CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-1231
6.8 MEDIUM

The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins …

Mar 25, 2024
CVE-2023-37886
5.4 MEDIUM

Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2.

Mar 25, 2024
CVE-2023-37885
4.3 MEDIUM

Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2.

Mar 25, 2024
CVE-2023-33923
4.3 MEDIUM

Missing Authorization vulnerability in HashThemes Viral News, HashThemes Viral, HashThemes HashOne.This issue affects Viral News: from n/a through 1.4.5; Viral: from n/a through 1.8.0; HashOne: …

Mar 25, 2024
CVE-2023-30480
4.3 MEDIUM

Missing Authorization vulnerability in Sparkle WP Educenter.This issue affects Educenter: from n/a through 1.5.5.

Mar 25, 2024
CVE-2024-29034
6.8 MEDIUM

CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. The vulnerability CVE-2023-49090 wasn't fully addressed. This vulnerability is caused …

Mar 24, 2024
CVE-2020-36825
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** ** DISPUTED ** A vulnerability has been found in cyberaz0r WebRAT up to 20191222 and classified as critical. This vulnerability …

Mar 24, 2024
CVE-2024-2854
6.3 MEDIUM

A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. Affected is the function formSetSambaConf of the file /goform/setsambacfg. The manipulation of the …

Mar 24, 2024
CVE-2024-2853
6.3 MEDIUM

A vulnerability was found in Tenda AC10U 15.03.06.48/15.03.06.49. It has been rated as critical. This issue affects the function formSetSambaConf of the file /goform/setsambacfg. The …

Mar 24, 2024
CVE-2024-2851
6.3 MEDIUM

A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. It has been classified as critical. This affects the function formSetSambaConf of the file /goform/setsambacfg. The manipulation …

Mar 24, 2024
CVE-2024-30161
6.5 MEDIUM

In Qt 6.5.4, 6.5.5, and 6.6.2, QNetworkReply header data might be accessed via a dangling pointer in Qt for WebAssembly (wasm). (Earlier and later versions …

Mar 24, 2024
CVE-2020-36827
5.4 MEDIUM

The XAO::Web module before 1.84 for Perl mishandles < and > characters in JSON output during use of json-embed in Web::Action.

Mar 24, 2024
CVE-2018-25100
5.3 MEDIUM

The Mojolicious module before 7.66 for Perl may leak cookies in certain situations related to multiple similar cookies for the same domain. This affects Mojo::UserAgent::CookieJar.

Mar 24, 2024
CVE-2024-2849
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Simple File Manager 1.0. This vulnerability affects unknown code. The manipulation of the argument photo leads …

Mar 23, 2024
CVE-2024-24840
4.3 MEDIUM

Missing Authorization vulnerability in BdThemes Element Pack Elementor Addons.This issue affects Element Pack Elementor Addons: from n/a through 5.4.11.

Mar 23, 2024
CVE-2024-24835
4.3 MEDIUM

Missing Authorization vulnerability in realmag777 BEAR.This issue affects BEAR: from n/a through 1.1.4.

Mar 23, 2024
CVE-2024-2326
4.3 MEDIUM

The Pretty Links – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions …

Mar 23, 2024
CVE-2024-1049
6.4 MEDIUM

The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon Widget's in all versions up …

Mar 23, 2024
CVE-2024-2688
5.4 MEDIUM

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress …

Mar 23, 2024
CVE-2024-2468
6.4 MEDIUM

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress …

Mar 23, 2024
CVE-2024-2202
6.4 MEDIUM

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the legacy Image widget in all versions up to, and …

Mar 23, 2024
CVE-2024-2131
6.4 MEDIUM

The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's infobox and button widget in all versions up …

Mar 23, 2024
CVE-2024-1697
6.4 MEDIUM

The Custom WooCommerce Checkout Fields Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the save_wcfe_options function in all versions up to, and …

Mar 23, 2024
CVE-2024-29057
4.3 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Mar 22, 2024
CVE-2024-26247
4.7 MEDIUM

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Mar 22, 2024
CVE-2024-2828
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in lakernote EasyAdmin up to 20240315. Affected is the function thumbnail of the file src/main/java/com/laker/admin/module/sys/controller/IndexController.java. The …

Mar 22, 2024
CVE-2024-2827
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in lakernote EasyAdmin up to 20240315. This issue affects some unknown processing of the file …

