CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10393
5.3 MEDIUM

The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6. This is due to a …

Nov 21, 2024
CVE-2024-10316
4.3 MEDIUM

The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.4 in includes/templates/content-switcher.php. This …

Nov 21, 2024
CVE-2024-10177
6.4 MEDIUM

The Beds24 Online Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's beds24-link shortcode in all versions up to, and including, …

Nov 21, 2024
CVE-2024-10172
6.4 MEDIUM

The WPBakery Visual Composer WHMCS Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's void_wbwhmcse_laouts_search shortcode in all versions up to, …

Nov 21, 2024
CVE-2024-10164
6.4 MEDIUM

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdmpp_pay_link shortcode in all versions …

Nov 21, 2024
CVE-2022-43937
5.7 MEDIUM

Possible information exposure through log file vulnerability where sensitive fields are recorded in the debug-enabled logs when debugging is turned on in Brocade SANnav before …

Nov 21, 2024
CVE-2022-43936
6.8 MEDIUM

Brocade SANnav versions before 2.2.2 log Brocade Fabric OS switch passwords when debugging is enabled.

Nov 21, 2024
CVE-2022-43935
5.3 MEDIUM

An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where Brocade Fabric OS Switch passwords and authorization IDs are …

Nov 21, 2024
CVE-2022-43934
6.5 MEDIUM

Brocade SANnav before Brocade SANnav 2.2.2 supports key exchange algorithms, which are considered weak on ports 24, 6514, 18023, 19094, and 19095.

Nov 21, 2024
CVE-2022-43933
4.4 MEDIUM

An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where configuration secrets are logged in supportsave. Supportsave file is …

Nov 21, 2024
CVE-2024-9875
7.1 HIGH

Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo command bundles feature is enabled. …

Nov 21, 2024
CVE-2024-52755
4.9 MEDIUM

D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the host_ip parameter in the ipsec_road_asp function.

Nov 21, 2024
CVE-2024-51151
9.8 CRITICAL

D-Link DI-8200 16.07.26A1 is vulnerable to remote command execution in the msp_info_htm function via the flag parameter and cmd parameter.

Nov 21, 2024
CVE-2024-52765
9.8 CRITICAL

H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code execution (RCE) via the aspForm parameter.

Nov 20, 2024
CVE-2024-52702
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the component install\index.php of MyBB v1.8.38 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Nov 20, 2024
CVE-2024-52701
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Configuration page of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Nov 20, 2024
CVE-2024-52677
9.8 CRITICAL

HkCms <= v2.3.2.240702 is vulnerable to file upload in the getFileName method in /app/common/library/Upload.php.

Nov 20, 2024
CVE-2024-52581
7.5 HIGH

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.13.0, the multipart form parser shipped with litestar expects the entire request body …

Nov 20, 2024
CVE-2024-49203

Querydsl 5.1.0 and OpenFeign Querydsl 6.8 allows SQL/HQL injection in orderBy in JPAQuery. NOTE: this is disputed by a Querydsl community member because the product …

Nov 20, 2024
CVE-2024-48986
7.5 HIGH

An issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci packets by reading a byte from …

Nov 20, 2024
CVE-2024-48984
9.8 CRITICAL

An issue was discovered in MBed OS 6.16.0. When parsing hci reports, the hci parsing software dynamically determines the length of a list of reports …

Nov 20, 2024
CVE-2024-48982
7.5 HIGH

An issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci packets by reading a byte from …

Nov 20, 2024
CVE-2024-48536
7.5 HIGH

Incorrect access control in eSoft Planner 3.24.08271-USA allow attackers to view all transactions performed by the company via supplying a crafted web request.

