CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-2516
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in MAGESH-K21 Online-College-Event-Hall-Reservation-System 1.0. This affects an unknown part of the file home.php. The manipulation of …

Mar 16, 2024
CVE-2024-1857
5.3 MEDIUM

The Ultimate Gift Cards for WooCommerce – Create, Redeem & Manage Digital Gift Certificates with Personalized Templates plugin for WordPress is vulnerable to Sensitive Information …

Mar 16, 2024
CVE-2024-22513
5.5 MEDIUM

djangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure. A user can access web application resources even after their account has been disabled due …

Mar 16, 2024
CVE-2024-28070
6.8 MEDIUM

A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a reflected cross-site scripting …

Mar 16, 2024
CVE-2024-24156
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Gnuboard g6 before Github commit 58c737a263ac0c523592fd87ff71b9e3c07d7cf5, allows remote attackers execute arbitrary code via the wr_content parameter.

Mar 16, 2024
CVE-2024-1733
5.3 MEDIUM

The Word Replacer Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the word_replacer_ultra() function in …

Mar 16, 2024
CVE-2024-24845
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sewpafly Post Thumbnail Editor.This issue affects Post Thumbnail Editor: from n/a through 2.4.8.

Mar 16, 2024
CVE-2024-23523
6.5 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Elementor Pro.This issue affects Elementor Pro: from n/a through 3.19.2.

Mar 16, 2024
CVE-2023-36483
6.5 MEDIUM

Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android version 1.16.18 and earlier and MASmobile Classic iOS version 1.7.24 and earlier …

Mar 16, 2024
CVE-2024-2042
6.4 MEDIUM

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordion widget in all versions up to, and including, …

Mar 16, 2024
CVE-2024-1239
6.4 MEDIUM

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blog post read more button in all versions up to, …

Mar 16, 2024
CVE-2023-6525
5.5 MEDIUM

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the progress bar element attributes in all versions up to, and …

Mar 16, 2024
CVE-2024-2308
6.4 MEDIUM

The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button link in the EliSlider in all versions up …

Mar 16, 2024
CVE-2024-2294
4.9 MEDIUM

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.7 via …

Mar 16, 2024
CVE-2023-51487
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in ARI Soft ARI Stream Quiz.This issue affects ARI Stream Quiz: from n/a through 1.2.32.

Mar 16, 2024
CVE-2023-51486
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in RedNao WooCommerce PDF Invoice Builder.This issue affects WooCommerce PDF Invoice Builder: from n/a through 1.2.101.

Mar 16, 2024
CVE-2023-51521
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.18.

Mar 16, 2024
CVE-2023-51512
4.3 MEDIUM

Cross Site Request Forgery (CSRF) vulnerability in WBW Product Table by WBW.This issue affects Product Table by WBW: from n/a through 1.8.6.

Mar 16, 2024
CVE-2023-51510
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Atlas Gondal Export Media URLs.This issue affects Export Media URLs: from n/a through 1.0.

Mar 16, 2024
CVE-2023-51491
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Averta Depicter Slider.This issue affects Depicter Slider: from n/a through 2.0.6.

Mar 16, 2024
CVE-2023-51489
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from …

Mar 16, 2024
CVE-2023-51407
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Rocket Elements Split Test For Elementor.This issue affects Split Test For Elementor: from n/a through 1.6.9.

Mar 16, 2024
CVE-2024-28862
5.3 MEDIUM

The Ruby One Time Password library (ROTP) is an open source library for generating and validating one time passwords. Affected versions had overly permissive default …

Mar 16, 2024
CVE-2024-28859
5.0 MEDIUM

Symfony1 is a community fork of symfony 1.4 with DIC, form enhancements, latest Swiftmailer, better performance, composer compatible and PHP 8 support. Symfony 1 has …

Mar 15, 2024
CVE-2024-23298
5.5 MEDIUM

A logic issue was addressed with improved state management. This issue is fixed in Xcode 15.3. An app may bypass Gatekeeper checks.

