CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-52912
7.5 HIGH

Bitcoin Core before 0.21.0 allows a network split that is resultant from an integer overflow (calculating the time offset for newly connecting peers) and an …

Nov 18, 2024
CVE-2024-38828
5.3 MEDIUM

Spring MVC controller methods with an @RequestBody byte[] method parameter are vulnerable to a DoS attack.

Nov 18, 2024
CVE-2019-25220
7.5 HIGH

Bitcoin Core before 24.0.1 allows remote attackers to cause a denial of service (daemon crash) via a flood of low-difficulty header chains (aka a "Chain …

Nov 18, 2024
CVE-2015-20111
9.8 CRITICAL

miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other products, lacks checks for snprintf return values, leading to a buffer overflow and …

Nov 18, 2024
CVE-2024-11306
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Altenergy Power Control Software up to 20241108. This issue affects some unknown processing of …

Nov 18, 2024
CVE-2024-11305
6.3 MEDIUM

A vulnerability classified as critical was found in Altenergy Power Control Software up to 20241108. This vulnerability affects the function get_status_zigbee of the file /index.php/display/status_zigbee. …

Nov 18, 2024
CVE-2023-43091
9.8 CRITICAL

A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file. If the configuration file is …

Nov 17, 2024
CVE-2024-0793
7.7 HIGH

A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking a .spec.behavior.scaleUp block causes a denial …

Nov 17, 2024
CVE-2023-6110
5.5 MEDIUM

A flaw was found in OpenStack. When a user tries to delete a non-existing access rule in it's scope, it deletes other existing access rules …

Nov 17, 2024
CVE-2023-4639
7.4 HIGH

A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct …

Nov 17, 2024
CVE-2023-1419
5.9 MEDIUM

A script injection vulnerability was found in the Debezium database connector, where it does not properly sanitize some parameters. This flaw allows an attacker to …

Nov 17, 2024
CVE-2023-0657
3.4 LOW

A flaw was found in Keycloak. This issue occurs due to improperly enforcing token types when validating signatures locally. This could allow an authenticated attacker …

Nov 17, 2024
CVE-2020-25720
7.5 HIGH

A vulnerability was found in Samba where a delegated administrator with permission to create objects in Active Directory can write to all attributes of the …

Nov 17, 2024
CVE-2024-52876
7.5 HIGH

Holy Stone Remote ID Module HSRID01, firmware distributed with the Drone Go2 mobile application before 1.1.8, allows unauthenticated "remote power off" actions (in broadcast mode) …

Nov 17, 2024
CVE-2024-52872
7.5 HIGH

In Flagsmith before 2.134.1, the get_document endpoint is not correctly protected by permissions.

Nov 17, 2024
CVE-2024-52871
7.5 HIGH

In Flagsmith before 2.134.1, it is possible to bypass the ALLOW_REGISTRATION_WITHOUT_INVITE setting.

Nov 17, 2024
CVE-2024-52867
8.1 HIGH

guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users before file metadata concerns (e.g., for setuid and …

Nov 17, 2024
CVE-2024-52397
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Davor Zeljkovic Convert Docx2post convert-docx2post allows Upload a Web Shell to a Web Server.This issue affects …

Nov 16, 2024
CVE-2024-52416
10.0 CRITICAL

Missing Authorization vulnerability in Eugen Bobrowski Debug Tool debug-tool allows Upload a Web Shell to a Web Server.This issue affects Debug Tool: from n/a through …

Nov 16, 2024
CVE-2024-52415
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in skipstorm SK WP Settings Backup sk-wp-settings-backup allows Object Injection.This issue affects SK WP Settings Backup: from n/a through <= …

Nov 16, 2024
CVE-2024-52414
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Anthony Carbon WDES Responsive Mobile Menu wdes-responsive-mobile-menu allows Object Injection.This issue affects WDES Responsive Mobile Menu: from n/a through …

Nov 16, 2024
CVE-2024-52413
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in dmcwebzone Airin Blog airin-blog allows Object Injection.This issue affects Airin Blog: from n/a through <= 1.6.1.

Nov 16, 2024
CVE-2024-52412
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Stephen Cui Xin allows Object Injection.This issue affects Xin: from n/a through 1.0.8.1.

