CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9944
5.3 MEDIUM

The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This is due to the plugin not …

Oct 15, 2024
CVE-2024-0129
6.3 MEDIUM

NVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe .tar file extraction. A successful exploit …

Oct 15, 2024
CVE-2024-21535
6.1 MEDIUM

Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property due to improper input sanitization. An attacker can …

Oct 15, 2024
CVE-2024-9969
5.4 MEDIUM

NewType WebEIP v3.0 does not properly validate user input, allowing a remote attacker with regular privileges to insert JavaScript into specific parameters, resulting in a …

Oct 15, 2024
CVE-2024-9820
6.5 MEDIUM

The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 3.0. This is due to …

Oct 15, 2024
CVE-2024-6757
4.3 MEDIUM

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, …

Oct 15, 2024
CVE-2024-9546
5.3 MEDIUM

The WPIDE – File Manager & Code Editor plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.9. …

Oct 15, 2024
CVE-2024-9953
4.9 MEDIUM

A potential denial-of-service (DoS) vulnerability exists in CERT VINCE software versions prior to 3.0.8. An authenticated administrative user can inject an arbitrary pickle object into …

Oct 14, 2024
CVE-2024-48821
6.1 MEDIUM

Cross Site Scripting vulnerability in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the FtpConfig.php component.

Oct 14, 2024
CVE-2024-47885
5.9 MEDIUM

The Astro web framework has a DOM Clobbering gadget in the client-side router starting in version 3.0.0 and prior to version 4.16.1. It can lead …

Oct 14, 2024
CVE-2024-48795
5.3 MEDIUM

An issue in Creative Labs Pte Ltd com.creative.apps.xficonnect 2.00.02 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 14, 2024
CVE-2024-48793
5.9 MEDIUM

An issue in INATRONIC com.inatronic.bmw 2.7.1 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 14, 2024
CVE-2024-48790
5.3 MEDIUM

An issue in ILIFE com.ilife.home.global 1.8.7 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 14, 2024
CVE-2024-47831
5.9 MEDIUM

Next.js is a React Framework for the Web. Cersions on the 10.x, 11.x, 12.x, 13.x, and 14.x branches before version 14.2.7 contain a vulnerability in …

Oct 14, 2024
CVE-2024-47767
4.3 MEDIUM

Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.113, Tuleap Enterprise Edition 15.13-5, and …

Oct 14, 2024
CVE-2024-47766
4.9 MEDIUM

Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and …

Oct 14, 2024
CVE-2024-46988
4.8 MEDIUM

Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.40, Tuleap Enterprise Edition 15.13-3, and …

Oct 14, 2024
CVE-2024-46980
4.8 MEDIUM

Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.37, Tuleap Enterprise Edition 15.13-3, and …

Oct 14, 2024
CVE-2024-46528
4.3 MEDIUM

An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSphere Enterprise 4.x before 4.1.3 and 3.x through …

Oct 14, 2024
CVE-2024-45741
5.4 MEDIUM

In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108 and 9.1.2312.205, a low-privileged user that does not hold the …

Oct 14, 2024
CVE-2024-45740
5.4 MEDIUM

In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403, a low-privileged user that does not hold the "admin" or …

Oct 14, 2024
CVE-2024-45739
4.9 MEDIUM

In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes plaintext passwords for local native authentication Splunk users. This exposure could happen …

Oct 14, 2024
CVE-2024-45738
4.9 MEDIUM

In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes sensitive HTTP parameters to the `_internal` index. This exposure could happen if …

Oct 14, 2024
CVE-2024-45737
4.3 MEDIUM

In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108, and 9.1.2312.204, a low-privileged user that does not hold …

Oct 14, 2024
CVE-2024-45736
6.5 MEDIUM

In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.107, 9.1.2312.204, and 9.1.2312.111, a low-privileged user that does not …

Oct 14, 2024
CVE-2024-45735
4.3 MEDIUM

In Splunk Enterprise versions below 9.2.3 and 9.1.6, and Splunk Secure Gateway versions on Splunk Cloud Platform versions below 3.4.259, 3.6.17, and 3.7.0, a low-privileged …

