CVE Database

59325+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10250
6.1 MEDIUM

The Nioland theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter in all versions up to, and including, 1.2.6 due to …

Oct 23, 2024
CVE-2024-10041
4.7 MEDIUM

A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending …

Oct 23, 2024
CVE-2024-10279
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. This vulnerability affects unknown code of the file /com/esafenet/servlet/policy/PrintPolicyService.java. The manipulation …

Oct 23, 2024
CVE-2024-10278
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. This affects an unknown part of the file /com/esafenet/servlet/user/ReUserOrganiseService.java. The manipulation …

Oct 23, 2024
CVE-2024-10289
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability affecting LocalServer 1.0.9 that could allow a remote user to send a specially crafted query to an authenticated user and steal …

Oct 23, 2024
CVE-2024-10288
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability affecting LocalServer 1.0.9 that could allow a remote user to send a specially crafted query to an authenticated user and steal …

Oct 23, 2024
CVE-2024-10287
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability affecting LocalServer 1.0.9 that could allow a remote user to send a specially crafted query to an authenticated user and steal …

Oct 23, 2024
CVE-2024-10286
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability affecting LocalServer 1.0.9 that could allow a remote user to send a specially crafted query to an authenticated user and steal …

Oct 23, 2024
CVE-2024-10277
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5 and classified as critical. Affected by this issue is some unknown functionality of the file /com/esafenet/servlet/ajax/UsbKeyAjax.java. The …

Oct 23, 2024
CVE-2024-8500
5.4 MEDIUM

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, …

Oct 23, 2024
CVE-2023-50310
4.9 MEDIUM

IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized …

Oct 23, 2024
CVE-2024-9530
4.3 MEDIUM

The Qi Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.0 via private templates. …

Oct 23, 2024
CVE-2024-43924
5.3 MEDIUM

Missing Authorization vulnerability in dFactory Responsive Lightbox allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Responsive Lightbox: from n/a through 2.4.7.

Oct 23, 2024
CVE-2024-10045
4.3 MEDIUM

The Transients Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.6. This is due to missing …

Oct 23, 2024
CVE-2024-9583
4.3 MEDIUM

The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized use of functionality due to …

Oct 23, 2024
CVE-2024-9829
6.5 MEDIUM

The Download Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the 'dpwap_handle_download_user' and 'dpwap_handle_download_comment' functions …

Oct 23, 2024
CVE-2024-31880
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service, under specific configurations, …

Oct 23, 2024
CVE-2024-48656
4.8 MEDIUM

Cross Site Scripting vulnerability in student management system in php with source code v.1.0.0 allows a remote attacker to execute arbitrary code.

Oct 22, 2024
CVE-2024-48652
4.8 MEDIUM

Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows remote attacker to execute arbitrary code via the content group name field.

Oct 22, 2024
CVE-2024-48644
5.3 MEDIUM

Accounts enumeration vulnerability in the Login Component of Reolink Duo 2 WiFi Camera (Firmware Version v3.0.0.1889_23031701) allows remote attackers to determine valid user accounts via …

Oct 22, 2024
CVE-2024-48415
5.0 MEDIUM

itsourcecode Loan Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the lastname, firstname, middlename, address, contact_no, email and …

Oct 22, 2024
CVE-2024-45526
5.3 MEDIUM

An issue was discovered in OPC Foundation OPCFoundation/UA-.NETStandard through 1.5.374.78. A remote attacker can send requests with invalid credentials and cause the server performance to …

Oct 22, 2024
CVE-2024-46903
6.5 MEDIUM

A vulnerability in Trend Micro Deep Discovery Inspector (DDI) versions 5.8 and above could allow an attacker to disclose sensitive information affected installations. Please note: …

Oct 22, 2024
CVE-2024-49211
5.2 MEDIUM

Reflected XSS was discovered in a Dashboard Listing Archer Platform UX page in Archer Platform 6.x before version 2024.08. A remote unauthenticated attacker could potentially …

Oct 22, 2024
CVE-2024-49210
5.2 MEDIUM

Reflected XSS was discovered in an iView List Archer Platform UX page in Archer Platform 6.x before version 2024.09. A remote unauthenticated attacker could potentially …