Mar 15, 2024
CVE-2021-47134
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: efi/fdt: fix panic when no valid fdt found setup_arch() would invoke efi_init()->efi_get_fdt_params(). If no valid …

Mar 15, 2024
CVE-2021-47133
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: amd_sfh: Fix memory leak in amd_sfh_work Kmemleak tool detected a memory leak in the …

Mar 15, 2024
CVE-2021-47130
4.4 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvmet: fix freeing unallocated p2pmem In case p2p device was found but the p2p pool …

Mar 15, 2024
CVE-2021-47129
4.6 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: skip expectations for confirmed conntrack nft_ct_expect_obj_eval() calls nf_ct_ext_add() for a confirmed conntrack entry. …

Mar 15, 2024
CVE-2021-47128
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf, lockdown, audit: Fix buggy SELinux lockdown permission checks Commit 59438b46471a ("security,lockdown,selinux: implement SELinux lockdown") …

Mar 15, 2024
CVE-2021-47127
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ice: track AF_XDP ZC enabled queues in bitmap Commit c7a219048e45 ("ice: Remove xsk_buff_pool from VSI …

Mar 15, 2024
CVE-2021-47126
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix KASAN: slab-out-of-bounds Read in fib6_nh_flush_exceptions Reported by syzbot: HEAD commit: 90c911ad Merge tag …

Mar 15, 2024
CVE-2021-47125
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sch_htb: fix refcount leak in htb_parent_to_leaf_offload The commit ae81feb7338c ("sch_htb: fix null pointer dereference on …

Mar 15, 2024
CVE-2021-47124
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring: fix link timeout refs WARNING: CPU: 0 PID: 10242 at lib/refcount.c:28 refcount_warn_saturate+0x15b/0x1a0 lib/refcount.c:28 RIP: …

Mar 15, 2024
CVE-2021-47122
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: caif: fix memory leak in caif_device_notify In case of caif_enroll_dev() fail, allocated link_support won't …

Mar 15, 2024
CVE-2021-47121
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: caif: fix memory leak in cfusbl_device_notify In case of caif_enroll_dev() fail, allocated link_support won't …

Mar 15, 2024
CVE-2021-47120
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: magicmouse: fix NULL-deref on disconnect Commit 9d7b18668956 ("HID: magicmouse: add support for Apple Magic …

Mar 15, 2024
CVE-2021-47119
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: fix memory leak in ext4_fill_super Buffer head references must be released before calling kill_bdev(); …

Mar 15, 2024
CVE-2021-47117
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: fix bug on in ext4_es_cache_extent as ext4_split_extent_at failed We got follow bug_on when run …

Mar 15, 2024
CVE-2021-47116
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: fix memory leak in ext4_mb_init_backend on error path. Fix a memory leak discovered by …

Mar 15, 2024
CVE-2021-47114
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix data corruption by fallocate When fallocate punches holes out of inode size, if …

Mar 15, 2024
CVE-2021-47113
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: abort in rename_exchange if we fail to insert the second ref Error injection stress …

Mar 15, 2024
CVE-2021-47112
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/kvm: Teardown PV features on boot CPU as well Various PV features (Async PF, PV …

Mar 15, 2024
CVE-2021-47109
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: neighbour: allow NUD_NOARP entries to be forced GCed IFF_POINTOPOINT interfaces use NUD_NOARP entries for IPv6. …

Mar 15, 2024
CVE-2024-28242
5.3 MEDIUM

Discourse is an open source platform for community discussion. In affected versions an attacker can learn that secret categories exist when they have backgrounds set. …

Mar 15, 2024
CVE-2024-27351
5.3 MEDIUM

In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.text.Truncator.words() method (with html=True) and the truncatewords_html template filter are subject to …

Mar 15, 2024
CVE-2024-27100
6.5 MEDIUM

Discourse is an open source platform for community discussion. In affected versions the endpoints for suspending users, silencing users and exporting CSV files weren't enforcing …

Mar 15, 2024
CVE-2024-27085
6.5 MEDIUM

Discourse is an open source platform for community discussion. In affected versions users that are allowed to invite others can inject arbitrarily large data in …

Mar 15, 2024
CVE-2024-24827
5.3 MEDIUM

Discourse is an open source platform for community discussion. Without a rate limit on the POST /uploads endpoint, it makes it easier for an attacker …

Mar 15, 2024
CVE-2024-24748
5.3 MEDIUM

Discourse is an open source platform for community discussion. In affected versions an attacker can learn that a secret subcategory exists under a public category …

Mar 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.