Oct 14, 2024
CVE-2024-45734
4.3 MEDIUM

In Splunk Enterprise versions 9.3.0, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could view images on …

Oct 14, 2024
CVE-2024-8184
5.9 MEDIUM

There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack. By repeatedly sending crafted …

Oct 14, 2024
CVE-2024-41997
6.6 MEDIUM

An issue was discovered in version of Warp Terminal prior to 2024.07.18 (v0.2024.07.16.08.02). A command injection vulnerability exists in the Docker integration functionality. An attacker …

Oct 14, 2024
CVE-2024-9823
5.3 MEDIUM

There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack on the server using …

Oct 14, 2024
CVE-2024-9936
6.5 MEDIUM

When manipulating the selection node cache, an attacker may have been able to cause unexpected behavior, potentially leading to an exploitable crash. This vulnerability affects …

Oct 14, 2024
CVE-2024-48120
5.4 MEDIUM

X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module. An attacker can inject malicious JavaScript code into the "Name" field …

Oct 14, 2024
CVE-2024-48119
5.4 MEDIUM

Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary HTML.

Oct 14, 2024
CVE-2024-46911
4.7 MEDIUM

Cross-site Resource Forgery (CSRF), Privilege escalation vulnerability in Apache Roller. On multi-blog/user Roller websites, by default weblog owners are trusted to publish arbitrary weblog content …

Oct 14, 2024
CVE-2024-38862
4.4 MEDIUM

Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35, <2.1.0p48 and <=2.0.0p39 (EOL) causes SNMP and IMPI secrets of host …

Oct 14, 2024
CVE-2024-9923
4.9 MEDIUM

The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with administrator privileges to move arbitrary system files to …

Oct 14, 2024
CVE-2024-49214
5.3 MEDIUM

QUIC in HAProxy 3.1.x before 3.1-dev7, 3.0.x before 3.0.5, and 2.9.x before 2.9.11 allows opening a 0-RTT session with a spoofed IP address. This can …

Oct 14, 2024
CVE-2024-9918
4.7 MEDIUM

A vulnerability has been found in HuangDou UTCMS V9 and classified as critical. This vulnerability affects the function RunSql of the file app/modules/ut-data/admin/sql.php. The manipulation …

Oct 13, 2024
CVE-2024-9917
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in HuangDou UTCMS V9. This affects an unknown part of the file app/modules/ut-template/admin/template_creat.php. The manipulation of …

Oct 13, 2024
CVE-2024-9908
5.5 MEDIUM

A vulnerability, which was classified as critical, was found in D-Link DIR-619L B1 2.06. Affected is the function formSetMACFilter of the file /goform/formSetMACFilter. The manipulation …

Oct 13, 2024
CVE-2024-9905
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the file …

Oct 13, 2024
CVE-2024-9904
4.7 MEDIUM

A vulnerability classified as critical was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This vulnerability affects the function pictureUpload of the file /admin/File/pictureUpload. …

Oct 13, 2024
CVE-2024-9903
4.7 MEDIUM

A vulnerability classified as critical has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This affects the function fileUpload of the file /admin/File/fileUpload. …

Oct 12, 2024
CVE-2024-9894
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Blood Bank System 1.0. Affected is an unknown function of the file reset.php. The …

Oct 12, 2024
CVE-2024-8902
4.3 MEDIUM

The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.8 via the render_column function …

Oct 12, 2024
CVE-2024-9696
6.4 MEDIUM

The Rescue Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rescue_tab' shortcode in all versions up to, and including, 2.8 …

Oct 12, 2024
CVE-2024-9595
6.4 MEDIUM

The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the table cell content in all versions …

Oct 12, 2024
CVE-2024-8915
6.4 MEDIUM

The Category Icon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due …

Oct 12, 2024
CVE-2024-8760
5.3 MEDIUM

The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to CSS Injection in all versions up to, and including, 3.13.6. This makes …

Oct 12, 2024
CVE-2024-9756
4.3 MEDIUM

The Order Attachments for WooCommerce plugin for WordPress is vulnerable to unauthorized limited arbitrary file uploads due to a missing capability check on the wcoa_add_attachment …

Oct 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.