CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9262
6.5 MEDIUM

The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up …

Nov 9, 2024
CVE-2024-8960
6.4 MEDIUM

The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Nov 9, 2024
CVE-2024-10779
5.3 MEDIUM

The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.0 via the 'ce_template' shortcode …

Nov 9, 2024
CVE-2024-10588
4.3 MEDIUM

The Debug Tool plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the info() function in all …

Nov 9, 2024
CVE-2024-10294
6.5 MEDIUM

The CE21 Suite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ce21_single_sign_on_save_api_settings' function in versions …

Nov 9, 2024
CVE-2024-52314
4.9 MEDIUM

A data.all admin team member who has access to the customer-owned AWS Account where data.all is deployed may be able to extract user data from …

Nov 9, 2024
CVE-2024-52313
4.3 MEDIUM

An authenticated data.all user is able to manipulate a getDataset query to fetch additional information regarding the parent Environment resource that the user otherwise would …

Nov 9, 2024
CVE-2024-52312
5.4 MEDIUM

Due to inconsistent authorization permissions, data.all may allow an external actor with an authenticated account to perform restricted operations against DataSets and Environments.

Nov 9, 2024
CVE-2024-52311
6.3 MEDIUM

Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticated user to continue execution of authorized API Requests …

Nov 9, 2024
CVE-2024-10953
4.3 MEDIUM

An authenticated data.all user is able to perform mutating UPDATE operations on persisted Notification records in data.all for group notifications that their user is not …

Nov 9, 2024
CVE-2024-52001
4.3 MEDIUM

Combodo iTop is a simple, web based IT Service Management tool. In affected versions portal users are able to access forbidden services information. This issue …

Nov 8, 2024
CVE-2024-52000
6.1 MEDIUM

Combodo iTop is a simple, web based IT Service Management tool. Affected versions are subject to a reflected Cross-site Scripting (XSS) exploit by way of …

Nov 8, 2024
CVE-2024-35427
5.5 MEDIUM

vmir e8117 was discovered to contain a segmentation violation via the export_function function at /src/vmir_wasm_parser.c.

Nov 8, 2024
CVE-2024-35425
5.5 MEDIUM

vmir e8117 was discovered to contain a segmentation violation via the function_prepare_parse function at /src/vmir_function.c.

Nov 8, 2024
CVE-2024-35424
5.5 MEDIUM

vmir e8117 was discovered to contain a segmentation violation via the import_function function at /src/vmir_wasm_parser.c.

Nov 8, 2024
CVE-2024-35421
5.5 MEDIUM

vmir e8117 was discovered to contain a segmentation violation via the wasm_parse_block function at /src/vmir_wasm_parser.c.

Nov 8, 2024
CVE-2024-35420
6.2 MEDIUM

wac commit 385e1 was discovered to contain a heap overflow.

Nov 8, 2024
CVE-2024-35419
5.5 MEDIUM

wac commit 385e1 was discovered to contain a heap overflow via the load_module function at /wac-asan/wa.c. This vulnerability allows attackers to cause a Denial of …

Nov 8, 2024
CVE-2024-35418
6.2 MEDIUM

wac commit 385e1 was discovered to contain a heap overflow via the setup_call function at /wac-asan/wa.c. This vulnerability allows attackers to cause a Denial of …

Nov 8, 2024
CVE-2024-35410
6.2 MEDIUM

wac commit 385e1 was discovered to contain a heap overflow via the interpret function at /wac-asan/wa.c. This vulnerability allows attackers to cause a Denial of …

Nov 8, 2024
CVE-2024-51157
4.7 MEDIUM

07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component http://erp.07fly.net:80/oa/OaSchedule/add.html.

Nov 8, 2024
CVE-2024-21994
4.3 MEDIUM

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9 are susceptible to a Denial of Service (DoS) vulnerability. Successful exploit by an authenticated attacker could lead …

Nov 8, 2024
CVE-2024-51055
6.5 MEDIUM

An issue Hoosk v1.7.1 allows a remote attacker to execute arbitrary code via a crafted script to the config.php component.

