CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-13323
6.4 MEDIUM

The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'booking' shortcode in all versions up to, and including, …

Jan 14, 2025
CVE-2025-23038
5.4 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified …

Jan 14, 2025
CVE-2025-23037
5.4 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified …

Jan 14, 2025
CVE-2025-23036
5.4 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified …

Jan 14, 2025
CVE-2025-23035
5.4 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified …

Jan 14, 2025
CVE-2025-23034
6.1 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified …

Jan 14, 2025
CVE-2025-23033
5.4 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified …

Jan 14, 2025
CVE-2025-23032
5.4 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified …

Jan 14, 2025
CVE-2025-23031
5.4 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified …

Jan 14, 2025
CVE-2025-23030
6.1 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified …

Jan 14, 2025
CVE-2025-0068
4.3 MEDIUM

An obsolete functionality in SAP NetWeaver Application Server ABAP did not perform necessary authorization checks. Because of this, an authenticated attacker could obtain information that …

Jan 14, 2025
CVE-2025-0067
6.3 MEDIUM

Due to a missing authorization check on service endpoints in the SAP NetWeaver Application Server Java, an attacker with standard user role can create JCo …

Jan 14, 2025
CVE-2025-0060
6.5 MEDIUM

SAP BusinessObjects Business Intelligence Platform allows an authenticated user with restricted access to inject malicious JS code which can read sensitive information from the server …

Jan 14, 2025
CVE-2025-0059
6.0 MEDIUM

Applications based on SAP GUI for HTML in SAP NetWeaver Application Server ABAP store user input in the local browser storage to improve usability. An …

Jan 14, 2025
CVE-2025-0058
6.5 MEDIUM

In SAP Business Workflow and SAP Flexible Workflow, an authenticated attacker can manipulate a parameter in an otherwise legitimate resource request to view sensitive information …

Jan 14, 2025
CVE-2025-0057
4.8 MEDIUM

SAP NetWeaver AS JAVA (User Admin Application) is vulnerable to stored cross site scripting vulnerability. An attacker posing as an admin can upload a photo …

Jan 14, 2025
CVE-2025-0056
6.0 MEDIUM

SAP GUI for Java saves user input on the client PC to improve usability. An attacker with administrative privileges or access to the victim�s user …

Jan 14, 2025
CVE-2025-0055
6.0 MEDIUM

SAP GUI for Windows stores user input on the client PC to improve usability. Under very specific circumstances an attacker with administrative privileges or access …

Jan 14, 2025
CVE-2025-0053
5.3 MEDIUM

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to gain unauthorized access to system information. By using a specific URL parameter, …

Jan 14, 2025
CVE-2024-12298
5.5 MEDIUM

We found a vulnerability Improper Restriction of XML External Entity Reference (CWE-611) in NB-series NX-Designer. Attackers may be able to abuse this vulnerability to disclose …

Jan 14, 2025
CVE-2024-12083
6.6 MEDIUM

Path Traversal Vulnerabilities (CWE-22) exist in NJ/NX-series Machine Automation Controllers. An attacker may use these vulnerabilities to perform unauthorized access and to execute unauthorized code …

Jan 14, 2025
CVE-2024-11396
5.3 MEDIUM

The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, …

Jan 14, 2025
CVE-2024-56138
4.0 MEDIUM

notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. This issue was identified during Quarkslab's audit …

Jan 13, 2025
CVE-2023-42250
6.1 MEDIUM

Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via /common/autocomplete.php.

Jan 13, 2025
CVE-2023-42249
6.1 MEDIUM

Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via vam/vam_visits.php.

Jan 13, 2025
CVE-2023-42248
6.5 MEDIUM

An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can write arbitrary files by manipulating POST parameters of …

Jan 13, 2025
CVE-2023-42247
6.1 MEDIUM

Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via monitor/s_monitor_map.php.

Jan 13, 2025
CVE-2023-42246
6.1 MEDIUM

Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via /vam/vam_ep.php.

Jan 13, 2025
CVE-2023-42245
6.1 MEDIUM

Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via monitor/s_scheduledfile.php.

Jan 13, 2025
CVE-2023-42243
5.4 MEDIUM

In Selesta Visual Access Manager < 4.42.2, an authenticated user can access the administrative page /common/vam_Sql.php, which allows for arbitrary SQL queries.

Jan 13, 2025
CVE-2023-42234
5.4 MEDIUM

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Request Forgery (CSRF) via the WSCView function.

Jan 13, 2025
CVE-2023-42233
6.1 MEDIUM

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the Filter/FilterEditor function.

Jan 13, 2025
CVE-2023-42230
6.1 MEDIUM

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the WSCView/Save function.

Jan 13, 2025
CVE-2023-42229
6.5 MEDIUM

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal. Arbitrary files can be created on the system via authenticated SOAP requests to the …

Jan 13, 2025
CVE-2025-22619
6.1 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified …

Jan 13, 2025
CVE-2025-22618
5.4 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified …

Jan 13, 2025
CVE-2025-22617
6.1 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified …

Jan 13, 2025
CVE-2025-22616
5.4 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified …

Jan 13, 2025
CVE-2025-22615
6.1 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified …

Jan 13, 2025
CVE-2025-22614
5.4 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified …

Jan 13, 2025
CVE-2025-22613
5.4 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified …

Jan 13, 2025
CVE-2025-22134
4.2 MEDIUM

When switching to other buffers using the :all command and visual mode still being active, this may cause a heap-buffer overflow, because Vim does not …

Jan 13, 2025
CVE-2025-23026
6.1 MEDIUM

jte (Java Template Engine) is a secure and lightweight template engine for Java and Kotlin. In affected versions Jte HTML templates with `script` tags or …

Jan 13, 2025
CVE-2025-22142
5.4 MEDIUM

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In affected versions an admin can add the ability to have …

Jan 13, 2025
CVE-2024-46921
6.5 MEDIUM

An issue was discovered in Samsung Mobile Processor and Modem Exynos 9820, 9825, 980, 990, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W1000, …

Jan 13, 2025
CVE-2024-44771
6.1 MEDIUM

BigId PrivacyPortal v179 is vulnerable to Cross Site Scripting (XSS) via the "Label" field in the Report template function.

Jan 13, 2025
CVE-2024-46920
6.5 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a length check leads to …

Jan 13, 2025
CVE-2024-6352
4.3 MEDIUM

A malformed packet can cause a buffer overflow in the APS layer of the Ember ZNet stack and lead to an assert

Jan 13, 2025
CVE-2024-57488
6.5 MEDIUM

Code-Projects Online Car Rental System 1.0 is vulnerable to Cross Site Scripting (XSS) via the vehicalorcview parameter in /admin/edit-vehicle.php.

Jan 13, 2025
CVE-2024-57487
6.5 MEDIUM

In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types allowing an attacker to upload a …

Jan 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.