CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-24136
6.1 MEDIUM

The 'Your Name' field in the Submit Score section of Sourcecodester Math Game with Leaderboard v1.0 is vulnerable to Cross-Site Scripting (XSS) attacks.

Jan 29, 2024
CVE-2024-22570
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in /install.php?m=install&c=index&a=step3 of GreenCMS v2.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Jan 29, 2024
CVE-2024-24135
6.1 MEDIUM

Product Name and Product Code in the 'Add Product' section of Sourcecodester Product Inventory with Export to Excel 1.0 are vulnerable to XSS attacks.

Jan 29, 2024
CVE-2024-24134
4.8 MEDIUM

Sourcecodester Online Food Menu 1.0 is vulnerable to Cross Site Scripting (XSS) via the 'Menu Name' and 'Description' fields in the Update Menu section.

Jan 29, 2024
CVE-2024-1017
5.3 MEDIUM

A vulnerability was found in Gabriels FTP Server 1.2. It has been rated as problematic. This issue affects some unknown processing. The manipulation of the …

Jan 29, 2024
CVE-2023-30970
6.5 MEDIUM

Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on …

Jan 29, 2024
CVE-2024-1016
5.3 MEDIUM

A vulnerability was found in Solar FTP Server 2.1.1/2.1.2. It has been declared as problematic. This vulnerability affects unknown code of the component PASV Command …

Jan 29, 2024
CVE-2024-1011
4.3 MEDIUM

A vulnerability classified as problematic was found in SourceCodester Employee Management System 1.0. This vulnerability affects unknown code of the file delete-leave.php of the component …

Jan 29, 2024
CVE-2024-0788
6.6 MEDIUM

SUPERAntiSpyware Pro X v10.0.1260 is vulnerable to kernel-level API parameters manipulation and Denial of Service vulnerabilities by triggering the 0x9C402140 IOCTL code of the saskutil64.sys …

Jan 29, 2024
CVE-2023-40551
5.1 MEDIUM

A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive …

Jan 29, 2024
CVE-2023-40550
5.5 MEDIUM

An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This issue may expose sensitive data during the system's …

Jan 29, 2024
CVE-2023-40549
6.2 MEDIUM

An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw …

Jan 29, 2024
CVE-2023-40546
6.2 MEDIUM

A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new variable, it …

Jan 29, 2024
CVE-2024-23826
6.8 MEDIUM

spbu_se_site is the website of the Department of System Programming of St. Petersburg State University. Before 2024.01.29, when uploading an avatar image, an authenticated user …

Jan 29, 2024
CVE-2024-23822
5.4 MEDIUM

Thruk is a multibackend monitoring webinterface. Prior to 3.12, the Thruk web monitoring application presents a vulnerability in a file upload form that allows a …

Jan 29, 2024
CVE-2024-23441
5.5 MEDIUM

Vba32 Antivirus v3.36.0 is vulnerable to a Denial of Service vulnerability by triggering the 0x2220A7 IOCTL code of the Vba32m64.sys driver.

Jan 29, 2024
CVE-2024-1008
4.7 MEDIUM

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jan 29, 2024
CVE-2024-1007
6.3 MEDIUM

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been classified as critical. Affected is an unknown function of the file edit_profile.php. …

Jan 29, 2024
CVE-2024-1005
5.3 MEDIUM

A vulnerability has been found in Shanxi Diankeyun Technology NODERP up to 6.0.2 and classified as critical. This vulnerability affects unknown code of the file …

Jan 29, 2024
CVE-2023-7200
6.1 MEDIUM

The EventON WordPress plugin before 4.4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jan 29, 2024
CVE-2023-7199
5.3 MEDIUM

The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthenticated user to read draft and private posts via a crafted …

Jan 29, 2024
CVE-2023-7089
5.4 MEDIUM

The Easy SVG Allow WordPress plugin through 1.0 does not sanitize uploaded SVG files, which could allow users with a role as low as Author …

Jan 29, 2024
CVE-2023-6633
4.3 MEDIUM

The Site Notes WordPress plugin through 2.0.0 does not have CSRF checks in some of its functionalities, which could allow attackers to make logged in …

Jan 29, 2024
CVE-2023-6530
5.4 MEDIUM

The TJ Shortcodes WordPress plugin through 0.1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Jan 29, 2024
CVE-2023-6503
5.4 MEDIUM

The WP Plugin Lister WordPress plugin through 2.1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which …

