121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of the 'tag' attribute in the wprm-recipe-name, wprm-recipe-date, and …
The WP Recipe Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Referer' header in all versions up to, and including, 9.1.0 …
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 9.1.0 …
A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be …
A vulnerability has been found in Novel-Plus 4.3.0-RC1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /novel/bookSetting/list. The …
In autotest driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with …
In drm driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …
In vsp driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …
In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …
In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …
In telephone service, there is a possible improper input validation. This could lead to local information disclosure with no additional execution privileges needed
In vsp driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System …
In phasecheckserver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with …
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …
In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with …
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with …
In video decoder, there is a possible improper input validation. This could lead to local denial of service with no additional execution privileges needed
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with …
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with …
In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with …
In media service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with …
In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with …
In jpg driver, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed
A vulnerability, which was classified as problematic, was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22. Affected is an unknown function of the file mainscripts/Util.py. The manipulation leads …
A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality …
A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …
Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting
A vulnerability was found in Karjasoft Sami HTTP Server 2.0. It has been classified as problematic. Affected is an unknown function of the component HTTP …
The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.
pyLoad is a free and open-source Download Manager written in pure Python. The `pyload` API allows any API call to be made using GET requests. …
A vulnerability was found in Project Worlds Visitor Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file …
SonicWall Capture Client version 3.7.10, NetExtender client version 10.2.337 and earlier versions are installed with sfpmonitor.sys driver. The driver has been found to be vulnerable …
A vulnerability was found in ZhiHuiYun up to 4.4.13 and classified as critical. This issue affects the function download_network_image of the file /app/Http/Controllers/ImageController.php of the …
A vulnerability has been found in Yunyou CMS up to 2.2.6 and classified as critical. This vulnerability affects unknown code of the file /app/index/controller/Common.php. The …
flaskBlog is a simple blog app built with Flask. Improper storage and rendering of the `/user/<user>` page allows a user's comments to execute arbitrary javascript …
Creditcoin is a network that enables cross-blockchain credit transactions. The Windows binary of the Creditcoin node loads a suite of DLLs provided by Microsoft at …
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory …
Cross-site scripting (XSS)
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with …
A Cross-site scripting (XSS) vulnerability in login page php code in Armex ABO.CMS 5.9 allows remote attackers to inject arbitrary web script or HTML via …
Studio Network Solutions ShareBrowser before 7.0 on macOS mishandles signature verification, aka PMP-2636.
A vulnerability, which was classified as problematic, was found in Sparksuite SimpleMDE up to 1.11.2. This affects an unknown part of the component iFrame Handler. …
Insecure Direct Object Reference vulnerabilities were discovered in the Avaya Aura Experience Portal Manager which may allow partial information disclosure to an authenticated non-privileged user. …
Missing Authorization vulnerability in ThemeinProgress WIP Custom Login.This issue affects WIP Custom Login: from n/a through 1.2.7.
Stupid Simple CMS <=1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin-edit.php.
Stupid Simple CMS <=1.2.4 is vulnerable to Cross Site Scripting (XSS) in the editing section of the article content.
Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.1.76.
Free website and port scanning — find vulnerabilities before attackers do.