CVE Database

59325+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9141
5.4 MEDIUM

Cross-Site Scripting (XSS) vulnerability in the Oct8ne system. This flaw could allow an attacker to embed harmful JavaScript code into the body of a chat …

Sep 25, 2024
CVE-2024-8942
6.3 MEDIUM

Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input validation, affecting the “id_form_msg_title” parameter, among others. …

Sep 25, 2024
CVE-2024-8919
6.4 MEDIUM

The Confetti Fall Animation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'confetti-fall-animation' shortcode in all versions up to, and including, …

Sep 25, 2024
CVE-2024-8917
6.4 MEDIUM

The AnWP Football Leagues plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.16.7 …

Sep 25, 2024
CVE-2024-8801
4.3 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.2 via the Content …

Sep 25, 2024
CVE-2024-8437
4.3 MEDIUM

The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions …

Sep 25, 2024
CVE-2024-8291
4.8 MEDIUM

Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in Image Editor Background Color. A rogue admin could add malicious …

Sep 25, 2024
CVE-2024-8267
6.4 MEDIUM

The Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Sep 25, 2024
CVE-2024-8103
6.4 MEDIUM

The WP Category Dropdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' parameter in all versions up to, and including, 1.8 …

Sep 25, 2024
CVE-2024-7398
5.4 MEDIUM

Concrete CMS versions 9 through 9.3.3 and versions below 8.5.19 are vulnerable to stored XSS in the calendar event addition feature because the calendar event …

Sep 25, 2024
CVE-2024-47048
5.4 MEDIUM

Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier allows stored XSS in the description and release notes of the marketplace and private apps.

Sep 25, 2024
CVE-2024-46934
6.1 MEDIUM

Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to DOM-based Cross-site Scripting (XSS). Attackers may be able to abuse the UpdateOTRAck method …

Sep 25, 2024
CVE-2024-38324
5.9 MEDIUM

IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registration and unregistration operations which could expose sensitive information to …

Sep 25, 2024
CVE-2023-26688
5.4 MEDIUM

Cross Site Scripting (XSS) vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the product_data parameter of add/edit product in the …

Sep 25, 2024
CVE-2024-8794
5.3 MEDIUM

The BA Book Everything plugin for WordPress is vulnerable to arbitrary password reset in all versions up to, and including, 1.6.20. This is due to …

Sep 24, 2024
CVE-2024-8628
5.4 MEDIUM

The Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's …

Sep 24, 2024
CVE-2024-8738
6.1 MEDIUM

The Seriously Simple Stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Sep 24, 2024
CVE-2024-8716
6.1 MEDIUM

The XT Ajax Add To Cart for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate …

Sep 24, 2024
CVE-2024-8662
6.1 MEDIUM

The Koko Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in …

Sep 24, 2024
CVE-2024-8657
6.4 MEDIUM

The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ggpkg shortcode in all versions up to, and including, …

Sep 24, 2024
CVE-2024-8544
6.1 MEDIUM

The Pixel Cat – Conversion Pixel Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping …

Sep 24, 2024
CVE-2024-8432
4.3 MEDIUM

The Appointment & Event Booking Calendar Plugin – Webba Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Sep 24, 2024
CVE-2024-38269
4.9 MEDIUM

An improper restriction of operations within the bounds of a memory buffer in the USB file-sharing handler of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 …

Sep 24, 2024
CVE-2024-38268
4.9 MEDIUM

An improper restriction of operations within the bounds of a memory buffer in the MAC address parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 …

Sep 24, 2024
CVE-2024-38267
4.9 MEDIUM

An improper restriction of operations within the bounds of a memory buffer in the IPv6 address parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 …

Sep 24, 2024
CVE-2024-38266
4.9 MEDIUM

An improper restriction of operations within the bounds of a memory buffer in the parameter type parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 …

Sep 24, 2024
CVE-2024-7022
4.3 MEDIUM

Uninitialized Use in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML …

Sep 23, 2024
CVE-2024-7020
4.3 MEDIUM

Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Sep 23, 2024
CVE-2024-7019
4.3 MEDIUM

Inappropriate implementation in UI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Sep 23, 2024
CVE-2023-7282
4.3 MEDIUM

Inappropriate implementation in Navigation in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Sep 23, 2024
CVE-2023-7281
4.3 MEDIUM

Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Sep 23, 2024
CVE-2024-8770
6.1 MEDIUM

A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attackers to steal sensitive user information via …

Sep 23, 2024
CVE-2024-44540
6.6 MEDIUM

Ubiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command shell via the UART Debugging Port.

Sep 23, 2024
CVE-2024-39843
6.7 MEDIUM

A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via create user form inputs.

Sep 23, 2024
CVE-2024-39342
6.6 MEDIUM

Entrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier uses a DLL library (i.e. DCG.Security.dll) with a custom …

Sep 23, 2024
CVE-2024-39341
5.9 MEDIUM

Entrust Instant Financial Issuance (On Premise) Software (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier leaves behind a configuration file (i.e. …

Sep 23, 2024
CVE-2023-46948
5.4 MEDIUM

A reflected Cross-Site Scripting (XSS) vulnerability was found on Temenos T24 Browser R19.40 that enables a remote attacker to execute arbitrary JavaScript code via the …

Sep 23, 2024
CVE-2024-40441
6.6 MEDIUM

An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 …

Sep 23, 2024
CVE-2024-47069
6.1 MEDIUM

Oveleon Cookie Bar is a cookie bar is for the Contao Open Source CMS and allows a visitor to define cookie & privacy settings for …

Sep 23, 2024
CVE-2024-47068
6.1 MEDIUM

Rollup is a module bundler for JavaScript. Versions prior to 2.79.2, 3.29.5, and 4.22.4 are susceptible to a DOM Clobbering vulnerability when bundling scripts with …

Sep 23, 2024
CVE-2024-23972
6.8 MEDIUM

Sony XAV-AX5500 USB Configuration Descriptor Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of …

Sep 23, 2024
CVE-2024-23933
6.8 MEDIUM

Sony XAV-AX5500 CarPlay TLV Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of …

Sep 23, 2024
CVE-2024-23922
6.8 MEDIUM

Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Sony …

Sep 23, 2024
CVE-2024-46241
5.9 MEDIUM

PHPGurukul Dairy Farm Shop Management System v1.1 is vulnerable to Cross-Site Scripting (XSS) via the pname parameter in add_product.php and edit_product.php.

Sep 23, 2024
CVE-2024-46544
5.9 MEDIUM

Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration which may lead to information …

Sep 23, 2024
CVE-2022-48945
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: vivid: fix compose size exceed boundary syzkaller found a bug: BUG: unable to handle …

Sep 23, 2024
CVE-2024-8903
4.7 MEDIUM

Local active protection service settings manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows, macOS) before build …

Sep 23, 2024
CVE-2024-45348
6.4 MEDIUM

Xiaomi Router AX9000 has a post-authorization command injection vulnerability. This vulnerability is caused by the lack of validation of user input, and an attacker can …

Sep 23, 2024
CVE-2024-8758
4.8 MEDIUM

The Quiz and Survey Master (QSM) WordPress plugin before 9.1.3 does not sanitise and escape some of its settings, which could allow high privilege users …

Sep 23, 2024
CVE-2024-7846
5.4 MEDIUM

YITH WooCommerce Ajax Search is vulnerable to a XSS vulnerability due to insufficient sanitization of user supplied block attributes. This makes it possible for Contributors+ …

Sep 23, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.