CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4401
6.4 MEDIUM

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ and 'eae_slider_animation' parameters in all versions up to, and …

Aug 30, 2024
CVE-2024-8328
5.4 MEDIUM

Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular …

Aug 30, 2024
CVE-2024-2881
6.7 MEDIUM

Fault Injection vulnerability in wc_ed25519_sign_msg function in wolfssl/wolfcrypt/src/ed25519.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remote attacker co-resides in the same system with a victim process …

Aug 30, 2024
CVE-2024-1545
5.9 MEDIUM

Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remote attacker co-resides in the same system with a victim process …

Aug 29, 2024
CVE-2024-1543
4.1 MEDIUM

The side-channel protected T-Table implementation in wolfSSL up to version 5.6.5 protects against a side-channel attacker with cache-line resolution. In a controlled environment such as …

Aug 29, 2024
CVE-2024-45302
6.1 MEDIUM

RestSharp is a Simple REST and HTTP API Client for .NET. The second argument to `RestRequest.AddHeader` (the header value) is vulnerable to CRLF injection. The …

Aug 29, 2024
CVE-2024-41349
6.1 MEDIUM

unmark 1.9.2 is vulnerable to Cross Site Scripting (XSS) via application/views/marks/add_by_url.php.

Aug 29, 2024
CVE-2024-41371
6.1 MEDIUM

Organizr v1.90 is vulnerable to Cross Site Scripting (XSS) via api.php.

Aug 29, 2024
CVE-2024-41358
6.1 MEDIUM

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.

Aug 29, 2024
CVE-2024-41351
6.1 MEDIUM

bjyadmin commit a560fd5 is vulnerable to Cross Site Scripting (XSS) via Public/statics/umeditor1_2_3/php/getContent.php

Aug 29, 2024
CVE-2024-41350
6.1 MEDIUM

bjyadmin commit a560fd5 is vulnerable to Cross Site Scripting (XSS) via Public/statics/umeditor1_2_3/php/imageUp.php

Aug 29, 2024
CVE-2024-41348
6.1 MEDIUM

openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/alsearch.php

Aug 29, 2024
CVE-2024-41347
6.1 MEDIUM

openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/settings.php

Aug 29, 2024
CVE-2024-41346
5.4 MEDIUM

openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/submit.php

Aug 29, 2024
CVE-2024-41345
5.4 MEDIUM

openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/trip.php

Aug 29, 2024
CVE-2024-34018
5.5 MEDIUM

Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 4569.

Aug 29, 2024
CVE-2024-43947
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Dinesh Karki WP Armour Extended.This issue affects WP Armour Extended: from n/a through 1.26.

Aug 29, 2024
CVE-2024-43920
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jegstudio Gutenverse allows Stored XSS.This issue affects Gutenverse: from n/a through …

Aug 29, 2024
CVE-2024-44930
6.5 MEDIUM

Serilog before v2.1.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP …

Aug 29, 2024
CVE-2024-44776
6.1 MEDIUM

An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a crafted URL.

Aug 29, 2024
CVE-2024-44717
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in DedeBIZ v6.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Aug 29, 2024
CVE-2024-44716
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in DedeBIZ v6.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Aug 29, 2024
CVE-2024-43964
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Leithold DSGVO All in one for WP allows Stored XSS.This …

Aug 29, 2024
CVE-2024-43961
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in azurecurve azurecurve Toggle Show/Hide allows Stored XSS.This issue affects azurecurve Toggle …

Aug 29, 2024
CVE-2024-43960
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Page Builder Addons Web and WooCommerce Addons for WPBakery Builder allows …

Aug 29, 2024
CVE-2024-43953
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webcodingplace Classic Addons – WPBakery Page Builder classic-addons-wpbakery-page-builder-addons allows Stored XSS.This issue affects …

Aug 29, 2024
CVE-2024-43952
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Esotera allows Stored XSS.This issue affects Esotera: from n/a through …

