CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-29186
5.3 MEDIUM

Bref is an open-source project that helps users go serverless on Amazon Web Services with PHP. When Bref prior to version 2.1.17 is used with …

Mar 22, 2024
CVE-2024-29042
5.3 MEDIUM

Translate is a package that allows users to convert text to different languages on Node.js and the browser. Prior to version 3.0.0, an attacker controlling …

Mar 22, 2024
CVE-2024-2821
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7. Affected by this issue is some unknown functionality of the file /src/dede/friendlink_edit.php. …

Mar 22, 2024
CVE-2024-2820
4.3 MEDIUM

A vulnerability classified as problematic was found in DedeCMS 5.7. Affected by this vulnerability is an unknown functionality of the file /src/dede/baidunews.php. The manipulation of …

Mar 22, 2024
CVE-2022-32754
4.8 MEDIUM

IBM Security Verify Directory 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …

Mar 22, 2024
CVE-2022-32753
4.5 MEDIUM

IBM Security Verify Directory 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 228444.

Mar 22, 2024
CVE-2022-32751
5.3 MEDIUM

IBM Security Verify Directory 10.0.0 could disclose sensitive server information that could be used in further attacks against the system. IBM X-Force ID: 228437.

Mar 22, 2024
CVE-2024-29865
5.4 MEDIUM

Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form.

Mar 22, 2024
CVE-2024-28593
5.4 MEDIUM

The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to …

Mar 22, 2024
CVE-2024-2728
4.1 MEDIUM

Information exposure vulnerability in the CIGESv2 system. This vulnerability could allow a local attacker to intercept traffic due to the lack of proper implementation of …

Mar 22, 2024
CVE-2024-2727
6.1 MEDIUM

HTML injection vulnerability affecting the CIGESv2 system, which allows an attacker to inject arbitrary code and modify elements of the website and email confirmation message.

Mar 22, 2024
CVE-2024-2726
6.1 MEDIUM

Stored Cross-Site Scripting (Stored-XSS) vulnerability affecting the CIGESv2 system, allowing an attacker to execute and store malicious javascript code in the application form without prior …

Mar 22, 2024
CVE-2024-28560
5.4 MEDIUM

SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the deleteArea() function of the Address.php component.

Mar 22, 2024
CVE-2024-25168
6.3 MEDIUM

SQL injection vulnerability in snow snow v.2.0.0 allows a remote attacker to execute arbitrary code via the dataScope parameter of the system/role/list interface.

Mar 22, 2024
CVE-2024-2817
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Tenda AC15 15.03.05.18. Affected by this issue is the function fromSysToolRestoreSet of the file …

Mar 22, 2024
CVE-2024-2816
4.3 MEDIUM

A vulnerability classified as problematic was found in Tenda AC15 15.03.05.18. Affected by this vulnerability is the function fromSysToolReboot of the file /goform/SysToolReboot. The manipulation …

Mar 22, 2024
CVE-2024-2812
6.3 MEDIUM

A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. It has been classified as critical. This affects the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation …

Mar 22, 2024
CVE-2024-29273
6.1 MEDIUM

There is Stored Cross-Site Scripting (XSS) in dzzoffice 2.02.1 SC UTF8 in uploadfile to index.php, with the XSS payload in an SVG document.

Mar 22, 2024
CVE-2024-29272
6.5 MEDIUM

Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and obtain sensitive information via the sanitizeFileName parameter …

Mar 22, 2024
CVE-2024-29271
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) vulnerability in VvvebJs before version 1.7.7, allows remote attackers to execute arbitrary code and obtain sensitive information via the action parameter …

Mar 22, 2024
CVE-2024-26557
5.4 MEDIUM

Codiad v2.8.4 allows reflected XSS via the components/market/dialog.php type parameter.

Mar 22, 2024
CVE-2024-25807
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Lychee 3.1.6, allows remote attackers to execute arbitrary code and obtain sensitive information via the title parameter when creating …

Mar 22, 2024
CVE-2024-2500
6.4 MEDIUM

The ColorMag theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.1.6 due …

Mar 22, 2024
CVE-2024-2392
6.4 MEDIUM

The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Newsletter widget in all versions up to, and including, 2.0.31 …

Mar 22, 2024
CVE-2024-2080
4.3 MEDIUM

The LiquidPoll – Polls, Surveys, NPS and Feedback Reviews plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, …

