CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-55452
5.4 MEDIUM

A URL redirection vulnerability exists in UJCMS 9.6.3 due to improper validation of URLs in the upload and rendering of new block / carousel items. …

Dec 16, 2024
CVE-2024-55451
4.8 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability exists in authenticated SVG file upload and viewing functionality in UJCMS 9.6.3. The vulnerability arises from insufficient sanitization of …

Dec 16, 2024
CVE-2024-55085
9.8 CRITICAL

GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background management system, which can be used by an …

Dec 16, 2024
CVE-2024-35230
5.3 MEDIUM

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. In affected versions the welcome and …

Dec 16, 2024
CVE-2024-12443
6.4 MEDIUM

The CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'crm-perks-tickets' shortcode …

Dec 16, 2024
CVE-2024-55554
5.4 MEDIUM

Intrexx Portal Server before 12.0.2 allows XSS via a user-defined portlet.

Dec 16, 2024
CVE-2024-52949
7.5 HIGH

iptraf-ng 1.2.1 has a stack-based buffer overflow. In src/ifaces.c, the strcpy function consistently fails to control the size, and it is consequently possible to overflow …

Dec 16, 2024
CVE-2024-37776
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in Sunbird DCIM dcTrack v9.1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in some …

Dec 16, 2024
CVE-2024-37775
7.5 HIGH

Incorrect access control in Sunbird DCIM dcTrack v9.1.2 allows attackers to create or update a ticket with a location which bypasses an RBAC check.

Dec 16, 2024
CVE-2024-37774
8.0 HIGH

A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their privileges by forcing an Administrator user to perform sensitive …

Dec 16, 2024
CVE-2024-37773
4.8 MEDIUM

An HTML injection vulnerability in Sunbird DCIM dcTrack 9.1.2 allows attackers authenticated as administrators to inject arbitrary HTML code in an admin screen.

Dec 16, 2024
CVE-2024-29671
9.8 CRITICAL

Buffer Overflow vulnerability in NEXTU FLATA AX1500 Router v.1.0.2 allows a remote attacker to execute arbitrary code via the POST request handler component.

Dec 16, 2024
CVE-2024-55557
9.8 CRITICAL

ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credentials.

Dec 16, 2024
CVE-2024-55104
7.2 HIGH

Online Nurse Hiring System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component /admin/add-nurse.php via the gender and emailid parameters.

Dec 16, 2024
CVE-2024-55103
7.2 HIGH

Online Nurse Hiring System v1.0 was discovered to contain a SQL injection vulnerability in the component /admin/profile.php via the fullname parameter.

Dec 16, 2024
CVE-2024-55100
4.8 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Online Nurse Hiring System v1.0 allows attackers to execute arbitrary web scripts or HTML …

Dec 16, 2024
CVE-2024-55951

Metabase is an open-source data analytics platform. For new sandboxing configurations created in 1.52.0 till 1.52.2.4, sandboxed users are able to see field filter values …

Dec 16, 2024
CVE-2024-55949

MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a privilege escalation in IAM import API, …

Dec 16, 2024
CVE-2024-12687
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in PlexTrac (Runbooks modules) which allows Object Injection and arbitrary file writes. This issue affects PlexTrac: from 1.61.3 before 2.8.1.

Dec 16, 2024
CVE-2024-12667
3.7 LOW

A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /invoices/view. …

Dec 16, 2024
CVE-2024-12666
4.7 MEDIUM

A vulnerability has been found in ClassCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file …

Dec 16, 2024
CVE-2024-12665
3.5 LOW

A vulnerability, which was classified as problematic, was found in ruifang-tech Rebuild 3.8.5. Affected is an unknown function of the component Task Comment Attachment Upload. …

Dec 16, 2024
CVE-2024-12664
3.5 LOW

A vulnerability, which was classified as problematic, has been found in ruifang-tech Rebuild 3.8.5. This issue affects some unknown processing of the component Project Task …

Dec 16, 2024
CVE-2024-12663
3.7 LOW

A vulnerability classified as problematic was found in funnyzpc Mee-Admin up to 1.6. This vulnerability affects unknown code of the file /mee/login of the component …

Dec 16, 2024
CVE-2024-12662
5.5 MEDIUM

A vulnerability classified as problematic has been found in IObit Advanced SystemCare Utimate up to 17.0.0. This affects the function 0x8001E040 in the library AscRegistryFilter.sys …

