CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-38324
5.9 MEDIUM

IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registration and unregistration operations which could expose sensitive information to …

Sep 25, 2024
CVE-2023-26688
5.4 MEDIUM

Cross Site Scripting (XSS) vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the product_data parameter of add/edit product in the …

Sep 25, 2024
CVE-2024-8794
5.3 MEDIUM

The BA Book Everything plugin for WordPress is vulnerable to arbitrary password reset in all versions up to, and including, 1.6.20. This is due to …

Sep 24, 2024
CVE-2024-8628
5.4 MEDIUM

The Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's …

Sep 24, 2024
CVE-2024-8738
6.1 MEDIUM

The Seriously Simple Stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Sep 24, 2024
CVE-2024-8716
6.1 MEDIUM

The XT Ajax Add To Cart for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate …

Sep 24, 2024
CVE-2024-8662
6.1 MEDIUM

The Koko Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in …

Sep 24, 2024
CVE-2024-8657
6.4 MEDIUM

The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ggpkg shortcode in all versions up to, and including, …

Sep 24, 2024
CVE-2024-8544
6.1 MEDIUM

The Pixel Cat – Conversion Pixel Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping …

Sep 24, 2024
CVE-2024-8432
4.3 MEDIUM

The Appointment & Event Booking Calendar Plugin – Webba Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Sep 24, 2024
CVE-2024-38269
4.9 MEDIUM

An improper restriction of operations within the bounds of a memory buffer in the USB file-sharing handler of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 …

Sep 24, 2024
CVE-2024-38268
4.9 MEDIUM

An improper restriction of operations within the bounds of a memory buffer in the MAC address parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 …

Sep 24, 2024
CVE-2024-38267
4.9 MEDIUM

An improper restriction of operations within the bounds of a memory buffer in the IPv6 address parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 …

Sep 24, 2024
CVE-2024-38266
4.9 MEDIUM

An improper restriction of operations within the bounds of a memory buffer in the parameter type parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 …

Sep 24, 2024
CVE-2024-7022
4.3 MEDIUM

Uninitialized Use in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML …

Sep 23, 2024
CVE-2024-7020
4.3 MEDIUM

Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Sep 23, 2024
CVE-2024-7019
4.3 MEDIUM

Inappropriate implementation in UI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Sep 23, 2024
CVE-2023-7282
4.3 MEDIUM

Inappropriate implementation in Navigation in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Sep 23, 2024
CVE-2023-7281
4.3 MEDIUM

Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Sep 23, 2024
CVE-2024-8770
6.1 MEDIUM

A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attackers to steal sensitive user information via …

Sep 23, 2024
CVE-2024-44540
6.6 MEDIUM

Ubiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command shell via the UART Debugging Port.

Sep 23, 2024
CVE-2024-39843
6.7 MEDIUM

A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via create user form inputs.

Sep 23, 2024
CVE-2024-39342
6.6 MEDIUM

Entrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier uses a DLL library (i.e. DCG.Security.dll) with a custom …

Sep 23, 2024
CVE-2024-39341
5.9 MEDIUM

Entrust Instant Financial Issuance (On Premise) Software (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier leaves behind a configuration file (i.e. …

Sep 23, 2024
CVE-2023-46948
5.4 MEDIUM

A reflected Cross-Site Scripting (XSS) vulnerability was found on Temenos T24 Browser R19.40 that enables a remote attacker to execute arbitrary JavaScript code via the …

Sep 23, 2024
CVE-2024-40441
6.6 MEDIUM

An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 …

Sep 23, 2024
CVE-2024-47069
6.1 MEDIUM

Oveleon Cookie Bar is a cookie bar is for the Contao Open Source CMS and allows a visitor to define cookie & privacy settings for …

Sep 23, 2024
CVE-2024-47068
6.1 MEDIUM

Rollup is a module bundler for JavaScript. Versions prior to 2.79.2, 3.29.5, and 4.22.4 are susceptible to a DOM Clobbering vulnerability when bundling scripts with …

Sep 23, 2024
CVE-2024-23972
6.8 MEDIUM

Sony XAV-AX5500 USB Configuration Descriptor Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of …

Sep 23, 2024
CVE-2024-23933
6.8 MEDIUM

Sony XAV-AX5500 CarPlay TLV Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of …

Sep 23, 2024
CVE-2024-23922
6.8 MEDIUM

Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Sony …

Sep 23, 2024
CVE-2024-46241
5.9 MEDIUM

PHPGurukul Dairy Farm Shop Management System v1.1 is vulnerable to Cross-Site Scripting (XSS) via the pname parameter in add_product.php and edit_product.php.

Sep 23, 2024
CVE-2024-46544
5.9 MEDIUM

Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration which may lead to information …

Sep 23, 2024
CVE-2022-48945
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: vivid: fix compose size exceed boundary syzkaller found a bug: BUG: unable to handle …

Sep 23, 2024
CVE-2024-8903
4.7 MEDIUM

Local active protection service settings manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows, macOS) before build …

Sep 23, 2024
CVE-2024-45348
6.4 MEDIUM

Xiaomi Router AX9000 has a post-authorization command injection vulnerability. This vulnerability is caused by the lack of validation of user input, and an attacker can …

Sep 23, 2024
CVE-2024-8758
4.8 MEDIUM

The Quiz and Survey Master (QSM) WordPress plugin before 9.1.3 does not sanitise and escape some of its settings, which could allow high privilege users …

Sep 23, 2024
CVE-2024-7846
5.4 MEDIUM

YITH WooCommerce Ajax Search is vulnerable to a XSS vulnerability due to insufficient sanitization of user supplied block attributes. This makes it possible for Contributors+ …

Sep 23, 2024
CVE-2024-47227
6.1 MEDIUM

iRedAdmin before 2.6 allows XSS, e.g., via order_name.

Sep 23, 2024
CVE-2024-9094
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Blood Bank System 1.0. This vulnerability affects unknown code of the file /admin/blood/update/o-.php. The manipulation of …

Sep 23, 2024
CVE-2024-9093
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Profile Registration without Reload Refresh 1.0. This affects an unknown part of the file del.php …

Sep 23, 2024
CVE-2024-44048
6.5 MEDIUM

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpWax Product Carousel Slider & Grid Ultimate for WooCommerce …

Sep 23, 2024
CVE-2024-43996
6.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ElementsKit ElementsKit Pro allows PHP Local File Inclusion.This issue affects ElementsKit Pro: …

Sep 23, 2024
CVE-2024-9090
6.3 MEDIUM

A vulnerability was found in SourceCodester Modern Loan Management System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Sep 23, 2024
CVE-2024-9088
6.3 MEDIUM

A vulnerability has been found in SourceCodester Telecom Billing Management System 1.0 and classified as critical. This vulnerability affects the function login. The manipulation of …

Sep 22, 2024
CVE-2024-9086
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Restaurant Reservation System 1.0. Affected is an unknown function of the file /filter.php. The manipulation …

Sep 22, 2024
CVE-2024-40703
5.5 MEDIUM

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker …

Sep 22, 2024
CVE-2024-9082
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Sep 22, 2024
CVE-2024-9081
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Sep 22, 2024
CVE-2024-47226
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An …

Sep 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.