CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-29273
6.1 MEDIUM

There is Stored Cross-Site Scripting (XSS) in dzzoffice 2.02.1 SC UTF8 in uploadfile to index.php, with the XSS payload in an SVG document.

Mar 22, 2024
CVE-2024-29272
6.5 MEDIUM

Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and obtain sensitive information via the sanitizeFileName parameter …

Mar 22, 2024
CVE-2024-29271
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) vulnerability in VvvebJs before version 1.7.7, allows remote attackers to execute arbitrary code and obtain sensitive information via the action parameter …

Mar 22, 2024
CVE-2024-26557
5.4 MEDIUM

Codiad v2.8.4 allows reflected XSS via the components/market/dialog.php type parameter.

Mar 22, 2024
CVE-2024-25807
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Lychee 3.1.6, allows remote attackers to execute arbitrary code and obtain sensitive information via the title parameter when creating …

Mar 22, 2024
CVE-2024-2500
6.4 MEDIUM

The ColorMag theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.1.6 due …

Mar 22, 2024
CVE-2024-2392
6.4 MEDIUM

The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Newsletter widget in all versions up to, and including, 2.0.31 …

Mar 22, 2024
CVE-2024-2080
4.3 MEDIUM

The LiquidPoll – Polls, Surveys, NPS and Feedback Reviews plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, …

Mar 22, 2024
CVE-2024-0957
6.1 MEDIUM

The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Customer Notes field …

Mar 22, 2024
CVE-2024-2777
6.3 MEDIUM

A vulnerability has been found in Campcodes/PHPGurukul Online Marriage Registration System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Mar 22, 2024
CVE-2024-2776
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Campcodes Online Marriage Registration System 1.0. Affected is an unknown function of the file /admin/search.php. …

Mar 22, 2024
CVE-2024-2774
6.3 MEDIUM

A vulnerability classified as critical was found in Campcodes Online Marriage Registration System 1.0. This vulnerability affects unknown code of the file /user/search.php. The manipulation …

Mar 21, 2024
CVE-2024-2770
6.3 MEDIUM

A vulnerability was found in Campcodes Complete Online Beauty Parlor Management System 1.0. It has been rated as critical. Affected by this issue is some …

Mar 21, 2024
CVE-2024-2453
6.4 MEDIUM

There is an SQL injection vulnerability in Advantech WebAccess/SCADA software that allows an authenticated attacker to remotely inject SQL code in the database. Successful exploitation …

Mar 21, 2024
CVE-2024-28863
6.5 MEDIUM

node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. …

Mar 21, 2024
CVE-2024-28045
4.6 MEDIUM

Improper neutralization of input within the affected product could lead to cross-site scripting.

Mar 21, 2024
CVE-2023-42954
4.9 MEDIUM

A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in to the Admin Console with an administrator …

Mar 21, 2024
CVE-2024-2769
6.3 MEDIUM

A vulnerability was detected in Campcodes Complete Online Beauty Parlor Management System 1.0. The affected element is an unknown function of the file /admin/admin-profile.php. The …

Mar 21, 2024
CVE-2024-2768
6.3 MEDIUM

A vulnerability was found in Campcodes Complete Online Beauty Parlor Management System 1.0. It has been classified as critical. Affected is an unknown function of …

Mar 21, 2024
CVE-2024-2767
6.3 MEDIUM

A vulnerability was found in Campcodes Complete Online Beauty Parlor Management System 1.0 and classified as critical. This issue affects some unknown processing of the …

Mar 21, 2024
CVE-2024-2766
6.3 MEDIUM

A vulnerability has been found in Campcodes Complete Online Beauty Parlor Management System 1.0 and classified as critical. This vulnerability affects unknown code of the …

Mar 21, 2024
CVE-2024-28756
5.9 MEDIUM

The SolarEdge mySolarEdge application before 2.20.1 for Android has a certificate verification issue that allows a Machine-in-the-middle (MitM) attacker to read and alter all network …

Mar 21, 2024
CVE-2024-1727
4.3 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability in gradio-app/gradio allows attackers to upload multiple large files to a victim's system if they are running Gradio locally. …

Mar 21, 2024
CVE-2024-29374
6.1 MEDIUM

A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.

