CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-51659
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in GeekRMX Twitter @Anywhere Plus twitter-anywhere-plus allows Stored XSS.This issue affects Twitter @Anywhere Plus: from n/a through <= 2.0.

Nov 14, 2024
CVE-2024-51658
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Henrik Hoff WP Course Manager wp-course-manager allows Stored XSS.This issue affects WP Course Manager: from n/a through <= 1.3.

Nov 14, 2024
CVE-2024-51156
4.7 MEDIUM

07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component 'erp.07fly.net:80/admin/SysNotifyUser/del.html?id=93'.

Nov 14, 2024
CVE-2024-50968
7.5 HIGH

A business logic vulnerability exists in the Add to Cart function of itsourcecode Agri-Trading Online Shopping System 1.0, which allows remote attackers to manipulate the …

Nov 14, 2024
CVE-2024-48974
9.3 CRITICAL

The ventilator does not perform proper file integrity checks when adopting firmware updates. This makes it possible for an attacker to force unauthorized changes to …

Nov 14, 2024
CVE-2024-48973
9.3 CRITICAL

The debug port on the ventilator's serial interface is enabled by default. This could allow an attacker to send and receive messages over the debug …

Nov 14, 2024
CVE-2024-48971
9.3 CRITICAL

The Clinician Password and Serial Number Clinician Password are hard-coded into the ventilator in plaintext form. This could allow an attacker to obtain the password …

Nov 14, 2024
CVE-2024-48970
9.3 CRITICAL

The ventilator's microcontroller lacks memory protection. An attacker could connect to the internal JTAG interface and read or write to flash memory using an off-the-shelf …

Nov 14, 2024
CVE-2024-48967
10.0 CRITICAL

The ventilator and the Service PC lack sufficient audit logging capabilities to allow for detection of malicious activity and subsequent forensic examination. An attacker with …

Nov 14, 2024
CVE-2024-48966
10.0 CRITICAL

The software tools used by service personnel to test & calibrate the ventilator do not support user authentication. An attacker with access to the Service …

Nov 14, 2024
CVE-2024-40579
5.4 MEDIUM

Cross Site Scripting vulnerability in Virtuozzo Hybrid Server for WHMCS Open Source v.1.7.1 allows a remote attacker to obtain sensitive information via modification of the …

Nov 14, 2024
CVE-2024-39707
5.3 MEDIUM

Insyde IHISI function 0x49 can restore factory defaults for certain UEFI variables without further authentication by default, which could lead to a possible roll-back attack …

Nov 14, 2024
CVE-2024-31695
9.8 CRITICAL

A misconfiguration in the fingerprint authentication mechanism of Binance: BTC, Crypto and NFTS v2.85.4, allows attackers to bypass authentication when adding a new fingerprint.

Nov 14, 2024
CVE-2024-9834
9.3 CRITICAL

Improper data protection on the ventilator's serial interface could allow an attacker to send and receive messages that result in unauthorized disclosure of information and/or …

Nov 14, 2024
CVE-2024-9832
9.3 CRITICAL

There is no limit on the number of failed login attempts permitted with the Clinician Password or the Serial Number Clinician Password. An attacker could …

Nov 14, 2024
CVE-2024-51687
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Platform.ly Platform.ly Official platformly allows Stored XSS.This issue affects Platform.ly Official: from n/a through <= 1.1.3.

Nov 14, 2024
CVE-2024-51684
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu W3P SEO wp-perfect-plugin allows Stored XSS.This issue affects W3P SEO: from n/a through < 1.8.6.

Nov 14, 2024
CVE-2024-51688
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in fraudlabspro FraudLabs Pro SMS Verification fraudlabs-pro-sms-verification allows Stored XSS.This issue affects FraudLabs Pro SMS Verification: from n/a through <= …

Nov 14, 2024
CVE-2024-49025
5.4 MEDIUM

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Nov 14, 2024
CVE-2024-10397
7.8 HIGH

A malicious server can crash the OpenAFS cache manager and other client utilities, and possibly execute arbitrary code.

Nov 14, 2024
CVE-2024-10396
6.5 MEDIUM

An authenticated user can provide a malformed ACL to the fileserver's StoreACL RPC, causing the fileserver to crash, possibly expose uninitialized memory, and possibly store …

Nov 14, 2024
CVE-2024-10394
7.8 HIGH

A local user can bypass the OpenAFS PAG (Process Authentication Group) throttling mechanism in Unix clients, allowing the user to create a PAG using an …

Nov 14, 2024
CVE-2024-52370
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Hive Support Hive Support hive-support allows Upload a Web Shell to a Web Server.This issue affects …

Nov 14, 2024
CVE-2024-52369
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Optimal Access KBucket kbucket allows Upload a Web Shell to a Web Server.This issue affects KBucket: …

