CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-22813
4.4 MEDIUM

An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to overwrite the hardcoded IP address in the device memory, disrupting network connectivity …

Apr 22, 2024
CVE-2024-22811
8.2 HIGH

An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) by disrupting the communication between the …

Apr 22, 2024
CVE-2024-22809
6.5 MEDIUM

Incorrect access control in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to access the G code's shared folder and view sensitive information.

Apr 22, 2024
CVE-2024-22808
7.5 HIGH

An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) by disrupting the communication between the …

Apr 22, 2024
CVE-2024-22807
6.5 MEDIUM

An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to erase a critical sector of the flash memory, causing the machine to …

Apr 22, 2024
CVE-2024-32691
5.3 MEDIUM

Missing Authorization vulnerability in realmag777 Active Products Tables for WooCommerce.This issue affects Active Products Tables for WooCommerce: from n/a through 1.0.6.2.

Apr 22, 2024
CVE-2024-32688
6.5 MEDIUM

Missing Authorization vulnerability in Long Watch Studio MyRewards.This issue affects MyRewards: from n/a through 5.3.0.

Apr 22, 2024
CVE-2024-32687
4.3 MEDIUM

Missing Authorization vulnerability in WPClever WPC Frequently Bought Together for WooCommerce.This issue affects WPC Frequently Bought Together for WooCommerce: from n/a through 7.0.3.

Apr 22, 2024
CVE-2024-32684
5.3 MEDIUM

Missing Authorization vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through 2.2.5.

Apr 22, 2024
CVE-2024-32682
7.1 HIGH

Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Addons For Elementor: from n/a through 3.13.2.

Apr 22, 2024
CVE-2024-32681
4.3 MEDIUM

Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Addons For Elementor: from n/a through 3.13.2.

Apr 22, 2024
CVE-2024-32698
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons.This issue affects Happy Addons for Elementor: from …

Apr 22, 2024
CVE-2024-32697
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HelloAsso allows Stored XSS.This issue affects HelloAsso: from n/a through 1.1.5.

Apr 22, 2024
CVE-2024-32696
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Infographic Maker – iList allows Stored XSS.This issue affects Infographic Maker – …

Apr 22, 2024
CVE-2024-32695
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marco Gasi Language Switcher for Transposh allows Reflected XSS.This issue affects Language Switcher …

Apr 22, 2024
CVE-2024-32694
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Creative interactive media 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook …

Apr 22, 2024
CVE-2024-32693
7.6 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in ValvePress Automatic.This issue affects Automatic: from n/a before 3.93.0.

Apr 22, 2024
CVE-2024-32690
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood RSS Feed Widget allows Stored XSS.This issue affects RSS Feed Widget: …

Apr 22, 2024
CVE-2023-7252
5.3 MEDIUM

The Tickera WordPress plugin before 3.5.2.5 does not prevent users from leaking other users' tickets.

Apr 22, 2024
CVE-2018-25101
3.5 LOW

A vulnerability, which was classified as problematic, has been found in l2c2technologies Koha up to 20180108. This issue affects some unknown processing of the file …

Apr 22, 2024
CVE-2024-32418
9.8 CRITICAL

An issue in flusity CMS v2.33 allows a remote attacker to execute arbitrary code via the add_addon.php component.

Apr 22, 2024
CVE-2024-30799
4.4 MEDIUM

An issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of service via the Breach …

Apr 22, 2024
CVE-2024-28722
6.3 MEDIUM

Cross Site Scripting vulnerability in Innovaphone myPBX v.14r1, v.13r3, v.12r2 allows a remote attacker to execute arbitrary code via the query parameter to the /CMD0/xml_modes.xml …

Apr 22, 2024
CVE-2015-10132
3.5 LOW

A vulnerability classified as problematic was found in Thimo Grauerholz WP-Spreadplugin up to 3.8.6.1 on WordPress. This vulnerability affects unknown code of the file spreadplugin.php. …

Apr 21, 2024
CVE-2024-29733
2.7 LOW

Improper Certificate Validation vulnerability in Apache Airflow FTP Provider. The FTP hook lacks complete certificate validation in FTP_TLS connections, which can potentially be leveraged. Implementing …

Apr 21, 2024
CVE-2024-29217
4.6 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: before 1.3.0. XSS attack when user changes …

