CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-11182
6.1 MEDIUM KEV

An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img …

Nov 15, 2024
CVE-2024-10534
9.8 CRITICAL

Origin Validation Error vulnerability in Dataprom Informatics Personnel Attendance Control Systems (PACS) / Access Control Security Systems (ACSS) allows Traffic Injection.This issue affects Personnel Attendance …

Nov 15, 2024
CVE-2024-10443
9.8 CRITICAL

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 …

Nov 15, 2024
CVE-2024-0875
4.8 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in openemr/openemr version 7.0.1. An attacker can inject malicious payloads into the 'inputBody' field in the Secure Messaging …

Nov 15, 2024
CVE-2024-0787
5.9 MEDIUM

phpIPAM version 1.5.1 contains a vulnerability where an attacker can bypass the IP block mechanism to brute force passwords for users by using the 'X-Forwarded-For' …

Nov 15, 2024
CVE-2023-4679
5.5 MEDIUM

A use after free vulnerability exists in GPAC version 2.3-DEV-revrelease, specifically in the gf_filterpacket_del function in filter_core/filter.c at line 38. This vulnerability can lead to …

Nov 15, 2024
CVE-2023-2332
4.8 MEDIUM

A stored Cross-site Scripting (XSS) vulnerability exists in the Conditions tab of Pricing Rules in pimcore/pimcore versions 10.5.19. The vulnerability is present in the From …

Nov 15, 2024
CVE-2023-0737
6.5 MEDIUM

wallabag version 2.5.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to arbitrarily delete user accounts via the /account/delete endpoint. This issue is …

Nov 15, 2024
CVE-2023-0109
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a JavaScript file containing a malicious …

Nov 15, 2024
CVE-2022-1884
9.8 CRITICAL

A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to improper validation of the …

Nov 15, 2024
CVE-2022-1226
4.8 MEDIUM

A Cross-Site Scripting (XSS) vulnerability in phpipam/phpipam versions prior to 1.4.7 allows attackers to execute arbitrary JavaScript code in the browser of a victim. This …

Nov 15, 2024
CVE-2021-3991
4.3 MEDIUM

An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to …

Nov 15, 2024
CVE-2021-3988
6.1 MEDIUM

A Cross-site Scripting (XSS) vulnerability exists in janeczku/calibre-web, specifically in the file `edit_books.js`. The vulnerability occurs when editing book properties, such as uploading a cover …

Nov 15, 2024
CVE-2021-3987
4.3 MEDIUM

An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without public shelf permissions to create public shelves. The vulnerability is due …

Nov 15, 2024
CVE-2021-3986
4.3 MEDIUM

A vulnerability in janeczku/calibre-web allows unauthorized users to view the names of private shelves belonging to other users. This issue occurs in the file shelf.py …

Nov 15, 2024
CVE-2021-3902
9.8 CRITICAL

An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Request Forgery (SSRF) and deserialization attacks. This issue affects all …

Nov 15, 2024
CVE-2021-3841
5.4 MEDIUM

sylius/sylius versions prior to 1.9.10, 1.10.11, and 1.11.2 are vulnerable to stored cross-site scripting (XSS) through SVG files. This vulnerability allows attackers to inject malicious …

Nov 15, 2024
CVE-2021-3838
9.8 CRITICAL

DomPDF before version 2.0.0 is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the file_get_contents() function. …

Nov 15, 2024
CVE-2021-3742
8.8 HIGH

A Server-Side Request Forgery (SSRF) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.5.0. The vulnerability allows an attacker to upload an SVG …

Nov 15, 2024
CVE-2021-3741
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.6. The vulnerability occurs when a user uploads an SVG …

Nov 15, 2024
CVE-2021-3740
6.8 MEDIUM

A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The application does not invalidate existing sessions on other devices when a user changes …

Nov 15, 2024
CVE-2024-8979
8.0 HIGH

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in …

Nov 15, 2024
CVE-2024-8978
5.7 MEDIUM

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in …

Nov 15, 2024
CVE-2024-10311
7.5 HIGH

The External Database Based Actions plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.1. This is due to a …

