CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-50447
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo's Elementor Templates & Widgets for WooCommerce envo-elementor-for-woocommerce allows Stored XSS.This issue …

Oct 28, 2024
CVE-2024-50446
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FuturioWP Futurio Extra futurio-extra.This issue affects Futurio Extra: from n/a through <= 2.0.11.

Oct 28, 2024
CVE-2024-50445
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in merkulove Selection Lite selection-lite allows Stored XSS.This issue affects Selection Lite: from n/a …

Oct 28, 2024
CVE-2024-50441
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CozyThemes Cozy Blocks cozy-addons allows Stored XSS.This issue affects Cozy Blocks: from n/a …

Oct 28, 2024
CVE-2024-50440
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris Coyier CodePen Embedded Pens Shortcode codepen-embedded-pen-shortcode allows Stored XSS.This issue affects CodePen …

Oct 28, 2024
CVE-2024-50439
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Widgets astra-widgets allows Stored XSS.This issue affects Astra Widgets: from …

Oct 28, 2024
CVE-2024-49771
5.3 MEDIUM

MPXJ is an open source library to read and write project plans from a variety of file formats and databases. The patch for the historical …

Oct 28, 2024
CVE-2024-47827
5.7 MEDIUM

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Due to a race condition in a global variable in …

Oct 28, 2024
CVE-2024-10469
6.5 MEDIUM

VINCE versions before 3.0.9 is vulnerable to exposure of User information to authenticated users.

Oct 28, 2024
CVE-2024-48291
6.3 MEDIUM

dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=editAdmin&id=17

Oct 28, 2024
CVE-2024-10450
6.3 MEDIUM

A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. This vulnerability affects unknown code of the …

Oct 28, 2024
CVE-2024-50443
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPXPO PostX ultimate-post.This issue affects PostX: from n/a through <= 4.1.12.

Oct 28, 2024
CVE-2024-48191
6.3 MEDIUM

dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=delAdmin&id=17

Oct 28, 2024
CVE-2024-34537
4.9 MEDIUM

TYPO3 before 13.3.1 allows denial of service (interface error) in the Bookmark Toolbar (ext:backend), exploitable by an administrator-level backend user account via manipulated data saved …

Oct 28, 2024
CVE-2024-10448
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank Management System 1.0. Affected by this issue is some unknown functionality …

Oct 28, 2024
CVE-2024-50582
4.6 MEDIUM

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements

Oct 28, 2024
CVE-2024-50581
4.6 MEDIUM

In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag

Oct 28, 2024
CVE-2024-50580
4.6 MEDIUM

In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule

Oct 28, 2024
CVE-2024-50579
4.6 MEDIUM

In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible

Oct 28, 2024
CVE-2024-50578
4.6 MEDIUM

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page

Oct 28, 2024
CVE-2024-50577
4.6 MEDIUM

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings

Oct 28, 2024
CVE-2024-50576
4.6 MEDIUM

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest

Oct 28, 2024
CVE-2024-50575
5.4 MEDIUM

In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API

Oct 28, 2024
CVE-2024-50574
5.3 MEDIUM

In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality

Oct 28, 2024
CVE-2024-50573
4.3 MEDIUM

In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized services

Oct 28, 2024
CVE-2024-50502
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CozyThemes Cozy Blocks cozy-addons allows DOM-Based XSS.This issue affects Cozy Blocks: from n/a …

Oct 28, 2024
CVE-2024-50501
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Climax Themes Kata Plus kata-plus allows DOM-Based XSS.This issue affects Kata Plus: from …

Oct 28, 2024
CVE-2024-50472
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in martindrapeau Amilia Store amilia-store allows Stored XSS.This issue affects Amilia Store: from n/a …

Oct 28, 2024
CVE-2024-50471
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in checklistcom Trip Plan tripplan allows DOM-Based XSS.This issue affects Trip Plan: from n/a …

Oct 28, 2024
CVE-2024-50470
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themes4WP Themes4WP YouTube External Subtitles themes4wp-youtube-external-subtitles allows DOM-Based XSS.This issue affects Themes4WP YouTube …

Oct 28, 2024
CVE-2024-50463
4.7 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.9.

Oct 28, 2024
CVE-2024-10447
6.3 MEDIUM

A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. Affected by this vulnerability is an unknown functionality of the …

Oct 28, 2024
CVE-2024-50442
6.5 MEDIUM

Improper Restriction of XML External Entity Reference vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows XML Injection.This issue affects Royal Elementor Addons: from n/a …

Oct 28, 2024
CVE-2024-10446
6.3 MEDIUM

A vulnerability classified as critical has been found in Project Worlds Online Time Table Generator 1.0. Affected is an unknown function of the file /timetable/admin/admindashboard.php?info=add_course. …

Oct 28, 2024
CVE-2024-50307
5.5 MEDIUM

Use of potentially dangerous function issue exists in Chatwork Desktop Application (Windows) versions prior to 2.9.2. If a user clicks a specially crafted link in …

Oct 28, 2024
CVE-2024-48936
5.0 MEDIUM

SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. …

Oct 28, 2024
CVE-2024-10439
5.3 MEDIUM

The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to access arbitrary …

Oct 28, 2024
CVE-2024-10435
6.3 MEDIUM

A vulnerability was found in didi Super-Jacoco 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /cov/triggerEnvCov. The manipulation …

Oct 28, 2024
CVE-2024-50624
5.9 MEDIUM

ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled mail server because cleartext HTTP is used for a URL …

Oct 28, 2024
CVE-2024-50615
6.5 MEDIUM

TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/digit, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.

Oct 27, 2024
CVE-2024-50614
6.5 MEDIUM

TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/16, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.

Oct 27, 2024
CVE-2024-50613
6.5 MEDIUM

libsndfile through 1.2.2 has a reachable assertion, that may lead to application exit, in mpeg_l3_encode.c mpeg_l3_encoder_close.

Oct 27, 2024
CVE-2024-50612
5.5 MEDIUM

libsndfile through 1.2.2 has an ogg_vorbis.c vorbis_analysis_wrote out-of-bounds read.

Oct 27, 2024
CVE-2024-10427
6.3 MEDIUM

A vulnerability was found in Codezips Pet Shop Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Oct 27, 2024
CVE-2024-10426
6.3 MEDIUM

A vulnerability was found in Codezips Pet Shop Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Oct 27, 2024
CVE-2024-10425
6.3 MEDIUM

A vulnerability was found in Project Worlds Student Project Allocation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of …

Oct 27, 2024
CVE-2024-10424
6.3 MEDIUM

A vulnerability has been found in Project Worlds Student Project Allocation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality …

Oct 27, 2024
CVE-2024-10423
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Project Worlds Student Project Allocation System 1.0. Affected is an unknown function of the file …

Oct 27, 2024
CVE-2024-10422
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Attendance and Payroll System 1.0. This issue affects some unknown processing of the …

Oct 27, 2024
CVE-2024-10421
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Attendance and Payroll System 1.0. This vulnerability affects unknown code of the file /admin/overtime_row.php. The manipulation …

Oct 27, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.