Dec 16, 2024
CVE-2024-12661
5.5 MEDIUM

A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0. It has been rated as problematic. Affected by this issue is the function …

Dec 16, 2024
CVE-2024-6002

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Dec 16, 2024
CVE-2024-12660
5.5 MEDIUM

A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0. It has been declared as problematic. Affected by this vulnerability is the function …

Dec 16, 2024
CVE-2024-12659
5.5 MEDIUM

A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0. It has been classified as problematic. Affected is the function 0x8001E004 in the …

Dec 16, 2024
CVE-2024-12658
5.5 MEDIUM

A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0 and classified as problematic. This issue affects the function 0x8001E01C in the library …

Dec 16, 2024
CVE-2024-8058
7.6 HIGH

An improper parsing vulnerability was reported in the FileZ client that could allow a crafted file in the FileZ directory to read arbitrary files on …

Dec 16, 2024
CVE-2024-6001
8.1 HIGH

An improper certificate validation vulnerability was reported in LADM that could allow a network attacker with the ability to redirect an update request to a …

Dec 16, 2024
CVE-2024-4762
7.8 HIGH

An improper validation vulnerability was reported in the firmware update mechanism of LADM and LDCC that could allow a local attacker to escalate privileges.

Dec 16, 2024
CVE-2024-12657
5.5 MEDIUM

A vulnerability has been found in IObit Advanced SystemCare Utimate up to 17.0.0 and classified as problematic. This vulnerability affects the function 0x8001E000 in the …

Dec 16, 2024
CVE-2024-12656
5.5 MEDIUM

A vulnerability, which was classified as problematic, was found in FabulaTech USB over Network 6.0.6.1. This affects the function 0x220448 in the library ftusbbus2.sys of …

Dec 16, 2024
CVE-2024-12655
5.5 MEDIUM

A vulnerability, which was classified as problematic, has been found in FabulaTech USB over Network 6.0.6.1. Affected by this issue is the function 0x220420 in …

Dec 16, 2024
CVE-2024-11358
5.7 MEDIUM

Mattermost Android Mobile Apps versions <=2.21.0 fail to properly configure file providers which allows an attacker with local access to access files via file provider.

Dec 16, 2024
CVE-2024-11144
7.5 HIGH

The server lacks thread safety and can be crashed by anomalous data sent by an anonymous user from a remote network. The crash causes the …

Dec 16, 2024
CVE-2024-10095
8.4 HIGH

In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible through an insecure deserialization vulnerability.

Dec 16, 2024
CVE-2024-56003
4.3 MEDIUM

Missing Authorization vulnerability in David Cramer Caldera SMTP Mailer caldera-smtp-mailer.This issue affects Caldera SMTP Mailer: from n/a through <= 1.0.1.

Dec 16, 2024
CVE-2024-55999
5.3 MEDIUM

Missing Authorization vulnerability in Marco Giannini XML Multilanguage Sitemap Generator xml-multilanguage-sitemap-generator.This issue affects XML Multilanguage Sitemap Generator: from n/a through <= 2.0.6.

Dec 16, 2024
CVE-2024-54376
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Spider Themes EazyDocs eazydocs allows PHP Local File Inclusion.This …

Dec 16, 2024
CVE-2024-54357
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada avada.This issue affects Avada: from n/a through <= 7.11.10.

Dec 16, 2024
CVE-2024-54348
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yaycommerce Brand brand allows Stored XSS.This issue affects Brand: from n/a through <= …

Dec 16, 2024
CVE-2024-54285
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in SeedProd LLC SeedProd Pro allows Upload a Web Shell to a Web Server.This issue affects SeedProd …

Dec 16, 2024
CVE-2024-54284
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SeedProd LLC SeedProd Pro allows SQL Injection.This issue affects SeedProd Pro: …

Dec 16, 2024
CVE-2024-54283
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SeedProd LLC SeedProd Pro allows SQL Injection.This issue affects SeedProd Pro: …

Dec 16, 2024
CVE-2024-54280
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WPBookit wpbookit allows SQL Injection.This issue affects WPBookit: from …

Dec 16, 2024
CVE-2024-54279
7.5 HIGH

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tobias Keller WP-NERD Toolkit wp-nerd-toolkit.This issue affects WP-NERD Toolkit: from n/a through <= …

Dec 16, 2024
CVE-2024-54257
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Molefed allows Reflected XSS.This issue affects tydskrif: from n/a through 1.1.3.

Dec 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.