CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-39431
8.3 HIGH

In UMTS RLC driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of …

Sep 27, 2024
CVE-2024-9049
6.4 MEDIUM

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Group module in all versions …

Sep 27, 2024
CVE-2024-9029
7.5 HIGH

A flaw was found in the freeimage library. Processing a crafted image can cause a buffer over-read of 1 byte in the read_iptc_profile function in …

Sep 27, 2024
CVE-2024-8991
6.4 MEDIUM

The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's osm_map and osm_map_v3 shortcodes in all versions up to, …

Sep 27, 2024
CVE-2024-8681
6.4 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Media Grid widget in all versions up to, …

Sep 27, 2024
CVE-2024-7400

The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file on the Windows operating system to delete …

Sep 27, 2024
CVE-2024-9130
7.2 HIGH

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up …

Sep 27, 2024
CVE-2024-8965
6.4 MEDIUM

The Absolute Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Name' field of a custom post criteria in all versions up …

Sep 27, 2024
CVE-2024-8922
8.8 HIGH

The Product Enquiry for WooCommerce, WooCommerce product catalog plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.2.33.32 …

Sep 27, 2024
CVE-2024-7714
7.5 HIGH

The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the …

Sep 27, 2024
CVE-2024-7713
7.5 HIGH

The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, allowing unauthenticated users to obtain …

Sep 27, 2024
CVE-2024-7011
6.5 MEDIUM

Sharp NEC Projectors (NP-CB4500UL, NP-CB4500WL, NP-CB4700UL, NP-P525UL, NP-P525UL+, NP-P525ULG, NP-P525ULJL, NP-P525WL, NP-P525WL+, NP-P525WLG, NP-P525WLJL, NP-CG6500UL, NP-CG6500WL, NP-CG6700UL, NP-P605UL, NP-P605UL+, NP-P605ULG, NP-P605ULJL, NP-CA4120X, NP-CA4160W, NP-CA4160X, NP-CA4200U, …

Sep 27, 2024
CVE-2024-8974
2.6 LOW

Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions …

Sep 26, 2024
CVE-2024-4099
3.1 LOW

An issue has been discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 …

Sep 26, 2024
CVE-2024-47176
5.3 MEDIUM

CUPS is a standards-based, open-source printing system, and `cups-browsed` contains network printing functionality including, but not limited to, auto-discovering print services and shared printers. `cups-browsed` …

Sep 26, 2024
CVE-2024-47175
8.6 HIGH

CUPS is a standards-based, open-source printing system, and `libppd` can be used for legacy PPD file support. The `libppd` function `ppdCreatePPDFromIPP2` does not sanitize IPP …

Sep 26, 2024
CVE-2024-47076
8.6 HIGH

CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package as library functions to be …

Sep 26, 2024
CVE-2024-40508
7.3 HIGH

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMConference.asmx function.

Sep 26, 2024
CVE-2024-40507
7.3 HIGH

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMPersonnel.asmx function.

Sep 26, 2024
CVE-2024-40506
7.3 HIGH

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMHospitality.asmx function.

Sep 26, 2024
CVE-2024-6769
6.7 MEDIUM

A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows …

Sep 26, 2024
CVE-2024-45986
5.4 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability was identified in Projectworld Online Voting System 1.0 that occurs when an account is registered with a malicious javascript …

Sep 26, 2024
CVE-2024-7594
7.5 HIGH

Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields of the SSH …

Sep 26, 2024
CVE-2024-47180
8.8 HIGH

Shields.io is a service for concise, consistent, and legible badges in SVG and raster format. Shields.io and users self-hosting their own instance of shields using …

Sep 26, 2024
CVE-2024-47179
8.8 HIGH

RSSHub is an RSS network. Prior to commit 64e00e7, RSSHub's `docker-test-cont.yml` workflow is vulnerable to Artifact Poisoning, which could have lead to a full repository …

Sep 26, 2024
CVE-2024-46628
9.8 CRITICAL

Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function.

