CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-50637
5.4 MEDIUM

UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows attackers to perform XSS via an SVG …

Nov 6, 2024
CVE-2024-20540
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) could allow an authenticated, remote attacker with low privileges …

Nov 6, 2024
CVE-2024-20539
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct a stored XSS attack against a user …

Nov 6, 2024
CVE-2024-20538
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of …

Nov 6, 2024
CVE-2024-20537
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions. …

Nov 6, 2024
CVE-2024-20536
8.8 HIGH

A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with …

Nov 6, 2024
CVE-2024-20534
4.8 MEDIUM

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 …

Nov 6, 2024
CVE-2024-20533
4.8 MEDIUM

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 …

Nov 6, 2024
CVE-2024-20532
5.5 MEDIUM

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and delete arbitrary files on an affected device. To …

Nov 6, 2024
CVE-2024-20531
5.5 MEDIUM

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an …

Nov 6, 2024
CVE-2024-20530
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of …

Nov 6, 2024
CVE-2024-20529
5.5 MEDIUM

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and delete arbitrary files on an affected device. To …

Nov 6, 2024
CVE-2024-20528
3.8 LOW

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to upload files to arbitrary locations on the underlying operating system …

Nov 6, 2024
CVE-2024-20527
5.5 MEDIUM

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and delete arbitrary files on an affected device. To …

Nov 6, 2024
CVE-2024-20525
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of …

Nov 6, 2024
CVE-2024-20514
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, low-privileged, remote attacker …

Nov 6, 2024
CVE-2024-20511
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) …

Nov 6, 2024
CVE-2024-20507
4.3 MEDIUM

A vulnerability in the logging subsystem of Cisco Meeting Management could allow an authenticated, remote attacker to view sensitive information in clear text on an …

Nov 6, 2024
CVE-2024-20504
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance …

Nov 6, 2024
CVE-2024-20487
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct a stored XSS attack against a user …

Nov 6, 2024
CVE-2024-20484
7.5 HIGH

A vulnerability in the External Agent Assignment Service (EAAS) feature of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to cause …

Nov 6, 2024
CVE-2024-20476
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific file management …

Nov 6, 2024
CVE-2024-20457
6.5 MEDIUM

A vulnerability in the logging component of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to …

Nov 6, 2024
CVE-2024-20445
5.3 MEDIUM

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could …

Nov 6, 2024
CVE-2024-20418
10.0 CRITICAL

A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB) Access Points could allow an unauthenticated, …

Nov 6, 2024
CVE-2024-20371
5.3 MEDIUM

A vulnerability in the access control list (ACL) programming of Cisco Nexus 3550-F Switches could allow an unauthenticated, remote attacker to send traffic that should …

Nov 6, 2024
CVE-2024-10827
8.8 HIGH

Use after free in Serial in Google Chrome prior to 130.0.6723.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Nov 6, 2024
CVE-2024-10826
8.8 HIGH

Use after free in Family Experiences in Google Chrome on Android prior to 130.0.6723.116 allowed a remote attacker to potentially exploit heap corruption via a …

Nov 6, 2024
CVE-2024-10318
5.4 MEDIUM

A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows …

Nov 6, 2024
CVE-2024-10920
3.1 LOW

A vulnerability was found in mariazevedo88 travels-java-api up to 5.0.1 and classified as problematic. Affected by this issue is the function doFilterInternal of the file …

Nov 6, 2024
CVE-2024-10919
6.3 MEDIUM

A vulnerability has been found in didi Super-Jacoco 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /cov/triggerUnitCover. …

Nov 6, 2024
CVE-2024-6861
7.5 HIGH

A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers …

Nov 6, 2024
CVE-2024-35146
5.4 MEDIUM

IBM Maximo Application Suite - Monitor Component 8.10.11, 8.11.8, and 9.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary …

Nov 6, 2024
CVE-2024-10916
5.3 MEDIUM

A vulnerability classified as problematic has been found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. This affects an unknown part of the …

Nov 6, 2024
CVE-2024-10082
8.7 HIGH

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication method confusion allows logging in as …

Nov 6, 2024
CVE-2024-10081
10.0 CRITICAL

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the API URL …

Nov 6, 2024
CVE-2024-10915
8.1 HIGH

A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been rated as critical. Affected by this issue is …

Nov 6, 2024
CVE-2024-10914
8.1 HIGH

A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulnerability is …

Nov 6, 2024
CVE-2020-11859
7.6 HIGH

Improper Input Validation vulnerability in OpenText iManager allows Cross-Site Scripting (XSS). This issue affects iManager before 3.2.3

Nov 6, 2024
CVE-2024-10186
6.4 MEDIUM

The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's events_cal shortcode in all versions up to, and including, 5.9.6 …

Nov 6, 2024
CVE-2024-8323
6.4 MEDIUM

The Pricing Tables WordPress Plugin – Easy Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fontFamily’ attribute in all versions …

Nov 6, 2024
CVE-2024-10168
6.4 MEDIUM

The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woot_button shortcode …

Nov 6, 2024
CVE-2024-10715
6.4 MEDIUM

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map block in all versions up to, and …

Nov 6, 2024
CVE-2024-9902
6.3 MEDIUM

A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file …

Nov 6, 2024
CVE-2024-8615
10.0 CRITICAL

The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_location_load_excel_file_callback() function in …

Nov 6, 2024
CVE-2024-8614
9.9 CRITICAL

The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_wp_handle_upload() function in …

Nov 6, 2024
CVE-2024-9681
6.5 MEDIUM

When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it end sooner or …

Nov 6, 2024
CVE-2024-52043
5.3 MEDIUM

Generation of Error Message Containing Sensitive Information in HumHub GmbH & Co. KG - HumHub on Linux allows: Excavation (user enumeration).This issue affects all released …

Nov 6, 2024
CVE-2024-9946
8.1 HIGH

The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authentication bypass in all versions up to, …

Nov 6, 2024
CVE-2024-9307
9.9 CRITICAL

The mFolio Lite plugin for WordPress is vulnerable to file uploads due to a missing capability check in all versions up to, and including, 1.2.1. …

Nov 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.