CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8778
6.5 MEDIUM

OMFLOW from The SYSCOM Group does not properly validate user input of the download functionality, allowing remote attackers with regular privileges to read arbitrary system …

Sep 16, 2024
CVE-2024-8776
6.1 MEDIUM

SmartRobot from INTUMIT does not properly validate a specific page parameter, allowing unautheticated remote attackers to inject JavaScript code to the parameter for Reflected Cross-site …

Sep 16, 2024
CVE-2024-8880
5.6 MEDIUM

A vulnerability classified as critical has been found in playSMS 1.4.4/1.4.5/1.4.6/1.4.7. Affected is an unknown function of the file /playsms/index.php?app=main&inc=core_auth&route=forgot&op=forgot of the component Template Handler. …

Sep 16, 2024
CVE-2024-46942
6.5 MEDIUM

In OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) through 13.0.1, a controller with a follower role can configure flow entries in an OpenDaylight clustering deployment.

Sep 15, 2024
CVE-2024-8876
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in xiaohe4966 TpMeCMS up to 1.3.3.1. Affected by this issue is some unknown functionality of …

Sep 15, 2024
CVE-2024-8875
5.4 MEDIUM

A vulnerability classified as critical was found in vedees wcms up to 0.3.2. Affected by this vulnerability is an unknown functionality of the file /wex/finder.php. …

Sep 15, 2024
CVE-2024-46918
4.9 MEDIUM

app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 does not prevent an org admin from viewing sensitive login fields of another org admin in the same org.

Sep 15, 2024
CVE-2024-8869
5.0 MEDIUM

A vulnerability classified as critical has been found in TOTOLINK A720R 4.1.5. Affected is the function exportOvpn. The manipulation leads to os command injection. It …

Sep 15, 2024
CVE-2024-44059
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ronald Huereca Custom Query Blocks post-type-archive-mapping allows DOM-Based XSS.This issue affects Custom Query …

Sep 15, 2024
CVE-2024-44058
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Parabola allows Stored XSS.This issue affects Parabola: from n/a through …

Sep 15, 2024
CVE-2024-44057
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Nirvana allows Stored XSS.This issue affects Nirvana: from n/a through …

Sep 15, 2024
CVE-2024-44056
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Mantra allows Stored XSS.This issue affects Mantra: from n/a through …

Sep 15, 2024
CVE-2024-44054
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Fluida allows Stored XSS.This issue affects Fluida: from n/a through …

Sep 15, 2024
CVE-2024-45460
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in manu225 Flipping Cards flipping-cards allows Stored XSS.This issue affects Flipping Cards: from n/a …

Sep 15, 2024
CVE-2024-45457
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows Stored XSS.This issue affects Spiffy Calendar: from …

Sep 15, 2024
CVE-2024-45456
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JoomUnited WP Meta SEO wp-meta-seo allows Stored XSS.This issue affects WP Meta SEO: …

Sep 15, 2024
CVE-2024-45455
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JoomUnited WP Meta SEO wp-meta-seo allows Stored XSS.This issue affects WP Meta SEO: …

Sep 15, 2024
CVE-2024-44063
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Happyforms allows Stored XSS.This issue affects Happyforms: from n/a through 1.26.0.

Sep 15, 2024
CVE-2024-44062
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hiroaki Miyashita Custom Field Template allows Stored XSS.This issue affects Custom …

Sep 15, 2024
CVE-2024-8866
4.3 MEDIUM

A vulnerability was found in AutoCMS 5.4. It has been classified as problematic. This affects an unknown part of the file /admin/robot.php. The manipulation of …

Sep 15, 2024
CVE-2024-8864
5.5 MEDIUM

A vulnerability has been found in composiohq composio up to 0.5.6 and classified as critical. Affected by this vulnerability is the function Calculator of the …

Sep 15, 2024
CVE-2023-3410
5.4 MEDIUM

The Bricks theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘customTag' attribute in versions up to, and including, 1.10.1 due to insufficient …

Sep 14, 2024
CVE-2024-8797
6.1 MEDIUM

The WP Booking System – Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without …

Sep 14, 2024
CVE-2024-8724
6.1 MEDIUM

The Waitlist Woocommerce ( Back in stock notifier ) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without …

Sep 14, 2024
CVE-2024-8775
5.5 MEDIUM

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. …

Sep 14, 2024
CVE-2022-3459
5.3 MEDIUM

The WooCommerce Multiple Free Gift plugin for WordPress is vulnerable to gift manipulation in all versions up to, and including, 1.2.3. This is due to …

