CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-29271
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) vulnerability in VvvebJs before version 1.7.7, allows remote attackers to execute arbitrary code and obtain sensitive information via the action parameter …

Mar 22, 2024
CVE-2024-25808
8.3 HIGH

Cross-site Request Forgery (CSRF) vulnerability in Lychee version 3.1.6, allows remote attackers to execute arbitrary code via the create new album function.

Mar 22, 2024
CVE-2024-2805
8.8 HIGH

A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. It has been rated as critical. Affected by this issue is the function formSetSpeedWan of the file …

Mar 22, 2024
CVE-2024-26557
5.4 MEDIUM

Codiad v2.8.4 allows reflected XSS via the components/market/dialog.php type parameter.

Mar 22, 2024
CVE-2024-25807
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Lychee 3.1.6, allows remote attackers to execute arbitrary code and obtain sensitive information via the title parameter when creating …

Mar 22, 2024
CVE-2024-2780
3.5 LOW

A vulnerability was found in Campcodes Online Marriage Registration System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file …

Mar 22, 2024
CVE-2024-2500
6.4 MEDIUM

The ColorMag theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.1.6 due …

Mar 22, 2024
CVE-2024-2392
6.4 MEDIUM

The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Newsletter widget in all versions up to, and including, 2.0.31 …

Mar 22, 2024
CVE-2024-2080
4.3 MEDIUM

The LiquidPoll – Polls, Surveys, NPS and Feedback Reviews plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, …

Mar 22, 2024
CVE-2024-28441
9.8 CRITICAL

File Upload vulnerability in magicflue v.7.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the messageid parameter of …

Mar 22, 2024
CVE-2024-0957
6.1 MEDIUM

The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Customer Notes field …

Mar 22, 2024
CVE-2024-2779
3.5 LOW

A vulnerability was found in Campcodes Online Marriage Registration System 1.0. It has been classified as problematic. This affects an unknown part of the file …

Mar 22, 2024
CVE-2024-2778
3.5 LOW

A vulnerability was found in Campcodes Online Marriage Registration System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the …

Mar 22, 2024
CVE-2024-2777
6.3 MEDIUM

A vulnerability has been found in Campcodes/PHPGurukul Online Marriage Registration System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Mar 22, 2024
CVE-2024-2776
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Campcodes Online Marriage Registration System 1.0. Affected is an unknown function of the file /admin/search.php. …

Mar 22, 2024
CVE-2024-2775
3.5 LOW

A vulnerability, which was classified as problematic, has been found in Campcodes Online Marriage Registration System 1.0. This issue affects some unknown processing of the …

Mar 21, 2024
CVE-2024-2774
6.3 MEDIUM

A vulnerability classified as critical was found in Campcodes Online Marriage Registration System 1.0. This vulnerability affects unknown code of the file /user/search.php. The manipulation …

Mar 21, 2024
CVE-2024-2773
3.5 LOW

A vulnerability classified as problematic has been found in Campcodes Online Marriage Registration System 1.0. This affects an unknown part of the file /user/search.php. The …

Mar 21, 2024
CVE-2024-2770
6.3 MEDIUM

A vulnerability was found in Campcodes Complete Online Beauty Parlor Management System 1.0. It has been rated as critical. Affected by this issue is some …

Mar 21, 2024
CVE-2024-2453
6.4 MEDIUM

There is an SQL injection vulnerability in Advantech WebAccess/SCADA software that allows an authenticated attacker to remotely inject SQL code in the database. Successful exploitation …

Mar 21, 2024
CVE-2024-29031
7.5 HIGH

Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructure and applications. A SQL injection vulnerability in Meshery …

Mar 21, 2024
CVE-2024-28863
6.5 MEDIUM

node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. …

Mar 21, 2024
CVE-2024-28171
8.1 HIGH

It is possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists …

Mar 21, 2024
CVE-2024-28045
4.6 MEDIUM

Improper neutralization of input within the affected product could lead to cross-site scripting.

Mar 21, 2024
CVE-2024-28040
8.8 HIGH

SQL injection vulnerability exists in GetDIAE_astListParameters.

