CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-2713
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Campcodes Complete Online DJ Booking System 1.0. Affected is an unknown function of the file …

Mar 21, 2024
CVE-2024-2712
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Campcodes Complete Online DJ Booking System 1.0. This issue affects some unknown processing of …

Mar 21, 2024
CVE-2024-2016
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in ZhiCms 4.0. Affected is the function index of the file app/manage/controller/setcontroller.php. The manipulation of the …

Mar 21, 2024
CVE-2024-2015
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in ZhiCms 4.0. This issue affects the function getindexdata of the file app/index/controller/mcontroller.php. The manipulation …

Mar 21, 2024
CVE-2024-2007
5.3 MEDIUM

A vulnerability was found in OpenBMB XAgent 1.0.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component …

Mar 21, 2024
CVE-2024-28102
6.8 MEDIUM

JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service attack by passing in …

Mar 21, 2024
CVE-2024-27932
4.6 MEDIUM

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.8.0 and prior to version 1.40.4, Deno improperly checks that an import specifier's hostname …

Mar 21, 2024
CVE-2024-27927
6.5 MEDIUM

RSSHub is an open source RSS feed generator. Prior to version 1.0.0-master.a429472, RSSHub allows remote attackers to use the server as a proxy to send …

Mar 21, 2024
CVE-2024-27926
6.1 MEDIUM

RSSHub is an open source RSS feed generator. Starting in version 1.0.0-master.cbbd829 and prior to version 1.0.0-master.d8ca915, ahen the specially crafted image is supplied to …

Mar 21, 2024
CVE-2024-27626
6.1 MEDIUM

A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29. The flaw exists within the Search functionality of the Admin Panel.

Mar 21, 2024
CVE-2024-27291
6.1 MEDIUM

Docassemble is an expert system for guided interviews and document assembly. Prior to 1.4.97, it is possible to create a URL that acts as an …

Mar 21, 2024
CVE-2024-27290
6.1 MEDIUM

Docassemble is an expert system for guided interviews and document assembly. Prior to 1.4.97, a user could type HTML into a field, including the field …

Mar 21, 2024
CVE-2024-27094
6.5 MEDIUM

OpenZeppelin Contracts is a library for secure smart contract development. The `Base64.encode` function encodes a `bytes` input by iterating over it in chunks of 3 …

Mar 21, 2024
CVE-2024-26196
4.3 MEDIUM

Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability

Mar 21, 2024
CVE-2024-25811
6.5 MEDIUM

An access control issue in Dreamer CMS v4.0.1 allows attackers to download backup files and leak sensitive information.

Mar 21, 2024
CVE-2024-25359
6.6 MEDIUM

An issue in zuoxingdong lagom v.0.1.2 allows a local attacker to execute arbitrary code via the pickle_load function of the serialize.py file.

Mar 21, 2024
CVE-2024-25167
6.1 MEDIUM

Cross Site Scripting vulnerability in eblog v1.0 allows a remote attacker to execute arbitrary code via a crafted script to the argument description parameter when …

Mar 21, 2024
CVE-2024-24818
5.9 MEDIUM

EspoCRM is an Open Source Customer Relationship Management software. An attacker can inject arbitrary IP or domain in "Password Change" page and redirect victim to …

Mar 21, 2024
CVE-2024-24110
6.5 MEDIUM

SQL Injection vulnerability in crmeb_java before v1.3.4 allows attackers to run arbitrary SQL commands via crafted GET request to the component /api/front/spread/people.

Mar 21, 2024
CVE-2024-24028
5.9 MEDIUM

Server Side Request Forgery (SSRF) vulnerability in Likeshop before 2.5.7 allows attackers to view sensitive information via the avatar parameter in function UserLogic::updateWechatInfo.

Mar 21, 2024
CVE-2024-22352
6.5 MEDIUM

IBM InfoSphere Information Server 11.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 280361.

