CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-3987
4.3 MEDIUM

An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without public shelf permissions to create public shelves. The vulnerability is due …

Nov 15, 2024
CVE-2021-3986
4.3 MEDIUM

A vulnerability in janeczku/calibre-web allows unauthorized users to view the names of private shelves belonging to other users. This issue occurs in the file shelf.py …

Nov 15, 2024
CVE-2021-3841
5.4 MEDIUM

sylius/sylius versions prior to 1.9.10, 1.10.11, and 1.11.2 are vulnerable to stored cross-site scripting (XSS) through SVG files. This vulnerability allows attackers to inject malicious …

Nov 15, 2024
CVE-2021-3741
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.6. The vulnerability occurs when a user uploads an SVG …

Nov 15, 2024
CVE-2021-3740
6.8 MEDIUM

A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The application does not invalidate existing sessions on other devices when a user changes …

Nov 15, 2024
CVE-2024-8978
5.7 MEDIUM

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in …

Nov 15, 2024
CVE-2024-9529
6.6 MEDIUM

The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not …

Nov 15, 2024
CVE-2024-8961
6.4 MEDIUM

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Nov 15, 2024
CVE-2024-10825
6.1 MEDIUM

The Hide My WP Ghost – Security & Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL in all versions up …

Nov 15, 2024
CVE-2024-10104
5.9 MEDIUM

The Jobs for WordPress plugin before 2.7.8 does not sanitise and escape some of its Job settings, which could allow high privilege users such as …

Nov 15, 2024
CVE-2024-9356
6.1 MEDIUM

The Yotpo: Product & Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'yotpo_user_email' and 'yotpo_user_name' parameters in all …

Nov 15, 2024
CVE-2024-42499
5.3 MEDIUM

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an …

Nov 15, 2024
CVE-2024-39610
6.1 MEDIUM

Cross-site scripting vulnerability exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an arbitrary script may be executed on the web browser …

Nov 15, 2024
CVE-2024-10582
4.3 MEDIUM

The Music Player for Elementor – Audio Player & Podcast Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Nov 15, 2024
CVE-2024-10113
6.4 MEDIUM

The WP AdCenter – Ad Manager & Adsense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpadcenter_ad shortcode in all …

Nov 15, 2024
CVE-2024-9609
6.1 MEDIUM

The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'learnpress_import_form_server' parameter in all versions …

Nov 15, 2024
CVE-2024-10897
4.3 MEDIUM

The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the install_etlms_dependency_plugin() function in …

Nov 15, 2024
CVE-2024-52613
5.5 MEDIUM

A heap-based buffer under-read in tsMuxer version nightly-2024-05-12-02-01-18 allows attackers to cause Denial of Service (DoS) via a crafted MOV video file.

Nov 14, 2024
CVE-2024-49776
6.5 MEDIUM

A negative-size-param in tsMuxer version nightly-2024-04-05-01-53-02 allows attackers to cause Denial of Service (DoS) via a crafted TS video file.

Nov 14, 2024
CVE-2024-41217
6.5 MEDIUM

A heap-based buffer overflow in tsMuxer version nightly-2024-05-10-02-00-45 allows attackers to cause Denial of Service (DoS) via a crafted MKV video file.

Nov 14, 2024
CVE-2024-41206
6.5 MEDIUM

A stack-based buffer over-read in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Information Disclosure via a crafted TS video file.

Nov 14, 2024
CVE-2017-13227
5.5 MEDIUM

In the autofill service, the package name that is provided by the app process is trusted inappropriately. This could lead to information disclosure with no …

Nov 14, 2024
CVE-2024-51156
4.7 MEDIUM

07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component 'erp.07fly.net:80/admin/SysNotifyUser/del.html?id=93'.

