CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-25694
4.8 MEDIUM

There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise versions 11.1 and below that may allow a remote, authenticated attacker to …

Oct 4, 2024
CVE-2024-25691
6.1 MEDIUM

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 11.1 and below which may allow a remote, unauthenticated attacker to create a …

Oct 4, 2024
CVE-2024-46409
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in SeedDMS v6.0.28 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the …

Oct 4, 2024
CVE-2024-47765
6.1 MEDIUM

Minecraft MOTD Parser is a PHP library to parse minecraft server motd. The HtmlGenerator class is subject to potential cross-site scripting (XSS) attack through a …

Oct 4, 2024
CVE-2024-9410
5.3 MEDIUM

Ada.cx's Sentry configuration allowed for blind server-side request forgeries (SSRF) through the use of a data scraping endpoint.

Oct 4, 2024
CVE-2024-9484
5.1 MEDIUM

An null-pointer-derefrence in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed xar file to crash the application …

Oct 4, 2024
CVE-2024-9483
5.1 MEDIUM

A null-pointer-dereference in the signature verification module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS may allow a malformed xar file to crash …

Oct 4, 2024
CVE-2024-9482
5.1 MEDIUM

An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed Mach-O file to crash the …

Oct 4, 2024
CVE-2024-9481
5.1 MEDIUM

An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed eml file to crash the …

Oct 4, 2024
CVE-2024-8499
4.7 MEDIUM

The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘render_review_request_notice’ function in all versions up …

Oct 4, 2024
CVE-2024-47657
6.5 MEDIUM

This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this …

Oct 4, 2024
CVE-2024-47653
6.5 MEDIUM

This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requests through certain API endpoints. An authenticated remote attacker …

Oct 4, 2024
CVE-2024-47651
6.5 MEDIUM

This vulnerability exists in Shilpi Client Dashboard due to improper handling of multiple parameters in the API endpoint. An authenticated remote attacker could exploit this …

Oct 4, 2024
CVE-2024-9271
6.4 MEDIUM

The Re:WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.1 due to …

Oct 4, 2024
CVE-2024-9071
6.4 MEDIUM

The Easy Demo Importer – A Modern One-Click Demo Import Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in …

Oct 4, 2024
CVE-2024-9435
6.1 MEDIUM

The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL keys in all versions up to, and including, 4.9.66 …

Oct 4, 2024
CVE-2024-9306
4.4 MEDIUM

The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 10.6 due …

Oct 4, 2024
CVE-2024-6444
6.3 MEDIUM

No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c.

Oct 4, 2024
CVE-2024-9242
6.4 MEDIUM

The Memberful – Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'memberful_buy_subscription_link' and 'memberful_podcasts_link' shortcodes in all versions up …

Oct 4, 2024
CVE-2024-8804
6.4 MEDIUM

The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's script embed functionality in all versions up to, and including, …

Oct 4, 2024
CVE-2024-6443
6.3 MEDIUM

In utf8_trunc in zephyr/lib/utils/utf8.c, last_byte_p can point to one byte before the string pointer if the string is empty.

Oct 4, 2024
CVE-2024-6442
6.3 MEDIUM

In ascs_cp_rsp_add in /subsys/bluetooth/audio/ascs.c, an unchecked tailroom could lead to a global buffer overflow.

Oct 4, 2024
CVE-2024-47855
5.3 MEDIUM

util/JSONTokener.java in JSON-lib before 3.1.0 mishandles an unbalanced comment string.

Oct 4, 2024
CVE-2024-47854
6.1 MEDIUM

An XSS vulnerability was discovered in Veritas Data Insight before 7.1. It allows a remote attacker to inject an arbitrary web script into an HTTP …

Oct 4, 2024
CVE-2024-9445
6.4 MEDIUM

The Display Medium Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_medium_posts shortcode in all versions up to, and including, …

Oct 4, 2024
CVE-2024-9421
6.4 MEDIUM

The Login Logout Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in all versions up to, and including, 1.1.0 …

Oct 4, 2024
CVE-2024-9384
6.1 MEDIUM

The Quantity Dynamic Pricing & Bulk Discounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without …

Oct 4, 2024
CVE-2024-9375
6.1 MEDIUM

The WordPress Captcha Plugin by Captcha Bank plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping …

Oct 4, 2024
CVE-2024-9372
6.4 MEDIUM

The WP Blocks Hub plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.2 …

Oct 4, 2024
CVE-2024-9368
6.4 MEDIUM

The Aggregator Advanced Settings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.1 …

Oct 4, 2024
CVE-2024-9353
6.1 MEDIUM

The Popularis Extra plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the …

Oct 4, 2024
CVE-2024-9349
6.1 MEDIUM

The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without …

Oct 4, 2024
CVE-2024-9345
6.1 MEDIUM

The Product Delivery Date for WooCommerce – Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate …

Oct 4, 2024
CVE-2024-9237
6.1 MEDIUM

The Fish and Ships – Most flexible shipping table rate. A WooCommerce shipping rate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to …

Oct 4, 2024
CVE-2024-9204
6.1 MEDIUM

The Smart Custom 404 Error Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER['REQUEST_URI'] in all versions up to, and including, 11.4.7 …

Oct 4, 2024
CVE-2024-8802
6.1 MEDIUM

The Clio Grow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in …

Oct 4, 2024
CVE-2024-8520
5.3 MEDIUM

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in …

Oct 4, 2024
CVE-2024-8519
6.4 MEDIUM

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Oct 4, 2024
CVE-2024-44207
4.3 MEDIUM

This issue was addressed with improved checks. This issue is fixed in iOS 18.0.1 and iPadOS 18.0.1. Audio messages in Messages may be able to …

Oct 4, 2024
CVE-2024-44204
5.5 MEDIUM

A logic issue was addressed with improved validation. This issue is fixed in iOS 18.0.1 and iPadOS 18.0.1. A user's saved passwords may be read …

Oct 4, 2024
CVE-2024-9266
4.7 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Express. This vulnerability affects the use of the Express Response object. This issue impacts Express: from …

Oct 3, 2024
CVE-2024-41591
6.1 MEDIUM

DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS.

Oct 3, 2024
CVE-2024-41587
5.4 MEDIUM

Stored XSS, by authenticated users, is caused by poor sanitization of the Login Page Greeting message in DrayTek Vigor310 devices through 4.3.2.6.

Oct 3, 2024
CVE-2024-41585
6.8 MEDIUM

DrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker to leverage the recvCmd binary to escape from …

Oct 3, 2024
CVE-2024-41584
4.7 MEDIUM

DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to reflected XSS by authenticated users, caused by missing validation of the sFormAuthStr parameter.

Oct 3, 2024
CVE-2024-41583
4.7 MEDIUM

DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to stored Cross Site Scripting (XSS) by authenticated users due to poor sanitization of the router name.

Oct 3, 2024
CVE-2024-47762
5.8 MEDIUM

Backstage is an open framework for building developer portals. Configuration supplied through APP_CONFIG_* environment variables, for example APP_CONFIG_backend_listen_port=7007, where unexpectedly ignoring the visibility defined in …

Oct 3, 2024
CVE-2024-34535
5.9 MEDIUM

In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header.

Oct 3, 2024
CVE-2024-8508
5.3 MEDIUM

NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRsets that it needs to perform name …

Oct 3, 2024
CVE-2024-45872
6.3 MEDIUM

Bandisoft BandiView 7.05 is vulnerable to Buffer Overflow via sub_0x410d1d. The vulnerability occurs due to insufficient validation of PSD files.

Oct 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.