CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10599
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Tongda OA 2017 up to 11.7. This issue affects some unknown processing of the …

Oct 31, 2024
CVE-2024-10598
5.3 MEDIUM

A vulnerability classified as critical was found in Tongda OA 11.2/11.3/11.4/11.5/11.6. This vulnerability affects unknown code of the file general/hr/setting/attendance/leave/data.php of the component Annual Leave …

Oct 31, 2024
CVE-2024-10597
6.3 MEDIUM

A vulnerability classified as critical has been found in ESAFENET CDG 5. This affects the function delPolicyAction of the file /com/esafenet/servlet/system/PolicyActionService.java. The manipulation of the …

Oct 31, 2024
CVE-2024-10596
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. Affected by this issue is the function delEntryptPolicySort of the file …

Oct 31, 2024
CVE-2024-10595
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. Affected by this vulnerability is the function delFile/delDifferCourseList of the file …

Oct 31, 2024
CVE-2024-10594
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. Affected is the function docHistory of the file /com/esafenet/servlet/fileManagement/FileDirectoryService.java. The manipulation …

Oct 31, 2024
CVE-2024-50802
6.0 MEDIUM

A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controller/responses/listing_grid/email_templates.php. The vulnerability is exploitable via the id parameter.

Oct 31, 2024
CVE-2024-50801
6.0 MEDIUM

A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controller/responses/listing_grid/collections.php. The vulnerability is exploitable via the id parameter.

Oct 31, 2024
CVE-2024-10573
6.7 MEDIUM

An out-of-bounds write flaw was found in mpg123 when handling crafted streams. When decoding PCM, the libmpg123 may write past the end of a heap-located …

Oct 31, 2024
CVE-2023-52045
6.1 MEDIUM

Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability.

Oct 31, 2024
CVE-2024-51430
6.4 MEDIUM

Cross Site Scripting vulnerability in online diagnostic lab management system using php v.1.0 allows a remote attacker to execute arbitrary code via the Test Name …

Oct 31, 2024
CVE-2024-50354
5.5 MEDIUM

gnark is a fast zk-SNARK library that offers a high-level API to design circuits. In gnark 0.11.0 and earlier, deserialization of Groth16 verification keys allocate …

Oct 31, 2024
CVE-2024-8553
6.3 MEDIUM

A vulnerability was found in Foreman's loader macros introduced with report templates. These macros may allow an authenticated user with permissions to view and create …

Oct 31, 2024
CVE-2024-8934
6.5 MEDIUM

A local user with administrative access rights can enter specialy crafted values for settings at the user interface (UI) of the TwinCAT Package Manager which …

Oct 31, 2024
CVE-2024-10454
6.1 MEDIUM

Clickjacking vulnerability in Clibo Manager v1.1.9.12 in the '/public/login' directory, a login panel. This vulnerability occurs due to the absence of an X-Frame-Options server-side header. …

Oct 31, 2024
CVE-2024-49685
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Custom Twitter Feeds (Tweets Widget) custom-twitter-feeds allows Cross Site Request Forgery.This issue affects Custom Twitter Feeds (Tweets …

Oct 31, 2024
CVE-2024-43933
4.3 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja allows Stored XSS.This issue affects WPMobile.App: from n/a through <= …

Oct 31, 2024
CVE-2024-43930
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in eyecix JobSearch allows Cross Site Request Forgery.This issue affects JobSearch: from n/a through 2.5.3.

Oct 31, 2024
CVE-2024-30149
4.8 MEDIUM

HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable.

Oct 31, 2024
CVE-2024-9446
6.4 MEDIUM

The WP Simple Anchors Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpanchor shortcode in all versions up to, and …

Oct 31, 2024
CVE-2024-9434
6.1 MEDIUM

The WPGlobus Translate Options plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to …

Oct 31, 2024
CVE-2024-9430
5.3 MEDIUM

The Get Quote For Woocommerce – Request A Quote For Woocommerce plugin for WordPress is vulnerable to unauthorized access of Quote data due to a …

Oct 31, 2024
CVE-2024-9165
6.4 MEDIUM

The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions …

Oct 31, 2024
CVE-2024-9700
5.3 MEDIUM

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions …

Oct 31, 2024
CVE-2024-9708
6.4 MEDIUM

The Easy SVG Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1 …

Oct 31, 2024
CVE-2024-10559
5.3 MEDIUM

A vulnerability was found in SourceCodester Airport Booking Management System 1.0 and classified as critical. Affected by this issue is the function Details. The manipulation …

Oct 31, 2024
CVE-2024-10544
5.3 MEDIUM

The Woo Manage Fraud Orders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.1 through publicly exposed …

Oct 31, 2024
CVE-2024-10557
4.3 MEDIUM

A vulnerability has been found in code-projects Blood Bank Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of …

Oct 31, 2024
CVE-2024-10086
6.1 MEDIUM

A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Content-Type HTTP header, allowing user-provided inputs …

Oct 30, 2024
CVE-2024-51419
6.1 MEDIUM

Cross Site Scripting vulnerability in Shenzhen Interconnection Harbor Network Technology Co., Ltd Ofweek Online Exhibition v.1.0.0 allows a remote attacker to execute arbitrary code.

