CVE Database

59325+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-46605
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /admin.php?page=album of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Oct 16, 2024
CVE-2024-45072
5.5 MEDIUM

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A privileged user could …

Oct 16, 2024
CVE-2024-45071
5.5 MEDIUM

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in …

Oct 16, 2024
CVE-2024-20512
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) could allow an unauthenticated, remote attacker to conduct a …

Oct 16, 2024
CVE-2024-20463
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to modify the …

Oct 16, 2024
CVE-2024-20462
5.5 MEDIUM

A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter firmware could allow an authenticated, local attacker with low …

Oct 16, 2024
CVE-2024-20461
6.0 MEDIUM

A vulnerability in the CLI of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an authenticated, local attacker with high privileges to execute arbitrary …

Oct 16, 2024
CVE-2024-20460
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to conduct a …

Oct 16, 2024
CVE-2024-20459
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco ATA 190 Multiplatform Series Analog Telephone Adapter firmware could allow an authenticated, remote attacker with high …

Oct 16, 2024
CVE-2024-20420
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an authenticated, remote attacker with low privileges …

Oct 16, 2024
CVE-2024-20280
6.3 MEDIUM

A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information …

Oct 16, 2024
CVE-2024-10033
6.1 MEDIUM

A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious user to perform actions …

Oct 16, 2024
CVE-2024-49265
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SPBooking.com Booking.com Banner Creator bookingcom-banner-creator.This issue affects Booking.com Banner Creator: from n/a through …

Oct 16, 2024
CVE-2024-29155
4.3 MEDIUM

On Microchip RN4870 devices, when more than one consecutive PairReqNoInputNoOutput request is received, the device becomes incapable of completing the pairing process. A third party …

Oct 16, 2024
CVE-2024-49267
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nayon46 Unlimited Addon For Elementor unlimited-addon-for-elementor allows Stored XSS.This issue affects Unlimited Addon …

Oct 16, 2024
CVE-2024-49266
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thimo Grauerholz WP-Spreadplugin wp-spreadplugin allows Cross-Site Scripting (XSS).This issue affects WP-Spreadplugin: from n/a …

Oct 16, 2024
CVE-2024-48744
6.1 MEDIUM

A Reflected Cross Site Scripting (XSS) vulnerability was found in /trms/listed- teachers.php in PHPGurukul Teachers Record Management System v2.1, which allows remote attackers to execute …

Oct 16, 2024
CVE-2024-47139
6.8 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the Administrator role to …

Oct 16, 2024
CVE-2024-49270
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Smart Blocks smart-blocks allows Stored XSS.This issue affects Smart Blocks: from n/a …

Oct 16, 2024
CVE-2024-49258
6.5 MEDIUM

Path Traversal: '.../...//' vulnerability in Limbcode WordPress Gallery Plugin – Limb Image Gallery limb-gallery.This issue affects WordPress Gallery Plugin – Limb Image Gallery: from n/a …

Oct 16, 2024
CVE-2024-49252
5.3 MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in VaultDweller Leyka leyka.This issue affects Leyka: from n/a through <= 3.31.6.

Oct 16, 2024
CVE-2024-22034
5.5 MEDIUM

Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc …

Oct 16, 2024
CVE-2024-22033
6.3 MEDIUM

The OBS service obs-service-download_url was vulnerable to a command injection vulnerability. The attacker could provide a configuration to the service that allowed to execute command …

Oct 16, 2024
CVE-2024-22032
6.5 MEDIUM

A vulnerability has been identified in which an RKE1 cluster keeps constantly reconciling when secrets encryption configuration is enabled. When reconciling, the Kube API secret …

Oct 16, 2024
CVE-2023-32189
5.9 MEDIUM

Insecure handling of ssh keys used to bootstrap clients allows local attackers to potentially gain access to the keys

Oct 16, 2024
CVE-2024-10024
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Pharmacy Management System 1.0. This issue affects some unknown processing of the file …

Oct 16, 2024
CVE-2024-10023
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Pharmacy Management System 1.0. This vulnerability affects unknown code of the file /php/add_new_medicine.php. The manipulation of …

Oct 16, 2024
CVE-2023-32196
6.6 MEDIUM

A vulnerability has been identified whereby privilege escalation checks are not properly enforced for RoleTemplateobjects when external=true, which in specific scenarios can lead to privilege …

Oct 16, 2024
CVE-2020-36841
5.3 MEDIUM

The WooCommerce Smart Coupons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the woocommerce_coupon_admin_init function in versions up …

Oct 16, 2024
CVE-2024-10022
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. This affects an unknown part of the file /php/manage_supplier.php?action=search. The manipulation …

Oct 16, 2024
CVE-2024-10021
6.3 MEDIUM

A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Oct 16, 2024
CVE-2024-8921
6.4 MEDIUM

The Zita Elementor Site Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Oct 16, 2024
CVE-2024-9444
6.4 MEDIUM

The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Oct 16, 2024
CVE-2024-9540
4.3 MEDIUM

The Sina Extension for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.7 via the render …

Oct 16, 2024
CVE-2024-45714
4.8 MEDIUM

Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a variable with a payload.

Oct 16, 2024
CVE-2024-45462
6.3 MEDIUM

The logout operation in the CloudStack web interface does not expire the user session completely which is valid until expiry by time or restart of …

Oct 16, 2024
CVE-2024-45461
5.7 MEDIUM

The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources, and is disabled by default. In environments …

Oct 16, 2024
CVE-2023-7296
6.4 MEDIUM

The BigBlueButton plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the moderator code and viewer code fields in versions up to, and …

Oct 16, 2024
CVE-2023-7295
6.1 MEDIUM

The Video Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.21 due to …

Oct 16, 2024
CVE-2017-20194
5.3 MEDIUM

The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. …

Oct 16, 2024
CVE-2017-20193
4.7 MEDIUM

The Product Vendors is vulnerable to Reflected Cross-Site Scripting via the 'vendor_description' parameter in versions up to, and including, 2.0.35 due to insufficient input sanitization …

Oct 16, 2024
CVE-2024-9582
6.4 MEDIUM

The Accordion Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ attribute of an accordion slider in all versions up to, …

Oct 16, 2024
CVE-2023-7293
4.3 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the …

Oct 16, 2024
CVE-2023-7292
4.3 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized notification dismissal due to a missing capability check on the paytium_notice_dismiss …

Oct 16, 2024
CVE-2023-7290
4.3 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the …

Oct 16, 2024
CVE-2023-7289
5.4 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized API key update due to a missing capability check on the …

Oct 16, 2024
CVE-2023-7288
5.4 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_profile_preference …

Oct 16, 2024
CVE-2023-7287
5.4 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized subscription cancellation due to a missing capability check on the pt_cancel_subscription …

Oct 16, 2024
CVE-2023-7286
6.5 MEDIUM

The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.2.2. This makes it …

Oct 16, 2024
CVE-2022-4974
6.3 MEDIUM

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing …

Oct 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.