CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-23715
5.2 MEDIUM

Missing Authorization vulnerability in JobBoardWP JobBoardWP – Job Board Listings and Submissions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobBoardWP – Job …

Dec 9, 2024
CVE-2023-22708
4.3 MEDIUM

Missing Authorization vulnerability in Karim Salman Kraken.io Image Optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kraken.io Image Optimizer: from n/a through …

Dec 9, 2024
CVE-2023-22701
7.5 HIGH

Missing Authorization vulnerability in Shopfiles Ltd Ebook Store allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ebook Store: from n/a through 5.775.

Dec 9, 2024
CVE-2024-46901
3.1 LOW

Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, …

Dec 9, 2024
CVE-2024-12307
4.3 MEDIUM

A function-level access control vulnerability in Unifiedtransform version 2.0 and potentially earlier versions allows teachers to modify student personal data without proper authorization. The vulnerability …

Dec 9, 2024
CVE-2024-12306
4.3 MEDIUM

Multiple access control vulnerabilities in Unifiedtransform version 2.0 and potentially earlier versions allow unauthorized access to personal information of students and teachers. The vulnerabilities include …

Dec 9, 2024
CVE-2024-12305
4.3 MEDIUM

An object-level access control vulnerability in Unifiedtransform version 2.0 and potentially earlier versions allows unauthorized access to student grades. A malicious student user can view …

Dec 9, 2024
CVE-2024-9651
6.1 MEDIUM

The Fluent Forms WordPress plugin before 5.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Dec 9, 2024
CVE-2024-12360
6.3 MEDIUM

A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been rated as critical. This issue affects some unknown processing …

Dec 9, 2024
CVE-2024-12359
3.5 LOW

A vulnerability was found in code-projects Admin Dashboard 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /vendor_management.php. The …

Dec 9, 2024
CVE-2024-12358
6.3 MEDIUM

A vulnerability was found in WeiYe-Jing datax-web 2.1.1. It has been classified as critical. This affects an unknown part of the file /api/job/add/. The manipulation …

Dec 9, 2024
CVE-2024-12357
4.3 MEDIUM

A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of …

Dec 9, 2024
CVE-2024-53285
5.9 MEDIUM

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in DDNS Record functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated …

Dec 9, 2024
CVE-2024-53284
5.9 MEDIUM

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote …

Dec 9, 2024
CVE-2024-53283
5.9 MEDIUM

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Router Port Forward functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote …

Dec 9, 2024
CVE-2024-53282
5.9 MEDIUM

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect MAC Filter functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows …

Dec 9, 2024
CVE-2024-53281
5.9 MEDIUM

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Network WOL functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated …

Dec 9, 2024
CVE-2024-53280
5.9 MEDIUM

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in network center policy route functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows …

Dec 9, 2024
CVE-2024-53279
5.9 MEDIUM

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in file station functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated …

Dec 9, 2024
CVE-2024-55582
5.7 MEDIUM

Oxide before 6 has unencrypted Control Plane datastores.

Dec 9, 2024
CVE-2024-55580
7.5 HIGH

An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. Unprivileged users with network access may be able to execute remote …

Dec 9, 2024
CVE-2024-55579
8.8 HIGH

An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. An unprivileged user with network access may be able to create …

Dec 9, 2024
CVE-2024-55578
4.3 MEDIUM

Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files.

Dec 9, 2024
CVE-2024-55566
6.6 MEDIUM

ColPack 1.0.10 through 9a7293a has a predictable temporary file (located under /tmp with a name derived from an unseeded RNG). The impact can be overwriting …

Dec 9, 2024
CVE-2024-55565
4.3 MEDIUM

nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.

Dec 9, 2024
CVE-2024-55564
9.8 CRITICAL

The POSIX::2008 package before 0.24 for Perl has a potential _execve50c env buffer overflow.