Nov 14, 2024
CVE-2024-40579
5.4 MEDIUM

Cross Site Scripting vulnerability in Virtuozzo Hybrid Server for WHMCS Open Source v.1.7.1 allows a remote attacker to obtain sensitive information via modification of the …

Nov 14, 2024
CVE-2024-39707
5.3 MEDIUM

Insyde IHISI function 0x49 can restore factory defaults for certain UEFI variables without further authentication by default, which could lead to a possible roll-back attack …

Nov 14, 2024
CVE-2024-49025
5.4 MEDIUM

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Nov 14, 2024
CVE-2024-10396
6.5 MEDIUM

An authenticated user can provide a malformed ACL to the fileserver's StoreACL RPC, causing the fileserver to crash, possibly expose uninitialized memory, and possibly store …

Nov 14, 2024
CVE-2024-52396
4.9 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-editor allows Path Traversal.This issue affects WOLF: from n/a through …

Nov 14, 2024
CVE-2024-4311
5.4 MEDIUM

zenml-io/zenml version 0.56.4 is vulnerable to an account takeover due to the lack of rate-limiting in the password change function. An attacker can brute-force the …

Nov 14, 2024
CVE-2024-48284
4.8 MEDIUM

A Reflected Cross-Site Scripting (XSS) vulnerability was found in the /search-result.php page of the PHPGurukul User Registration & Login and User Management System 3.2. This …

Nov 14, 2024
CVE-2024-1682
4.3 MEDIUM

An unclaimed Amazon S3 bucket, 'codeconf', is referenced in an audio file link within the .rst documentation file. This bucket has been claimed by an …

Nov 14, 2024
CVE-2024-50836
4.8 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/teachers.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary …

Nov 14, 2024
CVE-2024-52505
5.4 MEDIUM

matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The provisioning API of the matrix-appservice-irc bridge up to version 3.0.2 contains a vulnerability …

Nov 14, 2024
CVE-2024-11214
4.7 MEDIUM

A vulnerability has been found in SourceCodester Best Employee Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/profile.php. …

Nov 14, 2024
CVE-2024-11213
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Best Employee Management System 1.0. This affects an unknown part of the file /admin/edit_role.php. …

Nov 14, 2024
CVE-2024-10921
6.8 MEDIUM

An authorized user may trigger crashes or receive the contents of buffer over-reads of Server memory by issuing specially crafted requests that construct malformed BSON …

Nov 14, 2024
CVE-2024-50838
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/department.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary …

Nov 14, 2024
CVE-2024-50837
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/admin_user.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary …

Nov 14, 2024
CVE-2024-11212
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Best Employee Management System 1.0. Affected by this issue is some unknown functionality …

Nov 14, 2024
CVE-2024-11211
4.7 MEDIUM

A vulnerability classified as critical has been found in EyouCMS up to 1.6.7. Affected is an unknown function of the component Website Logo Handler. The …

Nov 14, 2024
CVE-2024-11210
5.4 MEDIUM

A vulnerability was found in EyouCMS 1.51. It has been rated as critical. This issue affects the function editFile of the file application/admin/logic/FilemanagerLogic.php. The manipulation …

Nov 14, 2024
CVE-2024-50843
5.3 MEDIUM

A Directory listing issue was found in PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers attacker to access sensitive …

Nov 14, 2024
CVE-2024-50842
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/school_year.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary …

Nov 14, 2024
CVE-2024-50841
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/calendar_of_events.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary …

Nov 14, 2024
CVE-2024-50840
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/class.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary …

Nov 14, 2024
CVE-2024-50839
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/add_subject.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary …

Nov 14, 2024
CVE-2024-11215
6.5 MEDIUM

Absolute path traversal (incorrect restriction of a path to a restricted directory) vulnerability in the EasyPHP web server, affecting version 14.1. This vulnerability could allow …

Nov 14, 2024
CVE-2024-11209
6.3 MEDIUM

A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the file /login?service of the …

Nov 14, 2024
CVE-2024-8648
6.1 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. The vulnerability could …

Nov 14, 2024
CVE-2024-7404
6.8 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from …

Nov 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.