CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-11809
6.1 MEDIUM

The Primer MyData for Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'img_src' parameter in all versions up to, and including, …

Dec 13, 2024
CVE-2024-11767
6.4 MEDIUM

The NewsmanApp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'newsman_subscribe_widget' shortcode in all versions up to, and including, 2.7.6 due …

Dec 13, 2024
CVE-2024-12572
6.1 MEDIUM

The Hello In All Languages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6. This is due …

Dec 13, 2024
CVE-2024-12300
3.7 LOW

The AR for WordPress plugin for WordPress is vulnerable to unauthorized double extension file upload due to a missing capability check on the set_ar_featured_image() function …

Dec 13, 2024
CVE-2019-25221
6.5 MEDIUM

The Responsive Filterable Portfolio plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.8 due …

Dec 13, 2024
CVE-2024-12603
9.8 CRITICAL

A logic vulnerability in the the mobile application (com.transsion.applock) can lead to bypassing the application password.

Dec 13, 2024
CVE-2024-9508
7.8 HIGH

Horner Automation Cscape contains a memory corruption vulnerability, which could allow an attacker to disclose information and execute arbitrary code.

Dec 13, 2024
CVE-2024-12212
7.8 HIGH

The vulnerability occurs in the parsing of CSP files. The issues result from the lack of proper validation of user-supplied data, which could allow reading …

Dec 13, 2024
CVE-2024-12289
5.9 MEDIUM

Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initialization of the Boundary controller, which may cause the Boundary server to …

Dec 12, 2024
CVE-2024-55888
7.1 HIGH

Hush Line is an open-source whistleblower management system. Starting in version 0.1.0 and prior to version 0.3.5, the productions server appeared to have been misconfigured …

Dec 12, 2024
CVE-2024-55886
6.9 MEDIUM

OpenSearch Data Prepper is a component of the OpenSearch project that accepts, filters, transforms, enriches, and routes data at scale. A vulnerability exists in the …

Dec 12, 2024
CVE-2024-55885
7.5 HIGH

beego is an open-source web framework for the Go programming language. Versions of beego prior to 2.3.4 use MD5 as a hashing algorithm. MD5 is …

Dec 12, 2024
CVE-2024-55879
9.1 CRITICAL

XWiki Platform is a generic wiki platform. Starting in version 2.3 and prior to versions 15.10.9, 16.3.0, any user with script rights can perform arbitrary …

Dec 12, 2024
CVE-2024-55878
6.8 MEDIUM

SimpleXLSX is software for parsing and retrieving data from Excel XLSx files. Starting in version 1.0.12 and prior to version 1.1.12, when calling the extended …

Dec 12, 2024
CVE-2024-55877
9.9 CRITICAL

XWiki Platform is a generic wiki platform. Starting in version 9.7-rc-1 and prior to versions 15.10.11, 16.4.1, and 16.5.0, any user with an account can …

Dec 12, 2024
CVE-2024-55876
5.4 MEDIUM

XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0, any user with an account on the …

Dec 12, 2024
CVE-2024-55875
9.8 CRITICAL

http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 5.41.0.0, there is a potential XXE (XML External Entity Injection) vulnerability when http4k …

Dec 12, 2024
CVE-2024-55663
9.8 CRITICAL

XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 13.10.5 and 14.3-rc-1, in `getdocument.vm`; the ordering of the returned …

Dec 12, 2024
CVE-2024-54811
9.8 CRITICAL

A SQL injection vulnerability in /index.php in PHPGurukul Park Ticketing Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "login" parameter.

Dec 12, 2024
CVE-2024-49147
9.3 CRITICAL

Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver.

Dec 12, 2024
CVE-2024-49071
6.5 MEDIUM

Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over …

Dec 12, 2024
CVE-2024-55662
9.9 CRITICAL

XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extension Repository Application` is …

Dec 12, 2024
CVE-2024-54810
9.8 CRITICAL

A SQL Injection vulnerability was found in /preschool/admin/password-recovery.php in PHPGurukul Pre-School Enrollment System Project v1.0, which allows remote attackers to execute arbitrary code via the …

Dec 12, 2024
CVE-2024-47238
7.5 HIGH

Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit …

Dec 12, 2024
CVE-2024-31670
6.3 MEDIUM

rizin before v0.6.3 is vulnerable to Buffer Overflow via create_cache_bins, read_cache_accel, and rz_dyldcache_new_buf functions in librz/bin/format/mach0/dyldcache.c.

Dec 12, 2024
CVE-2024-55099
9.8 CRITICAL

A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers to execute arbitrary SQL commands to …

Dec 12, 2024
CVE-2024-52901
6.5 MEDIUM

IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to improper input validation.

Dec 12, 2024
CVE-2024-55633
6.5 MEDIUM

Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed SQL DML statement that is …

Dec 12, 2024
CVE-2024-54842
9.8 CRITICAL

A SQL injection vulnerability was found in phpgurukul Online Nurse Hiring System v1.0 in /admin/password-recovery.php via the mobileno parameter.

Dec 12, 2024
CVE-2024-21575
8.6 HIGH

ComfyUI-Impact-Pack is vulnerable to Path Traversal. The issue stems from missing validation of the `image.filename` field in a POST request sent to the `/upload/temp` endpoint …

Dec 12, 2024
CVE-2024-50584
4.4 MEDIUM

An authenticated attacker with the user/role "Poweruser" can perform an SQL injection by accessing the /class/template_io.php file and supplying malicious GET parameters. The "templates" parameter …

Dec 12, 2024
CVE-2024-28146
8.4 HIGH

The application uses several hard-coded credentials to encrypt config files during backup, to decrypt the new firmware during an update and some passwords allow a …

Dec 12, 2024
CVE-2024-28145
5.9 MEDIUM

An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, …

Dec 12, 2024
CVE-2024-28144
5.5 MEDIUM

An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the session because of flaws in the self-developed …

Dec 12, 2024
CVE-2024-28143
8.4 HIGH

The password change function at /cgi/admin.cgi does not require the current/old password, which makes the application vulnerable to account takeover. An attacker can use this …

Dec 12, 2024
CVE-2024-54122
6.2 MEDIUM

Concurrent variable access vulnerability in the ability module Impact: Successful exploitation of this vulnerability may affect availability.

Dec 12, 2024
CVE-2024-54119
6.2 MEDIUM

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Dec 12, 2024
CVE-2024-54118

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Dec 12, 2024
CVE-2024-47947
4.7 MEDIUM

Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The "Edit Disclaimer Text" …

Dec 12, 2024
CVE-2024-36498
4.7 MEDIUM

Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The "Edit Disclaimer Text" …

Dec 12, 2024
CVE-2024-36494
4.7 MEDIUM

Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The login page at …

Dec 12, 2024
CVE-2024-28142
4.7 MEDIUM

Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The "File Name" page …

Dec 12, 2024
CVE-2024-12271
4.4 MEDIUM

The 360 Javascript Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ref’ parameter in all versions up to, and including, 1.7.29 …

Dec 12, 2024
CVE-2024-9387
6.4 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could potentially …

Dec 12, 2024
CVE-2024-9367
4.3 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2, that allows an …

Dec 12, 2024
CVE-2024-8647
5.4 MEDIUM

An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted …

Dec 12, 2024
CVE-2024-8233
7.5 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions from 9.4 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could …

Dec 12, 2024
CVE-2024-8179
5.4 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. Improper output encoding …

Dec 12, 2024
CVE-2024-54117
6.2 MEDIUM

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Dec 12, 2024
CVE-2024-54116
4.3 MEDIUM

Out-of-bounds read vulnerability in the M3U8 module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Dec 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.