Aug 29, 2024
CVE-2024-43951
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Tempera allows Stored XSS.This issue affects Tempera: from n/a through …

Aug 29, 2024
CVE-2024-43949
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic GHActivity allows Stored XSS.This issue affects GHActivity: from n/a through …

Aug 29, 2024
CVE-2024-43946
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SKT Themes SKT Blocks – Gutenberg based Page Builder allows Stored …

Aug 29, 2024
CVE-2024-43936
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper EmbedPress allows Stored XSS.This issue affects EmbedPress: from n/a through …

Aug 29, 2024
CVE-2024-43935
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Delicious Delicious Recipes – WordPress Recipe Plugin allows Stored XSS.This …

Aug 29, 2024
CVE-2024-43934
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Robert Felty Collapsing Archives allows Stored XSS.This issue affects Collapsing Archives: …

Aug 29, 2024
CVE-2024-45056
5.9 MEDIUM

zksolc is a Solidity compiler for ZKsync. All LLVM versions since 2015 fold `(xor (shl 1, x), -1)` to `(rotl ~1, x)` if run with …

Aug 29, 2024
CVE-2024-45045
6.3 MEDIUM

Collabora Online is a collaborative online office suite based on LibreOffice technology. In the mobile (Android/iOS) device variants of Collabora Online it was possible to …

Aug 29, 2024
CVE-2024-44919
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Aug 29, 2024
CVE-2024-35133
6.8 MEDIUM

IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct phishing attacks, using an open redirect attack. By …

Aug 29, 2024
CVE-2024-43957
6.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sk. Abul Hasan Animated Number Counters allows PHP Local File Inclusion.This issue …

Aug 29, 2024
CVE-2024-43954
6.3 MEDIUM

Incorrect Authorization vulnerability in Themeum Droip allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Droip: from n/a through 1.1.1.

Aug 29, 2024
CVE-2024-35118
4.6 MEDIUM

IBM MaaS360 for Android 6.31 through 8.60 is using hard coded credentials that can be obtained by a user with physical access to the device.

Aug 29, 2024
CVE-2024-8304
4.7 MEDIUM

A vulnerability has been found in jpress up to 5.1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file …

Aug 29, 2024
CVE-2024-8303
6.3 MEDIUM

A vulnerability classified as critical has been found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. This affects an unknown part of the file /ajax/getBasicInfo.php. The manipulation …

Aug 29, 2024
CVE-2024-43940
6.5 MEDIUM

Missing Authorization vulnerability in VIICTORY MEDIA LLC Z Y N I T H allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Z Y …

Aug 29, 2024
CVE-2024-43939
6.5 MEDIUM

Missing Authorization vulnerability in VIICTORY MEDIA LLC Z Y N I T H allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Z Y …

Aug 29, 2024
CVE-2024-43922
4.8 MEDIUM

Improper Control of Generation of Code ('Code Injection') vulnerability in NitroPack Inc. NitroPack allows Code Injection.This issue affects NitroPack: from n/a through 1.16.7.

Aug 29, 2024
CVE-2024-8302
6.3 MEDIUM

A vulnerability was found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. It has been rated as critical. Affected by this issue is some unknown functionality of …

Aug 29, 2024
CVE-2024-1056
6.4 MEDIUM

The FunnelKit Funnel Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'allow_iframe_tag_in_post' function which uses the 'wp_kses_allowed_html' filter to globally …

Aug 29, 2024
CVE-2024-8297
5.3 MEDIUM

A vulnerability was found in kitsada8621 Digital Library Management System 1.0. It has been classified as problematic. Affected is the function JwtRefreshAuth of the file …

Aug 29, 2024
CVE-2024-8296
6.3 MEDIUM

A vulnerability was found in FeehiCMS up to 2.1.1 and classified as critical. This issue affects the function insert of the file /admin/index.php?r=user%2Fcreate. The manipulation …

Aug 29, 2024
CVE-2024-3679
5.3 MEDIUM

The Premium SEO Pack – WP SEO Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.002. …

Aug 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.