Sep 26, 2024
CVE-2024-8118

In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also …

Sep 26, 2024
CVE-2024-47174
5.9 MEDIUM

Nix is a package manager for Linux and other Unix systems. Starting in version 1.11 and prior to versions 2.18.8 and 2.24.8, `<nix/fetchurl.nix>` did not …

Sep 26, 2024
CVE-2024-47171
4.3 MEDIUM

Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to upload image files at attacker-chosen location …

Sep 26, 2024
CVE-2024-47170
4.3 MEDIUM

Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to read arbitrary JSON files at attacker-chosen …

Sep 26, 2024
CVE-2024-47169
8.8 HIGH

Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to upload arbitrary files to attacker-chosen locations …

Sep 26, 2024
CVE-2024-47130
8.8 HIGH

The goTenna Pro App allows unauthenticated attackers to remotely update the local public keys used for P2P and group messages. It is advised to update …

Sep 26, 2024
CVE-2024-47129
4.3 MEDIUM

The goTenna Pro App does not inject extra characters into broadcasted frames to obfuscate the length of messages. This makes it possible to tell the …

Sep 26, 2024
CVE-2024-47128
4.3 MEDIUM

The goTenna Pro App encryption key name is always sent unencrypted when the key is shared over RF through a broadcast message. It is advised …

Sep 26, 2024
CVE-2024-47127
6.5 MEDIUM

In the goTenna Pro App there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a …

Sep 26, 2024
CVE-2024-47126
6.5 MEDIUM

The goTenna Pro App does not use SecureRandom when generating passwords for sharing cryptographic keys. The random function in use makes it easier for attackers …

Sep 26, 2024
CVE-2024-47125
8.1 HIGH

The goTenna Pro App does not authenticate public keys which allows an unauthenticated attacker to manipulate messages. It is advised to update your app to …

Sep 26, 2024
CVE-2024-47124
4.3 MEDIUM

The goTenna Pro App does not encrypt callsigns in messages. It is recommended to not use sensitive information in callsigns when using this and previous …

Sep 26, 2024
CVE-2024-47123
5.3 MEDIUM

The goTenna Pro App uses AES CTR type encryption for short, encrypted messages without any additional integrity checking mechanisms. This leaves messages malleable to an …

Sep 26, 2024
CVE-2024-47122
4.3 MEDIUM

In the goTenna Pro App, the encryption keys are stored along with a static IV on the End User Device (EUD). This allows for complete …

Sep 26, 2024
CVE-2024-47121
5.3 MEDIUM

The goTenna Pro App uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted encryption key is captured over …

Sep 26, 2024
CVE-2024-47075
6.4 MEDIUM

LayUI is a native minimalist modular Web UI component library. Versions prior to 2.9.17 have a DOM Clobbering vulnerability that can lead to Cross-site Scripting …

Sep 26, 2024
CVE-2024-45989
4.0 MEDIUM

Monica AI Assistant desktop application v2.3.0 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor. A prompt injection allows an attacker to modify …

Sep 26, 2024
CVE-2024-45987
6.5 MEDIUM

Projectworld Online Voting System Version 1.0 is vulnerable to Cross Site Request Forgery (CSRF) via voter.php. This vulnerability allows an attacker to craft a malicious …

Sep 26, 2024
CVE-2024-45985
4.7 MEDIUM

A Cross Site Scripting (XSS) vulnerability in update_contact.php of Blood Bank and Donation Management System v1.0 allows an attacker to inject malicious scripts via the …

Sep 26, 2024
CVE-2024-45984
4.7 MEDIUM

A Cross Site Scripting (XSS) vulnerability in add_donor.php of Blood Bank And Donation Management System 1.0 allows an attacker to inject malicious scripts that will …

Sep 26, 2024
CVE-2024-45838
4.3 MEDIUM

The goTenna Pro ATAK Plugin does not encrypt callsigns in messages. It is advised to not use sensitive information in callsigns when using this and …

Sep 26, 2024
CVE-2024-45723
6.5 MEDIUM

The goTenna Pro ATAK Plugin does not use SecureRandom when generating passwords for sharing cryptographic keys. The random function in use makes it easier for …

Sep 26, 2024
CVE-2024-45374
5.3 MEDIUM

The goTenna Pro ATAK plugin uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted encryption key is captured …

Sep 26, 2024
CVE-2024-45042
4.4 MEDIUM

Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 1.3.0, given a number of preconditions, the `highest_available` setting …

Sep 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.