CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9192
8.8 HIGH

The WordPress Video Robot - The Ultimate Video Importer plugin for WordPress is vulnerable to privilege escalation due to insufficient validation on user meta that …

Nov 16, 2024
CVE-2024-8873
6.1 MEDIUM

The PeproDev WooCommerce Receipt Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …

Nov 16, 2024
CVE-2024-6628
4.3 MEDIUM

The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up …

Nov 16, 2024
CVE-2024-11118
5.3 MEDIUM

The 404 Error Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to …

Nov 16, 2024
CVE-2024-11092
6.4 MEDIUM

The SVGPlus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.1.0 …

Nov 16, 2024
CVE-2024-11085
5.4 MEDIUM

The WP Log Viewer plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on several AJAX actions in …

Nov 16, 2024
CVE-2024-10884
6.1 MEDIUM

The SimpleForm Contact Form Submissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping …

Nov 16, 2024
CVE-2024-10883
6.1 MEDIUM

The SimpleForm – Contact form made simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without …

Nov 16, 2024
CVE-2024-10875
6.1 MEDIUM

The Gallery Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_Query_Arg without appropriate escaping on the URL in …

Nov 16, 2024
CVE-2024-10533
4.3 MEDIUM

The WP Chat App plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the ajax_install_plugin() function in all …

Nov 16, 2024
CVE-2024-10262
6.3 MEDIUM

The The Drop Shadow Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.7.14. This is due …

Nov 16, 2024
CVE-2024-10147
6.4 MEDIUM

The Steel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn shortcode in all versions up to, and including, 1.3.0 due …

Nov 16, 2024
CVE-2024-10017
6.4 MEDIUM

The PJW Mime Config plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0 …

Nov 16, 2024
CVE-2024-10015
6.4 MEDIUM

The ConvertCalculator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'type' parameters in all versions up to, and …

Nov 16, 2024
CVE-2024-10861
5.3 MEDIUM

The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Nov 16, 2024
CVE-2024-10795
4.3 MEDIUM

The Popularis Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.7 via the 'elementor-template' shortcode due to …

Nov 16, 2024
CVE-2024-10786
4.3 MEDIUM

The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the sla_clear_user_cache function in all …

Nov 16, 2024
CVE-2024-11263
9.3 CRITICAL

When the Global Pointer (GP) relative addressing is enabled (CONFIG_RISCV_GP=y), the gp reg points at 0x800 bytes past the start of the .sdata section which …

Nov 15, 2024
CVE-2024-11262
5.3 MEDIUM

A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as critical. Affected by this vulnerability is the function main of …

Nov 15, 2024
CVE-2024-9500
7.8 HIGH

A maliciously crafted DLL file when placed in temporary files and folders that are leveraged by the Autodesk Installer could lead to escalation of privileges …

Nov 15, 2024
CVE-2024-51765
5.5 MEDIUM

A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.

Nov 15, 2024
CVE-2024-51764
5.5 MEDIUM

A security vulnerability has been identified in HPE Data Management Framework (DMF) Suite (CXFS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.

Nov 15, 2024
CVE-2024-50983
5.4 MEDIUM

FlightPath 7.5 contains a Cross Site Scripting (XSS) vulnerability, which allows authenticated remote attackers with administrative rights to inject arbitrary JavaScript in the web browser …

Nov 15, 2024
CVE-2024-38370
5.3 MEDIUM

GLPI is a free asset and IT management software package. Starting in 9.2.0 and prior to 11.0.0, it is possible to download a document from …

Nov 15, 2024
CVE-2024-11261
5.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Student Record Management System 1.0. Affected is an unknown function of the file StudentRecordManagementSystem.cpp …

Nov 15, 2024
CVE-2017-13314
7.8 HIGH

In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This could lead to local escalation of privilege …

Nov 15, 2024
CVE-2017-13313
6.5 MEDIUM

In ElementaryStreamQueue::dequeueAccessUnitMPEG4Video of ESQueue.cpp, there is a possible infinite loop leading to resource exhaustion due to an incorrect bounds check. This could lead to remote …