Oct 22, 2024
CVE-2024-49209
6.5 MEDIUM

Archer Platform 2024.03 before version 2024.09 is affected by an API authorization bypass vulnerability related to supporting application files. A remote unprivileged attacker could potentially …

Oct 22, 2024
CVE-2024-49208
5.9 MEDIUM

Archer Platform 2024.03 before version 2024.08 is affected by an authorization bypass vulnerability related to supporting application files. A remote unprivileged attacker could potentially exploit …

Oct 22, 2024
CVE-2024-48708
5.4 MEDIUM

Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action = add/edit and in (b) file admin.php …

Oct 22, 2024
CVE-2024-48707
5.4 MEDIUM

Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under (a) action=add or action=edit within managemilestone.php file and (b) action=addpro within admin.php …

Oct 22, 2024
CVE-2024-48706
5.4 MEDIUM

Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform within the (a) managemessage.php file and (b) managetask.php file …

Oct 22, 2024
CVE-2024-46538
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $pconfig …

Oct 22, 2024
CVE-2024-49373
4.1 MEDIUM

No Fuss Computing Centurion ERP is open source enterprise resource planning (ERP) software. Prior to version 1.2.1, an authenticated user can view projects within organizations …

Oct 22, 2024
CVE-2024-48929
4.2 MEDIUM

Umbraco is a free and open source .NET content management system. In versions on the 13.x branch prior to 13.5.2 and versions on the 10.x …

Oct 22, 2024
CVE-2024-48927
4.6 MEDIUM

Umbraco, a free and open source .NET content management system, has a remote code execution issue in versions on the 13.x branch prior to 13.5.2, …

Oct 22, 2024
CVE-2024-48926
4.2 MEDIUM

Umbraco, a free and open source .NET content management system, has an insufficient session expiration issue in versions on the 13.x branch prior to 13.5.2, …

Oct 22, 2024
CVE-2024-47819
4.2 MEDIUM

Umbraco, a free and open source .NET content management system, has a cross-site scripting vulnerability starting in version 14.0.0 and prior to versions 14.3.1 and …

Oct 22, 2024
CVE-2024-46240
4.8 MEDIUM

Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under action=system and the company/contact parameters under action=addcust within admin.php file.

Oct 22, 2024
CVE-2022-23861
5.4 MEDIUM

Multiple Stored Cross-Site Scripting vulnerabilities were discovered in Y Soft SAFEQ 6 Build 53. Multiple fields in the YSoft SafeQ web application can be used …

Oct 22, 2024
CVE-2024-43177
5.9 MEDIUM

IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.

Oct 22, 2024
CVE-2024-50312
5.3 MEDIUM

A vulnerability was found in GraphQL due to improper access controls on the GraphQL introspection query. This flaw allows unauthorized users to retrieve a comprehensive …

Oct 22, 2024
CVE-2024-50311
6.5 MEDIUM

A denial of service (DoS) vulnerability was found in OpenShift. This flaw allows attackers to exploit the GraphQL batching functionality. The vulnerability arises when multiple …

Oct 22, 2024
CVE-2024-10234
6.1 MEDIUM

A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or insider …

Oct 22, 2024
CVE-2024-9231
6.1 MEDIUM

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Oct 22, 2024
CVE-2024-10189
6.4 MEDIUM

The Anchor Episodes Index (Spotify for Podcasters) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's anchor_episodes shortcode in all versions up …

Oct 22, 2024
CVE-2024-9591
5.5 MEDIUM

The Category and Taxonomy Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_category_image' parameter in versions up to, and including, 1.0.0 …

Oct 22, 2024
CVE-2024-9590
5.5 MEDIUM

The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image meta field value in the 'wpaft_add_meta_textinput' function …

Oct 22, 2024
CVE-2024-9589
5.5 MEDIUM

The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_meta_name' parameter in the 'wpaft_option_page' function in versions …

Oct 22, 2024
CVE-2024-9588
5.4 MEDIUM

The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.0. This is due …

Oct 22, 2024
CVE-2024-9541
4.3 MEDIUM

The News Kit Elementor Addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.1 via the render …

Oct 22, 2024
CVE-2023-52919
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix possible NULL pointer dereference in send_acknowledge() Handle memory allocation failure from nci_skb_alloc() …

Oct 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.