Nov 15, 2024
CVE-2024-45784
7.5 HIGH

Apache Airflow versions before 2.10.3 contain a vulnerability that could expose sensitive configuration variables in task logs. This vulnerability allows DAG authors to unintentionally or …

Nov 15, 2024
CVE-2024-9529
6.6 MEDIUM

The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not …

Nov 15, 2024
CVE-2024-8961
6.4 MEDIUM

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Nov 15, 2024
CVE-2024-10825
6.1 MEDIUM

The Hide My WP Ghost – Security & Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL in all versions up …

Nov 15, 2024
CVE-2024-10104
5.9 MEDIUM

The Jobs for WordPress plugin before 2.7.8 does not sanitise and escape some of its Job settings, which could allow high privilege users such as …

Nov 15, 2024
CVE-2024-9356
6.1 MEDIUM

The Yotpo: Product & Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'yotpo_user_email' and 'yotpo_user_name' parameters in all …

Nov 15, 2024
CVE-2024-42499
5.3 MEDIUM

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an …

Nov 15, 2024
CVE-2024-39610
6.1 MEDIUM

Cross-site scripting vulnerability exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an arbitrary script may be executed on the web browser …

Nov 15, 2024
CVE-2024-10793
7.2 HIGH

The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all versions up to, and including, 5.2.1 …

Nov 15, 2024
CVE-2024-10582
4.3 MEDIUM

The Music Player for Elementor – Audio Player & Podcast Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Nov 15, 2024
CVE-2024-10260
7.2 HIGH

The Tripetto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via File uploads in all versions up to, and including, 8.0.11 due to insufficient …

Nov 15, 2024
CVE-2024-10113
6.4 MEDIUM

The WP AdCenter – Ad Manager & Adsense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpadcenter_ad shortcode in all …

Nov 15, 2024
CVE-2024-9609
6.1 MEDIUM

The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'learnpress_import_form_server' parameter in all versions …

Nov 15, 2024
CVE-2024-10897
4.3 MEDIUM

The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the install_etlms_dependency_plugin() function in …

Nov 15, 2024
CVE-2024-10924
9.8 CRITICAL

The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due …

Nov 15, 2024
CVE-2024-11120
9.8 CRITICAL KEV

Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on …

Nov 15, 2024
CVE-2024-52613
5.5 MEDIUM

A heap-based buffer under-read in tsMuxer version nightly-2024-05-12-02-01-18 allows attackers to cause Denial of Service (DoS) via a crafted MOV video file.

Nov 14, 2024
CVE-2024-52308
8.0 HIGH

The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code execution through a malicious codespace SSH server when using `gh codespace ssh` or …

Nov 14, 2024
CVE-2024-49778
8.8 HIGH

A heap-based buffer overflow in tsMuxer version nightly-2024-05-12-02-01-18 allows attackers to cause Denial of Service (DoS) and Code Execution via a crafted MOV video file.

Nov 14, 2024
CVE-2024-49777
8.8 HIGH

A heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service (DoS), Information Disclosure and Code Execution via a crafted MKV …

Nov 14, 2024
CVE-2024-49776
6.5 MEDIUM

A negative-size-param in tsMuxer version nightly-2024-04-05-01-53-02 allows attackers to cause Denial of Service (DoS) via a crafted TS video file.

Nov 14, 2024
CVE-2024-41217
6.5 MEDIUM

A heap-based buffer overflow in tsMuxer version nightly-2024-05-10-02-00-45 allows attackers to cause Denial of Service (DoS) via a crafted MKV video file.

Nov 14, 2024
CVE-2024-41209
8.8 HIGH

A heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service (DoS) and Code Execution via a crafted MOV video file.

Nov 14, 2024
CVE-2024-41206
6.5 MEDIUM

A stack-based buffer over-read in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Information Disclosure via a crafted TS video file.

Nov 14, 2024
CVE-2017-13227
5.5 MEDIUM

In the autofill service, the package name that is provided by the app process is trusted inappropriately. This could lead to information disclosure with no …

Nov 14, 2024
CVE-2024-51679
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in gentlesource Appointmind appointmind allows Stored XSS.This issue affects Appointmind: from n/a through <= 4.0.0.

Nov 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.