Mar 22, 2024
CVE-2024-2826
6.3 MEDIUM

A vulnerability classified as problematic was found in lakernote EasyAdmin up to 20240315. This vulnerability affects unknown code of the file /ureport/designer/saveReportFile. The manipulation leads …

Mar 22, 2024
CVE-2024-2825
6.3 MEDIUM

A vulnerability classified as critical has been found in lakernote EasyAdmin up to 20240315. This affects an unknown part of the file /ureport/designer/saveReportFile. The manipulation …

Mar 22, 2024
CVE-2024-2824
6.3 MEDIUM

A vulnerability was found in Matthias-Wandel jhead 3.08 and classified as critical. This issue affects the function PrintFormatNumber of the file exif.c. The manipulation leads …

Mar 22, 2024
CVE-2023-4063
5.3 MEDIUM

Certain HP OfficeJet Pro printers are potentially vulnerable to a Denial of Service when using an improper eSCL URL GET request.

Mar 22, 2024
CVE-2024-2823
4.3 MEDIUM

A vulnerability has been found in DedeCMS 5.7 and classified as problematic. This vulnerability affects unknown code of the file /src/dede/mda_main.php. The manipulation leads to …

Mar 22, 2024
CVE-2024-2822
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in DedeCMS 5.7. This affects an unknown part of the file /src/dede/vote_edit.php. The manipulation of the …

Mar 22, 2024
CVE-2024-29186
5.3 MEDIUM

Bref is an open-source project that helps users go serverless on Amazon Web Services with PHP. When Bref prior to version 2.1.17 is used with …

Mar 22, 2024
CVE-2024-29042
5.3 MEDIUM

Translate is a package that allows users to convert text to different languages on Node.js and the browser. Prior to version 3.0.0, an attacker controlling …

Mar 22, 2024
CVE-2024-2821
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7. Affected by this issue is some unknown functionality of the file /src/dede/friendlink_edit.php. …

Mar 22, 2024
CVE-2024-2820
4.3 MEDIUM

A vulnerability classified as problematic was found in DedeCMS 5.7. Affected by this vulnerability is an unknown functionality of the file /src/dede/baidunews.php. The manipulation of …

Mar 22, 2024
CVE-2022-32754
4.8 MEDIUM

IBM Security Verify Directory 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …

Mar 22, 2024
CVE-2022-32753
4.5 MEDIUM

IBM Security Verify Directory 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 228444.

Mar 22, 2024
CVE-2022-32751
5.3 MEDIUM

IBM Security Verify Directory 10.0.0 could disclose sensitive server information that could be used in further attacks against the system. IBM X-Force ID: 228437.

Mar 22, 2024
CVE-2024-29865
5.4 MEDIUM

Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form.

Mar 22, 2024
CVE-2024-28593
5.4 MEDIUM

The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to …

Mar 22, 2024
CVE-2024-2728
4.1 MEDIUM

Information exposure vulnerability in the CIGESv2 system. This vulnerability could allow a local attacker to intercept traffic due to the lack of proper implementation of …

Mar 22, 2024
CVE-2024-2727
6.1 MEDIUM

HTML injection vulnerability affecting the CIGESv2 system, which allows an attacker to inject arbitrary code and modify elements of the website and email confirmation message.

Mar 22, 2024
CVE-2024-2726
6.1 MEDIUM

Stored Cross-Site Scripting (Stored-XSS) vulnerability affecting the CIGESv2 system, allowing an attacker to execute and store malicious javascript code in the application form without prior …

Mar 22, 2024
CVE-2024-28560
5.4 MEDIUM

SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the deleteArea() function of the Address.php component.

Mar 22, 2024
CVE-2024-25168
6.3 MEDIUM

SQL injection vulnerability in snow snow v.2.0.0 allows a remote attacker to execute arbitrary code via the dataScope parameter of the system/role/list interface.

Mar 22, 2024
CVE-2024-2817
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Tenda AC15 15.03.05.18. Affected by this issue is the function fromSysToolRestoreSet of the file …

Mar 22, 2024
CVE-2024-2816
4.3 MEDIUM

A vulnerability classified as problematic was found in Tenda AC15 15.03.05.18. Affected by this vulnerability is the function fromSysToolReboot of the file /goform/SysToolReboot. The manipulation …

Mar 22, 2024
CVE-2024-2812
6.3 MEDIUM

A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. It has been classified as critical. This affects the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation …

Mar 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.