CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-52438
8.8 HIGH

Missing Authentication for Critical Function vulnerability in deco.agency de:branding debranding allows Privilege Escalation.This issue affects de:branding: from n/a through <= 1.0.2.

Nov 20, 2024
CVE-2024-52437
8.8 HIGH

Missing Authentication for Critical Function vulnerability in Saul Morales Pacheco Banner System banner-system allows Privilege Escalation.This issue affects Banner System: from n/a through <= 1.0.0.

Nov 20, 2024
CVE-2024-11406
6.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django CMS Attributes Fields allows Stored XSS.This issue …

Nov 20, 2024
CVE-2024-11404
5.5 MEDIUM

Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in django CMS Association django …

Nov 20, 2024
CVE-2024-10520
5.3 MEDIUM

The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'check' method of …

Nov 20, 2024
CVE-2024-48899
4.3 MEDIUM

A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they …

Nov 20, 2024
CVE-2024-45691
5.4 MEDIUM

A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be bypassed or less secure due …

Nov 20, 2024
CVE-2024-45690
7.5 HIGH

A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts.

Nov 20, 2024
CVE-2024-45689
6.5 MEDIUM

A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they did …

Nov 20, 2024
CVE-2024-10872
6.4 MEDIUM

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `template-post-custom-field` block in all versions up to, and including, …

Nov 20, 2024
CVE-2024-10382
7.5 HIGH

There exists a code execution vulnerability in the Car App Android Jetpack Library. CarAppService uses deserialization logic that allows construction of arbitrary java classes. This …

Nov 20, 2024
CVE-2024-11494
7.5 HIGH

**UNSUPPORTED WHEN ASSIGNED** The improper authentication vulnerability in the Zyxel P-6101C ADSL modem firmware version P-6101CSA6AP_20140331 could allow an unauthenticated attacker to read some device …

Nov 20, 2024
CVE-2024-11179
6.5 MEDIUM

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to SQL Injection via the 'status_type' parameter …

Nov 20, 2024
CVE-2024-10891
6.4 MEDIUM

The Save as PDF Plugin by Pdfcrowd plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'save_as_pdf_pdfcrowd' shortcode in all versions up …

Nov 20, 2024
CVE-2024-10665
5.4 MEDIUM

The Yaad Sarig Payment Gateway For WC plugin for WordPress is vulnerable to unauthorized modification & access of data due to a missing capability check …

Nov 20, 2024
CVE-2024-11176

Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an authenticated user to access object information via incorrect evaluation of effective permissions.

Nov 20, 2024
CVE-2024-10127
9.8 CRITICAL

Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLDAP configurations that allowed user authentication without a password when …

Nov 20, 2024
CVE-2024-10126
4.3 MEDIUM

Local File Inclusion vulnerability in M-Files Server in versions before 24.11 (excluding 24.8 SR1, 24.2 SR3 and 23.8 SR7) allows an authenticated user to read …

Nov 20, 2024
CVE-2024-52033
5.3 MEDIUM

Exposure of sensitive system information to an unauthorized control sphere issue exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If this vulnerability is …

Nov 20, 2024
CVE-2024-48895
8.8 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If …

Nov 20, 2024
CVE-2024-47865
5.3 MEDIUM

Missing authentication for critical function vulnerability exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If this vulnerability is exploited, a remote unauthenticated attacker …

Nov 20, 2024
CVE-2024-9239
6.1 MEDIUM

The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on …

Nov 20, 2024
CVE-2024-8726
6.1 MEDIUM

The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …

Nov 20, 2024
CVE-2024-11277
6.1 MEDIUM

The 404 Solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 2.35.19 due to insufficient …

Nov 20, 2024
CVE-2024-10900
6.5 MEDIUM

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Nov 20, 2024
CVE-2024-10899
7.3 HIGH

The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.6. This is …

Nov 20, 2024
CVE-2024-10855
8.1 HIGH

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of …

Nov 20, 2024
CVE-2024-10365
4.3 MEDIUM

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in …

Nov 20, 2024
CVE-2024-9653
6.1 MEDIUM

The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' parameter in all …

Nov 20, 2024
CVE-2024-52614
4.0 MEDIUM

Use of hard-coded cryptographic key issue exists in "Kura Sushi Official App Produced by EPARK" for Android versions prior to 3.8.5. If this vulnerability is …

Nov 20, 2024
CVE-2024-10515
3.5 LOW

In the process of testing the SEO Plugin by Squirrly SEO WordPress plugin before 12.3.21, a vulnerability was found that allows you to implement Stored …

Nov 20, 2024
CVE-2024-11278
6.1 MEDIUM

The GD bbPress Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Nov 20, 2024
CVE-2024-44309
6.3 MEDIUM KEV

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and …

Nov 20, 2024
CVE-2024-44308
8.8 HIGH KEV

The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS …

Nov 20, 2024
CVE-2024-44307
7.8 HIGH

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to execute …

Nov 20, 2024
CVE-2024-44306
7.8 HIGH

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to execute …

Nov 20, 2024
CVE-2018-9467
9.8 CRITICAL

In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could lead to incorrect security decisions with no additional …

Nov 20, 2024
CVE-2018-9466
8.8 HIGH

In the xmlSnprintfElementContent function of valid.c, there is a possible out of bounds write. This could lead to remote escalation of privilege in an unprivileged …

Nov 19, 2024
CVE-2018-9456
7.5 HIGH

In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of …

Nov 19, 2024
CVE-2018-9440
6.5 MEDIUM

In parse of M3UParser.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial of service with no additional …

Nov 19, 2024
CVE-2024-52595
7.7 HIGH

lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.0, the HTML Parser in lxml does not properly handle context-switching …

Nov 19, 2024
CVE-2024-52392
6.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in w3speedster W3SPEEDSTER w3speedster-wp.This issue affects W3SPEEDSTER: from n/a through <= 7.25.

Nov 19, 2024
CVE-2024-51669
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Kalmang Dynamic Widgets dynamic-widgets.This issue affects Dynamic Widgets: from n/a through <= 1.6.4.

Nov 19, 2024
CVE-2024-30424
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Beaver Builder Addons by WPZOOM wpzoom-addons-for-beaver-builder allows Stored XSS.This issue affects Beaver …

Nov 19, 2024
CVE-2024-11400
6.1 MEDIUM

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the really_curr_tax parameter in all versions up …

Nov 19, 2024
CVE-2023-27609
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in NetTantra WP Roles at Registration allows Stored XSS.This issue affects WP …

Nov 19, 2024
CVE-2018-9433
8.8 HIGH

In ArrayConcatVisitor of builtins-array.cc, there is a possible type confusion due to improper input validation. This could lead to remote code execution with no additional …

Nov 19, 2024
CVE-2018-9432
7.8 HIGH

In createPhonebookDialogView and createMapDialogView of BluetoothPermissionActivity.java, there is a possible permissions bypass. This could lead to local escalation of privilege due to hiding and bypassing …

Nov 19, 2024
CVE-2018-9428
7.8 HIGH

In startDevice of AAudioServiceStreamBase.cpp there is a possible out of bounds write due to a use after free. This could lead to local arbitrary code …

Nov 19, 2024
CVE-2018-9424
7.8 HIGH

In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Nov 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.