Apr 21, 2024
CVE-2024-4022
5.3 MEDIUM

A vulnerability was found in Keenetic KN-1010, KN-1410, KN-1711, KN-1810 and KN-1910 up to 4.1.2.15. It has been rated as problematic. Affected by this issue …

Apr 21, 2024
CVE-2024-4021
5.3 MEDIUM

A vulnerability was found in Keenetic KN-1010, KN-1410, KN-1711, KN-1810 and KN-1910 up to 4.1.2.15. It has been declared as problematic. Affected by this vulnerability …

Apr 21, 2024
CVE-2024-4020
8.8 HIGH

A vulnerability was found in Tenda FH1206 1.2.0.8(8155) and classified as critical. This issue affects the function fromAddressNat of the file /goform/addressNat. The manipulation of …

Apr 20, 2024
CVE-2024-4019
6.3 MEDIUM

A vulnerability classified as critical has been found in Byzoro Smart S80 Management Platform up to 20240411. Affected is an unknown function of the file …

Apr 20, 2024
CVE-2024-4014
6.4 MEDIUM

The hCaptcha for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cf7-hcaptcha shortcode in all versions up to, and including, …

Apr 20, 2024
CVE-2024-1730
5.4 MEDIUM

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Media Slider, Drag Drop Slider, Video Slider, Product Slider, Ecommerce Slider) plugin …

Apr 20, 2024
CVE-2024-1057
6.4 MEDIUM

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored …

Apr 20, 2024
CVE-2024-31994
6.5 MEDIUM

Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, an attacker can point the image request to an arbitrarily large file. …

Apr 19, 2024
CVE-2024-1480
7.5 HIGH

Unitronics Vision Standard line of controllers allow the Information Mode password to be retrieved without authentication.

Apr 19, 2024
CVE-2024-4018
8.8 HIGH

Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (local appliance api modules) allows Privilege Escalation.This issue affects U-Series Appliance: from 3.4 …

Apr 19, 2024
CVE-2024-4017
8.8 HIGH

Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (filesystem modules) allows DLL Side-Loading.This issue affects U-Series Appliance: from 3.4 before 4.0.3.

Apr 19, 2024
CVE-2024-32392
4.5 MEDIUM

Cross Site Scripting vulnerability in CmSimple v.5.15 allows a remote attacker to execute arbitrary code via the functions.php component.

Apr 19, 2024
CVE-2024-32391
7.3 HIGH

Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.

Apr 19, 2024
CVE-2024-31993
6.2 MEDIUM

Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the scrape_image function will retrieve an image based on a user-provided URL, …

Apr 19, 2024
CVE-2024-31992
6.5 MEDIUM

Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-controlled URL to issue a request to …

Apr 19, 2024
CVE-2024-31991
4.1 MEDIUM

Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-controlled URL to issue a request to …

Apr 19, 2024
CVE-2024-31584
5.5 MEDIUM

Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.cpp.

Apr 19, 2024
CVE-2024-30974
7.3 HIGH

SQL Injection vulnerability in autoexpress v.1.3.0 allows attackers to run arbitrary SQL commands via the carId parameter.

Apr 19, 2024
CVE-2024-22905
7.0 HIGH

Buffer Overflow vulnerability in ARM mbed-os v.6.17.0 allows a remote attacker to execute arbitrary code via a crafted script to the hciTrSerialRxIncoming function.

Apr 19, 2024
CVE-2024-1681
5.3 MEDIUM

corydolphin/flask-cors is vulnerable to log injection when the log level is set to debug. An attacker can inject fake log entries into the log file …

Apr 19, 2024
CVE-2024-32652
7.5 HIGH

The adapter @hono/node-server allows you to run your Hono application on Node.js. Prior to 1.10.1, the application hangs when receiving a Host header with a …

Apr 19, 2024
CVE-2024-31450
2.7 LOW

Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. The Owncast application exposes an administrator API at the URL …

Apr 19, 2024
CVE-2024-3979
4.4 MEDIUM

A vulnerability, which was classified as problematic, has been found in COVESA vsomeip up to 3.4.10. Affected by this issue is some unknown functionality. The …

Apr 19, 2024
CVE-2024-31547
9.1 CRITICAL

Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/item/view_item.php.

Apr 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.