Nov 16, 2024
CVE-2024-52411
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in flowcraft Advanced Personalization personalization-by-flowcraft allows Object Injection.This issue affects Advanced Personalization: from n/a through <= 1.1.2.

Nov 16, 2024
CVE-2024-52410
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Phoenixheart Referrer Detector referrer-detector allows Object Injection.This issue affects Referrer Detector: from n/a through <= 4.2.1.0.

Nov 16, 2024
CVE-2024-52409
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Phoenixheart AJAX Random Posts ajax-random-posts allows Object Injection.This issue affects AJAX Random Posts: from n/a through <= 0.3.3.

Nov 16, 2024
CVE-2024-52408
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in pushassist Push Notifications for WordPress by PushAssist push-notification-for-wp-by-pushassist allows Upload a Web Shell to a Web …

Nov 16, 2024
CVE-2024-52407
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in BasePress BasePress Migration Tools basepress-migration-tools allows Upload a Web Shell to a Web Server.This issue affects …

Nov 16, 2024
CVE-2024-52406
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in wibergsweb CSV to html csv-to-html allows Upload a Web Shell to a Web Server.This issue affects …

Nov 16, 2024
CVE-2024-52405
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in bikramjoshii B-Banner Slider b-banner-slider allows Upload a Web Shell to a Web Server.This issue affects B-Banner …

Nov 16, 2024
CVE-2024-52404
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in bigfiveagency CF7 Reply Manager cf7-reply-manager.This issue affects CF7 Reply Manager: from n/a through <= 1.2.3.

Nov 16, 2024
CVE-2024-52403
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Saad Iqbal User Management user-management allows Upload a Web Shell to a Web Server.This issue affects …

Nov 16, 2024
CVE-2024-52400
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Subhasis Laha Gallerio gallerio allows Upload a Web Shell to a Web Server.This issue affects Gallerio: …

Nov 16, 2024
CVE-2024-52399
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Clarisse K. Writer Helper writer-helper allows Upload a Web Shell to a Web Server.This issue affects …

Nov 16, 2024
CVE-2024-52398
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Halyra CDI collect-and-deliver-interface-for-woocommerce.This issue affects CDI: from n/a through <= 5.5.3.

Nov 16, 2024
CVE-2024-52386
5.3 MEDIUM

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Classified Listing classified-listing allows PHP Local File Inclusion.This …

Nov 16, 2024
CVE-2024-9887
7.2 HIGH

The Login using WordPress Users ( WP as SAML IDP ) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in …

Nov 16, 2024
CVE-2024-11094
5.3 MEDIUM

The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.35.17 via the export feature. This …

Nov 16, 2024
CVE-2024-10592
6.4 MEDIUM

The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the popup class parameter in all versions up to, and including, …

Nov 16, 2024
CVE-2024-10645
7.5 HIGH

The Blogger 301 Redirect plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘br’ parameter in all versions up to, and including, …

Nov 16, 2024
CVE-2024-10614
4.3 MEDIUM

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cancel_import() function in all …

Nov 16, 2024
CVE-2024-8856
9.8 CRITICAL

The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the …

Nov 16, 2024
CVE-2024-10728
8.8 HIGH

The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability …

Nov 16, 2024
CVE-2024-9938
6.1 MEDIUM

The Bounce Handler MailPoet 3 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, …

Nov 16, 2024
CVE-2024-9935
7.5 HIGH

The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.0.0 via …

Nov 16, 2024
CVE-2024-9850
6.4 MEDIUM

The SVG Case Study plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0 …

Nov 16, 2024
CVE-2024-9849
8.8 HIGH

The Real3D Flipbook Lite – 3D FlipBook, PDF Viewer, PDF Embedder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type …

Nov 16, 2024
CVE-2024-9839
7.3 HIGH

The The Uix Slideshow plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.6.5. This is due to …

Nov 16, 2024
CVE-2024-9615
6.1 MEDIUM

The BulkPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all …

Nov 16, 2024
CVE-2024-9386
6.4 MEDIUM

The Exclusive Divi – Divi Preloader, Modules for Divi & Extra Theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads …

Nov 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.