Mar 22, 2024
CVE-2024-0957
6.1 MEDIUM

The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Customer Notes field …

Mar 22, 2024
CVE-2024-2777
6.3 MEDIUM

A vulnerability has been found in Campcodes/PHPGurukul Online Marriage Registration System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Mar 22, 2024
CVE-2024-2776
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Campcodes Online Marriage Registration System 1.0. Affected is an unknown function of the file /admin/search.php. …

Mar 22, 2024
CVE-2024-2774
6.3 MEDIUM

A vulnerability classified as critical was found in Campcodes Online Marriage Registration System 1.0. This vulnerability affects unknown code of the file /user/search.php. The manipulation …

Mar 21, 2024
CVE-2024-2770
6.3 MEDIUM

A vulnerability was found in Campcodes Complete Online Beauty Parlor Management System 1.0. It has been rated as critical. Affected by this issue is some …

Mar 21, 2024
CVE-2024-2453
6.4 MEDIUM

There is an SQL injection vulnerability in Advantech WebAccess/SCADA software that allows an authenticated attacker to remotely inject SQL code in the database. Successful exploitation …

Mar 21, 2024
CVE-2024-28863
6.5 MEDIUM

node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. …

Mar 21, 2024
CVE-2024-28045
4.6 MEDIUM

Improper neutralization of input within the affected product could lead to cross-site scripting.

Mar 21, 2024
CVE-2023-42954
4.9 MEDIUM

A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in to the Admin Console with an administrator …

Mar 21, 2024
CVE-2024-2769
6.3 MEDIUM

A vulnerability was detected in Campcodes Complete Online Beauty Parlor Management System 1.0. The affected element is an unknown function of the file /admin/admin-profile.php. The …

Mar 21, 2024
CVE-2024-2768
6.3 MEDIUM

A vulnerability was found in Campcodes Complete Online Beauty Parlor Management System 1.0. It has been classified as critical. Affected is an unknown function of …

Mar 21, 2024
CVE-2024-2767
6.3 MEDIUM

A vulnerability was found in Campcodes Complete Online Beauty Parlor Management System 1.0 and classified as critical. This issue affects some unknown processing of the …

Mar 21, 2024
CVE-2024-2766
6.3 MEDIUM

A vulnerability has been found in Campcodes Complete Online Beauty Parlor Management System 1.0 and classified as critical. This vulnerability affects unknown code of the …

Mar 21, 2024
CVE-2024-28756
5.9 MEDIUM

The SolarEdge mySolarEdge application before 2.20.1 for Android has a certificate verification issue that allows a Machine-in-the-middle (MitM) attacker to read and alter all network …

Mar 21, 2024
CVE-2024-1727
4.3 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability in gradio-app/gradio allows attackers to upload multiple large files to a victim's system if they are running Gradio locally. …

Mar 21, 2024
CVE-2024-29374
6.1 MEDIUM

A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.

Mar 21, 2024
CVE-2024-2580
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelKit Automation By Autonami allows Stored XSS.This issue affects Automation By Autonami: from …

Mar 21, 2024
CVE-2024-2579
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Tracking Code Manager.This issue affects Tracking Code Manager: from n/a through 2.0.16.

Mar 21, 2024
CVE-2024-2578
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPCoder WP Coder allows Stored XSS.This issue affects WP Coder: from n/a through …

Mar 21, 2024
CVE-2024-29916
5.6 MEDIUM

The dormakaba Saflok system before the November 2023 software update allows an attacker to unlock arbitrary doors at a property via forged keycards, if the …

Mar 21, 2024
CVE-2024-27965
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFunnels WPFunnels wpfunnels.This issue affects WPFunnels: from n/a through <= 3.0.6.

Mar 21, 2024
CVE-2024-27963
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crisp allows Stored XSS.This issue affects Crisp: from n/a through 0.44.

Mar 21, 2024
CVE-2024-27277
6.2 MEDIUM

The private key for the IBM Storage Protect Plus Server 10.1.0 through 10.1.16 certificate can be disclosed, undermining the security of the certificate. IBM X-Force …

Mar 21, 2024
CVE-2024-27190
4.3 MEDIUM

Missing Authorization vulnerability in Jean-David Daviet Download Media.This issue affects Download Media: from n/a through 1.4.2.

Mar 21, 2024
CVE-2023-49837
6.5 MEDIUM

Uncontrolled Resource Consumption vulnerability in David Artiss Code Embed.This issue affects Code Embed: from n/a through 2.3.6.

Mar 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.