CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-12507
6.4 MEDIUM

The Optio Dentistry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'optio-lightbox' shortcode in all versions up to, and including, 2.1 …

Dec 24, 2024
CVE-2024-12266
6.5 MEDIUM

The ELEX WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the …

Dec 24, 2024
CVE-2024-9427
5.4 MEDIUM

A vulnerability in Koji was found. An unsanitized input allows for an XSS attack. Javascript code from a malicious link could be reflected in the …

Dec 24, 2024
CVE-2024-47515
8.1 HIGH

A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the disclosure of local files. This flaw allows a …

Dec 24, 2024
CVE-2024-12582
7.1 HIGH

A flaw was found in the skupper console, a read-only interface that renders cluster network, traffic details, and metrics for a network application that a …

Dec 24, 2024
CVE-2018-25106
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in webuidesigning NebulaX Theme up to 5.0 on WordPress. This issue affects the function nebula_send_to_hubspot …

Dec 23, 2024
CVE-2024-53961
8.1 HIGH

ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead …

Dec 23, 2024
CVE-2024-56363
7.8 HIGH

APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed for penetration testers and security organizations. In 1.0, there is …

Dec 23, 2024
CVE-2024-56362
7.1 HIGH

Navidrome is an open source web-based music collection server and streamer. Navidrome stores the JWT secret in plaintext in the navidrome.db database file under the …

Dec 23, 2024
CVE-2024-53276

Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. In 1.15.0 and earlier, an open CORS policy in app.js may allow …

Dec 23, 2024
CVE-2024-53275

Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. In 1.15.0 and earlier, the default setup of home-gallery is vulnerable to …

Dec 23, 2024
CVE-2024-40896
9.1 CRITICAL

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX …

Dec 23, 2024
CVE-2024-56364
5.4 MEDIUM

SimpleXLSX is software for parsing and retrieving data from Excel XLSx files. Starting in 1.0.12 and ending in 1.1.13, when calling the extended toHTMLEx method, …

Dec 23, 2024
CVE-2024-56326
7.8 HIGH

Jinja is an extensible templating engine. Prior to 3.1.5, An oversight in how the Jinja sandboxed environment detects calls to str.format allows an attacker that …

Dec 23, 2024
CVE-2024-56201
8.8 HIGH

Jinja is an extensible templating engine. In versions on the 3.x branch prior to 3.1.5, a bug in the Jinja compiler allows an attacker that …

Dec 23, 2024
CVE-2024-55947
8.8 HIGH

Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the server to …

Dec 23, 2024
CVE-2024-54148
9.8 CRITICAL

Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a repository to …

Dec 23, 2024
CVE-2024-53256
7.8 HIGH

Rizin is a UNIX-like reverse engineering framework and command-line toolset. `rizin.c` still had an old snippet of code which suffered a command injection due the …

Dec 23, 2024
CVE-2024-45387
9.9 CRITICAL

An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", …

Dec 23, 2024
CVE-2024-23945
5.9 MEDIUM

Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authenticity and integrity. The signature helps prevent …

Dec 23, 2024
CVE-2024-55539
2.5 LOW

Weak algorithm used to sign RPM package. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux) before build 39185, Acronis Cyber Protect 16 …

Dec 23, 2024
CVE-2024-12903
7.8 HIGH

Incorrect default permissions vulnerability in Evoko Home, affecting version 2.4.2 to 2.7.4. A non-admin user could exploit weak file and folder permissions to escalate privileges, …

Dec 23, 2024
CVE-2024-12902
8.4 HIGH

ANCHOR from Global Wisdom Software is an integrated product running on a Windows virtual machine. The underlying Windows OS of the product contains high-privilege service …

Dec 23, 2024
CVE-2024-11230
6.4 MEDIUM

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘size’ parameter in all versions up to, and …

Dec 23, 2024
CVE-2024-12901
5.3 MEDIUM

A vulnerability classified as critical was found in FoxCMS up to 1.2. Affected by this vulnerability is an unknown functionality of the file /app/api/controller/Site.php of …

