CVE Database

38770+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9188
8.8 HIGH

Specially constructed queries cause cross platform scripting leaking administrator tokens

Jan 10, 2025
CVE-2024-9134
8.3 HIGH

Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL injection, allowing them to …

Jan 10, 2025
CVE-2024-9132
8.1 HIGH

The administrator is able to configure an insecure captive portal script

Jan 10, 2025
CVE-2024-9131
7.2 HIGH

A user with administrator privileges can perform command injection

Jan 10, 2025
CVE-2024-47520
7.6 HIGH

A user with advanced report application access rights can perform actions for which they are not authorized

Jan 10, 2025
CVE-2024-47519
8.3 HIGH

Backup uploads to ETM subject to man-in-the-middle interception

Jan 10, 2025
CVE-2024-54996
8.8 HIGH

MonicaHQ v4.1.2 was discovered to contain multiple authenticated Client-Side Injection vulnerabilities via the title and description parameters at /people/ID/reminders/create.

Jan 10, 2025
CVE-2024-57228
8.0 HIGH

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function.

Jan 10, 2025
CVE-2024-57227
8.0 HIGH

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function.

Jan 10, 2025
CVE-2024-57226
8.0 HIGH

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_enable function.

Jan 10, 2025
CVE-2024-57211
8.0 HIGH

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the modifyOne parameter in the enable_wsh function.

Jan 10, 2025
CVE-2024-54848
7.4 HIGH

Improper handling and storage of certificates in CP Plus CP-VNR-3104 B3223P22C02424 allow attackers to decrypt communications or execute a man-in-the-middle attacks.

Jan 10, 2025
CVE-2025-22598
8.3 HIGH

WeGIA is a web manager for charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the cadastrarSocio.php endpoint of the WeGIA application. This …

Jan 10, 2025
CVE-2025-22597
8.3 HIGH

WeGIA is a web manager for charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the CobrancaController.php endpoint of the WeGIA application. This …

Jan 10, 2025
CVE-2024-46210
7.2 HIGH

An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitrary code via uploading a crafted file.

Jan 10, 2025
CVE-2024-25371
7.5 HIGH

Gramine before a390e33e16ed374a40de2344562a937f289be2e1 suffers from an Interface vulnerability due to mismatching SW signals vs HW exceptions.

Jan 10, 2025
CVE-2025-21380
8.8 HIGH

Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network.

Jan 9, 2025
CVE-2025-21385
8.8 HIGH

A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview allows an authorized attacker to disclose information over a network.

Jan 9, 2025
CVE-2024-51229
8.8 HIGH

Cross Site Scripting vulnerability in LinZhaoguan pb-cms v.2.0 allows a remote attacker to execute arbitrary code via the theme management function.

Jan 9, 2025
CVE-2024-46464
7.8 HIGH

In PRIMX ZED Enterprise up to 2024.3, technical files stored in local folders with common user access can be manipulated to render the host computer …

Jan 9, 2025
CVE-2024-13311
7.3 HIGH

Vulnerability in Drupal Allow All File Extensions for file fields.This issue affects Allow All File Extensions for file fields: *.*.

Jan 9, 2025
CVE-2024-13291
7.3 HIGH

Incorrect Authorization vulnerability in Drupal Basic HTTP Authentication allows Forceful Browsing.This issue affects Basic HTTP Authentication: from 7.X-1.0 before 7.X-1.4.

Jan 9, 2025
CVE-2024-56113
7.5 HIGH

Smart Toilet Lab - Motius 1.3.11 is running with debug mode turned on (DEBUG = True) and exposing sensitive information defined in Django settings file …

Jan 9, 2025
CVE-2024-54887
8.0 HIGH

TP-Link TL-WR940N V3 and V4 with firmware 3.16.9 and earlier contain a buffer overflow via the dnsserver1 and dnsserver2 parameters at /userRpm/Wan6to4TunnelCfgRpm.htm. This vulnerability allows …

Jan 9, 2025
CVE-2024-13284
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Gutenberg allows Cross Site Request Forgery.This issue affects Gutenberg: from 0.0.0 before 2.13.0, from 3.0.0 before 3.0.5.

Jan 9, 2025
CVE-2024-13282
8.8 HIGH

Incorrect Authorization vulnerability in Drupal Block permissions allows Forceful Browsing.This issue affects Block permissions: from 1.0.0 before 1.2.0.

