CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-12842
4.3 MEDIUM

A vulnerability was found in Emlog Pro up to 2.4.1. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/user.php. …

Dec 20, 2024
CVE-2024-55342
4.7 MEDIUM

A file upload functionality in Piranha CMS 11.1 allows authenticated remote attackers to upload a crafted PDF file to /manager/media. This PDF can contain malicious …

Dec 20, 2024
CVE-2024-37758
8.8 HIGH

Improper access control in the endpoint /RoleMenuMapping/AddRoleMenu of Digiteam v4.21.0.0 allows authenticated attackers to escalate privileges.

Dec 20, 2024
CVE-2024-12841
4.3 MEDIUM

A vulnerability was found in Emlog Pro up to 2.4.1. It has been classified as problematic. This affects an unknown part of the file /admin/tag.php. …

Dec 20, 2024
CVE-2024-12677
7.8 HIGH

Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary code.

Dec 20, 2024
CVE-2024-56337
9.8 CRITICAL

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through …

Dec 20, 2024
CVE-2024-55471
6.5 MEDIUM

Oqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This allows unauthorized users to access sensitive information of other users by manipulating …

Dec 20, 2024
CVE-2024-55470
7.5 HIGH

Oqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can bypass passcode validation and successfully log into the application …

Dec 20, 2024
CVE-2024-55186
4.3 MEDIUM

An IDOR (Insecure Direct Object Reference) vulnerability exists in oqtane Framework 6.0.0, allowing a logged-in user to access inbox messages of other users by manipulating …

Dec 20, 2024
CVE-2024-12840

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. The problem described was inteded behavior and therefore …

Dec 20, 2024
CVE-2024-10385

Ticket management system in DirectAdmin Evolution Skin is vulnerable to XSS (Cross-site Scripting), which allows a low-privileged user to inject and store malicious JavaScript code. …

Dec 20, 2024
CVE-2024-56356
5.9 MEDIUM

In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack

Dec 20, 2024
CVE-2024-56355
4.6 MEDIUM

In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS

Dec 20, 2024
CVE-2024-56354
5.5 MEDIUM

In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission

Dec 20, 2024
CVE-2024-56353
5.5 MEDIUM

In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies

Dec 20, 2024
CVE-2024-56352
4.6 MEDIUM

In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page

Dec 20, 2024
CVE-2024-56351
6.3 MEDIUM

In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles

Dec 20, 2024
CVE-2024-56350
4.3 MEDIUM

In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects

Dec 20, 2024
CVE-2024-56349
5.3 MEDIUM

In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs

Dec 20, 2024
CVE-2024-56348
4.3 MEDIUM

In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents

Dec 20, 2024
CVE-2024-51466
9.0 CRITICAL

IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 is vulnerable to an Expression Language (EL) Injection vulnerability. A remote attacker could exploit …

Dec 20, 2024
CVE-2024-40695
8.0 HIGH

IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 could be vulnerable to malicious file upload by not validating the content of the …

Dec 20, 2024
CVE-2024-28767
6.8 MEDIUM

IBM Security Directory Integrator 7.2.0 through 7.2.0.13 and 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by …

Dec 20, 2024
CVE-2024-12014

Path Traversal vulnerability in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files …

Dec 20, 2024
CVE-2024-7726
6.8 MEDIUM

There exists an unauthenticated accessible JTAG port on the Kioxia PM6, PM7 and CM6 devices - On the Kioxia CM6, PM6 and PM7 disk drives …

Dec 20, 2024
CVE-2024-9619
6.4 MEDIUM

The WP SHAPES plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due …

Dec 20, 2024
CVE-2024-9503
4.3 MEDIUM

The Maintenance & Coming Soon Redirect Animation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Dec 20, 2024
CVE-2024-12571
9.8 CRITICAL

The Store Locator for WordPress with Google Maps – LotsOfLocales plugin for WordPress is vulnerable to Local File Inclusion in version 3.98.9 via the 'sl_engine' …

Dec 20, 2024
CVE-2024-12509
6.4 MEDIUM

The Embed Twine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'embed_twine' shortcode in all versions up to, and including, 0.1.0 …

Dec 20, 2024
CVE-2024-12506
6.4 MEDIUM

The NACC WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'nacc' shortcode in all versions up to, and including, …

Dec 20, 2024
CVE-2024-11893
6.4 MEDIUM

The Spoki – Chat Buttons and WooCommerce Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spoki_button' shortcode in all versions …

Dec 20, 2024
CVE-2024-11878
6.4 MEDIUM

The Category Post Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'category-post-slider' shortcode in all versions up to, and including, …

Dec 20, 2024
CVE-2024-11812
6.1 MEDIUM

The Wtyczka SeoPilot dla WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.091. This is due …

Dec 20, 2024
CVE-2024-11806
6.1 MEDIUM

The PKT1 Centro de envios plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'success' and 'error' parameters in all versions up to, …

Dec 20, 2024
CVE-2024-11784
6.4 MEDIUM

The Sell Tickets Online – TicketSource Ticket Shop for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ticketshop' shortcode in …

Dec 20, 2024
CVE-2024-11783
6.4 MEDIUM

The Financial Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'finance_calculator' shortcode in all versions up to, and including, 2.2.1 …

Dec 20, 2024
CVE-2024-11775
6.4 MEDIUM

The Particle Background plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'particleground' shortcode in all versions up to, and including, 1.0.2 …

Dec 20, 2024
CVE-2024-11774
6.4 MEDIUM

The Outdooractive Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'list2go' shortcode in all versions up to, and including, 1.5 …

Dec 20, 2024
CVE-2024-11411
6.4 MEDIUM

The Spotlightr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spotlightr-v' shortcode in all versions up to, and including, 0.1.11 due …

Dec 20, 2024
CVE-2024-11331
6.1 MEDIUM

The استخراج محصولات ووکامرس برای آیسی plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate …

Dec 20, 2024
CVE-2024-11297
5.3 MEDIUM

The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, …

Dec 20, 2024
CVE-2024-8968
4.7 MEDIUM

The WordPress Button Plugin MaxButtons WordPress plugin before 9.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such …

Dec 20, 2024
CVE-2024-5955
5.4 MEDIUM

Cross-site scripting vulnerability in Trellix ePolicy Orchestrator prior to ePO 5.10 Service Pack 1 Update 3 allows a remote authenticated attacker to craft requests causing …

Dec 20, 2024
CVE-2024-11108
5.4 MEDIUM

The Serious Slider WordPress plugin before 1.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Dec 20, 2024
CVE-2024-10706
4.8 MEDIUM

The Download Manager WordPress plugin before 3.3.03 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Dec 20, 2024
CVE-2024-10555
4.8 MEDIUM

The WordPress Button Plugin MaxButtons WordPress plugin before 9.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such …

Dec 20, 2024
CVE-2024-21549
8.6 HIGH

Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method. An attacker can …

Dec 20, 2024
CVE-2024-44298
3.3 LOW

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1. An app may be …

Dec 20, 2024
CVE-2024-44293
5.5 MEDIUM

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1. A user may be …

Dec 20, 2024
CVE-2024-44292
5.5 MEDIUM

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1. An app may be …

Dec 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.