CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9626
4.3 MEDIUM

The Editorial Assistant by Sovrn plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_zemanta_set_featured_image' function …

Oct 26, 2024
CVE-2024-9613
6.1 MEDIUM

The FormFacade – WordPress plugin for Google Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'userId' and 'publishId' parameters in all …

Oct 26, 2024
CVE-2024-9475
4.9 MEDIUM

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to generic SQL Injection via the order_by parameter in all …

Oct 26, 2024
CVE-2024-9462
5.5 MEDIUM

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Stored Cross-Site Scripting via poll settings in all versions …

Oct 26, 2024
CVE-2024-9454
6.4 MEDIUM

The PriPre plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.4.11 due to …

Oct 26, 2024
CVE-2024-10091
6.4 MEDIUM

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Comparison Widget in all versions up to, and including, …

Oct 26, 2024
CVE-2024-48239
4.8 MEDIUM

An issue was discovered in WTCMS 1.0. In the plupload method in \AssetController.class.php, the app parameters aren't processed, resulting in Cross Site Scripting (XSS).

Oct 25, 2024
CVE-2024-48238
4.7 MEDIUM

WTCMS 1.0 is vulnerable to SQL Injection in the edit_post method of /Admin\Controller\NavControl.class.php via the parentid parameter.

Oct 25, 2024
CVE-2024-48236
6.5 MEDIUM

An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of the ofcms-admin\src\main\java\com\ofsoft\cms\core\uitle\FileUtils.java …

Oct 25, 2024
CVE-2024-48235
6.5 MEDIUM

An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file.

Oct 25, 2024
CVE-2024-48234
4.9 MEDIUM

An issue was discovered in mipjz 5.0.5. In the push method of app\tag\controller\ApiAdminTag.php the value of the postAddress parameter is not processed and is directly …

Oct 25, 2024
CVE-2024-48228
6.1 MEDIUM

An issue was found in funadmin 5.0.2. The selectfiles method in \backend\controller\sys\Attachh.php directly stores the passed parameters and values into the param parameter without filtering, …

Oct 25, 2024
CVE-2024-48396
6.1 MEDIUM

AIML Chatbot 1.0 (fixed in 2.0) is vulnerable to Cross Site Scripting (XSS). The vulnerability is exploited through the message input field, where attackers can …

Oct 25, 2024
CVE-2024-48233
4.8 MEDIUM

mipjz 5.0.5 is vulnerable to Cross Site Scripting (XSS) in \app\setting\controller\ApiAdminSetting.php via the ICP parameter.

Oct 25, 2024
CVE-2024-48232
4.9 MEDIUM

An issue was found in mipjz 5.0.5. In the mipPost method of \app\setting\controller\ApiAdminTool.php, the value of the postAddress parameter is not processed and is directly …

Oct 25, 2024
CVE-2024-48227
4.9 MEDIUM

Funadmin 5.0.2 has a logical flaw in the Curd one click command deletion function, which can result in a Denial of Service (DOS).

Oct 25, 2024
CVE-2024-48225
6.5 MEDIUM

Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile.

Oct 25, 2024
CVE-2024-48224
4.9 MEDIUM

Funadmin v5.0.2 has an arbitrary file read vulnerability in /curd/index/editfile.

Oct 25, 2024
CVE-2024-49766
5.3 MEDIUM

Werkzeug is a Web Server Gateway Interface web application library. On Python < 3.11 on Windows, os.path.isabs() does not catch UNC paths like //server/share. Werkzeug's …

Oct 25, 2024
CVE-2024-48450
6.5 MEDIUM

An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploading a crafted HTML file into chat group.

Oct 25, 2024
CVE-2024-37846
4.6 MEDIUM

MangoOS before 5.2.0 was discovered to contain a Client-Side Template Injection (CSTI) vulnerability via the Platform Management Edit page.

Oct 25, 2024
CVE-2024-37844
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in MangoOS before 5.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Oct 25, 2024
CVE-2024-9585
6.4 MEDIUM

The Image Map Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'save_project' function with an arbitrary shortcode in versions up to, …

Oct 25, 2024
CVE-2024-9584
5.4 MEDIUM

The Image Map Pro plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on …

Oct 25, 2024
CVE-2024-48448
6.1 MEDIUM

An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploading a crafted HTML file into the tracker comments …

Oct 25, 2024
CVE-2024-48343
6.3 MEDIUM

A SQL Injection vulnerability in ESAFENET CDG 5 and earlier allows an attacker to execute arbitrary code via the id parameter of the dataSearch.jsp page.

