CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-28564
6.2 MEDIUM

Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the Imf_2_2::CharPtrIO::readChars() function when …

Mar 20, 2024
CVE-2024-28563
5.9 MEDIUM

Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the Imf_2_2::DwaCompressor::Classifier::Classifier() function when …

Mar 20, 2024
CVE-2024-28562
6.8 MEDIUM

Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Imf_2_2::copyIntoFrameBuffer() component when reading images in …

Mar 20, 2024
CVE-2024-2673
6.3 MEDIUM

A vulnerability classified as critical has been found in Campcodes Online Job Finder System 1.0. This affects an unknown part of the file /admin/login.php. The …

Mar 20, 2024
CVE-2024-2672
6.3 MEDIUM

A vulnerability was found in Campcodes Online Job Finder System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Mar 20, 2024
CVE-2024-2474
6.4 MEDIUM

The Standout Color Boxes and Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'color-button' shortcode in all versions up to, …

Mar 20, 2024
CVE-2024-2124
6.4 MEDIUM

The Translate WordPress and go Multilingual – Weglot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget/block in all versions up …

Mar 20, 2024
CVE-2024-22085
6.2 MEDIUM

An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The shadow file is world readable.

Mar 20, 2024
CVE-2024-22084
7.5 HIGH

An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Cleartext passwords and hashes are exposed through log files.

Mar 20, 2024
CVE-2024-22083
6.5 MEDIUM

An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. A hardcoded backdoor session ID exists that can be used for …

Mar 20, 2024
CVE-2024-22082
7.5 HIGH

An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated directory listing can occur: the web interface cay be abused …

Mar 20, 2024
CVE-2024-22081
9.8 CRITICAL

An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated memory corruption can occur in the HTTP header parsing mechanism.

Mar 20, 2024
CVE-2024-22080
9.8 CRITICAL

An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated memory corruption can occur during XML body parsing.

Mar 20, 2024
CVE-2024-22079
7.5 HIGH

An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Directory traversal can occur via the system logs download mechanism.

Mar 20, 2024
CVE-2024-22078
8.8 HIGH

An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Privilege escalation can occur via world writable files. The network configuration …

Mar 20, 2024
CVE-2024-22077
5.3 MEDIUM

An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The SQLite database file has weak permissions.

Mar 20, 2024
CVE-2024-1983
7.1 HIGH

The Simple Ajax Chat WordPress plugin before 20240223 does not prevent visitors from using malicious Names when using the chat, which will be reflected unsanitized …

Mar 20, 2024
CVE-2024-0856
8.8 HIGH

The Appointment Booking Calendar WordPress plugin before 1.3.83 does not have CSRF checks in some places, which could allow attackers to make logged in users …

Mar 20, 2024
CVE-2024-0337
6.1 MEDIUM

The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on the travelpayouts_redirect variable. …

Mar 20, 2024
CVE-2023-7246
5.4 MEDIUM

The System Dashboard WordPress plugin before 2.8.10 does not sanitize and escape some parameters, which could allow administrators in multisite WordPress configurations to perform Cross-Site …

Mar 20, 2024
CVE-2024-2671
6.3 MEDIUM

A vulnerability was found in Campcodes Online Job Finder System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Mar 20, 2024
CVE-2024-2670
6.3 MEDIUM

A vulnerability was found in Campcodes Online Job Finder System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Mar 20, 2024
CVE-2024-2255
6.4 MEDIUM

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in …

Mar 20, 2024
CVE-2024-22258
6.1 MEDIUM

Spring Authorization Server versions 1.0.0 - 1.0.5, 1.1.0 - 1.1.5, 1.2.0 - 1.2.2 and older unsupported versions are susceptible to a PKCE Downgrade Attack for …

Mar 20, 2024
CVE-2024-2460
6.4 MEDIUM

The GamiPress – Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gamipress_button' shortcode in all versions up to, and including, …

Mar 20, 2024
CVE-2024-2384
4.3 MEDIUM

The WooCommerce POS plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.4.11. This is due to the plugin …

Mar 20, 2024
CVE-2024-1799
8.8 HIGH

The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to SQL Injection via …

Mar 20, 2024
CVE-2024-2669
6.3 MEDIUM

A vulnerability was found in Campcodes Online Job Finder System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/employee/controller.php …

Mar 20, 2024
CVE-2024-2668
6.3 MEDIUM

A vulnerability has been found in Campcodes Online Job Finder System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/vacancy/controller.php. …

