CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-44099
5.5 MEDIUM

There is a possible Local bypass of user interaction due to an insecure default value. This could lead to local information disclosure with no additional …

Oct 25, 2024
CVE-2024-10377
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. This issue affects the function actionPassDecryptApplication1 of the file /com/esafenet/servlet/client/DecryptApplicationService.java. The …

Oct 25, 2024
CVE-2024-10376
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. This vulnerability affects the function actionPassOrNotAutoSign of the file /com/esafenet/servlet/service/processsign/AutoSignService.java. The …

Oct 25, 2024
CVE-2024-8666
6.4 MEDIUM

The Shoutcast Icecast HTML5 Radio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'html5radio' shortcode in all versions up to, …

Oct 25, 2024
CVE-2024-10343
6.4 MEDIUM

The Beek Widget Extention plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 0.9.5 due to insufficient …

Oct 25, 2024
CVE-2024-10112
6.4 MEDIUM

The Simple News plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'news' shortcode in all versions up to, and including, 2.8 …

Oct 25, 2024
CVE-2024-10016
6.4 MEDIUM

The File Upload Types by WPForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and …

Oct 25, 2024
CVE-2024-9630
5.4 MEDIUM

The WPS Telegram Chat plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when accessing messages in versions up to, …

Oct 25, 2024
CVE-2024-9628
6.3 MEDIUM

The WPS Telegram Chat plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on …

Oct 25, 2024
CVE-2024-47158
5.4 MEDIUM

N-LINE 2.0.6 and prior versions contain a code injection vulnerability. If this vulnerability is exploited, arbitrary code may be executed on the instructor's browser, or …

Oct 25, 2024
CVE-2024-10342
6.4 MEDIUM

The League of Legends Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 1.0.1 due to …

Oct 25, 2024
CVE-2024-10341
6.5 MEDIUM

The League of Legends Shortcodes plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.0.1 due …

Oct 25, 2024
CVE-2024-10150
6.4 MEDIUM

The Bamazoo – Button Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's dgs shortcode in all versions up to, and …

Oct 25, 2024
CVE-2024-9607
6.1 MEDIUM

The 10Web Social Post Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …

Oct 25, 2024
CVE-2024-50583
6.3 MEDIUM

Whale browser Installer before 3.1.0.0 allows an attacker to execute a malicious DLL in the user environment due to improper permission settings.

Oct 25, 2024
CVE-2024-48870
6.2 MEDIUM

Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scripting vulnerability. If crafted input is stored …

Oct 25, 2024
CVE-2024-45842
5.3 MEDIUM

Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability. Unintended internal files may be retrieved …

Oct 25, 2024
CVE-2024-45829
4.9 MEDIUM

Sharp and Toshiba Tec MFPs provide the web page to download data, where query parameters in HTTP requests are improperly processed and resulting in an …

Oct 25, 2024
CVE-2024-10148
6.4 MEDIUM

The Awesome buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn2 shortcode in all versions up to, and including, 1.0 …

Oct 25, 2024
CVE-2024-9109
4.3 MEDIUM

The WooCommerce UPS Shipping – Live Rates and Access Points plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Oct 25, 2024
CVE-2024-9686
5.3 MEDIUM

The Order Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing capability check on the 'nktgnfw_send_test_message' function …

Oct 25, 2024
CVE-2024-10372
4.5 MEDIUM

A vulnerability classified as problematic was found in chidiwilliams buzz 1.1.0. This vulnerability affects the function download_model of the file buzz/model_loader.py. The manipulation leads to …

Oct 25, 2024
CVE-2024-10371
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Payroll Management System 1.0. This affects the function login of the file main. The manipulation …

Oct 25, 2024
CVE-2024-10355
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0. Affected by this issue is some unknown functionality …

Oct 25, 2024
CVE-2024-10354
4.7 MEDIUM

A vulnerability classified as critical was found in SourceCodester Petrol Pump Management Software 1.0. Affected by this vulnerability is an unknown functionality of the file …

