CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-45607
5.8 MEDIUM

whatsapp-api-js is a TypeScript server agnostic Whatsapp's Official API framework. It's possible to check the payload validation using the WhatsAppAPI.verifyRequestSignature and expect false when the …

Sep 12, 2024
CVE-2024-8641
6.7 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 …

Sep 12, 2024
CVE-2024-8311
6.5 MEDIUM

An issue was discovered with pipeline execution policies in GitLab EE affecting all versions from 17.2 prior to 17.2.5, 17.3 prior to 17.3.2 which allows …

Sep 12, 2024
CVE-2024-4472
4.0 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from …

Sep 12, 2024
CVE-2024-45383
5.0 MEDIUM

A mishandling of IRP requests vulnerability exists in the HDAudBus_DMA interface of Microsoft High Definition Audio Bus Driver 10.0.19041.3636 (WinBuild.160101.0800). A specially crafted application can …

Sep 12, 2024
CVE-2024-45303
6.1 MEDIUM

Discourse Calendar plugin adds the ability to create a dynamic calendar in the first post of a topic to Discourse. Rendering event names can be …

Sep 12, 2024
CVE-2024-45182
5.5 MEDIUM

An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70 An improper bounds check allows specially crafted packets to cause …

Sep 12, 2024
CVE-2024-34336
5.3 MEDIUM

User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists in the application by comparing the server responses of …

Sep 12, 2024
CVE-2024-34335
6.1 MEDIUM

ORDAT FOSS-Online before version 2.24.01 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login page.

Sep 12, 2024
CVE-2024-25270
4.3 MEDIUM

An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulnerability by manipulating the ID parameter and increment …

Sep 12, 2024
CVE-2024-41629
5.5 MEDIUM

An issue in Texas Instruments Fusion Digital Power Designer v.7.10.1 allows a local attacker to obtain sensitive information via the plaintext storage of credentials

Sep 12, 2024
CVE-2020-24061
4.3 MEDIUM

Cross Site Scripting (XSS) Vulnerability in Firewall menu in Control Panel in KASDA KW5515 version 4.3.1.0, allows attackers to execute arbitrary code and steal cookies …

Sep 12, 2024
CVE-2024-8754
6.4 MEDIUM

An issue has been discovered in GitLab EE/CE affecting all versions from 16.9.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2. …

Sep 12, 2024
CVE-2024-8631
5.5 MEDIUM

A privilege escalation issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.1.7, from 17.2 prior to 17.2.5, and …

Sep 12, 2024
CVE-2024-6840
6.6 MEDIUM

An improper authorization flaw exists in the Ansible Automation Controller. This flaw allows an attacker using the k8S API server to send an HTTP request …

Sep 12, 2024
CVE-2024-6389
4.3 MEDIUM

An issue was discovered in GitLab-CE/EE affecting all versions starting with 17.0 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. An attacker as a …

Sep 12, 2024
CVE-2024-5435
4.5 MEDIUM

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 15.10 before 17.1.7, all versions starting from 17.2 before 17.2.5, all …

Sep 12, 2024
CVE-2024-4660
6.5 MEDIUM

An issue has been discovered in GitLab EE affecting all versions starting from 11.2 before 17.1.7, all versions starting from 17.2 before 17.2.5, all versions …

Sep 12, 2024
CVE-2024-4612
6.4 MEDIUM

An issue has been discovered in GitLab EE affecting all versions starting from 12.9 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under certain …

Sep 12, 2024
CVE-2024-2743
5.3 MEDIUM

An issue was discovered in GitLab-EE starting with version 13.3 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2 that would allow an attacker to …

Sep 12, 2024
CVE-2024-6702
5.2 MEDIUM

Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.

Sep 12, 2024
CVE-2024-6701
5.5 MEDIUM

Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type.

Sep 12, 2024
CVE-2024-6700
5.5 MEDIUM

Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name.