Dec 9, 2024
CVE-2024-12355
3.3 LOW

A vulnerability has been found in SourceCodester Phone Contact Manager System 1.0 and classified as problematic. Affected by this vulnerability is the function ContactBook::adding of …

Dec 9, 2024
CVE-2024-12354
5.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Phone Contact Manager System 1.0. Affected is the function UserInterface::MenuDisplayStart of the component User …

Dec 9, 2024
CVE-2024-12353
3.3 LOW

A vulnerability, which was classified as problematic, has been found in SourceCodester Phone Contact Manager System 1.0. This issue affects the function UserInterface::MenuDisplayStart of the …

Dec 9, 2024
CVE-2024-12352
4.3 MEDIUM

A vulnerability classified as problematic was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affects the function sub_40662C of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Dec 9, 2024
CVE-2024-55563
5.3 MEDIUM

Bitcoin Core through 27.2 allows transaction-relay jamming via an off-chain protocol attack, a related issue to CVE-2024-52913. For example, the outcome of an HTLC (Hashed …

Dec 9, 2024
CVE-2024-12351
6.3 MEDIUM

A vulnerability classified as critical has been found in JFinalCMS 1.0. This affects the function findPage of the file src\main\java\com\cms\entity\ContentModel.java of the component File Content …

Dec 9, 2024
CVE-2024-12350
6.3 MEDIUM

A vulnerability was found in JFinalCMS 1.0. It has been rated as critical. Affected by this issue is the function update of the file \src\main\java\com\cms\controller\admin\TemplateController.java …

Dec 9, 2024
CVE-2024-12349
4.3 MEDIUM

A vulnerability was found in JFinalCMS 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/tag/save. …

Dec 9, 2024
CVE-2024-12348
3.5 LOW

A vulnerability was found in Guizhou Xiaoma Technology jpress 5.1.2. It has been classified as problematic. Affected is the function AttachmentUtils.isUnSafe of the file /commons/attachment/upload …

Dec 9, 2024
CVE-2024-12347
5.3 MEDIUM

A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms up to 1.0.0 and classified as critical. This issue affects some unknown processing of the …

Dec 9, 2024
CVE-2024-12346
3.5 LOW

A vulnerability has been found in Talentera up to 20241128 and classified as problematic. This vulnerability affects unknown code of the file /app/control/byt_cv_manager. The manipulation …

Dec 9, 2024
CVE-2024-55560
9.8 CRITICAL

MailCleaner before 28d913e has default values of ssh_host_dsa_key, ssh_host_rsa_key, and ssh_host_ed25519_key that persist after installation.

Dec 8, 2024
CVE-2024-12344
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in TP-Link VN020 F3v(T) TT_V6.2.1021. This affects an unknown part of the component FTP USER Command …

Dec 8, 2024
CVE-2024-12343
6.5 MEDIUM

A vulnerability classified as critical has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected is an unknown function of the file /control/WANIPConnection of the component …

Dec 8, 2024
CVE-2024-12342
6.5 MEDIUM

A vulnerability was found in TP-Link VN020 F3v(T) TT_V6.2.1021. It has been rated as critical. This issue affects some unknown processing of the file /control/WANIPConnection …

Dec 8, 2024
CVE-2024-12209
9.8 CRITICAL

The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.17.0 …

Dec 8, 2024
CVE-2024-53473
7.5 HIGH

WeGIA 3.2.0 before 3998672 does not verify permission to change a password.

Dec 7, 2024
CVE-2024-47107
6.4 MEDIUM

IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus …

Dec 7, 2024
CVE-2024-41762
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server …

Dec 7, 2024
CVE-2024-47115
7.8 HIGH

IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improper neutralization …

Dec 7, 2024
CVE-2024-37071
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user to cause a denial of …

Dec 7, 2024
CVE-2024-11501
8.8 HIGH

The Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3 via deserialization of untrusted input from …

Dec 7, 2024
CVE-2024-11464
6.1 MEDIUM

The Easy Code Snippets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0.2 …

Dec 7, 2024
CVE-2024-11457
6.1 MEDIUM

The Feedpress Generator – External RSS Frontend Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up …

Dec 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.