Oct 25, 2024
CVE-2024-10353
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Online Exam System 1.0. Affected is an unknown function of the file /admin-dashboard. The manipulation …

Oct 25, 2024
CVE-2024-10350
4.7 MEDIUM

A vulnerability was found in code-projects Hospital Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/add-doctor.php. …

Oct 24, 2024
CVE-2024-49762
4.6 MEDIUM

Pterodactyl is a free, open-source game server management panel. When a user disables two-factor authentication via the Panel, a `DELETE` request with their current password …

Oct 24, 2024
CVE-2024-49750
5.5 MEDIUM

The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Prior to version …

Oct 24, 2024
CVE-2024-49358
5.3 MEDIUM

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the …

Oct 24, 2024
CVE-2024-10349
6.3 MEDIUM

A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and classified as critical. Affected by this issue is the function delete_tenant of …

Oct 24, 2024
CVE-2024-48932
5.3 MEDIUM

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions below 1.5.0, the API endpoint `http://<Server-ip>/v1/users/name` …

Oct 24, 2024
CVE-2024-48426
6.2 MEDIUM

A segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz testing with AddressSanitizer. The crash occurred due to a …

Oct 24, 2024
CVE-2024-48425
5.5 MEDIUM

A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the Assimp library during fuzz testing using AddressSanitizer. The crash occurs due to a …

Oct 24, 2024
CVE-2024-48424
5.5 MEDIUM

A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files.

Oct 24, 2024
CVE-2024-47882
5.9 MEDIUM

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the built-in "Something went wrong!" error page includes the …

Oct 24, 2024
CVE-2024-45259
6.5 MEDIUM

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By intercepting an HTTP request and changing the filename …

Oct 24, 2024
CVE-2024-47173
5.5 MEDIUM

Aimeos is an e-commerce framework. All SaaS and marketplace setups using the Aimeos GraphQL API admin interface version from 2024.04 up to 2024.07.1 are affected …

Oct 24, 2024
CVE-2024-46996
6.3 MEDIUM

baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Blog posts feature. Version 5.1.2 fixes this issue.

Oct 24, 2024
CVE-2024-46995
6.1 MEDIUM

baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in HTTP 400 Bad Request. Version 5.1.2 fixes this issue.

Oct 24, 2024
CVE-2024-46994
5.4 MEDIUM

baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in Blog posts and Contents list Feature. Version 5.1.2 fixes …

Oct 24, 2024
CVE-2024-48442
6.5 MEDIUM

Incorrect access control in Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 allows attackers to access the SSH protocol without authentication.

Oct 24, 2024
CVE-2024-38314
5.9 MEDIUM

IBM Maximo Application Suite - Monitor Component 8.10, 8.11, and 9.0 could disclose information in the form of the hard-coded cryptographic key to an attacker …

Oct 24, 2024
CVE-2024-10338
4.7 MEDIUM

A vulnerability classified as critical was found in SourceCodeHero Clothes Recommendation System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/home.php. …

Oct 24, 2024
CVE-2024-10337
4.7 MEDIUM

A vulnerability classified as critical has been found in SourceCodeHero Clothes Recommendation System 1.0. Affected is an unknown function of the file /admin/home.php?con=add. The manipulation …

Oct 24, 2024
CVE-2024-48540
6.2 MEDIUM

Incorrect access control in XIAO HE Smart 4.3.1 allows attackers to access sensitive information by analyzing the code and data within the APK file.

Oct 24, 2024
CVE-2024-44205
5.5 MEDIUM

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 …

Oct 24, 2024
CVE-2024-44185
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS …

Oct 24, 2024
CVE-2024-44141
6.8 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. A person with physical access to an unlocked Mac may …

Oct 24, 2024
CVE-2024-40810
5.5 MEDIUM

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An app may be able to cause …

Oct 24, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.