Nov 20, 2024
CVE-2024-48535
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into …

Nov 20, 2024
CVE-2024-48534
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability on the Camp Details module of eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary code in the context of …

Nov 20, 2024
CVE-2024-48533
5.3 MEDIUM

A discrepancy between responses for valid and invalid e-mail accounts in the Forgot your Login? module of eSoft Planner 3.24.08271-USA allows attackers to enumerate valid …

Nov 20, 2024
CVE-2024-48531
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability on the Rental Availability module of eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary code in the context of …

Nov 20, 2024
CVE-2024-48530
7.5 HIGH

An issue in the Instructor Appointment Availability module of eSoft Planner 3.24.08271-USA allows attackers to cause a Denial of Service (DoS) via a crafted POST …

Nov 20, 2024
CVE-2024-52757
4.9 MEDIUM

D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the notify parameter in the arp_sys_asp function.

Nov 20, 2024
CVE-2024-52754
4.9 MEDIUM

D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the fn parameter in the tgfile_htm function.

Nov 20, 2024
CVE-2024-48985
7.5 HIGH

An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet data by reading …

Nov 20, 2024
CVE-2024-48983
7.5 HIGH

An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet data by reading …

Nov 20, 2024
CVE-2024-48981
7.5 HIGH

An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet header by looking …

Nov 20, 2024
CVE-2024-45510
5.4 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) through 10.0. Zimbra Webmail (Modern UI) is vulnerable to a stored Cross-Site Scripting (XSS) attack due to …

Nov 20, 2024
CVE-2024-45511
5.4 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A reflected Cross-Site Scripting (XSS) issue exists through the Briefcase module due to improper sanitization …

Nov 20, 2024
CVE-2024-33439
9.1 CRITICAL

An issue in Kasda LinkSmart Router KW5515 v1.7 and before allows an authenticated remote attacker to execute arbitrary OS commands via cgi parameters.

Nov 20, 2024
CVE-2024-52739
8.0 HIGH

D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple remote command execution (RCE) vulnerabilities in the msp_info_htm function via the flag and cmd parameters.

Nov 20, 2024
CVE-2024-29292
9.1 CRITICAL

Multiple OS Command Injection vulnerabilities affecting Kasda LinkSmart Router KW6512 <= v1.3 enable an authenticated remote attacker to execute arbitrary OS commands via various cgi …

Nov 20, 2024
CVE-2024-11493
3.5 LOW

A vulnerability classified as problematic was found in 115cms up to 20240807. This vulnerability affects unknown code of the file /index.php/setpage/admin/pageAE.html. The manipulation of the …

Nov 20, 2024
CVE-2024-11492
3.5 LOW

A vulnerability classified as problematic has been found in 115cms up to 20240807. This affects an unknown part of the file /index.php/admin/web/appurladd.html. The manipulation of …

Nov 20, 2024
CVE-2018-9487
5.5 MEDIUM

In setVpnForcedLocked of Vpn.java, there is a possible blocking of internet traffic through vpn due to a bad uid check. This could lead to local …

Nov 20, 2024
CVE-2018-9486
6.5 MEDIUM

In hidh_l2cif_data_ind of hidh_conn.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Nov 20, 2024
CVE-2018-9485
6.5 MEDIUM

In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure …

Nov 20, 2024
CVE-2018-9484
7.5 HIGH

In l2cu_send_peer_config_rej of l2c_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure …

Nov 20, 2024
CVE-2018-9483
6.5 MEDIUM

In bta_dm_remove_sec_dev_entry of bta_dm_act.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure …

Nov 20, 2024
CVE-2018-9482
6.5 MEDIUM

In intr_data_copy_cb of btif_hd.cc, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure in …

Nov 20, 2024
CVE-2018-9481
6.5 MEDIUM

In bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure in the Bluetooth …

Nov 20, 2024
CVE-2018-9480
6.5 MEDIUM

In bta_hd_get_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to improper input validation. This could lead to remote information disclosure in the Bluetooth …

Nov 20, 2024
CVE-2018-9479
9.8 CRITICAL

In process_service_attr_req and process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missing bounds check. This could lead to remote code …

Nov 20, 2024
CVE-2018-9478
9.8 CRITICAL

In process_service_attr_req and process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missing bounds check. This could lead to remote code …

Nov 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.