CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-22068
6.0 MEDIUM

Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 64 bit allows Functionality Bypass.This issue affects ZXR10 1800-2S series …

Oct 10, 2024
CVE-2024-9802
5.3 MEDIUM

The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific information about the service, including …

Oct 10, 2024
CVE-2024-7049
5.4 MEDIUM

In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the …

Oct 10, 2024
CVE-2024-6747
5.3 MEDIUM

Information leakage in mknotifyd in Checkmk before 2.3.0p18, 2.2.0p36, 2.1.0p49 and in 2.0.0p39 (EOL) allows attacker to get potentially sensitive data

Oct 10, 2024
CVE-2024-9520
6.3 MEDIUM

The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in …

Oct 10, 2024
CVE-2024-9074
6.4 MEDIUM

The Advanced Blocks Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 …

Oct 10, 2024
CVE-2024-9067
4.3 MEDIUM

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due …

Oct 10, 2024
CVE-2024-8477
4.3 MEDIUM

The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up …

Oct 10, 2024
CVE-2024-9685
4.3 MEDIUM

The Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing capability check on the 'nftb_test_action' function in …

Oct 10, 2024
CVE-2024-9457
6.4 MEDIUM

The WP Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.0.7 due …

Oct 10, 2024
CVE-2024-9377
6.1 MEDIUM

The Products, Order & Customers Export for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg …

Oct 10, 2024
CVE-2024-9205
6.1 MEDIUM

The Maximum Products per User for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping …

Oct 10, 2024
CVE-2024-9072
6.4 MEDIUM

The GDPR-Extensions-com – Consent Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Oct 10, 2024
CVE-2024-9066
6.4 MEDIUM

The Marketing and SEO Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Oct 10, 2024
CVE-2024-9065
5.3 MEDIUM

The WP Helper Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'whp_smtp_send_mail_test' function in …

Oct 10, 2024
CVE-2024-9064
6.4 MEDIUM

The Elementor Inline SVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.0 …

Oct 10, 2024
CVE-2024-9057
6.4 MEDIUM

The Curator.io: Show all your social media posts in a beautiful feed. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘feed_id’ attribute …

Oct 10, 2024
CVE-2024-8987
6.4 MEDIUM

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Oct 10, 2024
CVE-2024-8729
6.1 MEDIUM

The Easy Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …

Oct 10, 2024
CVE-2024-8513
5.3 MEDIUM

The QA Analytics – Web Analytics Tool with Heatmaps & Session Replay Across All Pages plugin for WordPress is vulnerable to unauthorized modification of data …

Oct 10, 2024
CVE-2024-7048
5.4 MEDIUM

In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/documents/ and POST /rag/api/v1/doc. This vulnerability allows a lower-privileged …

Oct 10, 2024
CVE-2024-48942
5.9 MEDIUM

The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to easily brute-force the 2FA PIN via the plugins/servlet/twofactor/public/pinvalidation …

Oct 10, 2024
CVE-2024-48941
5.4 MEDIUM

The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to bypass 2FA by interacting with the /rest endpoint …

Oct 10, 2024
CVE-2024-8264
5.5 MEDIUM

Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent log file when detailed logging is enabled.

Oct 9, 2024
CVE-2024-48933
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary web script or HTML into the login page via a …

Oct 9, 2024
CVE-2024-7041
6.5 MEDIUM

An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerability occurs in the API endpoint `http://0.0.0.0:3000/api/v1/memories/{id}/update`, where the decentralization design is …

Oct 9, 2024
CVE-2024-38818
6.7 MEDIUM

VMware NSX contains a local privilege escalation vulnerability. An authenticated malicious actor may exploit this vulnerability to obtain permissions from a separate group role than …

Oct 9, 2024
CVE-2024-38817
6.7 MEDIUM

VMware NSX contains a command injection vulnerability. A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious payloads …

Oct 9, 2024
CVE-2024-38815
4.3 MEDIUM

VMware NSX contains a content spoofing vulnerability. An unauthenticated malicious actor may be able to craft a URL and redirect a victim to an attacker …

Oct 9, 2024
CVE-2024-47833
6.5 MEDIUM

Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected versions session cookies are served …

Oct 9, 2024
CVE-2024-47828
5.3 MEDIUM

ampache is a web based audio/video streaming application and file manager. A CSRF attack can be performed in order to delete objects (Playlist, smartlist etc.). …

Oct 9, 2024
CVE-2024-47816
6.4 MEDIUM

ImportDump is a mediawiki extension designed to automate user import requests. A user's local actor ID is stored in the database to tell who made …

Oct 9, 2024
CVE-2024-47815
6.0 MEDIUM

IncidentReporting is a MediaWiki extension for moving incident reports from wikitext to database tables. There are a variety of Cross-site Scripting issues, though all of …

Oct 9, 2024
CVE-2024-47812
6.0 MEDIUM

ImportDump is an extension for mediawiki designed to automate user import requests. Anyone who can edit the interface strings of a wiki (typically administrators and …

Oct 9, 2024
CVE-2024-47763
5.5 MEDIUM

Wasmtime is an open source runtime for WebAssembly. Wasmtime's implementation of WebAssembly tail calls combined with stack traces can result in a runtime crash in …

Oct 9, 2024
CVE-2024-9471
4.7 MEDIUM

A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated PAN-OS administrator with restricted privileges to use …

Oct 9, 2024
CVE-2024-9469
5.5 MEDIUM

A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to …

Oct 9, 2024
CVE-2024-9467
6.1 MEDIUM

A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context of an authenticated Expedition user's browser if that …

Oct 9, 2024
CVE-2024-9466
6.5 MEDIUM

A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated …

Oct 9, 2024
CVE-2024-9464
6.5 MEDIUM

An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in …

Oct 9, 2024
CVE-2024-42988
4.3 MEDIUM

Lack of access control in ChallengeSolves (/api/v1/challenges/<challenge id>/solves) of CTFd v2.0.0 - v3.7.2 allows authenticated users to retrieve a list of users who have solved …

Oct 9, 2024
CVE-2024-9671
5.3 MEDIUM

A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. …

Oct 9, 2024
CVE-2024-47673
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: pause TCM when the firmware is stopped Not doing so will make …

Oct 9, 2024
CVE-2024-47671
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: USB: usbtmc: prevent kernel-usb-infoleak The syzbot reported a kernel-usb-infoleak in usbtmc_write, we need to clear …

Oct 9, 2024
CVE-2024-47669
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix state management in error path of log writing function After commit a694291a6211 ("nilfs2: …

Oct 9, 2024
CVE-2024-47668
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: lib/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc() If we need to increase the tree depth, allocate …

Oct 9, 2024
CVE-2024-47667
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI: keystone: Add workaround for Errata #i2037 (AM65x SR 1.0) Errata #i2037 in AM65x/DRA80xM Processors …

Oct 9, 2024
CVE-2024-47666
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: pm80xx: Set phy->enable_completion only when we wait for it pm8001_phy_control() populates the enable_completion pointer …

Oct 9, 2024
CVE-2024-47665
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i3c: mipi-i3c-hci: Error out instead on BUG_ON() in IBI DMA setup Definitely condition dma_get_cache_alignment * …

Oct 9, 2024
CVE-2024-47664
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: spi: hisi-kunpeng: Add verification for the max_frequency provided by the firmware If the value of …

Oct 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.