CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-38132
5.3 MEDIUM

Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.

Sep 12, 2024
CVE-2021-38131
5.4 MEDIUM

Possible Cross-Site Scripting (XSS) Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.5.0000.

Sep 12, 2024
CVE-2021-22533
6.5 MEDIUM

Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.4.0000.

Sep 12, 2024
CVE-2021-22518
5.8 MEDIUM

A vulnerability identified in OpenText™ Identity Manager AzureAD Driver that allows logging of sensitive information into log file. This impacts all versions before 5.1.4.0

Sep 12, 2024
CVE-2021-22503
5.4 MEDIUM

Possible Improper Neutralization of Input During Web Page Generation Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.3.0000.

Sep 12, 2024
CVE-2024-8750
5.4 MEDIUM

Cross-site Scripting (XSS) vulnerability in idoit pro version 28. This vulnerability allows an attacker to retrieve session details of an authenticated user due to lack …

Sep 12, 2024
CVE-2024-8622
6.1 MEDIUM

The amCharts: Charts and Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'amcharts_javascript' parameter in all versions up to, and including, …

Sep 12, 2024
CVE-2024-2010
6.1 MEDIUM

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in TE Informatics V5 allows Reflected XSS.This issue affects V5: before 6.2.

Sep 12, 2024
CVE-2024-8056
6.1 MEDIUM

The MM-Breaking News WordPress plugin through 0.7.9 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected …

Sep 12, 2024
CVE-2024-8054
6.1 MEDIUM

The MM-Breaking News WordPress plugin through 0.7.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Sep 12, 2024
CVE-2024-7862
6.5 MEDIUM

The blogintroduction-wordpress-plugin WordPress plugin through 0.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged …

Sep 12, 2024
CVE-2024-7861
6.1 MEDIUM

The Misiek Paypal WordPress plugin through 1.1.20090324 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Sep 12, 2024
CVE-2024-7860
6.1 MEDIUM

The Simple Headline Rotator WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which …

Sep 12, 2024
CVE-2024-7859
6.5 MEDIUM

The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Sep 12, 2024
CVE-2024-7822
6.1 MEDIUM

The Quick Code WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Sep 12, 2024
CVE-2024-7820
6.5 MEDIUM

The ILC Thickbox WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Sep 12, 2024
CVE-2024-7818
6.1 MEDIUM

The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which …

Sep 12, 2024
CVE-2024-7817
6.5 MEDIUM

The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF checks in some places, which could allow attackers to make logged in users …

Sep 12, 2024
CVE-2024-7816
6.1 MEDIUM

The Gixaw Chat WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Sep 12, 2024
CVE-2024-6887
4.8 MEDIUM

The Giveaways and Contests by RafflePress WordPress plugin before 1.12.16 does not sanitise and escape some of its Giveaways settings, which could allow high privilege …

Sep 12, 2024
CVE-2024-6019
6.1 MEDIUM

The Music Request Manager WordPress plugin through 1.3 does not sanitise and escape incoming music requests, which could allow unauthenticated users to perform Cross-Site Scripting …

Sep 12, 2024
CVE-2024-6018
6.1 MEDIUM

The Music Request Manager WordPress plugin through 1.3 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to …

Sep 12, 2024
CVE-2024-6017
6.1 MEDIUM

The Music Request Manager WordPress plugin through 1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which …

Sep 12, 2024
CVE-2024-5799
4.8 MEDIUM

The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which could allow high privilege users …

Sep 12, 2024
CVE-2024-3163
4.3 MEDIUM

The Easy Property Listings WordPress plugin before 3.5.4 does not have CSRF check when deleting contacts in bulk, which could allow attackers to make a …

Sep 12, 2024
CVE-2024-8711
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in SourceCodester Food Ordering Management System 1.0. Affected by this issue is some unknown functionality …

Sep 12, 2024
CVE-2024-8710
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Inventory Management 1.0. Affected by this vulnerability is an unknown functionality of the file /model/viewProduct.php of …

Sep 12, 2024
CVE-2024-8709
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. Affected is the function delete_user/save_user of the file /admin_class.php. …

Sep 12, 2024
CVE-2024-38222
6.5 MEDIUM

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Sep 12, 2024
CVE-2024-8707
4.3 MEDIUM

A vulnerability was found in 云课网络科技有限公司 Yunke Online School System up to 3.0.6. It has been declared as problematic. This vulnerability affects the function downfile …

Sep 12, 2024
CVE-2024-8706
4.3 MEDIUM

A vulnerability was found in JFinalCMS up to 20240903. It has been classified as problematic. This affects the function update of the file /admin/template/update of …

Sep 12, 2024
CVE-2024-8705
6.3 MEDIUM

A vulnerability was found in Shandong Star Measurement and Control Equipment Heating Network Wireless Monitoring System 5.6.2 and classified as critical. Affected by this issue …

Sep 11, 2024
CVE-2024-8692
5.3 MEDIUM

A vulnerability classified as critical was found in TDuckCloud TDuckPro up to 6.3. Affected by this vulnerability is an unknown functionality. The manipulation leads to …

Sep 11, 2024
CVE-2024-8690
4.4 MEDIUM

A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows administrator privileges to …

Sep 11, 2024
CVE-2024-8688
4.4 MEDIUM

An improper neutralization of matching symbols vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables authenticated administrators (including read-only administrators) with access …

Sep 11, 2024
CVE-2024-44573
4.7 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the VLAN configuration of RELY-PCIe v22.2.1 to v23.1.0 allows attackers to execute arbitrary web scripts or HTML via …

Sep 11, 2024
CVE-2024-20390
5.3 MEDIUM

A vulnerability in the Dedicated XML Agent feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service …

Sep 11, 2024
CVE-2024-20343
5.5 MEDIUM

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to read any file in the file system of …

Sep 11, 2024
CVE-2024-7312
6.1 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from …

Sep 11, 2024
CVE-2024-46672
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: cfg80211: Handle SSID based pmksa deletion wpa_supplicant 2.11 sends since 1efdba5fdc2c ("Handle PMKSA …

Sep 11, 2024
CVE-2024-45030
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: igb: cope with large MAX_SKB_FRAGS Sabrina reports that the igb driver does not cope well …

Sep 11, 2024
CVE-2024-45029
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i2c: tegra: Do not mark ACPI devices as irq safe On ACPI machines, the tegra …

Sep 11, 2024
CVE-2024-45028
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mmc: mmc_test: Fix NULL dereference on allocation failure If the "test->highmem = alloc_pages()" allocation fails …

Sep 11, 2024
CVE-2024-45027
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Check for xhci->interrupters being allocated in xhci_mem_clearup() If xhci_mem_init() fails, it calls into …

Sep 11, 2024
CVE-2024-45025
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE copy_fd_bitmaps(new, old, count) is expected to copy the …

Sep 11, 2024
CVE-2024-45024
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix hugetlb vs. core-mm PT locking We recently made GUP's common page table walking …

Sep 11, 2024
CVE-2024-45022
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: fix page mapping if vm_area_alloc_pages() with high order fallback to order 0 The __vmap_pages_range_noflush() …

Sep 11, 2024
CVE-2024-45021
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: memcg_write_event_control(): fix a user-triggerable oops we are *not* guaranteed that anything past the terminating NUL …

Sep 11, 2024
CVE-2024-45020
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix a kernel verifier crash in stacksafe() Daniel Hodges reported a kernel verifier crash …

Sep 11, 2024
CVE-2024-45019
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Take state lock during tx timeout reporter mlx5e_safe_reopen_channels() requires the state lock taken. The …

Sep 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.