Nov 8, 2024
CVE-2024-50810
5.4 MEDIUM

hopetree izone lts c011b48 contains a Cross Site Scripting (XSS) vulnerability in the article comment function. In \apps\comment\views.py, AddCommintView() does not securely filter user input …

Nov 8, 2024
CVE-2024-44765
6.5 MEDIUM

An Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH CloudPanel v2.0.0 to v2.4.2 allows low-privilege users to bypass access controls and gain unauthorized access …

Nov 8, 2024
CVE-2024-9841
6.1 MEDIUM

A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform. The vulnerability could be remotely exploited.

Nov 8, 2024
CVE-2024-51032
5.4 MEDIUM

A Cross-site Scripting (XSS) vulnerability in manage_recipient.php of Sourcecodester Toll Tax Management System 1.0 allows remote authenticated users to inject arbitrary web scripts via the …

Nov 8, 2024
CVE-2024-51031
5.4 MEDIUM

A Cross-site Scripting (XSS) vulnerability in manage_account.php in Sourcecodester Cab Management System 1.0 allows remote authenticated users to inject arbitrary web scripts via the "First …

Nov 8, 2024
CVE-2024-51030
6.5 MEDIUM

A SQL injection vulnerability in manage_client.php and view_cab.php of Sourcecodester Cab Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the id …

Nov 8, 2024
CVE-2024-40240
6.8 MEDIUM

An incorrect access control issue in HomeServe Home Repair' android app - 3.3.4 allows a physically proximate attacker to escalate privileges via the fingerprint authentication …

Nov 8, 2024
CVE-2024-40239
6.8 MEDIUM

An incorrect access control issue in Life: Personal Diary, Journal android app 17.5.0 allows a physically proximate attacker to escalate privileges via the fingerprint authentication …

Nov 8, 2024
CVE-2024-46948
4.3 MEDIUM

Northern.tech Mender before 3.6.5 and 3.7.x before 3.7.5 has Incorrect Access Control.

Nov 8, 2024
CVE-2024-46947
6.5 MEDIUM

Northern.tech Mender before 3.6.6 and 3.7.x before 3.7.7 allows SSRF.

Nov 8, 2024
CVE-2024-50378
4.9 MEDIUM

Airflow versions before 2.10.3 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should …

Nov 8, 2024
CVE-2024-10325
6.4 MEDIUM

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up …

Nov 8, 2024
CVE-2024-10187
6.4 MEDIUM

The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification …

Nov 8, 2024
CVE-2024-11000
4.7 MEDIUM

A vulnerability classified as problematic was found in CodeAstro Real Estate Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Nov 8, 2024
CVE-2024-10999
4.7 MEDIUM

A vulnerability classified as problematic has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /aboutadd.php of …

Nov 8, 2024
CVE-2024-10997
6.3 MEDIUM

A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Nov 8, 2024
CVE-2024-10269
6.4 MEDIUM

The Easy SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and …

Nov 8, 2024
CVE-2024-50210
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: posix-clock: posix-clock: Fix unbalanced locking in pc_clock_settime() If get_clock_desc() succeeds, it calls fget() for the …

Nov 8, 2024
CVE-2024-50208
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix a bug while setting up Level-2 PBL pages Avoid memory corruption while setting …

Nov 8, 2024
CVE-2024-50207
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix reader locking when changing the sub buffer order The function ring_buffer_subbuf_order_set() updates each …

Nov 8, 2024
CVE-2024-50206
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: fix memory corruption during fq dma init The loop responsible for allocating …

Nov 8, 2024
CVE-2024-50205
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-lib: Avoid division by zero in apply_constraint_to_size() The step variable is initialized to zero. …

Nov 8, 2024
CVE-2024-50204
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs: don't try and remove empty rbtree node When copying a namespace we won't have …

Nov 8, 2024
CVE-2024-50202
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nilfs2: propagate directory read errors from nilfs_find_entry() Syzbot reported that a task hang occurs in …

Nov 8, 2024
CVE-2024-50201
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/radeon: Fix encoder->possible_clones Include the encoder itself in its possible_clones bitmask. In the past nothing …

Nov 8, 2024
CVE-2024-50200
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: maple_tree: correct tree corruption on spanning store Patch series "maple_tree: correct tree corruption on spanning …

Nov 8, 2024
CVE-2024-50199
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/swapfile: skip HugeTLB pages for unuse_vma I got a bad pud error and lost a …

Nov 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.