CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-51521
5.7 MEDIUM

Input parameter verification vulnerability in the background service module Impact: Successful exploitation of this vulnerability may affect availability.

Nov 5, 2024
CVE-2024-51520
5.5 MEDIUM

Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect availability.

Nov 5, 2024
CVE-2024-51519
5.0 MEDIUM

Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect availability.

Nov 5, 2024
CVE-2024-51518
5.3 MEDIUM

Vulnerability of message types not being verified in the advanced messaging modul Impact: Successful exploitation of this vulnerability may affect availability.

Nov 5, 2024
CVE-2024-51517
5.1 MEDIUM

Vulnerability of improper memory access in the phone service module Impact: Successful exploitation of this vulnerability may affect availability.

Nov 5, 2024
CVE-2024-47255
4.7 MEDIUM

In 2N Access Commander versions 3.1.1.2 and prior, a local attacker can escalate their privileges in the system which could allow for arbitrary code execution …

Nov 5, 2024
CVE-2024-47254
6.3 MEDIUM

In 2N Access Commander versions 3.1.1.2 and prior, an Insufficient Verification of Data Authenticity vulnerability could allow an attacker to escalate their privileges and gain …

Nov 5, 2024
CVE-2024-47253
7.2 HIGH

In 2N Access Commander versions 3.1.1.2 and prior, a Path Traversal vulnerability could allow an attacker with administrative privileges to write files on the filesystem …

Nov 5, 2024
CVE-2024-10687
9.8 CRITICAL

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons plugin for WordPress is vulnerable to …

Nov 5, 2024
CVE-2023-52920
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: support non-r10 register spill/fill to/from stack in precision tracking Use instruction (jump) history to …

Nov 5, 2024
CVE-2024-9667
6.1 MEDIUM

The Seriously Simple Podcasting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Nov 5, 2024
CVE-2024-9443
6.4 MEDIUM

The Basticom Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.5.0 due …

Nov 5, 2024
CVE-2024-51516
6.2 MEDIUM

Permission control vulnerability in the ability module Impact: Successful exploitation of this vulnerability may cause features to function abnormally.

Nov 5, 2024
CVE-2024-51515
6.2 MEDIUM

Race condition vulnerability in the kernel network module Impact:Successful exploitation of this vulnerability may affect availability.

Nov 5, 2024
CVE-2024-51514
5.3 MEDIUM

Vulnerability of pop-up windows belonging to no app in the VPN module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 5, 2024
CVE-2024-51513
5.5 MEDIUM

Vulnerability of processes not being fully terminated in the VPN module Impact: Successful exploitation of this vulnerability will affect power consumption.

Nov 5, 2024
CVE-2024-51512
6.2 MEDIUM

Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulnerability may affect availability.

Nov 5, 2024
CVE-2024-51511
6.2 MEDIUM

Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulnerability may affect availability.

Nov 5, 2024
CVE-2024-51510
7.6 HIGH

Out-of-bounds access vulnerability in the logo module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 5, 2024
CVE-2024-10711
8.8 HIGH

The WooCommerce Report plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.1. This is due to missing …

Nov 5, 2024
CVE-2024-10114
8.1 HIGH

The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.7.7. This is due to …

Nov 5, 2024
CVE-2024-47797
8.4 HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through out-of-bounds write.

Nov 5, 2024
CVE-2024-47404
8.4 HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through double free.

Nov 5, 2024
CVE-2024-47402
3.3 LOW

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through out-of-bounds read.

Nov 5, 2024
CVE-2024-47137
8.4 HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through out-of-bounds write.

Nov 5, 2024
CVE-2024-10097
8.1 HIGH

The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication bypass in all versions up to, and including, 1.9.2. This is due to …

Nov 5, 2024
CVE-2024-9883
4.8 MEDIUM

The Pods WordPress plugin before 3.2.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Nov 5, 2024
CVE-2024-9689
4.3 MEDIUM

The Post From Frontend WordPress plugin through 1.0.0 does not have CSRF check when deleting posts, which could allow attackers to make logged in admin …

Nov 5, 2024
CVE-2024-9459
8.3 HIGH

Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in reports module.

