CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-33209
5.4 MEDIUM

FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which allows them …

Oct 2, 2024
CVE-2024-47612
3.5 LOW

DataDump is a MediaWiki extension that provides dumps of wikis. Several interface messages are unescaped (more specifically, (datadump-table-column-queued), (datadump-table-column-in-progress), (datadump-table-column-completed), (datadump-table-column-failed)). If these messages are …

Oct 2, 2024
CVE-2024-47611

XZ Utils provide a general-purpose data-compression library plus command-line tools. When built for native Windows (MinGW-w64 or MSVC), the command line tools from XZ Utils …

Oct 2, 2024
CVE-2024-44193
7.8 HIGH

A logic issue was addressed with improved restrictions. This issue is fixed in iTunes 12.13.3 for Windows. A local attacker may be able to elevate …

Oct 2, 2024
CVE-2024-44097
9.8 CRITICAL

According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the server certificate properly while initializing …

Oct 2, 2024
CVE-2024-9429
6.3 MEDIUM

A vulnerability has been found in code-projects Restaurant Reservation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Oct 2, 2024
CVE-2024-8885
8.8 HIGH

A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2024.2.0 and older allows writing of arbitrary files.

Oct 2, 2024
CVE-2024-8038
7.9 HIGH

Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authentication locally to network namespace users. This …

Oct 2, 2024
CVE-2024-8037
6.5 MEDIUM

Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the …

Oct 2, 2024
CVE-2024-7558
8.7 HIGH

JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace …

Oct 2, 2024
CVE-2024-35294
6.5 MEDIUM

An unauthenticated remote attacker may use the devices traffic capture without authentication to grab plaintext administrative credentials.

Oct 2, 2024
CVE-2024-8505
6.4 MEDIUM

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_label’ parameter in all versions up …

Oct 2, 2024
CVE-2024-8282
6.4 MEDIUM

The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ attribute within the 'wp:ive/ive-productscarousel' Gutenberg block in …

Oct 2, 2024
CVE-2024-44030
7.2 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mestres do WP Checkout Mestres WP checkout-mestres-wp allows Absolute Path Traversal.This issue …

Oct 2, 2024
CVE-2024-44017
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MinHyeong Lim MH Board mh-board allows PHP Local File Inclusion.This issue affects …

Oct 2, 2024
CVE-2024-35293
9.1 CRITICAL

An unauthenticated remote attacker may use a missing authentication for critical function vulnerability to reboot or erase the affected devices resulting in data loss and/or …

Oct 2, 2024
CVE-2024-9378
6.1 MEDIUM

The YML for Yandex Market plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, …

Oct 2, 2024
CVE-2024-9344
6.1 MEDIUM

The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is vulnerable to Reflected …

Oct 2, 2024
CVE-2024-9218
6.1 MEDIUM

The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to Reflected …

Oct 2, 2024
CVE-2024-9225
6.1 MEDIUM

The SEOPress – On-site SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping …

Oct 2, 2024
CVE-2024-9222
6.1 MEDIUM

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use …

Oct 2, 2024
CVE-2024-9210
6.1 MEDIUM

The MC4WP: Mailchimp Top Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …

Oct 2, 2024
CVE-2024-9172
6.4 MEDIUM

The Demo Importer Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0.1 …

Oct 2, 2024
CVE-2024-8967
6.4 MEDIUM

The PWA — easy way to Progressive Web App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions …

Oct 2, 2024
CVE-2024-8800
6.1 MEDIUM

The RabbitLoader – Website Speed Optimization for improving Core Web Vital metrics with Cache, Image Optimization, and more plugin for WordPress is vulnerable to Reflected …

Oct 2, 2024
CVE-2024-8254
5.4 MEDIUM

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in …

Oct 2, 2024
CVE-2024-9333

Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited amount of documents via incorrect access control list calculation

Oct 2, 2024
CVE-2024-9174
5.4 MEDIUM

Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UI

Oct 2, 2024
CVE-2024-7315
7.5 HIGH

The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that is created when generating a backup, which could …

Oct 2, 2024
CVE-2024-7855
8.8 HIGH

The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function in all …

Oct 2, 2024
CVE-2024-45186
9.8 CRITICAL

FileSender before 2.49 allows server-side template injection (SSTI) for retrieving credentials.

Oct 2, 2024
CVE-2024-33662
7.5 HIGH

Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.

Oct 2, 2024
CVE-2024-21530
4.5 MEDIUM

Versions of the package cocoon before 0.4.0 are vulnerable to Reusing a Nonce, Key Pair in Encryption when the encrypt, wrap, and dump functions are …

Oct 2, 2024
CVE-2024-9407
4.7 MEDIUM

A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not properly validate the input passed to this option, …

Oct 1, 2024
CVE-2024-47609

Tonic is a native gRPC client & server implementation with async/await support. When using tonic::transport::Server there is a remote DoS attack that can cause the …

Oct 1, 2024
CVE-2024-47528
4.8 MEDIUM

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Stored Cross-Site Scripting (XSS) can be achieved by uploading a new Background for a Custom Map. Users …

Oct 1, 2024
CVE-2024-47527
7.5 HIGH

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Device Dependencies" feature allows authenticated users to inject arbitrary …

Oct 1, 2024
CVE-2024-47526
3.5 LOW

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Self Cross-Site Scripting (Self-XSS) vulnerability in the "Alert Templates" feature allows users to inject arbitrary JavaScript …

Oct 1, 2024
CVE-2024-47525
7.5 HIGH

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Alert Rules" feature allows authenticated users to inject arbitrary …

Oct 1, 2024
CVE-2024-47524
7.2 HIGH

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can create a Device Groups, the application did not properly sanitize the user …

Oct 1, 2024
CVE-2024-47523
7.5 HIGH

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Alert Transports" feature allows authenticated users to inject arbitrary …

Oct 1, 2024
CVE-2024-46084
8.0 HIGH

Scriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function.

Oct 1, 2024
CVE-2024-46082
5.4 MEDIUM

Scriptcase v.9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in nm_cor.php via the form and field parameters.

Oct 1, 2024
CVE-2024-46080
8.0 HIGH

Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function.

Oct 1, 2024
CVE-2024-9411
3.5 LOW

A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument …

Oct 1, 2024
CVE-2024-45999
9.8 CRITICAL

A SQL Injection vulnerability was discovered in Cloudlog 2.6.15, specifically within the get_station_info()function located in the file /application/models/Oqrs_model.php. The vulnerability is exploitable via the station_id …

Oct 1, 2024
CVE-2024-9355
6.5 MEDIUM

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed …

Oct 1, 2024
CVE-2024-9341
5.4 MEDIUM

A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper …

Oct 1, 2024
CVE-2024-46083
5.4 MEDIUM

Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads using the messages feature, which allows the …

Oct 1, 2024
CVE-2024-46081
5.4 MEDIUM

Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads in the To-Do List. The assigned user …

Oct 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.