Nov 14, 2024
CVE-2024-3760
7.5 HIGH

In lunary-ai/lunary version 1.2.7, there is a lack of rate limiting on the forgot password page, leading to an email bombing vulnerability. Attackers can exploit …

Nov 14, 2024
CVE-2024-5125
7.3 HIGH

parisneo/lollms-webui version 9.6 is vulnerable to Cross-Site Scripting (XSS) and Open Redirect due to inadequate input validation and processing of SVG files during the upload …

Nov 14, 2024
CVE-2024-52524

Giskard is an evaluation and testing framework for AI systems. A Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security …

Nov 14, 2024
CVE-2024-52396
4.9 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-editor allows Path Traversal.This issue affects WOLF: from n/a through …

Nov 14, 2024
CVE-2024-52393
9.1 CRITICAL

Deserialization of Untrusted Data vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress.This issue affects Podlove Podcast Publisher: from n/a through <= 4.1.15.

Nov 14, 2024
CVE-2024-52384
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in wpmonks Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, Dalle-3 Image Generation ai-content-generator allows Upload a Web …

Nov 14, 2024
CVE-2024-52383
7.5 HIGH

Missing Authorization vulnerability in aitool Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One ai-auto-tool allows Exploiting Incorrectly Configured Access Control …

Nov 14, 2024
CVE-2024-52382
9.8 CRITICAL

Missing Authorization vulnerability in medmatech Matix Popup Builder medma-matix allows Privilege Escalation.This issue affects Matix Popup Builder: from n/a through <= 1.0.0.

Nov 14, 2024
CVE-2024-52381
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Shoaib Rehmat ZIJ KART zij-kart allows PHP Local File …

Nov 14, 2024
CVE-2024-52380
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in softpulseinfotech Picsmize picsmize allows Upload a Web Shell to a Web Server.This issue affects Picsmize: from …

Nov 14, 2024
CVE-2024-52379
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in faizalbahasan kineticPay for WooCommerce kineticpay-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects …

Nov 14, 2024
CVE-2024-52378
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in labs64 DigiPass digipass allows Absolute Path Traversal.This issue affects DigiPass: from n/a …

Nov 14, 2024
CVE-2024-52377
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in bdthemes Instant Image Generator ai-image allows Upload a Web Shell to a Web Server.This issue affects …

Nov 14, 2024
CVE-2024-52376
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in cmsMinds Boat Rental Plugin for WordPress boat-rental-system allows Upload a Web Shell to a Web Server.This …

Nov 14, 2024
CVE-2024-52375
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Arttia Creative Datasets Manager by Arttia Creative datasets-manager-by-arttia-creative.This issue affects Datasets Manager by Arttia Creative: from …

Nov 14, 2024
CVE-2024-52374
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in DoThatTask Do That Task do-that-task allows Upload a Web Shell to a Web Server.This issue affects …

Nov 14, 2024
CVE-2024-52373
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Team Devexhub Devexhub Gallery devexhub-gallery allows Upload a Web Shell to a Web Server.This issue affects …

Nov 14, 2024
CVE-2024-52372
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in WebTechGlobal Easy CSV Importer BETA easy-csv-importer allows Upload a Web Shell to a Web Server.This issue …

Nov 14, 2024
CVE-2024-52371
8.6 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DonnellC Global Gateway e4 | Payeezy Gateway | globe-gateway-e4.This issue affects Global …

Nov 14, 2024
CVE-2024-50831
7.2 HIGH

A SQL Injection was found in /admin/admin_user.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.

Nov 14, 2024
CVE-2024-50830
7.2 HIGH

A SQL Injection vulnerability was found in /admin/calendar_of_events.php in kashipara E-learning Management System Project 1.0 via the date_start, date_end, and title parameters.

Nov 14, 2024
CVE-2024-50829
7.2 HIGH

A SQL Injection vulnerability was found in /admin/edit_subject.php in kashipara E-learning Management System Project 1.0 via the unit parameter.

Nov 14, 2024
CVE-2024-50828
7.2 HIGH

A SQL Injection vulnerability was found in /admin/edit_department.php in kashipara E-learning Management System Project 1.0 via the d parameter.

Nov 14, 2024
CVE-2024-50827
7.2 HIGH

A SQL Injection vulnerability was found in /admin/add_subject.php in kashipara E-learning Management System Project 1.0 via the subject_code parameter.

Nov 14, 2024
CVE-2024-50826
7.2 HIGH

A SQL Injection vulnerability was found in /admin/add_content.php in kashipara E-learning Management System Project 1.0 via the title and content parameters.

Nov 14, 2024
CVE-2024-50825
7.2 HIGH

A SQL Injection vulnerability was found in /admin/school_year.php in kashipara E-learning Management System Project 1.0 via the school_year parameter.

Nov 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.