Mar 20, 2024
CVE-2024-2387
6.1 MEDIUM

The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for WordPress is vulnerable to SQL Injection …

Mar 20, 2024
CVE-2024-1995
4.3 MEDIUM

The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relational_posts_search() function in …

Mar 20, 2024
CVE-2024-1787
6.4 MEDIUM

The Contests by Rewards Fuel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'update_rewards_fuel_api_key' parameter in all versions up to, and including, …

Mar 20, 2024
CVE-2024-1785
5.4 MEDIUM

The Contests by Rewards Fuel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.62. This is due …

Mar 20, 2024
CVE-2024-2649
6.3 MEDIUM

A vulnerability has been found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Mar 20, 2024
CVE-2024-2197
4.3 MEDIUM

The Chirp Access app contains a hard-coded password, BEACON_PASSWORD. An attacker within Bluetooth range could change configuration settings within the Bluetooth beacon, effectively disabling the …

Mar 20, 2024
CVE-2024-2648
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Netentsec NS-ASG Application Security Gateway 6.3. Affected is an unknown function of the file /nac/naccheck.php. …

Mar 19, 2024
CVE-2024-2647
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Netentsec NS-ASG Application Security Gateway 6.3. This issue affects some unknown processing of the …

Mar 19, 2024
CVE-2024-2646
6.3 MEDIUM

A vulnerability classified as critical was found in Netentsec NS-ASG Application Security Gateway 6.3. This vulnerability affects unknown code of the file /vpnweb/index.php?para=index. The manipulation …

Mar 19, 2024
CVE-2024-2645
4.3 MEDIUM

A vulnerability classified as problematic has been found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /vpnweb/resetpwd/resetpwd.php. The …

Mar 19, 2024
CVE-2024-2644
6.3 MEDIUM

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been rated as critical. Affected by this issue is some unknown functionality …

Mar 19, 2024
CVE-2024-2642
7.3 HIGH

A vulnerability was found in Ruijie RG-NBS2009G-P up to 20240305. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Mar 19, 2024
CVE-2023-50811
6.5 MEDIUM

An issue discovered in SELESTA Visual Access Manager 4.38.6 allows attackers to modify the “computer” POST parameter related to the ID of a specific reception …

Mar 19, 2024
CVE-2024-2641
5.3 MEDIUM

A vulnerability was found in Ruijie RG-NBS2009G-P up to 20240305. It has been classified as critical. Affected is an unknown function of the file /system/passwdManage.htm …

Mar 19, 2024
CVE-2024-28715
8.8 HIGH

Cross Site Scripting vulnerability in DOraCMS v.2.18 and before allows a remote attacker to execute arbitrary code via the markdown0 function in the /app/public/apidoc/oas3/wrap-components/markdown.jsx endpoint.

Mar 19, 2024
CVE-2024-28389
9.8 CRITICAL

SQL injection vulnerability in KnowBand spinwheel v.3.0.3 and before allows a remote attacker to gain escalated privileges and obtain sensitive information via the SpinWheelFrameSpinWheelModuleFrontController::sendEmail() method.

Mar 19, 2024
CVE-2024-28283
6.7 MEDIUM

There is stack-based buffer overflow vulnerability in pc_change_act function in Linksys E1000 router firmware version v.2.1.03 and before, leading to remote code execution.

Mar 19, 2024
CVE-2024-28092
7.2 HIGH

UBEE DDW365 XCNDDW365 8.14.3105 software on hardware 3.13.1 allows a remote attacker within Wi-Fi proximity to conduct stored XSS attacks via RgFirewallEL.asp, RgDdns.asp, RgTime.asp, RgDiagnostics.asp, …

Mar 19, 2024
CVE-2024-24336
8.1 HIGH

A multiple Cross-site scripting (XSS) vulnerability in the '/members/moremember.pl', and ‘/members/members-home.pl’ endpoints within Koha Library Management System version 23.05.05 and earlier allows malicious staff users …

Mar 19, 2024
CVE-2024-2169
7.5 HIGH

Implementations of UDP application protocol are vulnerable to network loops. An unauthenticated attacker can use maliciously-crafted packets against a vulnerable implementation that can lead to …

Mar 19, 2024
CVE-2024-28595
9.8 CRITICAL

SQL Injection vulnerability in Employee Management System v1.0 allows attackers to run arbitrary SQL commands via the admin_id parameter in update-admin.php.

Mar 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.