Sep 12, 2024
CVE-2024-45826
6.8 MEDIUM

CVE-2024-45826 IMPACT Due to improper input validation, a path traversal and remote code execution vulnerability exists when the ThinManager® processes a crafted POST request. If …

Sep 12, 2024
CVE-2024-42484
6.5 MEDIUM

ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An Out-of-Bound (OOB) vulnerability was discovered in the implementation of the ESP-NOW group type message because there …

Sep 12, 2024
CVE-2024-42483
6.5 MEDIUM

ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An replay attacks vulnerability was discovered in the implementation of the ESP-NOW because the caches is not …

Sep 12, 2024
CVE-2024-28990
6.3 MEDIUM

SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability would allow access to the RabbitMQ …

Sep 12, 2024
CVE-2022-26322
4.9 MEDIUM

Possible Insertion of Sensitive Information into Log File Vulnerability in Identity Manager has been discovered in OpenText™ Identity Manager REST Driver. This impact version before …

Sep 12, 2024
CVE-2021-38132
5.3 MEDIUM

Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.

Sep 12, 2024
CVE-2021-38131
5.4 MEDIUM

Possible Cross-Site Scripting (XSS) Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.5.0000.

Sep 12, 2024
CVE-2021-22533
6.5 MEDIUM

Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.4.0000.

Sep 12, 2024
CVE-2021-22518
5.8 MEDIUM

A vulnerability identified in OpenText™ Identity Manager AzureAD Driver that allows logging of sensitive information into log file. This impacts all versions before 5.1.4.0

Sep 12, 2024
CVE-2021-22503
5.4 MEDIUM

Possible Improper Neutralization of Input During Web Page Generation Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.3.0000.

Sep 12, 2024
CVE-2024-8750
5.4 MEDIUM

Cross-site Scripting (XSS) vulnerability in idoit pro version 28. This vulnerability allows an attacker to retrieve session details of an authenticated user due to lack …

Sep 12, 2024
CVE-2024-8622
6.1 MEDIUM

The amCharts: Charts and Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'amcharts_javascript' parameter in all versions up to, and including, …

Sep 12, 2024
CVE-2024-2010
6.1 MEDIUM

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in TE Informatics V5 allows Reflected XSS.This issue affects V5: before 6.2.

Sep 12, 2024
CVE-2024-8056
6.1 MEDIUM

The MM-Breaking News WordPress plugin through 0.7.9 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected …

Sep 12, 2024
CVE-2024-8054
6.1 MEDIUM

The MM-Breaking News WordPress plugin through 0.7.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Sep 12, 2024
CVE-2024-7862
6.5 MEDIUM

The blogintroduction-wordpress-plugin WordPress plugin through 0.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged …

Sep 12, 2024
CVE-2024-7861
6.1 MEDIUM

The Misiek Paypal WordPress plugin through 1.1.20090324 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Sep 12, 2024
CVE-2024-7860
6.1 MEDIUM

The Simple Headline Rotator WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which …

Sep 12, 2024
CVE-2024-7859
6.5 MEDIUM

The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Sep 12, 2024
CVE-2024-7822
6.1 MEDIUM

The Quick Code WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Sep 12, 2024
CVE-2024-7820
6.5 MEDIUM

The ILC Thickbox WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Sep 12, 2024
CVE-2024-7818
6.1 MEDIUM

The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which …

Sep 12, 2024
CVE-2024-7817
6.5 MEDIUM

The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF checks in some places, which could allow attackers to make logged in users …

Sep 12, 2024
CVE-2024-7816
6.1 MEDIUM

The Gixaw Chat WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Sep 12, 2024
CVE-2024-6887
4.8 MEDIUM

The Giveaways and Contests by RafflePress WordPress plugin before 1.12.16 does not sanitise and escape some of its Giveaways settings, which could allow high privilege …

Sep 12, 2024
CVE-2024-6019
6.1 MEDIUM

The Music Request Manager WordPress plugin through 1.3 does not sanitise and escape incoming music requests, which could allow unauthenticated users to perform Cross-Site Scripting …

Sep 12, 2024
CVE-2024-6018
6.1 MEDIUM

The Music Request Manager WordPress plugin through 1.3 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to …

Sep 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.