Dec 23, 2024
CVE-2024-12900
6.3 MEDIUM

A vulnerability classified as critical has been found in FoxCMS up to 1.2. Affected is an unknown function of the file /install/installdb.php of the component …

Dec 23, 2024
CVE-2024-54082
7.2 HIGH

home 5G HR02 and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the configuration restore function. An arbitrary OS command may be executed …

Dec 23, 2024
CVE-2024-52321
5.9 MEDIUM

Multiple SHARP routers contain an improper authentication vulnerability in the configuration backup function. The product's backup files containing sensitive information may be retrieved by a …

Dec 23, 2024
CVE-2024-47864
5.3 MEDIUM

home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain a buffer overflow vulnerability in the hidden debug function. A remote unauthenticated attacker may …

Dec 23, 2024
CVE-2024-46873
9.8 CRITICAL

Multiple SHARP routers leave the hidden debug function enabled. An arbitrary OS command may be executed with the root privilege by a remote unauthenticated attacker.

Dec 23, 2024
CVE-2024-45721
7.2 HIGH

home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the HOST name configuration screen. An arbitrary OS …

Dec 23, 2024
CVE-2024-12899
7.3 HIGH

A vulnerability was found in 1000 Projects Attendance Tracking Management System 1.0. It has been rated as critical. This issue affects some unknown processing of …

Dec 23, 2024
CVE-2024-12898
6.3 MEDIUM

A vulnerability was found in 1000 Projects Attendance Tracking Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the …

Dec 23, 2024
CVE-2024-56378
4.3 MEDIUM

libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.

Dec 23, 2024
CVE-2024-12897
4.3 MEDIUM

A vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222. It has been …

Dec 23, 2024
CVE-2024-56375
7.5 HIGH

An integer underflow was discovered in Fort 1.6.3 and 1.6.4 before 1.6.5. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve …

Dec 22, 2024
CVE-2024-12896
5.3 MEDIUM

A vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222 and classified as …

Dec 22, 2024
CVE-2024-56314
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Project name of REDCap through 14.9.6 allows authenticated users to inject malicious scripts into the name field …

Dec 22, 2024
CVE-2024-56313
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Calendar feature of REDCap through 14.9.6 allows authenticated users to inject malicious scripts into the Notes field …

Dec 22, 2024
CVE-2024-56312
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Project Dashboard name of REDCap through 14.9.6 allows authenticated users to inject malicious scripts into the name …

Dec 22, 2024
CVE-2024-56311
8.8 HIGH

REDCap through 14.9.6 has a security flaw in the Notes section of calendar events, exposing users to a Cross-Site Request Forgery (CSRF) attack. An attacker …

Dec 22, 2024
CVE-2024-56310
8.8 HIGH

REDCap through 14.9.6 has a security flaw in the Project Dashboards name, exposing users to a Cross-Site Request Forgery (CSRF) attack. An attacker can exploit …

Dec 22, 2024
CVE-2024-12895
6.3 MEDIUM

A vulnerability has been found in TreasureHuntGame TreasureHunt up to 963e0e0 and classified as critical. Affected by this vulnerability is the function console_log of the …

Dec 22, 2024
CVE-2024-12894
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in TreasureHuntGame TreasureHunt up to 963e0e0. Affected is an unknown function of the file TreasureHunt/acesso.php. The …

Dec 22, 2024
CVE-2024-12893
2.4 LOW

A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar up to 2.9. Affected by this issue is some unknown functionality of …

Dec 22, 2024
CVE-2024-12892
3.5 LOW

A vulnerability classified as problematic was found in code-projects Online Exam Mastering System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Dec 22, 2024
CVE-2024-12891
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Online Exam Mastering System 1.0. Affected is an unknown function of the file /account.php?q=quiz&step=2. The …

Dec 22, 2024
CVE-2024-12890
6.3 MEDIUM

A vulnerability was found in code-projects Online Exam Mastering System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Dec 22, 2024
CVE-2024-11852
4.3 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for WordPress is vulnerable to unauthorized access of data …

Dec 22, 2024
CVE-2024-51464
4.3 MEDIUM

IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions. By sending a specially crafted request, an authenticated attacker could …

Dec 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.