CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-27102
9.9 CRITICAL

Wings is the server control plane for Pterodactyl Panel. This vulnerability impacts anyone running the affected versions of Wings. The vulnerability can potentially be used …

Mar 13, 2024
CVE-2024-27097
4.3 MEDIUM

A user endpoint didn't perform filtering on an incoming parameter, which was added directly to the application log. This could lead to an attacker injecting …

Mar 13, 2024
CVE-2024-25250
9.8 CRITICAL

SQL Injection vulnerability in code-projects Agro-School Management System 1.0 allows attackers to run arbitrary code via the Login page.

Mar 13, 2024
CVE-2024-24105
7.8 HIGH

SQL Injection vulnerability in Code-projects Computer Science Time Table System 1.0 allows attackers to run arbitrary code via adminFormvalidation.php.

Mar 13, 2024
CVE-2024-22167
7.9 HIGH

A potential DLL hijacking vulnerability in the SanDisk PrivateAccess application for Windows that could lead to arbitrary code execution in the context of the system …

Mar 13, 2024
CVE-2023-50726
6.4 MEDIUM

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. "Local sync" is an Argo CD feature that allows developers to temporarily override an …

Mar 13, 2024
CVE-2023-41505
9.8 CRITICAL

An arbitrary file upload vulnerability in the Add Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via …

Mar 13, 2024
CVE-2023-41504
8.8 HIGH

SQL Injection vulnerability in Student Enrollment In PHP 1.0 allows attackers to run arbitrary code via the Student Search function.

Mar 13, 2024
CVE-2023-36238
6.5 MEDIUM

Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the invoice ID parameter.

Mar 13, 2024
CVE-2024-24693
7.2 HIGH

Improper access control in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authenticated user to conduct a denial of …

Mar 13, 2024
CVE-2024-24692
5.3 MEDIUM

Race condition in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authenticated user to conduct a denial of service …

Mar 13, 2024
CVE-2024-28194
9.1 CRITICAL

your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify versions < 1.8.0 use a hardcoded JSON Web Token (JWT) secret to sign authentication …

Mar 13, 2024
CVE-2024-0801
7.5 HIGH

A denial of service vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in ASNative.dll.

Mar 13, 2024
CVE-2024-0800
8.8 HIGH

A path traversal vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.servlet.ImportNodeServlet.

Mar 13, 2024
CVE-2024-0799
9.8 CRITICAL

An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin.

Mar 13, 2024
CVE-2024-2433
4.3 MEDIUM

An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authenticated read-only administrator to upload files using the web interface and completely fill …

Mar 13, 2024
CVE-2024-2432
4.5 MEDIUM

A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. …

Mar 13, 2024
CVE-2024-2431
5.5 MEDIUM

An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a user to …

Mar 13, 2024
CVE-2024-2418
6.3 MEDIUM

A vulnerability was found in SourceCodester Best POS Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Mar 13, 2024
CVE-2024-2403
5.9 MEDIUM

Improper cleanup in temporary file handling component in Devolutions Remote Desktop Manager 2024.1.12 and earlier on Windows allows an attacker that compromised a user endpoint, …

Mar 13, 2024
CVE-2024-28196
6.5 MEDIUM

your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version < 1.9.0 does not prevent other pages from displaying it in an iframe …

Mar 13, 2024
CVE-2024-28195
8.1 HIGH

your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify versions < 1.9.0 do not protect the API and login flow against Cross-Site Request …

Mar 13, 2024
CVE-2024-27953
4.7 MEDIUM

Missing Authorization vulnerability in Cool Plugins Cryptocurrency Widgets – Price Ticker & Coins List.This issue affects Cryptocurrency Widgets – Price Ticker & Coins List: from …

Mar 13, 2024
CVE-2024-27952
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Codeus Advanced Sermons allows Reflected XSS.This issue affects Advanced Sermons: from n/a …

Mar 13, 2024
CVE-2024-20327
7.4 HIGH

A vulnerability in the PPP over Ethernet (PPPoE) termination feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow …

Mar 13, 2024
CVE-2024-20322
5.8 MEDIUM

A vulnerability in the access control list (ACL) processing on Pseudowire interfaces in the ingress direction of Cisco IOS XR Software could allow an unauthenticated, …

Mar 13, 2024
CVE-2024-20320
7.8 HIGH

A vulnerability in the SSH client feature of Cisco IOS XR Software for Cisco 8000 Series Routers and Cisco Network Convergence System (NCS) 540 Series …

Mar 13, 2024
CVE-2024-20319
4.3 MEDIUM

A vulnerability in the UDP forwarding code of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to bypass configured management plane protection policies …

Mar 13, 2024
CVE-2024-20318
7.4 HIGH

A vulnerability in the Layer 2 Ethernet services of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the line card network …

Mar 13, 2024
CVE-2024-20315
5.8 MEDIUM

A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR Software could allow an unauthenticated, …

Mar 13, 2024
CVE-2024-20266
5.3 MEDIUM

A vulnerability in the DHCP version 4 (DHCPv4) server feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to trigger a crash …

Mar 13, 2024
CVE-2024-20262
6.5 MEDIUM

A vulnerability in the Secure Copy Protocol (SCP) and SFTP feature of Cisco IOS XR Software could allow an authenticated, local attacker to create or …

Mar 13, 2024
CVE-2024-0173
3.8 LOW

Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability …

Mar 13, 2024
CVE-2024-0163
5.3 MEDIUM

Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain a TOCTOU race condition vulnerability. A local low privileged attacker could potentially exploit this vulnerability …

Mar 13, 2024
CVE-2024-0162
5.3 MEDIUM

Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit …

Mar 13, 2024
CVE-2024-0154
3.8 LOW

Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability …

Mar 13, 2024
CVE-2024-2293
6.4 MEDIUM

The Site Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user display name in all versions up to, and including, 6.11.4 …

Mar 13, 2024
CVE-2024-2286
6.4 MEDIUM

The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart) plugin for WordPress is vulnerable to Stored …

Mar 13, 2024
CVE-2024-2252
5.4 MEDIUM

The Droit Elementor Addons – Widgets, Blocks, Templates Library For Elementor Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets …

Mar 13, 2024
CVE-2024-2239
6.4 MEDIUM

The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Premium Magic Scroll module in all versions up to, and …

Mar 13, 2024
CVE-2024-2238
6.4 MEDIUM

The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Mouse Cursor module in all versions up to, and …

Mar 13, 2024
CVE-2024-2237
6.4 MEDIUM

The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Global Badge module in all versions up to, and including, …

Mar 13, 2024
CVE-2024-2194
7.2 HIGH

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL search parameter in all versions up to, and including, 14.5 …

Mar 13, 2024
CVE-2024-2172
9.8 CRITICAL

The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability …

Mar 13, 2024
CVE-2024-2126
6.4 MEDIUM

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Registration Form widget in all versions up to, and …

Mar 13, 2024
CVE-2024-2106
5.3 MEDIUM

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, …

Mar 13, 2024
CVE-2024-2030
6.4 MEDIUM

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions …

Mar 13, 2024
CVE-2024-2028
6.4 MEDIUM

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Covid-19 Stats Widget in all versions up to, and …

Mar 13, 2024
CVE-2024-2020
7.2 HIGH

The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form page href parameter in all versions up to, and …

Mar 13, 2024
CVE-2024-2006
8.8 HIGH

The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to PHP Object Injection in …

Mar 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.