CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-47657
6.5 MEDIUM

This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this …

Oct 4, 2024
CVE-2024-47656
9.8 CRITICAL

This vulnerability exists in Shilpi Client Dashboard due to missing restrictions for incorrect login attempts on its API based login. A remote attacker could exploit …

Oct 4, 2024
CVE-2024-47655
8.8 HIGH

This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than the specified extension. An authenticated remote attacker …

Oct 4, 2024
CVE-2024-47654
7.5 HIGH

This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP requests in certain API endpoint. An unauthenticated …

Oct 4, 2024
CVE-2024-47653
6.5 MEDIUM

This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requests through certain API endpoints. An authenticated remote attacker …

Oct 4, 2024
CVE-2024-47652
8.1 HIGH

This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechanism in the login module wherein access to any users account is …

Oct 4, 2024
CVE-2024-6400
7.5 HIGH

Cleartext Storage of Sensitive Information, Exposure of Sensitive Information Through Data Queries vulnerability in Finrota Netahsilat allows Retrieve Embedded Sensitive Data, Authentication Bypass, IMAP/SMTP Command …

Oct 4, 2024
CVE-2024-47651
6.5 MEDIUM

This vulnerability exists in Shilpi Client Dashboard due to improper handling of multiple parameters in the API endpoint. An authenticated remote attacker could exploit this …

Oct 4, 2024
CVE-2024-9271
6.4 MEDIUM

The Re:WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.1 due to …

Oct 4, 2024
CVE-2024-9071
6.4 MEDIUM

The Easy Demo Importer – A Modern One-Click Demo Import Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in …

Oct 4, 2024
CVE-2024-9435
6.1 MEDIUM

The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL keys in all versions up to, and including, 4.9.66 …

Oct 4, 2024
CVE-2024-9306
4.4 MEDIUM

The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 10.6 due …

Oct 4, 2024
CVE-2024-6444
6.3 MEDIUM

No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c.

Oct 4, 2024
CVE-2024-9242
6.4 MEDIUM

The Memberful – Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'memberful_buy_subscription_link' and 'memberful_podcasts_link' shortcodes in all versions up …

Oct 4, 2024
CVE-2024-8804
6.4 MEDIUM

The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's script embed functionality in all versions up to, and including, …

Oct 4, 2024
CVE-2024-6443
6.3 MEDIUM

In utf8_trunc in zephyr/lib/utils/utf8.c, last_byte_p can point to one byte before the string pointer if the string is empty.

Oct 4, 2024
CVE-2024-6442
6.3 MEDIUM

In ascs_cp_rsp_add in /subsys/bluetooth/audio/ascs.c, an unchecked tailroom could lead to a global buffer overflow.

Oct 4, 2024
CVE-2024-47855
5.3 MEDIUM

util/JSONTokener.java in JSON-lib before 3.1.0 mishandles an unbalanced comment string.

Oct 4, 2024
CVE-2024-47854
6.1 MEDIUM

An XSS vulnerability was discovered in Veritas Data Insight before 7.1. It allows a remote attacker to inject an arbitrary web script into an HTTP …

Oct 4, 2024
CVE-2024-9445
6.4 MEDIUM

The Display Medium Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_medium_posts shortcode in all versions up to, and including, …

Oct 4, 2024
CVE-2024-9421
6.4 MEDIUM

The Login Logout Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in all versions up to, and including, 1.1.0 …

Oct 4, 2024
CVE-2024-9384
6.1 MEDIUM

The Quantity Dynamic Pricing & Bulk Discounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without …

Oct 4, 2024
CVE-2024-9375
6.1 MEDIUM

The WordPress Captcha Plugin by Captcha Bank plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping …

Oct 4, 2024
CVE-2024-9372
6.4 MEDIUM

The WP Blocks Hub plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.2 …

Oct 4, 2024
CVE-2024-9368
6.4 MEDIUM

The Aggregator Advanced Settings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.1 …