Mar 21, 2024
CVE-2024-25567
8.1 HIGH

Path traversal attack is possible and write outside of the intended directory and may access sensitive information. If a file name is specified that already …

Mar 21, 2024
CVE-2024-23975
8.8 HIGH

SQL injection vulnerability exists in GetDIAE_slogListParameters.

Mar 21, 2024
CVE-2024-23494
8.8 HIGH

SQL injection vulnerability exists in GetDIAE_unListParameters.

Mar 21, 2024
CVE-2023-42954
4.9 MEDIUM

A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in to the Admin Console with an administrator …

Mar 21, 2024
CVE-2024-2769
6.3 MEDIUM

A vulnerability was detected in Campcodes Complete Online Beauty Parlor Management System 1.0. The affected element is an unknown function of the file /admin/admin-profile.php. The …

Mar 21, 2024
CVE-2024-2768
6.3 MEDIUM

A vulnerability was found in Campcodes Complete Online Beauty Parlor Management System 1.0. It has been classified as critical. Affected is an unknown function of …

Mar 21, 2024
CVE-2024-28891
8.8 HIGH

SQL injection vulnerability exists in the script Handler_CFG.ashx.

Mar 21, 2024
CVE-2024-28521
7.8 HIGH

SQL Injection vulnerability in Netcome NS-ASG Application Security Gateway v.6.3.1 allows a local attacker to execute arbitrary code and obtain sensitive information via a crafted …

Mar 21, 2024
CVE-2024-28119
8.8 HIGH

Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from grav context, an …

Mar 21, 2024
CVE-2024-28118
8.8 HIGH

Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from Grav context, an …

Mar 21, 2024
CVE-2024-28117
8.8 HIGH

Grav is an open-source, flat-file content management system. Prior to version 1.7.45, Grav validates accessible functions through the Utils::isDangerousFunction function, but does not impose restrictions …

Mar 21, 2024
CVE-2024-28116
8.8 HIGH

Grav is an open-source, flat-file content management system. Grav CMS prior to version 1.7.45 is vulnerable to a Server-Side Template Injection (SSTI), which allows any …

Mar 21, 2024
CVE-2024-28029
8.8 HIGH

Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality.

Mar 21, 2024
CVE-2024-27921
8.8 HIGH

Grav is an open-source, flat-file content management system. A file upload path traversal vulnerability has been identified in the application prior to version 1.7.45, enabling …

Mar 21, 2024
CVE-2024-25937
8.8 HIGH

SQL injection vulnerability exists in the script DIAE_tagHandler.ashx.

Mar 21, 2024
CVE-2024-24272
7.1 HIGH

An issue in iTop DualSafe Password Manager & Digital Vault before 1.4.24 allows a local attacker to obtain sensitive information via leaked credentials as plaintext …

Mar 21, 2024
CVE-2024-2767
6.3 MEDIUM

A vulnerability was found in Campcodes Complete Online Beauty Parlor Management System 1.0 and classified as critical. This issue affects some unknown processing of the …

Mar 21, 2024
CVE-2024-2766
6.3 MEDIUM

A vulnerability has been found in Campcodes Complete Online Beauty Parlor Management System 1.0 and classified as critical. This vulnerability affects unknown code of the …

Mar 21, 2024
CVE-2024-2764
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.48. This affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of …

Mar 21, 2024
CVE-2024-2763
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.48. Affected by this issue is the function formSetCfm of the file …

Mar 21, 2024
CVE-2024-28756
5.9 MEDIUM

The SolarEdge mySolarEdge application before 2.20.1 for Android has a certificate verification issue that allows a Machine-in-the-middle (MitM) attacker to read and alter all network …

Mar 21, 2024
CVE-2024-1727
4.3 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability in gradio-app/gradio allows attackers to upload multiple large files to a victim's system if they are running Gradio locally. …

Mar 21, 2024
CVE-2024-29374
6.1 MEDIUM

A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.

Mar 21, 2024
CVE-2024-2580
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelKit Automation By Autonami allows Stored XSS.This issue affects Automation By Autonami: from …

Mar 21, 2024
CVE-2024-2579
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Tracking Code Manager.This issue affects Tracking Code Manager: from n/a through 2.0.16.

Mar 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.