Nov 15, 2024
CVE-2017-13312
7.8 HIGH

In createFromParcel of MediaCas.java, there is a possible parcel read/write mismatch due to improper input validation. This could lead to local escalation of privilege where …

Nov 15, 2024
CVE-2017-13311
6.7 MEDIUM

In the read() function of ProcessStats.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local escalation of …

Nov 15, 2024
CVE-2017-13310
7.8 HIGH

In createFromParcel of ViewPager.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local escalation of privilege where …

Nov 15, 2024
CVE-2024-49592
6.7 MEDIUM

Trial installer for McAfee Total Protection (legacy trial installer software) 16.0.53 allows local privilege escalation because of an Uncontrolled Search Path Element. The attacker could …

Nov 15, 2024
CVE-2024-49060
8.8 HIGH

Azure Stack HCI Elevation of Privilege Vulnerability

Nov 15, 2024
CVE-2024-45611
5.7 MEDIUM

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can …

Nov 15, 2024
CVE-2024-45610
6.5 MEDIUM

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An unauthenticated user can …

Nov 15, 2024
CVE-2024-44758
9.8 CRITICAL

An arbitrary file upload vulnerability in the component /Production/UploadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to execute arbitrary code via uploading crafted files.

Nov 15, 2024
CVE-2024-11217
4.9 MEDIUM

A vulnerability was found in the OAuth-server. OAuth-server logs the OAuth2 client secret when the logLevel is Debug higher for OIDC/GitHub/GitLab/Google IDPs login options.

Nov 15, 2024
CVE-2017-13309
5.5 MEDIUM

In readEncryptedData of ConscryptEngine.java, there is a possible plaintext leak due to improperly used crypto. This could lead to local information disclosure with no additional …

Nov 15, 2024
CVE-2024-49536
5.5 MEDIUM

Audition versions 23.6.9, 24.4.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Nov 15, 2024
CVE-2024-45609
6.5 MEDIUM

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An unauthenticated user can …

Nov 15, 2024
CVE-2024-44759
7.5 HIGH

An arbitrary file download vulnerability in the component /Doc/DownloadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arbitrary files and access sensitive information …

Nov 15, 2024
CVE-2024-3334
4.3 MEDIUM

A security bypass vulnerability exists in the Removable Media Encryption (RME)component of Digital Guardian Windows Agents prior to version 8.2.0. This allows a user to …

Nov 15, 2024
CVE-2024-24459
5.9 MEDIUM

An invalid memory access when handling the ProtocolIE_ID field of S1Setup Request messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of …

Nov 15, 2024
CVE-2024-24458
5.9 MEDIUM

An invalid memory access when handling the ENB Configuration Transfer messages containing invalid PLMN Identities in Athonet vEPC MME v11.4.0 allows attackers to cause a …

Nov 15, 2024
CVE-2024-24457
5.9 MEDIUM

An invalid memory access when handling the ProtocolIE_ID field of E-RAB Setup List Context SURes messages in Athonet vEPC MME v11.4.0 allows attackers to cause …

Nov 15, 2024
CVE-2024-24455
5.9 MEDIUM

An invalid memory access when handling a UE Context Release message containing an invalid UE identifier in Athonet vEPC MME v11.4.0 allows attackers to cause …

Nov 15, 2024
CVE-2024-24454
5.9 MEDIUM

An invalid memory access when handling the ProtocolIE_ID field of E-RAB Modify Request messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial …

Nov 15, 2024
CVE-2024-24453
5.9 MEDIUM

An invalid memory access when handling the ProtocolIE_ID field of E-RAB NotToBeModifiedBearerModInd information element in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial …

Nov 15, 2024
CVE-2024-24452
5.9 MEDIUM

An invalid memory access when handling the ProtocolIE_ID field of E-RAB Release Indication messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial …

Nov 15, 2024
CVE-2024-11259
3.5 LOW

A vulnerability, which was classified as problematic, has been found in code-projects Farmacia 1.0. This issue affects some unknown processing of the file /fornecedores.php. The …

Nov 15, 2024
CVE-2024-11258
7.3 HIGH

A vulnerability classified as critical was found in 1000 Projects Beauty Parlour Management System 1.0. This vulnerability affects unknown code of the file /admin/index.php. The …

Nov 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.