CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-28048
9.8 CRITICAL

OS command injection vulnerability exists in ffBull ver.4.11, which may allow a remote unauthenticated attacker to execute an arbitrary OS command with the privilege of …

Mar 26, 2024
CVE-2024-28034
5.4 MEDIUM

Cross-site scripting vulnerability exists in Mini Thread Version 3.33βi. An arbitrary script may be executed on the web browser of the user accessing the website …

Mar 26, 2024
CVE-2024-28033
7.3 HIGH

OS command injection vulnerability exists in WebProxy 1.7.8 and 1.7.9, which may allow a remote unauthenticated attacker to execute an arbitrary OS command with the …

Mar 26, 2024
CVE-2024-26018
6.1 MEDIUM

Cross-site scripting vulnerability exists in TvRock 0.9t8a. An arbitrary script may be executed on the web browser of the user accessing the website that uses …

Mar 26, 2024
CVE-2024-24805
5.3 MEDIUM

Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator.This issue affects WP Dummy Content Generator: from n/a through 3.1.2.

Mar 26, 2024
CVE-2023-7251
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr User Submitted Posts allows Stored XSS.This issue affects User Submitted Posts: …

Mar 26, 2024
CVE-2023-49838
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in KlbTheme Clotya theme, KlbTheme Cosmetsy theme, KlbTheme Furnob theme, KlbTheme Bacola theme, KlbTheme Partdo theme, KlbTheme Medibazar theme, KlbTheme …

Mar 26, 2024
CVE-2023-45771
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Contact Form With Captcha allows Reflected XSS.This issue affects Contact Form With Captcha: …

Mar 26, 2024
CVE-2023-41696

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 26, 2024
CVE-2023-33322
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design Front End Users allows Reflected XSS.This issue affects Front End …

Mar 26, 2024
CVE-2023-32237
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem (Elementor), CodexThemes TheGem (WPBakery) allows Stored XSS.This issue affects TheGem (Elementor): …

Mar 26, 2024
CVE-2023-23991
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPdevelop / Oplugins Booking Calendar allows SQL Injection.This issue affects Booking …

Mar 26, 2024
CVE-2023-6175
7.8 HIGH

NetScreen file parser crash in Wireshark 4.0.0 to 4.0.10 and 3.6.0 to 3.6.18 allows denial of service via crafted capture file

Mar 26, 2024
CVE-2023-51416
6.5 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in EnvialoSimple EnvíaloSimple.This issue affects EnvíaloSimple: from n/a through 2.2.

Mar 26, 2024
CVE-2023-49839
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KlbTheme Cosmetsy theme (core plugin), KlbTheme Partdo theme (core plugin), KlbTheme Bacola theme …

Mar 26, 2024
CVE-2024-2889
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister Lite for Amazon wp-lister-for-amazon.This issue affects WP-Lister Lite for Amazon: …

Mar 26, 2024
CVE-2024-2888
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor …

Mar 26, 2024
CVE-2024-2303
6.4 MEDIUM

The Easy Textillate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'textillate' shortcode in all versions up to, and including, 2.01 …

Mar 26, 2024
CVE-2024-2170
6.4 MEDIUM

The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the child page index widget in all versions …

Mar 26, 2024
CVE-2024-1745
4.3 MEDIUM

The Testimonial Slider WordPress plugin before 2.3.7 does not properly ensure that a user has the necessary capabilities to edit certain sensitive Testimonial Slider WordPress …

Mar 26, 2024
CVE-2023-7232
5.3 MEDIUM

The Backup and Restore WordPress WordPress plugin through 1.45 does not protect some log files containing sensitive information such as site configuration etc, allowing unauthenticated …

Mar 26, 2024
CVE-2024-29199
3.7 LOW

Nautobot is a Network Source of Truth and Network Automation Platform. A number of Nautobot URL endpoints were found to be improperly accessible to unauthenticated …

Mar 26, 2024
CVE-2024-29196
3.8 LOW

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. There is a Path Traversal vulnerability in Attachments …

Mar 26, 2024
CVE-2024-29195
6.0 MEDIUM

The azure-c-shared-utility is a C library for AMQP/MQTT communication to Azure Cloud Services. This library may be used by the Azure IoT C SDK for …

