CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-11903
6.4 MEDIUM

The WP eCards plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ecard' shortcode in all versions up to, and including, 1.3.904 …

Dec 4, 2024
CVE-2024-11769
6.4 MEDIUM

The Flower Delivery by Florist One plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'flower-delivery' shortcode in all versions up to, …

Dec 4, 2024
CVE-2024-11466
6.1 MEDIUM

The Intro Tour Tutorial DeepPresentation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, …

Dec 4, 2024
CVE-2024-11293
8.1 HIGH

The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction Social Sites Login plugin for WordPress is vulnerable …

Dec 4, 2024
CVE-2024-10664
4.3 MEDIUM

The Knowledge Base documentation & wiki plugin – BasePress Docs plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Dec 4, 2024
CVE-2023-6978
6.1 MEDIUM

The WP Job Manager – Company Profiles plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'company' parameter in all versions up to, …

Dec 4, 2024
CVE-2024-45717
7.0 HIGH

The SolarWinds Platform was susceptible to a XSS vulnerability that affects the search and node information section of the user interface. This vulnerability requires authentication …

Dec 4, 2024
CVE-2024-11398
8.1 HIGH

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in OTP reset functionality in Synology Router Manager (SRM) before 1.3.1-9346-9 allows remote …

Dec 4, 2024
CVE-2023-52944
4.3 MEDIUM

Incorrect authorization vulnerability in ActionRule webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to perform limited actions on the …

Dec 4, 2024
CVE-2023-52943
4.3 MEDIUM

Incorrect authorization vulnerability in Alert.Setting webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to to perform limited actions on …

Dec 4, 2024
CVE-2024-54664

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-52945. Reason: This candidate is a reservation duplicate of CVE-2024-52945. Notes: All CVE users should reference …

Dec 4, 2024
CVE-2024-54661
9.8 CRITICAL

readline.sh in socat before1.8.0.2 relies on the /tmp/$USER/stderr2 file.

Dec 4, 2024
CVE-2024-9404
7.5 HIGH

This vulnerability could lead to denial-of-service or service crashes. Exploitation of the moxa_cmd service, because of insufficient input validation, allows attackers to disrupt operations. If …

Dec 4, 2024
CVE-2024-12123

A hidden field manipulation vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user. When an authenticated user submits a …

Dec 4, 2024
CVE-2024-12099
4.3 MEDIUM

The Dollie Hub – Build Your Own WordPress Cloud Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, …

Dec 4, 2024
CVE-2024-10885
6.4 MEDIUM

The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, …

Dec 4, 2024
CVE-2024-11897
6.4 MEDIUM

The Contact Form, Survey & Form Builder – MightyForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mightyforms' shortcode in all …

Dec 4, 2024
CVE-2024-11813
6.1 MEDIUM

The Pulsating Chat Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.1. This is due to …

Dec 4, 2024
CVE-2024-11807
6.1 MEDIUM

The NPS computy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'data1' and 'data2' parameters in all versions up to, and including, …

Dec 4, 2024
CVE-2024-11747
6.4 MEDIUM

The Responsive Videos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'somryv' shortcode in all versions up to, and including, 2.1 …

Dec 4, 2024
CVE-2024-11093
5.5 MEDIUM

The SG Helper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in version 1.0 due to insufficient input sanitization and …

Dec 4, 2024
CVE-2024-10952
7.3 HIGH

The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution via update_authors_list_ajax AJAX action in all versions up to, and including, 2.0.4. …

Dec 4, 2024
CVE-2024-10832
6.1 MEDIUM

The Posti Shipping plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the account_number and secret_key parameters in all versions up to, and including, …

Dec 4, 2024
CVE-2024-10663
4.3 MEDIUM

The Eleblog – Elementor Blog And Magazine Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Dec 4, 2024
CVE-2024-10587
8.8 HIGH

The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to PHP Object …

Dec 4, 2024
CVE-2024-45207
7.0 HIGH

DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the agent runs, it searches these directories …

Dec 4, 2024
CVE-2024-45206
6.5 MEDIUM

A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get …

Dec 4, 2024
CVE-2024-45205
7.1 HIGH

An Improper Certificate Validation on the UniFi iOS App managing a standalone UniFi Access Point (not using UniFi Network Application) could allow a malicious actor …

Dec 4, 2024
CVE-2024-45204
4.3 MEDIUM

A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved credentials. The exploitation involves using …

Dec 4, 2024
CVE-2024-42457
6.5 MEDIUM

A vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by leveraging a combination of methods in a …

Dec 4, 2024
CVE-2024-42456
8.8 HIGH

A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates critical configuration settings, …

Dec 4, 2024
CVE-2024-42455
8.1 HIGH

A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserialization by sending a serialized temporary …

Dec 4, 2024
CVE-2024-42453
8.1 HIGH

A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructure hosts. This includes the ability to power …

Dec 4, 2024
CVE-2024-42452
8.8 HIGH

A vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and obtain credentials, effectively escalating privileges …

Dec 4, 2024
CVE-2024-42451
6.5 MEDIUM

A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. This is achieved by calling a series of …

Dec 4, 2024
CVE-2024-42449
7.1 HIGH

From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to remove arbitrary files on …

Dec 4, 2024
CVE-2024-40717
8.8 HIGH

A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs. These …

Dec 4, 2024
CVE-2024-11985
4.4 MEDIUM

An improper input validation vulnerability leads to device crashes in certain ASUS router models. Refer to the '12/03/2024 ASUS Router Improper Input Validation' section on …

Dec 4, 2024
CVE-2024-11479

A HTML Injection vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user. HTML markup could be added to comments …

Dec 4, 2024
CVE-2024-46624
8.8 HIGH

An issue in InfoDom Performa 365 v4.0.1 allows authenticated attackers to elevate their privileges to Administrator via a crafted payload sent to /api/users.

Dec 3, 2024
CVE-2024-53502
3.8 LOW

Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page.

Dec 3, 2024
CVE-2024-51363
9.8 CRITICAL

Insecure deserialization in Hodoku v2.3.0 to v2.3.2 allows attackers to execute arbitrary code.

Dec 3, 2024
CVE-2024-46625
8.8 HIGH

An authenticated arbitrary file upload vulnerability in the /documentCache/upload endpoint of InfoDom Performa 365 v4.0.1 allows attackers to execute arbitrary code via uploading a crafted …

Dec 3, 2024
CVE-2024-40391

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Dec 3, 2024
CVE-2024-54131

The Kolide Agent (aka: Launcher) is the lightweight agent designed to work with Kolide's service. An implementation bug in the Kolide Agent (known as `launcher`) …

Dec 3, 2024
CVE-2024-53672
4.7 MEDIUM

A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploit could …

Dec 3, 2024
CVE-2024-51773
4.8 MEDIUM

A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote Attacker to conduct a stored cross-site scripting …

Dec 3, 2024
CVE-2024-51772
6.4 MEDIUM

An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful …

Dec 3, 2024
CVE-2024-45757
7.2 HIGH

An issue was discovered in Centreon centreon-bam 24.04, 23.10, 23.04, and 22.10. SQL injection can occur in the user-settings form. Exploitation is only accessible to …

Dec 3, 2024
CVE-2024-51771
7.2 HIGH

A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote threat actor to conduct a remote code …

Dec 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.