Mar 21, 2024
CVE-2024-2580
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelKit Automation By Autonami allows Stored XSS.This issue affects Automation By Autonami: from …

Mar 21, 2024
CVE-2024-2579
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Tracking Code Manager.This issue affects Tracking Code Manager: from n/a through 2.0.16.

Mar 21, 2024
CVE-2024-2578
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPCoder WP Coder allows Stored XSS.This issue affects WP Coder: from n/a through …

Mar 21, 2024
CVE-2024-29916
5.6 MEDIUM

The dormakaba Saflok system before the November 2023 software update allows an attacker to unlock arbitrary doors at a property via forged keycards, if the …

Mar 21, 2024
CVE-2024-27965
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFunnels WPFunnels wpfunnels.This issue affects WPFunnels: from n/a through <= 3.0.6.

Mar 21, 2024
CVE-2024-27963
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crisp allows Stored XSS.This issue affects Crisp: from n/a through 0.44.

Mar 21, 2024
CVE-2024-27277
6.2 MEDIUM

The private key for the IBM Storage Protect Plus Server 10.1.0 through 10.1.16 certificate can be disclosed, undermining the security of the certificate. IBM X-Force …

Mar 21, 2024
CVE-2024-27190
4.3 MEDIUM

Missing Authorization vulnerability in Jean-David Daviet Download Media.This issue affects Download Media: from n/a through 1.4.2.

Mar 21, 2024
CVE-2023-49837
6.5 MEDIUM

Uncontrolled Resource Consumption vulnerability in David Artiss Code Embed.This issue affects Code Embed: from n/a through 2.3.6.

Mar 21, 2024
CVE-2022-44595
5.3 MEDIUM

Improper Authentication vulnerability in Melapress WP 2FA allows Authentication Bypass.This issue affects WP 2FA: from n/a through 2.2.0.

Mar 21, 2024
CVE-2024-2464
6.3 MEDIUM

This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling …

Mar 21, 2024
CVE-2024-29244
5.3 MEDIUM

Shenzhen Libituo Technology Co., Ltd LBT-T300-mini v1.2.9 was discovered to contain a buffer overflow via the pin_code_3g parameter at /apply.cgi.

Mar 21, 2024
CVE-2024-27995
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Repute Infosystems ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & …

Mar 21, 2024
CVE-2023-47715
4.3 MEDIUM

IBM Storage Protect Plus Server 10.1.0 through 10.1.16 could allow an authenticated user with read-only permissions to add or delete entries from an existing HyperVisor …

Mar 21, 2024
CVE-2024-2494
6.2 MEDIUM

A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code allocates memory for arrays before the non-negative length check …

Mar 21, 2024
CVE-2024-29880
4.2 MEDIUM

In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process

Mar 21, 2024
CVE-2024-28834
5.3 MEDIUM

A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. …

Mar 21, 2024
CVE-2024-26643
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: mark set as dead when unbinding anonymous set with timeout While the rhashtable …

Mar 21, 2024
CVE-2024-26642
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: disallow anonymous set with timeout flag Anonymous sets are never used with timeout …

Mar 21, 2024
CVE-2024-26307
5.3 MEDIUM

Possible race condition vulnerability in Apache Doris. Some of code using `chmod()` method. This method run the risk of someone renaming the file out from …

Mar 21, 2024
CVE-2024-29133
5.4 MEDIUM

Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which …

Mar 21, 2024
CVE-2024-2754
4.7 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Complete E-Commerce Site 1.0. Affected is an unknown function of the file /admin/users_photo.php. The manipulation …

Mar 21, 2024
CVE-2024-28835
5.0 MEDIUM

A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the …

Mar 21, 2024
CVE-2024-28635
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in SurveyJS Survey Creator v.1.9.132 and before, allows attackers to execute arbitrary code and obtain sensitive information via the title …

Mar 21, 2024
CVE-2024-22724
6.6 MEDIUM

An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administrator profile photo upload feature.

Mar 21, 2024
CVE-2023-48903
6.1 MEDIUM

Stored Cross-Site Scripting (XSS) vulnerability in tramyardg autoexpress 1.3.0, allows remote unauthenticated attackers to inject arbitrary web script or HTML within parameter "imgType" via in …

Mar 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.