CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9004
6.3 MEDIUM

A vulnerability classified as critical has been found in D-Link DAR-7000 up to 20240912. Affected is an unknown function of the file /view/DBManage/Backup_Server_commit.php. The manipulation …

Sep 19, 2024
CVE-2024-9003
4.3 MEDIUM

A vulnerability was found in Jinan Chicheng Company JFlow 2.0.0. It has been rated as problematic. This issue affects the function AttachmentUploadController of the file …

Sep 19, 2024
CVE-2024-43496
6.5 MEDIUM

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Sep 19, 2024
CVE-2024-43489
6.5 MEDIUM

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Sep 19, 2024
CVE-2024-38221
4.3 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Sep 19, 2024
CVE-2024-9001
6.3 MEDIUM

A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. This vulnerability affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The …

Sep 19, 2024
CVE-2024-25673
6.1 MEDIUM

Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.

Sep 19, 2024
CVE-2024-47162
4.1 MEDIUM

In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page

Sep 19, 2024
CVE-2024-47160
4.3 MEDIUM

In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible

Sep 19, 2024
CVE-2024-47159
4.3 MEDIUM

In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project

Sep 19, 2024
CVE-2024-8653
6.1 MEDIUM

A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific paths on the site. This …

Sep 19, 2024
CVE-2024-8652
6.1 MEDIUM

A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific path on the site. This …

Sep 19, 2024
CVE-2024-8651
5.3 MEDIUM

A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whether a user exists …

Sep 19, 2024
CVE-2024-8883
6.1 MEDIUM

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' …

Sep 19, 2024
CVE-2024-8354
5.5 MEDIUM

A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from …

Sep 19, 2024
CVE-2024-45770
4.4 MEDIUM

A vulnerability was found in Performance Co-Pilot (PCP). This flaw can only be exploited if an attacker has access to a compromised PCP system account. …

Sep 19, 2024
CVE-2024-45769
5.5 MEDIUM

A vulnerability was found in Performance Co-Pilot (PCP). This flaw allows an attacker to send specially crafted data to the system, which could cause the …

Sep 19, 2024
CVE-2024-47089
6.5 MEDIUM

This vulnerability exists in the Apex Softcell LD Geo due to improper validation of the transaction token ID in the API endpoint. An authenticated remote …

Sep 19, 2024
CVE-2024-47087
6.5 MEDIUM

This vulnerability exists in Apex Softcell LD Geo due to improper validation of the certain parameters (Client ID, DPID or BOID) in the API endpoint. …

Sep 19, 2024
CVE-2024-47086
6.5 MEDIUM

This vulnerability exists in Apex Softcell LD DP Back Office due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote …

Sep 19, 2024
CVE-2024-47085
6.5 MEDIUM

This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClicentcode and cLdClientCode) in the API endpoint. An …

Sep 19, 2024
CVE-2024-8850
6.1 MEDIUM

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email' parameter when a placeholder such as {email} is …

Sep 19, 2024
CVE-2024-8364
6.4 MEDIUM

The WP Custom Fields Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcfs-preset shortcode in all versions up to, and …

Sep 19, 2024
CVE-2022-4533
5.3 MEDIUM

The Limit Login Attempts Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1.0. This is due to …

Sep 19, 2024
CVE-2024-47059
4.3 MEDIUM

When logging in with the correct username and incorrect weak password, the user receives the notification, that their password is too weak. However when an …

Sep 18, 2024
CVE-2024-47050
5.4 MEDIUM

Prior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable.

Sep 18, 2024
CVE-2024-46372
6.1 MEDIUM

DedeCMS 5.7.115 is vulnerable to Cross Site Scripting (XSS) via the advertisement code box in the advertisement management module.

Sep 18, 2024
CVE-2024-43025
6.1 MEDIUM

An HTML injection vulnerability in RWS MultiTrans v7.0.23324.2 and earlier allows attackers to alter the HTML-layout and possibly execute a phishing attack via a crafted …

Sep 18, 2024
CVE-2024-43024
6.1 MEDIUM

Multiple stored cross-site scripting (XSS) vulnerabilities in RWS MultiTrans v7.0.23324.2 and earlier allow attackers to execute arbitrary web scripts or HTML via a crafted payload.

Sep 18, 2024
CVE-2024-46979
5.3 MEDIUM

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to get access to notification filters …

Sep 18, 2024
CVE-2024-46978
6.5 MEDIUM

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible for any user knowing the ID …

Sep 18, 2024
CVE-2024-46959
6.5 MEDIUM

runofast Indoor Security Camera for Baby Monitor has a default password of password for the root account. This allows access to the /stream1 URI via …

Sep 18, 2024
CVE-2023-41611
6.5 MEDIUM

Victure PC420 1.1.39 was discovered to use a weak and partially hardcoded key to encrypt data.

Sep 18, 2024
CVE-2024-46990
5.0 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. When relying on blocking access to localhost using the default `0.0.0.0` filter …

Sep 18, 2024
CVE-2024-45813
5.3 MEDIUM

find-my-way is a fast, open source HTTP router, internally using a Radix Tree (aka compact Prefix Tree), supports route params, wildcards, and it's framework independent. …

Sep 18, 2024
CVE-2024-45298
4.3 MEDIUM

Wiki.js is an open source wiki app built on Node.js. A disabled user can still gain access to a wiki by abusing the password reset …

Sep 18, 2024
CVE-2022-25777
6.5 MEDIUM

Prior to the patched version, an authenticated user of Mautic could read system files and access the internal addresses of the application due to a …

Sep 18, 2024
CVE-2024-6877
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Software Panel allows Reflected XSS.This issue affects Panel: before v2.3.24.

Sep 18, 2024
CVE-2024-5959
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Software Panel allows Stored XSS.This issue affects Panel: before v2.3.24.

Sep 18, 2024
CVE-2022-25775
6.6 MEDIUM

Prior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle. The user could retrieve …

Sep 18, 2024
CVE-2022-25774
4.8 MEDIUM

Prior to the patched version, logged in users of Mautic are vulnerable to a self XSS vulnerability in the notifications within Mautic. Users could inject …

Sep 18, 2024
CVE-2024-8891
5.3 MEDIUM

An attacker with no knowledge of the current users in the web application, could build a dictionary of potential users and check the server responses …

Sep 18, 2024
CVE-2024-39081
4.2 MEDIUM

An issue in SMART TYRE CAR & BIKE v4.2.0 allows attackers to perform a man-in-the-middle attack via Bluetooth communications.

Sep 18, 2024
CVE-2024-31198
5.3 MEDIUM

Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::Port:unpack. This issue affects libfluid: 0.1.0.

Sep 18, 2024
CVE-2024-31197
5.3 MEDIUM

Improper Null Termination vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::Port:unpack. This issue affects libfluid: 0.1.0.

Sep 18, 2024
CVE-2024-31196
5.3 MEDIUM

Unchecked Return Value to NULL Pointer Dereference vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::ActionList::unpack10. This …

Sep 18, 2024
CVE-2024-31195
6.5 MEDIUM

Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MultipartReplyTable::unpack. This issue affects libfluid: 0.1.0.

Sep 18, 2024
CVE-2024-31194
6.5 MEDIUM

Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MultipartReplyPortStats::unpack. This issue affects libfluid: 0.1.0.

Sep 18, 2024
CVE-2024-31193
6.5 MEDIUM

Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MultipartReplyGroup::unpack. This issue affects libfluid: 0.1.0.

Sep 18, 2024
CVE-2024-31192
6.5 MEDIUM

Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MultipartReplyGroupDesc::unpack. This issue affects libfluid: 0.1.0.

Sep 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.