CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7918
4.8 MEDIUM

The Pocket Widget WordPress plugin through 0.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Sep 9, 2024
CVE-2024-7689
4.3 MEDIUM

The Snapshot Backup WordPress plugin through 2.1.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Sep 9, 2024
CVE-2024-7688
6.5 MEDIUM

The AZIndex WordPress plugin through 0.8.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin delete arbitrary …

Sep 9, 2024
CVE-2024-7687
4.3 MEDIUM

The AZIndex WordPress plugin through 0.8.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Sep 9, 2024
CVE-2024-6910
4.8 MEDIUM

The EventON WordPress plugin before 2.2.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Sep 9, 2024
CVE-2024-5561
4.8 MEDIUM

The Popup Maker WordPress plugin before 1.19.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Sep 9, 2024
CVE-2024-45625
6.1 MEDIUM

Cross-site scripting vulnerability exists in Forminator versions prior to 1.34.1. If this vulnerability is exploited, an arbitrary script may be executed on the web browser …

Sep 9, 2024
CVE-2024-8586
6.1 MEDIUM

WebITR from Uniong has an Open Redirect vulnerability, which allows unauthorized remote attackers to exploit this vulnerability to forge URLs. Users, believing they are accessing …

Sep 9, 2024
CVE-2024-8585
6.5 MEDIUM

Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowing a remote attacker with regular privileges to …

Sep 9, 2024
CVE-2024-42343
5.3 MEDIUM

Loway - CWE-204: Observable Response Discrepancy

Sep 8, 2024
CVE-2024-42342
4.3 MEDIUM

Loway - CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

Sep 8, 2024
CVE-2024-42341
6.1 MEDIUM

Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

Sep 8, 2024
CVE-2024-8574
6.3 MEDIUM

A vulnerability has been found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220 and classified as critical. This vulnerability affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The …

Sep 8, 2024
CVE-2024-8570
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Sep 8, 2024
CVE-2024-6925
4.3 MEDIUM

The TrueBooker WordPress plugin before 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged …

Sep 8, 2024
CVE-2024-6859
5.4 MEDIUM

The WP MultiTasking WordPress plugin through 0.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Sep 8, 2024
CVE-2024-6856
4.3 MEDIUM

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Sep 8, 2024
CVE-2024-6855
4.3 MEDIUM

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating exit popups, which could allow attackers to make logged admins perform …

Sep 8, 2024
CVE-2024-6853
4.3 MEDIUM

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating welcome popups, which could allow attackers to make logged admins perform …

Sep 8, 2024
CVE-2024-6852
4.3 MEDIUM

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Sep 8, 2024
CVE-2024-8568
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Mini-Tmall up to 20240901. Affected is the function rewardMapper.select of the file tmall/admin/order/1/1. The manipulation …

Sep 8, 2024
CVE-2024-8566
4.3 MEDIUM

A vulnerability classified as problematic was found in code-projects Online Shop Store 1.0. This vulnerability affects unknown code of the file /settings.php. The manipulation of …

Sep 8, 2024
CVE-2024-8564
6.3 MEDIUM

A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/update.php. The …

Sep 7, 2024
CVE-2024-8561
6.3 MEDIUM

A vulnerability has been found in SourceCodester PHP CRUD 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file …

Sep 7, 2024
CVE-2024-8560
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Simple Invoice Generator System 1.0. Affected is an unknown function of the file /save_invoice.php. …

Sep 7, 2024
CVE-2024-8559
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Online Food Menu 1.0. This issue affects some unknown processing of the file …

Sep 7, 2024
CVE-2024-42022
5.3 MEDIUM

An incorrect permission assignment vulnerability allows an attacker to modify product configuration files.

Sep 7, 2024
CVE-2024-42021
6.5 MEDIUM

An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.

Sep 7, 2024
CVE-2024-42020
5.4 MEDIUM

A Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection.

Sep 7, 2024
CVE-2024-8558
4.3 MEDIUM

A vulnerability classified as problematic was found in SourceCodester Food Ordering Management System 1.0. This vulnerability affects unknown code of the file /foms/routers/place-order.php of the …

Sep 7, 2024
CVE-2023-39333
5.3 MEDIUM

Maliciously crafted export names in an imported WebAssembly module can inject JavaScript code. The injected code may be able to access data and functions that …

Sep 7, 2024
CVE-2023-30582
5.3 MEDIUM

A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flag is used with a non-* …

Sep 7, 2024
CVE-2024-8557
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Food Ordering Management System 1.0. This affects an unknown part of the file /foms/routers/cancel-order.php. The …

Sep 7, 2024
CVE-2024-8555
4.3 MEDIUM

A vulnerability was found in SourceCodester Clinics Patient Management System 2.0. It has been classified as problematic. Affected is an unknown function of the file …

Sep 7, 2024
CVE-2024-40680
5.5 MEDIUM

IBM MQ 9.3 CD and 9.4 LTS/CD could allow a local user to cause a denial of service due to improper memory allocation causing a …

Sep 7, 2024
CVE-2024-37068
5.9 MEDIUM

IBM Maximo Application Suite - Manage Component 8.10, 8.11, and 9.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly …

Sep 7, 2024
CVE-2024-7620
6.6 MEDIUM

The Customizer Export/Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '_import' function in all versions …

Sep 7, 2024
CVE-2024-6010
5.3 MEDIUM

The Cost Calculator Builder PRO plugin for WordPress is vulnerable to price manipulation in all versions up to, and including, 3.2.1. This is due to …

Sep 7, 2024
CVE-2024-8538
4.3 MEDIUM

The Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and …

Sep 7, 2024
CVE-2024-8523
4.7 MEDIUM

A vulnerability was found in lmxcms up to 1.4 and classified as critical. Affected by this issue is the function formatData of the file /admin.php?m=Acquisi&a=testcj&lid=1 …

Sep 7, 2024
CVE-2024-6849
6.4 MEDIUM

The Preloader Plus – WordPress Loading Screen Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up …

Sep 7, 2024
CVE-2024-8521
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Wavelog up to 1.8.0. Affected is the function index of the file /qso of the …

Sep 7, 2024
CVE-2024-34155
4.3 MEDIUM

Calling any of the Parse functions on Go source code which contains deeply nested literals can cause a panic due to stack exhaustion.

Sep 6, 2024
CVE-2024-8394
6.5 MEDIUM

When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash. This vulnerability …

Sep 6, 2024
CVE-2024-38640
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via …

Sep 6, 2024
CVE-2024-27126
6.3 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow authenticated users to inject malicious code …

Sep 6, 2024
CVE-2024-27122
6.3 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow authenticated users to inject malicious code …

Sep 6, 2024
CVE-2024-21906
4.7 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Sep 6, 2024
CVE-2024-21904
5.9 MEDIUM

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents …

Sep 6, 2024
CVE-2024-21903
6.6 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Sep 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.