024-10616
6.3 MEDIUM

A vulnerability classified as critical has been found in Tongda OA up to 11.9. This affects an unknown part of the file /pda/workflow/webSignSubmit.php. The manipulation …

Nov 1, 2024
CVE-2024-10615
6.3 MEDIUM

A vulnerability was found in Tongda OA 2017 up to 11.10. It has been rated as critical. Affected by this issue is some unknown functionality …

Nov 1, 2024
CVE-2024-10613
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. Affected by this vulnerability is the function delSystemEncryptPolicy of the file …

Nov 1, 2024
CVE-2024-10612
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. Affected is the function removeHookInvalidCourse of the file /com/esafenet/servlet/system/HookInvalidCourseService.java. The manipulation …

Nov 1, 2024
CVE-2024-10611
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5 and classified as critical. This issue affects the function delProtocol of the file /com/esafenet/servlet/system/PrintScreenListService.java. The manipulation of …

Nov 1, 2024
CVE-2024-10610
6.3 MEDIUM

A vulnerability has been found in ESAFENET CDG 5 and classified as critical. This vulnerability affects the function delProtocol of the file /com/esafenet/servlet/system/ProtocolService.java. The manipulation …

Nov 1, 2024
CVE-2024-10609
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System Project 1.0. This affects an unknown part of the file typeadd.php. …

Nov 1, 2024
CVE-2024-10605
4.3 MEDIUM

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as problematic. This affects an unknown part of the file …

Nov 1, 2024
CVE-2024-10602
6.3 MEDIUM

A vulnerability was found in Tongda OA 2017 up to 11.9 and classified as critical. Affected by this issue is some unknown functionality of the …

Nov 1, 2024
CVE-2024-10601
6.3 MEDIUM

A vulnerability has been found in Tongda OA 2017 up to 11.10 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Oct 31, 2024
CVE-2024-6480
6.4 MEDIUM

The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'no_of_reviews' attribute in the woocommerce_reviews shortcode in all …

Oct 31, 2024
CVE-2024-6479
6.5 MEDIUM

The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'no_of_reviews' attribute in the woocommerce_reviews shortcode in all versions …

Oct 31, 2024
CVE-2024-10599
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Tongda OA 2017 up to 11.7. This issue affects some unknown processing of the …

Oct 31, 2024
CVE-2024-10598
5.3 MEDIUM

A vulnerability classified as critical was found in Tongda OA 11.2/11.3/11.4/11.5/11.6. This vulnerability affects unknown code of the file general/hr/setting/attendance/leave/data.php of the component Annual Leave …

Oct 31, 2024
CVE-2024-10597
6.3 MEDIUM

A vulnerability classified as critical has been found in ESAFENET CDG 5. This affects the function delPolicyAction of the file /com/esafenet/servlet/system/PolicyActionService.java. The manipulation of the …

Oct 31, 2024
CVE-2024-10596
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. Affected by this issue is the function delEntryptPolicySort of the file …

Oct 31, 2024
CVE-2024-10595
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. Affected by this vulnerability is the function delFile/delDifferCourseList of the file …

Oct 31, 2024
CVE-2024-10594
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. Affected is the function docHistory of the file /com/esafenet/servlet/fileManagement/FileDirectoryService.java. The manipulation …

Oct 31, 2024
CVE-2024-50802
6.0 MEDIUM

A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controller/responses/listing_grid/email_templates.php. The vulnerability is exploitable via the id parameter.

Oct 31, 2024
CVE-2024-50801
6.0 MEDIUM

A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controller/responses/listing_grid/collections.php. The vulnerability is exploitable via the id parameter.

Oct 31, 2024
CVE-2024-10573
6.7 MEDIUM

An out-of-bounds write flaw was found in mpg123 when handling crafted streams. When decoding PCM, the libmpg123 may write past the end of a heap-located …

Oct 31, 2024
CVE-2023-52045
6.1 MEDIUM

Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability.

Oct 31, 2024
CVE-2024-51430
6.4 MEDIUM

Cross Site Scripting vulnerability in online diagnostic lab management system using php v.1.0 allows a remote attacker to execute arbitrary code via the Test Name …

Oct 31, 2024
CVE-2024-50354
5.5 MEDIUM

gnark is a fast zk-SNARK library that offers a high-level API to design circuits. In gnark 0.11.0 and earlier, deserialization of Groth16 verification keys allocate …

Oct 31, 2024
CVE-2024-8553
6.3 MEDIUM

A vulnerability was found in Foreman's loader macros introduced with report templates. These macros may allow an authenticated user with permissions to view and create …

Oct 31, 2024
CVE-2024-8934
6.5 MEDIUM

A local user with administrative access rights can enter specialy crafted values for settings at the user interface (UI) of the TwinCAT Package Manager which …

Oct 31, 2024
CVE-2024-10454
6.1 MEDIUM

Clickjacking vulnerability in Clibo Manager v1.1.9.12 in the '/public/login' directory, a login panel. This vulnerability occurs due to the absence of an X-Frame-Options server-side header. …

Oct 31, 2024
CVE-2024-49685
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Custom Twitter Feeds (Tweets Widget) custom-twitter-feeds allows Cross Site Request Forgery.This issue affects Custom Twitter Feeds (Tweets …

Oct 31, 2024
CVE-2024-43933
4.3 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja allows Stored XSS.This issue affects WPMobile.App: from n/a through <= …

Oct 31, 2024
CVE-2024-43930
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in eyecix JobSearch allows Cross Site Request Forgery.This issue affects JobSearch: from n/a through 2.5.3.

Oct 31, 2024
CVE-2024-30149
4.8 MEDIUM

HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable.

Oct 31, 2024
CVE-2024-9446
6.4 MEDIUM

The WP Simple Anchors Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpanchor shortcode in all versions up to, and …

Oct 31, 2024
CVE-2024-9434
6.1 MEDIUM

The WPGlobus Translate Options plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to …

Oct 31, 2024
CVE-2024-9430
5.3 MEDIUM

The Get Quote For Woocommerce – Request A Quote For Woocommerce plugin for WordPress is vulnerable to unauthorized access of Quote data due to a …

Oct 31, 2024
CVE-2024-9165
6.4 MEDIUM

The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions …

Oct 31, 2024
CVE-2024-9700
5.3 MEDIUM

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions …

Oct 31, 2024
CVE-2024-9708
6.4 MEDIUM

The Easy SVG Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1 …

Oct 31, 2024
CVE-2024-10559
5.3 MEDIUM

A vulnerability was found in SourceCodester Airport Booking Management System 1.0 and classified as critical. Affected by this issue is the function Details. The manipulation …

Oct 31, 2024
CVE-2024-10544
5.3 MEDIUM

The Woo Manage Fraud Orders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.1 through publicly exposed …

Oct 31, 2024
CVE-2024-10557
4.3 MEDIUM

A vulnerability has been found in code-projects Blood Bank Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of …

Oct 31, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.