CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-43408
6.3 MEDIUM

Discourse Placeholder Forms will let you build dynamic documentation. Unsanitized and stored user input was injected in the html of the post. The vulnerability is …

Aug 20, 2024
CVE-2024-42598
6.7 MEDIUM

SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still …

Aug 20, 2024
CVE-2024-40743
6.1 MEDIUM

The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.

Aug 20, 2024
CVE-2024-27186
6.1 MEDIUM

The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.

Aug 20, 2024
CVE-2024-27184
6.1 MEDIUM

Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..

Aug 20, 2024
CVE-2024-43409
6.5 MEDIUM

Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and …

Aug 20, 2024
CVE-2024-43397
4.3 MEDIUM

Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks. …

Aug 20, 2024
CVE-2024-43377
5.4 MEDIUM

Umbraco CMS is an ASP.NET CMS. An authenticated user can access a few unintended endpoints. This issue is fixed in 14.1.2.

Aug 20, 2024
CVE-2024-43376
4.3 MEDIUM

Umbraco is an ASP.NET CMS. Some endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode. This …

Aug 20, 2024
CVE-2024-42369
4.1 MEDIUM

matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. A malicious homeserver can craft a room or room structure such that the predecessors form …

Aug 20, 2024
CVE-2024-39094
5.4 MEDIUM

Friendica 2024.03 is vulnerable to Cross Site Scripting (XSS) in settings/profile via the homepage, xmpp, and matrix parameters.

Aug 20, 2024
CVE-2024-42560
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the component update_page_details.php of Blood Bank And Donation Management System commit dc9e039 allows attackers to execute arbitrary web scripts …

Aug 20, 2024
CVE-2024-42335
5.4 MEDIUM

7Twenty - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Aug 20, 2024
CVE-2024-41699
4.4 MEDIUM

Priority – CWE-552: Files or Directories Accessible to External Parties

Aug 20, 2024
CVE-2024-41698
4.3 MEDIUM

Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Aug 20, 2024
CVE-2024-41697
6.1 MEDIUM

Priority - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Aug 20, 2024
CVE-2024-25009
6.5 MEDIUM

Ericsson Packet Core Controller (PCC) contains a vulnerability in Access and Mobility Management Function (AMF) where improper input validation can lead to denial of service …

Aug 20, 2024
CVE-2024-7054
6.4 MEDIUM

The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Aug 20, 2024
CVE-2024-38808
4.3 MEDIUM

In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language …

Aug 20, 2024
CVE-2024-5576
6.4 MEDIUM

The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'course_carousel_skin' attribute within the plugin's Course Carousel widget in …

Aug 20, 2024
CVE-2024-6864
6.4 MEDIUM

The WP Last Modified Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘template’ attribute of the lmt-post-modified-info shortcode in all versions …

Aug 20, 2024
CVE-2024-7775
5.5 MEDIUM

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable …

Aug 20, 2024
CVE-2024-6575
6.4 MEDIUM

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Aug 20, 2024
CVE-2024-5763
6.4 MEDIUM

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Aug 20, 2024
CVE-2024-38810
6.5 MEDIUM

Missing Authorization When Using @AuthorizeReturnObject in Spring Security 6.3.0 and 6.3.1 allows attacker to render security annotations inaffective.

Aug 20, 2024
CVE-2024-7949
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Online Graduate Tracer System up to 1.0. Affected is an unknown function of the …

Aug 20, 2024
CVE-2024-7944
6.3 MEDIUM

A vulnerability was found in itsourcecode Laravel Property Management System 1.0. It has been classified as critical. Affected is the function UpdateDocumentsRequest of the file …

Aug 20, 2024
CVE-2024-7850
6.1 MEDIUM

The BP Profile Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.7.5. This is due to …

Aug 20, 2024
CVE-2024-5941
5.4 MEDIUM

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access and deletion of data due to a missing capability …

Aug 20, 2024
CVE-2024-5940
6.5 MEDIUM

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Aug 20, 2024
CVE-2024-5939
5.3 MEDIUM

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on …

Aug 20, 2024
CVE-2024-7943
6.3 MEDIUM

A vulnerability was found in itsourcecode Laravel Property Management System 1.0 and classified as critical. This issue affects the function upload of the file PropertiesController.php. …

Aug 20, 2024
CVE-2024-7937
6.3 MEDIUM

A vulnerability classified as critical was found in itsourcecode Project Expense Monitoring System 1.0. This vulnerability affects unknown code of the file printtransfer.php. The manipulation …

Aug 20, 2024
CVE-2024-7936
6.3 MEDIUM

A vulnerability classified as critical has been found in itsourcecode Project Expense Monitoring System 1.0. This affects an unknown part of the file transferred_report.php. The …

Aug 20, 2024
CVE-2024-7935
6.3 MEDIUM

A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Aug 19, 2024
CVE-2024-7934
6.3 MEDIUM

A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Aug 19, 2024
CVE-2024-7931
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0 and classified as critical. This issue affects some unknown processing of the file /tracking/admin/view_csprofile.php. …

Aug 19, 2024
CVE-2024-7930
6.3 MEDIUM

A vulnerability has been found in SourceCodester Clinics Patient Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /pms/ajax/get_packings.php. …

Aug 19, 2024
CVE-2024-7929
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in SourceCodester Simple Forum Website 1.0. This affects an unknown part of the file /registration.php of …

Aug 19, 2024
CVE-2024-7928
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in FastAdmin up to 1.3.3.20220121. Affected by this issue is some unknown functionality of the …

Aug 19, 2024
CVE-2024-35539
6.5 MEDIUM

Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerability allows attackers to post several comments before the …

Aug 19, 2024
CVE-2024-35538
5.3 MEDIUM

Typecho v1.3.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as …

Aug 19, 2024
CVE-2024-43326
5.4 MEDIUM

Missing Authorization vulnerability in Jamie Bergen Plugin Notes Plus allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Plugin Notes Plus: from n/a through …

Aug 19, 2024
CVE-2024-43317
4.3 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Metagauss User Registration Team RegistrationMagic allows Cross-Site Scripting (XSS).This issue affects …

Aug 19, 2024
CVE-2024-23729
6.1 MEDIUM

The ColorOS Internet Browser com.heytap.browser application 45.10.3.4.1 for Android allows a remote attacker to execute arbitrary JavaScript code via the com.android.browser.RealBrowserActivity component.

Aug 19, 2024
CVE-2024-7925
4.3 MEDIUM

A vulnerability was found in ZZCMS 2023. It has been rated as problematic. This issue affects some unknown processing of the file 3/E_bak5.1/upload/eginfo.php. The manipulation …

Aug 19, 2024
CVE-2024-7924
5.3 MEDIUM

A vulnerability was found in ZZCMS 2023. It has been declared as critical. This vulnerability affects unknown code of the file /I/list.php. The manipulation of …

Aug 19, 2024
CVE-2024-43281
5.3 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in VOID CODERS Void Elementor Post Grid Addon for Elementor Page builder allows …

Aug 19, 2024
CVE-2024-43280
4.7 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking system: from n/a through 10.8.1.

Aug 19, 2024
CVE-2024-43272
5.3 MEDIUM

Missing Authentication for Critical Function vulnerability in icegram Icegram allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Icegram: from n/a through 3.1.24.

Aug 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.