Mar 26, 2024
CVE-2024-29189
7.4 HIGH

PyAnsys Geometry is a Python client library for the Ansys Geometry service and other CAD Ansys products. On file src/ansys/geometry/core/connection/product_instance.py, upon calling this method _start_program …

Mar 26, 2024
CVE-2024-0866
8.1 HIGH

The Check & Log Email plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 1.0.9 via the check_nonce …

Mar 26, 2024
CVE-2024-2732
5.4 MEDIUM

The Themify Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'themify_post_slider shortcode in all versions up to, and including, 2.0.8 …

Mar 26, 2024
CVE-2024-29303
9.8 CRITICAL

The delete admin users function of SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection

Mar 26, 2024
CVE-2024-29302
7.5 HIGH

SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-employee.php.

Mar 26, 2024
CVE-2024-29301
7.5 HIGH

SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-admin.php?admin_id=

Mar 26, 2024
CVE-2024-28421
9.8 CRITICAL

SQL Injection vulnerability in Razor 0.8.0 allows a remote attacker to escalate privileges via the ChannelModel::updateapk method of the channelmodle.php

Mar 25, 2024
CVE-2024-0901
7.5 HIGH

Remotely executed SEGV and out of bounds read allows malicious packet sender to crash or cause an out of bounds read via sending a malformed …

Mar 25, 2024
CVE-2024-2873
9.1 CRITICAL

A vulnerability was found in wolfSSH's server-side state machine before versions 1.4.17. A malicious client could create channels without first performing user authentication, resulting in …

Mar 25, 2024
CVE-2024-29442

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Mar 25, 2024
CVE-2024-21914
5.3 MEDIUM

A vulnerability exists in the affected product that allows a malicious user to restart the Rockwell Automation PanelView™ Plus 7 terminal remotely without security protections. …

Mar 25, 2024
CVE-2024-1973
8.5 HIGH

By leveraging the vulnerability, lower-privileged users of Content Manager can manipulate Content Manager clients to elevate privileges and perform unauthorized operations.

Mar 25, 2024
CVE-2023-47430
7.5 HIGH

Stack-buffer-overflow vulnerability in ReadyMedia (MiniDLNA) v1.3.3 allows attackers to cause a denial of service via via the SendContainer() function at tivo_commands.c.

Mar 25, 2024
CVE-2024-2427
7.5 HIGH

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper traffic throttling in the device. If multiple data packets are sent to …

Mar 25, 2024
CVE-2024-2426
7.5 HIGH

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, a disruption in the CIP …

Mar 25, 2024
CVE-2024-2425
7.5 HIGH

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, the web server will crash …

Mar 25, 2024
CVE-2024-29440

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Mar 25, 2024
CVE-2024-29179
4.8 MEDIUM

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. An attacker with admin privileges can upload an …

Mar 25, 2024
CVE-2024-29041
6.1 MEDIUM

Express.js minimalist web framework for node. Versions of Express.js prior to 4.19.0 and all pre-release alpha and beta versions of 5.0 are affected by an …

Mar 25, 2024
CVE-2024-29025
5.3 MEDIUM

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to …

Mar 25, 2024
CVE-2024-28246
5.5 MEDIUM

KaTeX is a JavaScript library for TeX math rendering on the web. Code that uses KaTeX's `trust` option, specifically that provides a function to blacklist …

Mar 25, 2024
CVE-2024-28245
6.3 MEDIUM

KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\includegraphics` …

Mar 25, 2024
CVE-2024-28244
6.5 MEDIUM

KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\def` …

Mar 25, 2024
CVE-2024-28243
6.5 MEDIUM

KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\edef` …

Mar 25, 2024
CVE-2024-29666
9.8 CRITICAL

Insecure Permissions vulnerability in Vehicle Monitoring platform system CMSV6 v.7.31.0.2 through v.7.32.0.3 allows a remote attacker to escalate privileges via the default password component.

Mar 25, 2024
CVE-2024-29515
8.8 HIGH

File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file to the save.php and …

Mar 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.