Mar 21, 2024
CVE-2024-1908
6.3 MEDIUM

An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use the Enterprise Actions GitHub Connect download token to …

Mar 21, 2024
CVE-2024-1503
4.3 MEDIUM

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Mar 21, 2024
CVE-2024-1502
5.4 MEDIUM

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check …

Mar 21, 2024
CVE-2024-1450
6.4 MEDIUM

The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortcode in all versions up to, and including, 4.6.10 …

Mar 21, 2024
CVE-2024-1326
6.4 MEDIUM

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML Tag attributes in all versions up to, and including, 2.6.2 …

Mar 21, 2024
CVE-2024-1278
6.4 MEDIUM

The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Mar 21, 2024
CVE-2024-1214
4.3 MEDIUM

The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all …

Mar 21, 2024
CVE-2024-1213
5.4 MEDIUM

The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all …

Mar 21, 2024
CVE-2024-1142
5.4 MEDIUM

Path Traversal in Sonatype IQ Server from version 143 allows remote authenticated attackers to overwrite or delete files via a specially crafted request. Version 171 …

Mar 21, 2024
CVE-2024-0966
6.4 MEDIUM

The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortcode in all versions up to, and including, 4.6.9 …

Mar 21, 2024
CVE-2023-6500
6.4 MEDIUM

The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortcode in all versions up to, and including, 4.6.9 …

Mar 21, 2024
CVE-2023-49985
6.5 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via …

Mar 21, 2024
CVE-2023-49984
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /management/settings of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via …

Mar 21, 2024
CVE-2023-49983
6.8 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via …

Mar 21, 2024
CVE-2023-38825
6.5 MEDIUM

SQL injection vulnerability in Vanderbilt REDCap before v.13.8.0 allows a remote attacker to obtain sensitive information via the password reset mechanism in MyCapMobileApp/update.php.

Mar 21, 2024
CVE-2022-4963
5.5 MEDIUM

A vulnerability was found in Folio Spring Module Core up to 1.1.5. It has been rated as critical. Affected by this issue is the function …

Mar 21, 2024
CVE-2024-2748
4.3 MEDIUM

A Cross Site Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker to execute unauthorized actions on behalf of an unsuspecting …

Mar 21, 2024
CVE-2024-24050
4.7 MEDIUM

Cross Site Scripting (XSS) vulnerability in Sourcecodester Workout Journal App 1.0 allows attackers to run arbitrary code via parameters firstname and lastname in /add-user.php.

Mar 20, 2024
CVE-2024-29474
5.4 MEDIUM

OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the User Management module.

Mar 20, 2024
CVE-2024-29473
6.1 MEDIUM

OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Role Management module.

Mar 20, 2024
CVE-2024-29472
5.4 MEDIUM

OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Privilege Management module.

Mar 20, 2024
CVE-2024-29471
5.4 MEDIUM

OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Notice Manage module.

Mar 20, 2024
CVE-2024-29470
6.1 MEDIUM

OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component {{rootpath}}/links.

Mar 20, 2024
CVE-2024-29469
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in OneBlog v2.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

Mar 20, 2024
CVE-2024-29036
4.3 MEDIUM

Saleor Storefront is software for building e-commerce experiences. Prior to commit 579241e75a5eb332ccf26e0bcdd54befa33f4783, when any user authenticates in the storefront, anonymous users are able to access …

Mar 20, 2024
CVE-2024-29032
5.3 MEDIUM

Qiskit IBM Runtime is an environment that streamlines quantum computations and provides optimal implementations of the Qiskit quantum computing SDK. Starting in version 0.1.0 and …

Mar 20, 2024
CVE-2024-29018
5.9 MEDIUM

Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. …

Mar 20, 2024
CVE-2024-2714
6.3 MEDIUM

A vulnerability has been found in Campcodes Complete Online DJ Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality …

Mar 20, 2024
CVE-2024-27286
6.5 MEDIUM

Zulip is an open-source team collaboration tool. When a user moves a Zulip message, they have the option to move all messages in the topic, …

Mar 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.