CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-45389
6.4 MEDIUM

Pagefind, a fully static search library, initializes its dynamic JavaScript and WebAssembly files relative to the location of the first script the user loads. This …

Sep 3, 2024
CVE-2024-45180
5.4 MEDIUM

SquaredUp DS for SCOM 6.2.1.11104 allows XSS.

Sep 3, 2024
CVE-2024-41434
4.3 MEDIUM

PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows attackers to cause a Denial of Service (DoS) via …

Sep 3, 2024
CVE-2024-43803
4.9 MEDIUM

The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. The `BareMetalHost` (BMH) CRD allows the `userData`, `metaData`, and …

Sep 3, 2024
CVE-2024-42904
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name …

Sep 3, 2024
CVE-2024-42903
6.5 MEDIUM

A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link …

Sep 3, 2024
CVE-2024-42901
4.8 MEDIUM

A CSV injection vulnerability in Lime Survey v6.5.12 allows attackers to execute arbitrary code via uploading a crafted CSV file.

Sep 3, 2024
CVE-2024-43412
4.6 MEDIUM

Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo …

Sep 3, 2024
CVE-2024-34463
5.1 MEDIUM

BPL Personal Weighing Scale PWS-01BT IND/09/18/599 devices send sensitive information in unencrypted BLE packets. (The packet data also lacks authentication and integrity protection.)

Sep 3, 2024
CVE-2024-8388
5.3 MEDIUM

Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullscreen mode after …

Sep 3, 2024
CVE-2024-8386
6.1 MEDIUM

If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to …

Sep 3, 2024
CVE-2024-44920
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Sep 3, 2024
CVE-2024-37136
6.8 MEDIUM

Dell Path to PowerProtect, versions 1.1, 1.2, contains an Exposure of Private Personal Information to an Unauthorized Actor vulnerability. A remote high privileged attacker could …

Sep 3, 2024
CVE-2024-42061
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the CGI program "dynamic_script.cgi" of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware …

Sep 3, 2024
CVE-2024-6343
4.9 MEDIUM

A buffer overflow vulnerability in the CGI program of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 …

Sep 3, 2024
CVE-2024-8380
6.3 MEDIUM

A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been rated as critical. This issue affects some unknown processing …

Sep 3, 2024
CVE-2024-45621
5.4 MEDIUM

The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related to failure to use a separate browser …

Sep 2, 2024
CVE-2024-6920
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Stored XSS.This issue affects NACPremium: through 01082024.

Sep 2, 2024
CVE-2024-45313
5.4 MEDIUM

Overleaf is a web-based collaborative LaTeX editor. When installing Server Pro using the Overleaf Toolkit from before 2024-07-17 or legacy docker-compose.yml from before 2024-08-28, the …

Sep 2, 2024
CVE-2024-45312
5.3 MEDIUM

Overleaf is a web-based collaborative LaTeX editor. Overleaf Community Edition and Server Pro prior to version 5.0.7 (or 4.2.7 for the 4.x series) contain a …

Sep 2, 2024
CVE-2024-45308
6.5 MEDIUM

HedgeDoc is an open source, real-time, collaborative, markdown notes application. When using HedgeDoc 1 with MySQL or MariaDB, it is possible to create notes with …

Sep 2, 2024
CVE-2024-45306
4.5 MEDIUM

Vim is an open source, command line text editor. Patch v9.1.0038 optimized how the cursor position is calculated and removed a loop, that verified that …

Sep 2, 2024
CVE-2024-44947
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fuse: Initialize beyond-EOF page contents before setting uptodate fuse_notify_store(), unlike fuse_do_readpage(), does not enable page …

Sep 2, 2024
CVE-2024-43801
4.6 MEDIUM

Jellyfin is an open source self hosted media server. The Jellyfin user profile image upload accepts SVG files, allowing for a stored XSS attack against …

Sep 2, 2024
CVE-2024-43797
6.3 MEDIUM

audiobookshelf is a self-hosted audiobook and podcast server. A non-admin user is not allowed to create libraries (or access only the ones they have permission …

Sep 2, 2024
CVE-2024-43792
6.3 MEDIUM

Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.17.0 of the Halo project. This vulnerability …

Sep 2, 2024
CVE-2020-36830
4.3 MEDIUM

A vulnerability was found in nescalante urlregex up to 0.5.0 and classified as problematic. This issue affects some unknown processing of the file index.js of …

Sep 2, 2024
CVE-2024-38858
6.1 MEDIUM

Improper neutralization of input in Checkmk before version 2.3.0p14 allows attackers to inject and run malicious scripts in the Robotmk logs view.

Sep 2, 2024
CVE-2024-33043
5.5 MEDIUM

Transient DOS while handling PS event when Program Service name length offset value is set to 255.

Sep 2, 2024
CVE-2024-33016
6.8 MEDIUM

memory corruption when an invalid firehose patch command is invoked.

Sep 2, 2024
CVE-2024-7692
6.1 MEDIUM

The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Sep 2, 2024
CVE-2024-7691
6.1 MEDIUM

The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks against …

Sep 2, 2024
CVE-2024-7690
4.3 MEDIUM

The DN Popup WordPress plugin through 1.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Sep 2, 2024
CVE-2024-7354
6.1 MEDIUM

The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting …

Sep 2, 2024
CVE-2024-8365
6.2 MEDIUM

Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token …

Sep 2, 2024
CVE-2024-45528
5.4 MEDIUM

CodeAstro MembershipM-PHP (aka Membership Management System in PHP) 1.0 allows add_members.php fullname stored XSS.

Sep 2, 2024
CVE-2024-45527
6.1 MEDIUM

REDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSRF via index.php?logout=1, and can …

Sep 2, 2024
CVE-2024-39775
6.5 MEDIUM

in OpenHarmony v4.1.0 and prior versions allow a remote attacker cause information leak through out-of-bounds Read.

Sep 2, 2024
CVE-2024-39612
5.5 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

Sep 2, 2024
CVE-2024-38382
5.5 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

Sep 2, 2024
CVE-2024-20088
4.4 MEDIUM

In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Sep 2, 2024
CVE-2024-20087
6.7 MEDIUM

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Sep 2, 2024
CVE-2024-20086
6.7 MEDIUM

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Sep 2, 2024
CVE-2024-20085
4.4 MEDIUM

In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Sep 2, 2024
CVE-2024-20084
4.4 MEDIUM

In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Sep 2, 2024
CVE-2024-45270
4.3 MEDIUM

WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Hero image selection feature. While logged in to the WordPress …

Sep 2, 2024
CVE-2024-45269
4.3 MEDIUM

WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Carousel image selection feature. While logged in to the WordPress …

Sep 2, 2024
CVE-2024-45509
6.5 MEDIUM

In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.

Sep 1, 2024
CVE-2024-5053
4.2 MEDIUM

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized Malichimp …

Sep 1, 2024
CVE-2024-8366
4.3 MEDIUM

A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php?id=userProfileEdit …

Aug 31, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.