CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-4507
6.1 MEDIUM

The Admission AppManager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'q' parameter in versions up to, and including, 1.0.0 due to …

Aug 17, 2024
CVE-2023-4027
5.3 MEDIUM

The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_settings function in versions …

Aug 17, 2024
CVE-2023-4025
5.3 MEDIUM

The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_player function in versions …

Aug 17, 2024
CVE-2023-4024
5.3 MEDIUM

The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_player function in versions …

Aug 17, 2024
CVE-2023-1604
4.7 MEDIUM

The Short URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.8. This is due to missing or …

Aug 17, 2024
CVE-2022-4532
6.5 MEDIUM

The LOGIN AND REGISTRATION ATTEMPTS LIMIT plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1. This is due …

Aug 17, 2024
CVE-2024-43472
5.8 MEDIUM

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Aug 16, 2024
CVE-2024-43011
4.9 MEDIUM

An arbitrary file deletion vulnerability exists in the admin/del.php file at line 62 in ZZCMS 2023 and earlier. Due to insufficient validation and sanitization of …

Aug 16, 2024
CVE-2024-43009
4.7 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in user/login.php at line 24 in ZZCMS 2023 and earlier. The application directly inserts the value of the …

Aug 16, 2024
CVE-2024-43006
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in ZZCMS2023 in the ask/show.php file at line 21. An attacker can exploit this vulnerability by sending a …

Aug 16, 2024
CVE-2024-43005
4.7 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the component dl_liuyan_save.php of ZZCMS v2023 allows attackers to execute arbitrary code in the context of a user's …

Aug 16, 2024
CVE-2023-47728
6.5 MEDIUM

IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a remote attacker to obtain sensitive information …

Aug 16, 2024
CVE-2024-42849
6.5 MEDIUM

An issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function.

Aug 16, 2024
CVE-2024-42758
5.4 MEDIUM

A Cross-site Scripting (XSS) vulnerability exists in version v2024-01-05 of the indexmenu plugin when is used and enabled in Dokuwiki (Open Source Wiki Engine). A …

Aug 16, 2024
CVE-2024-25837
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in October CMS Bloghub Plugin v1.3.8 and lower allows attackers to execute arbitrary web scripts or HTML via a …

Aug 16, 2024
CVE-2024-6098
5.3 MEDIUM

When performing an online tag generation to devices which communicate using the ControlLogix protocol, a machine-in-the-middle, or a device that is not configured correctly, could …

Aug 16, 2024
CVE-2024-6004
6.5 MEDIUM

A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to deny printer connections until the …

Aug 16, 2024
CVE-2024-5210
6.5 MEDIUM

A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to prevent printer services from being …

Aug 16, 2024
CVE-2024-5209
6.5 MEDIUM

A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to deny printing capabilities until the …

Aug 16, 2024
CVE-2024-4782
6.5 MEDIUM

A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to disrupt the printer's functionality until …

Aug 16, 2024
CVE-2024-4781
6.5 MEDIUM

A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to crash printer communications until the …

Aug 16, 2024
CVE-2024-43810
4.6 MEDIUM

In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin

Aug 16, 2024
CVE-2024-43807
4.6 MEDIUM

In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page

Aug 16, 2024
CVE-2024-43381
5.0 MEDIUM

reNgine is an automated reconnaissance framework for web applications. Versions 2.1.2 and prior are susceptible to Stored Cross-Site Scripting (XSS) attacks. This vulnerability occurs when …

Aug 16, 2024
CVE-2024-42486
5.4 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In versions on the 1.15.x branch prior to 1.15.8 and the 1.16.x branch …

Aug 16, 2024
CVE-2024-7144
6.4 MEDIUM

The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'slide_id' parameters in all versions up to, and including, 2.6.20 …

Aug 16, 2024
CVE-2024-42464
6.5 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Utilizing REST's Trust in the System Resource to Obtain Sensitive Data.This issue …

Aug 16, 2024
CVE-2024-42463
6.5 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Utilizing REST's Trust in the System Resource to Obtain Sensitive Data.This issue …

Aug 16, 2024
CVE-2024-7147
6.4 MEDIUM

The JetBlocks for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple placeholder parameters in all versions up to, and including, 1.3.12 …

Aug 16, 2024
CVE-2024-7136
6.4 MEDIUM

The JetSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 3.5.2 due to …

Aug 16, 2024
CVE-2024-25008
6.8 MEDIUM

Ericsson RAN Compute and Site Controller 6610 contains a vulnerability in the Control System where Improper Input Validation can lead to arbitrary code execution, for …

Aug 16, 2024
CVE-2024-7501
4.2 MEDIUM

The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Aug 16, 2024
CVE-2024-7422
4.3 MEDIUM

The Theme My Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.1.7. This is due to …

Aug 16, 2024
CVE-2024-7630
5.3 MEDIUM

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.22.2 (Free) and 2.25.1 …

Aug 16, 2024
CVE-2023-7049
4.3 MEDIUM

The Custom Field For WP Job Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2 …

Aug 16, 2024
CVE-2022-3399
4.4 MEDIUM

The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cookie_notice_options[refuse_code_head]' parameter in versions up …

Aug 16, 2024
CVE-2024-7853
6.3 MEDIUM

A vulnerability was found in SourceCodester Yoga Class Registration System up to 1.0. It has been classified as critical. Affected is an unknown function of …

Aug 16, 2024
CVE-2024-7851
6.3 MEDIUM

A vulnerability has been found in SourceCodester Yoga Class Registration System 1.0 and classified as critical. This vulnerability affects unknown code of the file /classes/Users.php?f=save …

Aug 16, 2024
CVE-2024-7845
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Aug 16, 2024
CVE-2024-43374
4.5 MEDIUM

The UNIX editor Vim prior to version 9.1.0678 has a use-after-free error in argument list handling. When adding a new file to the argument list, …

Aug 16, 2024
CVE-2024-7843
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0. Affected is an unknown function of the file /tracking/admin/exportcs.php. …

Aug 15, 2024
CVE-2024-7842
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in SourceCodester Online Graduate Tracer System 1.0. This issue affects some unknown processing of the …

Aug 15, 2024
CVE-2024-7841
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Clinics Patient Management System 1.0. This vulnerability affects unknown code of the file /pms/ajax/check_user_name.php. The manipulation …

Aug 15, 2024
CVE-2024-34742
5.5 MEDIUM

In shouldWrite of OwnersData.java, there is a possible edge case that prevents MDM policies from being persisted due to a logic error in the code. …

Aug 15, 2024
CVE-2024-42488
6.8 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.14.14 and 1.15.8, a race condition in the Cilium agent …

Aug 15, 2024
CVE-2024-42487
4.0 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In the 1.15 branch prior to 1.15.8 and the 1.16 branch prior to …

Aug 15, 2024
CVE-2024-7867
6.2 MEDIUM

In Xpdf 4.05 (and earlier), very large coordinates in a page box can cause an integer overflow and divide-by-zero.

Aug 15, 2024
CVE-2024-7866
5.5 MEDIUM

In Xpdf 4.05 (and earlier), a PDF object loop in a pattern resource leads to infinite recursion and a stack overflow.

Aug 15, 2024
CVE-2024-42476
6.5 MEDIUM

In the OAuth library for nim prior to version 0.11, the Authorization Code grant and Implicit grant both rely on the `state` parameter to prevent …

Aug 15, 2024
CVE-2024-42475
6.5 MEDIUM

In the OAuth library for nim prior to version 0.11, the `state` values generated by the `generateState` function do not have sufficient entropy. These can …

Aug 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.