Nov 5, 2024
CVE-2024-7877
4.8 MEDIUM

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Notification settings, which …

Nov 5, 2024
CVE-2024-7876
4.8 MEDIUM

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Appointment Type settings, …

Nov 5, 2024
CVE-2024-5578
4.8 MEDIUM

The Table of Contents Plus WordPress plugin through 2408 does not sanitise and escape some of its settings, which could allow high privilege users such …

Nov 5, 2024
CVE-2024-10810
6.3 MEDIUM

A vulnerability was found in code-projects E-Health Care System 1.0. It has been classified as critical. Affected is an unknown function of the file Doctor/app_request.php. …

Nov 5, 2024
CVE-2024-10809
6.3 MEDIUM

A vulnerability was found in code-projects E-Health Care System 1.0 and classified as critical. This issue affects some unknown processing of the file /Doctor/chat.php. The …

Nov 5, 2024
CVE-2024-10808
6.3 MEDIUM

A vulnerability has been found in code-projects E-Health Care System 1.0 and classified as critical. This vulnerability affects unknown code of the file Admin/req_detail.php. The …

Nov 5, 2024
CVE-2024-10807
2.4 LOW

A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been rated as problematic. This issue affects some unknown processing of the file …

Nov 5, 2024
CVE-2024-10340
6.4 MEDIUM

The Shortcodes Blocks Creator Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'scu' shortcode in versions up to, and including, 2.1.3 due …

Nov 5, 2024
CVE-2024-10806
2.4 LOW

A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as problematic. This vulnerability affects unknown code of the file betweendates-detailsreports.php. …

Nov 5, 2024
CVE-2024-51498

cobalt is a media downloader that doesn't piss you off. A malicious cobalt instance could serve links with the `javascript:` protocol, resulting in Cross-site Scripting …

Nov 5, 2024
CVE-2024-50346

WebFeed is a lightweight web feed reader extension for Firefox/Chrome. Multiple HTML injection vulnerabilities in WebFeed can lead to CSRF and UI spoofing attacks. A …

Nov 5, 2024
CVE-2024-32870
5.8 MEDIUM

Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and parameters) can be read …

Nov 5, 2024
CVE-2024-31998
8.8 HIGH

Combodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV import simulation. This issue has been fixed …

Nov 5, 2024
CVE-2024-31448
8.8 HIGH

Combodo iTop is a simple, web based IT Service Management tool. By filling malicious code in a CSV content, an Cross-site Scripting (XSS) attack can …

Nov 5, 2024
CVE-2023-34445
8.8 HIGH

Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.render.php XSS are possible for scripts outside of script tags. This issue …

Nov 5, 2024
CVE-2023-34444
8.8 HIGH

Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.searchform.php XSS are possible for scripts outside of script tags. This issue …

Nov 5, 2024
CVE-2023-34443
8.8 HIGH

Combodo iTop is a simple, web based IT Service Management tool. When displaying page Run queries Cross-site Scripting (XSS) are possible for scripts outside of …

Nov 5, 2024
CVE-2024-51734

Zope AccessControl provides a general security framework for use in Zope. In affected versions anonymous users can delete the user data maintained by an `AccessControl.userfolder.UserFolder` …

Nov 4, 2024
CVE-2024-51502

loona is an experimental, HTTP/1.1 and HTTP/2 implementation in Rust on top of io-uring. `loona-hpack` suffers from the same vulnerability as the original `hpack` as …

Nov 4, 2024
CVE-2024-51501

Refit is an automatic type-safe REST library for .NET Core, Xamarin and .NET The various header-related Refit attributes (Header, HeaderCollection and Authorize) are vulnerable to …

Nov 4, 2024
CVE-2024-51500
5.3 MEDIUM

Meshtastic firmware is a device firmware for the Meshtastic project. The Meshtastic firmware does not check for packets claiming to be from the special broadcast …

Nov 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.