Jan 9, 2025
CVE-2024-13276
7.5 HIGH

Insertion of Sensitive Information Into Sent Data vulnerability in Drupal File Entity (fieldable files) allows Forceful Browsing.This issue affects File Entity (fieldable files): from 7.X-* …

Jan 9, 2025
CVE-2024-13267
7.5 HIGH

Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno TinCan Question Type allows PHP Local File Inclusion.This issue affects …

Jan 9, 2025
CVE-2024-13265
7.5 HIGH

Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno Learning path allows PHP Local File Inclusion.This issue affects Opigno …

Jan 9, 2025
CVE-2024-13260
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate queue importer allows Cross Site Request Forgery.This issue affects Migrate queue importer: from 0.0.0 before 2.1.1.

Jan 9, 2025
CVE-2025-21598
7.5 HIGH

An Out-of-bounds Read vulnerability in Juniper Networks Junos OS and Junos OS Evolved's routing protocol daemon (rpd) allows an unauthenticated, network-based attacker to send malformed …

Jan 9, 2025
CVE-2024-13259
7.5 HIGH

Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Image Sizes allows Forceful Browsing.This issue affects Image Sizes: from 0.0.0 before 3.0.2.

Jan 9, 2025
CVE-2024-13256
7.5 HIGH

Insufficient Granularity of Access Control vulnerability in Drupal Email Contact allows Forceful Browsing.This issue affects Email Contact: from 0.0.0 before 2.0.4.

Jan 9, 2025
CVE-2024-13255
7.5 HIGH

Exposure of Sensitive Information Through Data Queries vulnerability in Drupal RESTful Web Services allows Forceful Browsing.This issue affects RESTful Web Services: from 7.X-2.0 before 7.X-2.10.

Jan 9, 2025
CVE-2024-13254
7.5 HIGH

Insertion of Sensitive Information Into Sent Data vulnerability in Drupal REST Views allows Forceful Browsing.This issue affects REST Views: from 0.0.0 before 3.0.1.

Jan 9, 2025
CVE-2024-13251
8.8 HIGH

Incorrect Privilege Assignment vulnerability in Drupal Registration role allows Privilege Escalation.This issue affects Registration role: from 0.0.0 before 2.0.1.

Jan 9, 2025
CVE-2024-13250
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Drupal Symfony Mailer Lite allows Cross Site Request Forgery.This issue affects Drupal Symfony Mailer Lite: from 0.0.0 before …

Jan 9, 2025
CVE-2024-13244
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate Tools allows Cross Site Request Forgery.This issue affects Migrate Tools: from 0.0.0 before 6.0.3.

Jan 9, 2025
CVE-2024-13240
7.5 HIGH

Improper Access Control vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue affects Open Social: from 0.0.0 before 12.05.

Jan 9, 2025
CVE-2025-21599
7.5 HIGH

A Missing Release of Memory after Effective Lifetime vulnerability in the Juniper Tunnel Driver (jtd) of Juniper Networks Junos OS Evolved allows an unauthenticated network-based …

Jan 9, 2025
CVE-2025-22814
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Dylan James Zephyr Admin Theme zephyr-modern-admin-theme allows Cross Site Request Forgery.This issue affects Zephyr Admin Theme: from n/a through …

Jan 9, 2025
CVE-2025-22595
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yamna Khawaja Mailing Group Listserv wp-mailing-group allows Reflected XSS.This issue affects Mailing Group …

Jan 9, 2025
CVE-2025-22594
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hccoder Better User Shortcodes better-user-shortcodes allows Reflected XSS.This issue affects Better User Shortcodes: …

Jan 9, 2025
CVE-2025-22539
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ka2 Custom DataBase Tables custom-database-tables allows Reflected XSS.This issue affects Custom DataBase Tables: …

Jan 9, 2025
CVE-2025-22537
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in traveller11 Google Maps Travel Route google-maps-travel-route allows SQL Injection.This issue affects …

Jan 9, 2025
CVE-2025-22535
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jonkern WPListCal wplistcal allows SQL Injection.This issue affects WPListCal: from n/a …

Jan 9, 2025
CVE-2025-22527
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yamna Khawaja Mailing Group Listserv wp-mailing-group allows SQL Injection.This issue affects …

Jan 9, 2025
CVE-2025-22521
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Farrell wp Hosting Performance Check wp-hosting-performance-check allows Reflected XSS.This issue affects wp …

Jan 9, 2025
CVE-2025-22510
7.2 HIGH

Deserialization of Untrusted Data vulnerability in kkarpieszuk WC Price History for Omnibus wc-price-history allows Object Injection.This issue affects WC Price History for Omnibus: from n/a …

Jan 9, 2025
CVE-2025-22508
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in roninwp FAT Event Lite fat-event-lite allows PHP Local File …

Jan 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.