Oct 25, 2024
CVE-2024-8036
5.9 MEDIUM

ABB is aware of privately reported vulnerabilities in the product versions referenced in this CVE. An attacker could exploit these vulnerabilities by sending a specially …

Oct 25, 2024
CVE-2024-48743
6.5 MEDIUM

Cross Site Scripting vulnerability in Sentry v.6.0.9 allows a remote attacker to execute arbitrary code via the z parameter.

Oct 25, 2024
CVE-2024-48654
6.1 MEDIUM

Cross Site Scripting vulnerability in Blood Bank v.1 allows a remote attacker to execute arbitrary code via a crafted script to the login.php component.

Oct 25, 2024
CVE-2022-30361
5.3 MEDIUM

OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserType. No authentication is required. The information disclosed …

Oct 25, 2024
CVE-2022-30360
6.4 MEDIUM

OvalEdge 5.2.8.0 and earlier is affected by multiple Stored XSS (AKA Persistent or Type II) vulnerabilities via a POST request to /profile/updateProfile via the slackid …

Oct 25, 2024
CVE-2022-30359
4.3 MEDIUM

OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserList. Authentication is required. The information disclosed is …

Oct 25, 2024
CVE-2022-30356
4.7 MEDIUM

OvalEdge 5.2.8.0 and earlier is affected by a Privilege Escalation vulnerability via a POST request to /user/assignuserrole via the userid and role parameters . Authentication …

Oct 25, 2024
CVE-2023-26248
5.3 MEDIUM

The Kademlia DHT (go-libp2p-kad-dht 0.20.0 and earlier) used in IPFS (0.18.1 and earlier) assigns routing information for content (i.e., information about who holds the content) …

Oct 25, 2024
CVE-2024-49753
5.9 MEDIUM

Zitadel is open-source identity infrastructure software. Versions prior to 2.64.1, 2.63.6, 2.62.8, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 have a flaw in the URL validation mechanism …

Oct 25, 2024
CVE-2024-49378
6.1 MEDIUM

smartUp, a web browser mouse gestures extension, has a universal cross-site scripting issue in the Edge and Firefox versions of smartUp 7.2.622.1170. The vulnerability allows …

Oct 25, 2024
CVE-2024-10380
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0. Affected by this issue is some unknown functionality …

Oct 25, 2024
CVE-2024-10379
4.3 MEDIUM

A vulnerability classified as problematic was found in ESAFENET CDG 5. Affected by this vulnerability is the function actionViewDecyptFile of the file /com/esafenet/servlet/client/DecryptApplicationService.java. The manipulation …

Oct 25, 2024
CVE-2024-10378
6.3 MEDIUM

A vulnerability classified as critical has been found in ESAFENET CDG 5. Affected is the function actionViewCDGRenewFile of the file /com/esafenet/servlet/client/CDGRenewApplicationService.java. The manipulation of the …

Oct 25, 2024
CVE-2024-10374
6.4 MEDIUM

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpmem_loginout shortcode in all versions up to, and including, …

Oct 25, 2024
CVE-2024-47481
6.5 MEDIUM

Dell Data Lakehouse, version(s) 1.0.0.0, 1.1.0., contain(s) an Improper Access Control vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading …

Oct 25, 2024
CVE-2024-47034
5.5 MEDIUM

there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution …

Oct 25, 2024
CVE-2024-47030
5.1 MEDIUM

Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ACPM component, A-315191818.

Oct 25, 2024
CVE-2024-47029
5.5 MEDIUM

In TrustySharedMemoryManager::GetSharedMemory of ondevice/trusty/trusty_shared_memory_manager.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure …

Oct 25, 2024
CVE-2024-47028
4.4 MEDIUM

In ffu_flash_pack of ffu.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with …

Oct 25, 2024
CVE-2024-47026
5.5 MEDIUM

In gsc_gsa_rescue of gsc_gsa.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure …

Oct 25, 2024
CVE-2024-47025
5.5 MEDIUM

In ppmp_protect_buf of drm_fw.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information disclosure …

Oct 25, 2024
CVE-2024-47019
5.5 MEDIUM

In ProtocolEmbmsSaiListAdapter::Init() of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Oct 25, 2024
CVE-2024-47018
5.5 MEDIUM

In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with …

Oct 25, 2024
CVE-2024-47015
5.5 MEDIUM

In ProtocolMiscHwConfigChangeAdapter::GetData() of protocolmiscadapter.cpp, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with baseband …

Oct 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.