Oct 30, 2024
CVE-2024-51242
6.5 MEDIUM

A Server-Side Request Forgery (SSRF) vulnerability has been identified in eladmin 2.7 and earlier in ServerDeployController.java. The manipulation of the HTTP Body ip parameter leads …

Oct 30, 2024
CVE-2024-48807
5.4 MEDIUM

Cross Site Scripting vulnerability in PHPGurukul Doctor Appointment Management System v.1.0 allows a local attacker to execute arbitrary code via the search parameter.

Oct 30, 2024
CVE-2024-48346
6.1 MEDIUM

xtreme1 <= v0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the /api/data/upload path. The vulnerability is triggered through the fileUrl parameter, which allows an …

Oct 30, 2024
CVE-2024-43382
5.9 MEDIUM

Snowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being uploaded to an encrypted stage …

Oct 30, 2024
CVE-2024-48272
6.5 MEDIUM

D-Link DSL6740C v6.TR069.20211230 was discovered to use an insecure default Wifi password, possibly allowing attackers to connect to the device via a bruteforce attack.

Oct 30, 2024
CVE-2024-10546
6.3 MEDIUM

A vulnerability classified as critical was found in open-scratch Teaching 在线教学平台 up to 2.7. This vulnerability affects unknown code of the file /api/sys/ng-alain/getDictItemsByTable/ of the …

Oct 30, 2024
CVE-2024-46531
6.3 MEDIUM

phpgurukul Vehicle Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchinputdata parameter at /index.php.

Oct 30, 2024
CVE-2024-48648
6.1 MEDIUM

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Sage 1000 v 7.0.0. This vulnerability allows attackers to inject malicious scripts into URLs, which are …

Oct 30, 2024
CVE-2024-48569
5.4 MEDIUM

Proactive Risk Manager version 9.1.1.0 is affected by multiple Cross-Site Scripting (XSS) vulnerabilities in the add/edit form fields, at the urls starting with the subpaths: …

Oct 30, 2024
CVE-2024-48241
5.5 MEDIUM

An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function.

Oct 30, 2024
CVE-2024-31975
4.8 MEDIUM

EnGenius EWS356-Fit devices through 1.1.30 allow a remote attacker to conduct stored XSS attacks via the Wi-Fi SSID parameters. JavaScript embedded into a vulnerable field …

Oct 30, 2024
CVE-2024-31973
5.2 MEDIUM

Hitron CODA-4582 2AHKM-CODA4589 7.2.4.5.1b8 devices allow a remote attacker within Wi-Fi proximity to conduct stored XSS attacks via the 'Network Name (SSID)' input fields to …

Oct 30, 2024
CVE-2024-31972
4.3 MEDIUM

EnGenius ESR580 A8J-EMR5000 devices allow a remote attacker to conduct stored XSS attacks that could lead to arbitrary JavaScript code execution (under the context of …

Oct 30, 2024
CVE-2024-9110
6.4 MEDIUM

A medium severity vulnerability has been identified within Privileged Identity which can allow an attacker to perform reflected cross-site scripting attacks.

Oct 30, 2024
CVE-2024-50344
4.6 MEDIUM

I, Librarian is an open-source version of a PDF managing SaaS. Supplemental Files are allowed to be viewed in the browser, only if they have …

Oct 30, 2024
CVE-2024-50419
5.4 MEDIUM

Incorrect Authorization vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Greenshift: from n/a through <= 9.7.

Oct 30, 2024
CVE-2024-50353
5.3 MEDIUM

ICG.AspNetCore.Utilities.CloudStorage is a collection of cloud storage utilities to assist with the management of files for cloud upload. Users of this library that set a …

Oct 30, 2024
CVE-2024-33626
5.3 MEDIUM

The LevelOne WBR-6012 router contains a vulnerability within its web application that allows unauthenticated disclosure of sensitive information, such as the WiFi WPS PIN, through …

Oct 30, 2024
CVE-2024-33603
5.3 MEDIUM

The LevelOne WBR-6012 router has an information disclosure vulnerability in its web application, which allows unauthenticated users to access a verbose system log page and …

Oct 30, 2024
CVE-2024-32946
5.9 MEDIUM

A vulnerability in the LevelOne WBR-6012 router's firmware version R0.40e6 allows sensitive information to be transmitted in cleartext via Web and FTP services, exposing it …

Oct 30, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.