CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10579
4.3 MEDIUM

The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check …

Nov 26, 2024
CVE-2024-10308
6.4 MEDIUM

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's JKit - Countdown widget in all versions up to, …

Nov 26, 2024
CVE-2024-11680
9.8 CRITICAL KEV

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to …

Nov 26, 2024
CVE-2024-11032
6.1 MEDIUM

The Parsi Date plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in …

Nov 26, 2024
CVE-2024-9170
5.5 MEDIUM

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wcj_product_meta shortcode in all versions up to, and including, …

Nov 26, 2024
CVE-2024-11192
6.4 MEDIUM

The Spotify Play Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's spotifyplaybutton shortcode in all versions up to, …

Nov 26, 2024
CVE-2024-11119
6.4 MEDIUM

The BNE Gallery Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' shortcode in all versions up to, and including, …

Nov 26, 2024
CVE-2024-11091
6.4 MEDIUM

The Support SVG – Upload svg files in wordpress without hassle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File …

Nov 26, 2024
CVE-2018-11952
8.4 HIGH

An image with a version lower than the fuse version may potentially be booted lead to improper authentication.

Nov 26, 2024
CVE-2018-11922
9.8 CRITICAL

Wrong configuration in Touch Pal application can collect user behavior data without awareness by the user.

Nov 26, 2024
CVE-2017-18153
8.4 HIGH

A race condition exists in a driver potentially leading to a use-after-free condition.

Nov 26, 2024
CVE-2017-17772
9.8 CRITICAL

In multiple functions that process 802.11 frames, out-of-bounds reads can occur due to insufficient validation.

Nov 26, 2024
CVE-2017-15832
8.4 HIGH

Buffer overwrite in the WLAN host driver by leveraging a compromised WLAN FW

Nov 26, 2024
CVE-2017-11076
9.8 CRITICAL

On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an …

Nov 26, 2024
CVE-2016-10394
8.4 HIGH

Initial xbl_sec revision does not have all the debug policy features and critical checks.

Nov 26, 2024
CVE-2024-9504
7.2 HIGH

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and …

Nov 26, 2024
CVE-2024-8772
4.3 MEDIUM

51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API managedoverlayimages.cgi was vulnerable to a race condition attack allowing for …

Nov 26, 2024
CVE-2024-8160
3.8 LOW

Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a sufficient input validation …

Nov 26, 2024
CVE-2024-6831
4.4 MEDIUM

Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program has found that it is possible to edit and/or remove views without the necessary …

Nov 26, 2024
CVE-2024-47257
7.5 HIGH

Florent Thiéry has found that selected Axis devices were vulnerable to handling certain ethernet frames which could lead to the Axis device becoming unavailable in …

Nov 26, 2024
CVE-2024-36254
7.5 HIGH

Out-of-bounds read vulnerability exists in Sharp Corporation and Toshiba Tec Corporation multiple MFPs (multifunction printers), which may lead to a denial-of-service (DoS) condition.

Nov 26, 2024
CVE-2024-36251
7.5 HIGH

The web interface of the affected devices process some crafted HTTP requests improperly, leading to a device crash. More precisely, a crafted parameter to billcodedef_sub_sel.html …

Nov 26, 2024
CVE-2024-36249
7.4 HIGH

Cross-site scripting vulnerability exists in Sharp Corporation and Toshiba Tech Corporation multiple MFPs (multifunction printers). If this vulnerability is exploited, an arbitrary script may be …

Nov 26, 2024
CVE-2024-36248
9.1 CRITICAL

API keys for some cloud services are hardcoded in the "main" binary. As for the details of affected product names, model numbers, and versions, refer …

Nov 26, 2024
CVE-2024-35244
9.1 CRITICAL

There are several hidden accounts. Some of them are intended for maintenance engineers, and with the knowledge of their passwords (e.g., by examining the coredump), …

Nov 26, 2024
CVE-2024-34162
5.3 MEDIUM

The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users. But configuring LDAP authentication to "SIMPLE", the …

Nov 26, 2024
CVE-2024-33616
5.3 MEDIUM

Admin authentication can be bypassed with some specific invalid credentials, which allows logging in with an administrative privilege. Sharp Corporation states the telnet feature is …

Nov 26, 2024
CVE-2024-33610
9.1 CRITICAL

"sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides logged-in users' session information including session cookies, and "sys_trayentryreboot.html" allows to reboot the device. As …

Nov 26, 2024
CVE-2024-33605
7.5 HIGH

Improper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for the details of affected product names, model numbers, and versions, …

Nov 26, 2024
CVE-2024-32151
5.9 MEDIUM

User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for …

Nov 26, 2024
CVE-2024-29978
5.9 MEDIUM

User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for …

Nov 26, 2024
CVE-2024-29146
5.9 MEDIUM

User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for …

Nov 26, 2024
CVE-2024-28955
5.9 MEDIUM

Affected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the device can examine the coredump files, and research …

Nov 26, 2024
CVE-2024-28038
9.0 CRITICAL

The web interface of the affected devices processes a cookie value improperly, leading to a stack buffer overflow. More precisely, giving too long character string …

Nov 26, 2024
CVE-2024-11202
6.1 MEDIUM

Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in various versions due to insufficient input sanitization and output escaping. …

Nov 26, 2024
CVE-2024-6749
6.3 MEDIUM

Seth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may expose sensitive credentials on the …

Nov 26, 2024
CVE-2024-6476
4.2 MEDIUM

Gee-netics, member of the AXIS Camera Station Pro Bug Bounty Program has found that it is possible for a non-admin user to gain system privileges …

Nov 26, 2024
CVE-2024-11002
6.3 MEDIUM

The The InPost Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution via the inpost_gallery_get_shortcode_template AJAX action in all versions up to, and including, …

Nov 26, 2024
CVE-2024-10857
6.5 MEDIUM

The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9 via the handle_downloads() …

Nov 26, 2024
CVE-2024-10781
8.1 HIGH

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on …

Nov 26, 2024
CVE-2024-10570
7.5 HIGH

The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized SQL Injection due to an authorization bypass via reverse DNS spoofing …

Nov 26, 2024
CVE-2024-10542
9.8 CRITICAL

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS …

Nov 26, 2024
CVE-2024-10471
4.8 MEDIUM

The Everest Forms WordPress plugin before 3.0.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Nov 26, 2024
CVE-2024-53278
4.8 MEDIUM

Cross-site scripting vulnerability exists in WP Admin UI Customize versions prior to ver 1.5.14. If a malicious admin user customizes the admin screen with some …

Nov 26, 2024
CVE-2018-11881

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. This CVE ID is unused and any reference to it …

Nov 26, 2024
CVE-2024-49353
7.5 HIGH

IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data 4.0.0 through 5.0.2 does not properly check inputs to resources that are used concurrently, …

Nov 26, 2024
CVE-2024-49351
5.5 MEDIUM

IBM Workload Scheduler 9.5, 10.1, and 10.2 stores user credentials in plain text which can be read by a local user.

Nov 26, 2024
CVE-2024-11418
6.1 MEDIUM

The Additional Order Filters for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shipping_method_filter' parameter in all versions up to, and …

Nov 26, 2024
CVE-2024-11342
6.1 MEDIUM

The Skt NURCaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.5.0. This is due to missing …

Nov 26, 2024
CVE-2024-49597
7.6 HIGH

Dell Wyse Management Suite, versions WMS 4.4 and prior, contain an Improper Restriction of Excessive Authentication Attempts vulnerability. A high privileged attacker with remote access …

Nov 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.