Jan 29, 2024
CVE-2023-6389
6.1 MEDIUM

The WordPress Toolbar WordPress plugin through 2.2.6 redirects to any URL via the "wptbto" parameter. This makes it possible for unauthenticated attackers to redirect users …

Jan 29, 2024
CVE-2023-6278
6.1 MEDIUM

The Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo WordPress plugin before 2.2.25 does not sanitise and escape the biteship_error and biteship_message parameters before outputting …

Jan 29, 2024
CVE-2023-6165
4.8 MEDIUM

The Restrict Usernames Emails Characters WordPress plugin before 3.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jan 29, 2024
CVE-2023-5956
4.8 MEDIUM

The Wp-Adv-Quiz WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jan 29, 2024
CVE-2023-5943
4.8 MEDIUM

The Wp-Adv-Quiz WordPress plugin before 1.0.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jan 29, 2024
CVE-2023-5124
4.8 MEDIUM

The Page Builder: Pagelayer WordPress plugin before 1.8.0 doesn't prevent attackers with administrator privileges from inserting malicious JavaScript inside a post's header or footer code, …

Jan 29, 2024
CVE-2024-22559
5.4 MEDIUM

LightCMS v2.0 is vulnerable to Cross Site Scripting (XSS) in the Content Management - Articles field.

Jan 29, 2024
CVE-2024-1014
6.2 MEDIUM

Uncontrolled resource consumption vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could interrupt the availability of the administration panel by sending …

Jan 29, 2024
CVE-2024-23792
5.3 MEDIUM

When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. The attack requires a logged-in other user to …

Jan 29, 2024
CVE-2024-23791
4.9 MEDIUM

Insertion of debug information into log file during building the elastic search index allows reading of sensitive information from articles.This issue affects OTRS: from 7.0.X …

Jan 29, 2024
CVE-2024-0989
5.4 MEDIUM

A vulnerability, which was classified as problematic, has been found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected by this issue is the function …

Jan 29, 2024
CVE-2024-0988
6.3 MEDIUM

A vulnerability classified as critical was found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected by this vulnerability is the function checklogin of the …

Jan 29, 2024
CVE-2024-0987
6.3 MEDIUM

A vulnerability classified as critical has been found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected is an unknown function of the file /runtime/log. …

Jan 29, 2024
CVE-2024-0986
4.7 MEDIUM

A vulnerability was found in Issabel PBX 4.0.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php?menu=asterisk_cli of …

Jan 29, 2024
CVE-2024-23782
5.4 MEDIUM

Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, …

Jan 28, 2024
CVE-2024-0841
6.6 MEDIUM

A null pointer dereference flaw was found in the hugetlbfs_fill_super function in the Linux kernel hugetlbfs (HugeTLB pages) functionality. This issue may allow a local …

Jan 28, 2024
CVE-2024-0962
6.3 MEDIUM

A vulnerability was found in obgm libcoap 4.3.4. It has been rated as critical. Affected by this issue is the function get_split_entry of the file …

Jan 27, 2024
CVE-2024-0960
5.0 MEDIUM

A vulnerability was found in flink-extended ai-flow 0.3.1. It has been declared as critical. Affected by this vulnerability is the function cloudpickle.loads of the file …

Jan 27, 2024
CVE-2024-0959
5.0 MEDIUM

A vulnerability was found in StanfordVL GibsonEnv 0.3.1. It has been classified as critical. Affected is the function cloudpickle.load of the file gibson\utils\pposgd_fuse.py. The manipulation …

Jan 27, 2024
CVE-2024-0618
4.4 MEDIUM

The Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jan 27, 2024
CVE-2023-48202
5.4 MEDIUM

Cross-Site Scripting (XSS) vulnerability in Sunlight CMS 8.0.1 allows an authenticated low-privileged user to escalate privileges via a crafted SVG file in the File Manager …

Jan 27, 2024
CVE-2023-48201
5.4 MEDIUM

Cross Site Scripting (XSS) vulnerability in Sunlight CMS v.8.0.1, allows remote authenticated attackers to execute arbitrary code and escalate privileges via a crafted script to …

Jan 27, 2024
CVE-2024-0824
6.4 MEDIUM

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Anything functionality in all versions up to, and …

Jan 27, 2024
CVE-2024-0697
6.5 MEDIUM

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.3 via …

Jan 27, 2024
CVE-2024-0667
5.4 MEDIUM

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions …

Jan 27, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.