Oct 4, 2024
CVE-2024-9353
6.1 MEDIUM

The Popularis Extra plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the …

Oct 4, 2024
CVE-2024-9349
6.1 MEDIUM

The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without …

Oct 4, 2024
CVE-2024-9345
6.1 MEDIUM

The Product Delivery Date for WooCommerce – Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate …

Oct 4, 2024
CVE-2024-9237
6.1 MEDIUM

The Fish and Ships – Most flexible shipping table rate. A WooCommerce shipping rate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to …

Oct 4, 2024
CVE-2024-9204
6.1 MEDIUM

The Smart Custom 404 Error Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER['REQUEST_URI'] in all versions up to, and including, 11.4.7 …

Oct 4, 2024
CVE-2024-8802
6.1 MEDIUM

The Clio Grow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in …

Oct 4, 2024
CVE-2024-8520
5.3 MEDIUM

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in …

Oct 4, 2024
CVE-2024-8519
6.4 MEDIUM

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Oct 4, 2024
CVE-2024-47850
7.5 HIGH

CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a single IPP UDP packet requesting …

Oct 4, 2024
CVE-2024-44207
4.3 MEDIUM

This issue was addressed with improved checks. This issue is fixed in iOS 18.0.1 and iPadOS 18.0.1. Audio messages in Messages may be able to …

Oct 4, 2024
CVE-2024-44204
5.5 MEDIUM

A logic issue was addressed with improved validation. This issue is fixed in iOS 18.0.1 and iPadOS 18.0.1. A user's saved passwords may be read …

Oct 4, 2024
CVE-2024-45367
9.1 CRITICAL

The web server for ONS-S8 - Spectra Aggregation Switch includes an incomplete authentication process, which can lead to an attacker authenticating without a password.

Oct 3, 2024
CVE-2024-43699
9.8 CRITICAL

Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script AM_RegReport.aspx. An unauthenticated attacker may be able to exploit this issue to obtain …

Oct 3, 2024
CVE-2024-42417
8.8 HIGH

Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script Handler_CFG.ashx. An authenticated attacker may be able to exploit this issue to cause …

Oct 3, 2024
CVE-2024-41925
9.8 CRITICAL

The web service for ONS-S8 - Spectra Aggregation Switch includes functions which do not properly validate user input, allowing an attacker to traverse directories, bypass …

Oct 3, 2024
CVE-2024-46658
8.0 HIGH

Syrotech SY-GOPON-8OLT-L3 v1.6.0_240629 was discovered to contain an authenticated command injection vulnerability.

Oct 3, 2024
CVE-2024-9266
4.7 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Express. This vulnerability affects the use of the Express Response object. This issue impacts Express: from …

Oct 3, 2024
CVE-2024-41596
8.0 HIGH

Buffer Overflow vulnerabilities exist in DrayTek Vigor310 devices through 4.3.2.6 (in the Vigor management UI) because of improper retrieval and handling of the CGI form …

Oct 3, 2024
CVE-2024-41595
8.0 HIGH

DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to change settings or cause a denial of service via .cgi pages because of missing bounds …

Oct 3, 2024
CVE-2024-41594
7.5 HIGH

An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the httpd server of the Vigor management UI uses …

Oct 3, 2024
CVE-2024-41593
9.8 CRITICAL

DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to execute arbitrary code via the function ft_payload_dns(), because a byte sign-extension operation occurs for the …

Oct 3, 2024
CVE-2024-41592
8.0 HIGH

DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because GetCGI mishandles extraneous ampersand characters and long key-value pairs.

Oct 3, 2024
CVE-2024-41591
6.1 MEDIUM

DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS.

Oct 3, 2024
CVE-2024-41590
8.0 HIGH

Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strcpy …

Oct 3, 2024
CVE-2024-41589
8.8 HIGH

DrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests.

Oct 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.