Sep 14, 2024
CVE-2024-44096
4.4 MEDIUM

there is a possible arbitrary read due to an insecure default value. This could lead to local information disclosure with System execution privileges needed. User …

Sep 13, 2024
CVE-2024-5931
6.3 MEDIUM

BT: Unchecked user input in bap_broadcast_assistant

Sep 13, 2024
CVE-2024-8784
6.3 MEDIUM

A vulnerability classified as critical was found in QDocs Smart School Management System 7.0.0. Affected by this vulnerability is an unknown functionality of the file …

Sep 13, 2024
CVE-2024-6258
6.8 MEDIUM

BT: Missing length checks of net_buf in rfcomm_handle_data

Sep 13, 2024
CVE-2024-8782
6.3 MEDIUM

A vulnerability was found in JFinalCMS up to 1.0. It has been rated as critical. This issue affects the function delete of the file /admin/template/edit. …

Sep 13, 2024
CVE-2024-8059
4.3 MEDIUM

IPMI credentials may be captured in XCC audit log entries when the account username length is 16 characters.

Sep 13, 2024
CVE-2024-7756
6.8 MEDIUM

A potential vulnerability was reported in the ThinkPad L390 Yoga and 10w Notebook that could allow a local attacker to escalate privileges by accessing an …

Sep 13, 2024
CVE-2024-4550
6.7 MEDIUM

A potential buffer overflow vulnerability was reported in some Lenovo ThinkSystem and ThinkStation products that could allow a local attacker with elevated privileges to execute …

Sep 13, 2024
CVE-2024-45105
6.7 MEDIUM

An internal product security audit discovered a UEFI SMM (System Management Mode) callout vulnerability in some ThinkSystem servers that could allow a local attacker with …

Sep 13, 2024
CVE-2024-45104
6.3 MEDIUM

A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially …

Sep 13, 2024
CVE-2024-45103
4.3 MEDIUM

A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileges.

Sep 13, 2024
CVE-2024-45101
6.8 MEDIUM

A privilege escalation vulnerability was discovered when Single Sign On (SSO) is enabled that could allow an attacker to intercept a valid, authenticated LXCA user’s …

Sep 13, 2024
CVE-2024-3100
6.7 MEDIUM

A potential buffer overflow vulnerability was reported in some Lenovo Notebook products that could allow a local attacker with elevated privileges to execute arbitrary code.

Sep 13, 2024
CVE-2024-39926
5.4 MEDIUM

An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A stored cross-site scripting (XSS) or, due to the default CSP, HTML injection vulnerability has been …

Sep 13, 2024
CVE-2024-39925
6.5 MEDIUM

An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. It lacks an offboarding process for members who leave an organization. As a result, the shared …

Sep 13, 2024
CVE-2024-6867
6.5 MEDIUM

An information disclosure vulnerability exists in the lunary-ai/lunary, specifically in the `runs/{run_id}/related` endpoint. This endpoint does not verify that the user has the necessary access …

Sep 13, 2024
CVE-2024-6582
4.3 MEDIUM

A broken access control vulnerability exists in the latest version of lunary-ai/lunary. The `saml.ts` file allows a user from one organization to update the Identity …

Sep 13, 2024
CVE-2024-6087
6.5 MEDIUM

An improper access control vulnerability exists in lunary-ai/lunary at the latest commit (a761d83) on the main branch. The vulnerability allows an attacker to use the …

Sep 13, 2024
CVE-2024-31416
5.6 MEDIUM

The Eaton Foreseer software provides multiple customizable input fields for the users to configure parameters in the tool like alarms, reports, etc. Some of these …

Sep 13, 2024
CVE-2024-31415
6.3 MEDIUM

The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The …

Sep 13, 2024
CVE-2024-31414
6.7 MEDIUM

The Eaton Foreseer software provides users the capability to customize the dashboard in WebView pages. However, the input fields for this feature in the Eaton …

Sep 13, 2024
CVE-2024-44798
4.8 MEDIUM

phpgurukul Bus Pass Management System 1.0 is vulnerable to Cross-site scripting (XSS) in /admin/pass-bwdates-reports-details.php via fromdate and todate parameters.

Sep 13, 2024
CVE-2024-44685
5.0 MEDIUM

Titan SFTP and Titan MFT Server 2.0.25.2426 and earlier have a vulnerability a vulnerability where sensitive information, including passwords, is exposed in clear text within …

Sep 13, 2024
CVE-2024-8747
6.4 MEDIUM

The Email Obfuscate Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email-obfuscate' shortcode in all versions up to, and including, …

Sep 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.