CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8128
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, …

Aug 24, 2024
CVE-2022-43915
6.8 MEDIUM

IBM App Connect Enterprise Certified Container 5.0, 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, …

Aug 24, 2024
CVE-2024-8127
6.3 MEDIUM

A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, …

Aug 24, 2024
CVE-2024-6499
5.3 MEDIUM

The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 9.7.8. This makes it possible …

Aug 24, 2024
CVE-2024-8120
4.7 MEDIUM

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.14. This is …

Aug 24, 2024
CVE-2024-6631
5.0 MEDIUM

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX …

Aug 24, 2024
CVE-2024-2254
6.4 MEDIUM

The RT Easy Builder – Advanced addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions …

Aug 24, 2024
CVE-2023-6987
6.1 MEDIUM

The String locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sql-column' parameter in all versions up to, and including, 2.6.5 due …

Aug 24, 2024
CVE-2023-0926
4.4 MEDIUM

The Custom Permalinks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.0 due to insufficient input sanitization and …

Aug 24, 2024
CVE-2024-38207
6.3 MEDIUM

Microsoft Edge (HTML-based) Memory Corruption Vulnerability

Aug 23, 2024
CVE-2024-40111
4.8 MEDIUM

A persistent (stored) cross-site scripting (XSS) vulnerability has been identified in Automad 2.0.0-alpha.4. This vulnerability enables an attacker to inject malicious JavaScript code into the …

Aug 23, 2024
CVE-2024-37392
6.1 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability has been identified in SMSEagle software version < 6.0. The vulnerability arises because the application did not properly sanitize …

Aug 23, 2024
CVE-2024-45190
6.5 MEDIUM

Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal in the "Pipeline …

Aug 23, 2024
CVE-2024-45189
6.5 MEDIUM

Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal in the "Git …

Aug 23, 2024
CVE-2024-45188
6.5 MEDIUM

Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal in the "File …

Aug 23, 2024
CVE-2024-42852
6.1 MEDIUM

Cross Site Scripting vulnerability in AcuToWeb server v.10.5.0.7577C8b allows a remote attacker to execute arbitrary code via the index.php component.

Aug 23, 2024
CVE-2024-44387
6.5 MEDIUM

Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the functino formWrlExtraGet.

Aug 23, 2024
CVE-2024-43794
6.1 MEDIUM

OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSearch Dashboards. Improper validation of the nextUrl parameter can lead …

Aug 23, 2024
CVE-2024-42918
5.4 MEDIUM

itsourcecode Online Accreditation Management System contains a Cross Site Scripting vulnerability, which allows an attacker to execute arbitrary code via a crafted payload to the …

Aug 23, 2024
CVE-2024-41878
5.4 MEDIUM

Adobe Experience Manager versions 6.5.19 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to inject and …

Aug 23, 2024
CVE-2024-41877
5.4 MEDIUM

Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Aug 23, 2024
CVE-2024-41876
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim …

Aug 23, 2024
CVE-2024-41875
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Aug 23, 2024
CVE-2024-41849
4.1 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could lead to a security feature bypass. An low-privileged …

Aug 23, 2024
CVE-2024-41848
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim …

Aug 23, 2024
CVE-2024-41847
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim …

Aug 23, 2024
CVE-2024-41846
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Aug 23, 2024
CVE-2024-41845
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Aug 23, 2024
CVE-2024-41844
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Aug 23, 2024
CVE-2024-41843
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Aug 23, 2024
CVE-2024-41842
4.8 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Aug 23, 2024
CVE-2024-41841
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim …

Aug 23, 2024
CVE-2024-43032
4.3 MEDIUM

autMan v2.9.6 allows attackers to bypass authentication via a crafted web request.

Aug 23, 2024
CVE-2024-43031
4.3 MEDIUM

autMan v2.9.6 was discovered to contain an access control issue.

Aug 23, 2024
CVE-2024-42364
6.5 MEDIUM

Homepage is a highly customizable homepage with Docker and service API integrations. The default setup of homepage 0.9.1 is vulnerable to DNS rebinding. Homepage is …

Aug 23, 2024
CVE-2024-8113
5.4 MEDIUM

Stored XSS in organizer and event settings of pretix up to 2024.7.0 allows malicious event organizers to inject HTML tags into e-mail previews on settings …

Aug 23, 2024
CVE-2024-8112
4.3 MEDIUM

A vulnerability was found in thinkgem JeeSite 5.3. It has been rated as problematic. This issue affects some unknown processing of the file /js/a/login of …

Aug 23, 2024
CVE-2024-42766
5.4 MEDIUM

Kashipara Bus Ticket Reservation System v1.0 0 is vulnerable to Incorrect Access Control via /deleteTicket.php.

Aug 23, 2024
CVE-2024-41150
6.3 MEDIUM

An Stored Cross-site Scripting vulnerability in request module affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus.This issue affects ServiceDesk Plus versions: through …

Aug 23, 2024
CVE-2024-5502
6.4 MEDIUM

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion, Dual Heading, and Vertical Timeline widgets …

Aug 23, 2024
CVE-2024-38807
6.3 MEDIUM

Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where …

Aug 23, 2024
CVE-2024-43105
4.3 MEDIUM

Mattermost Plugin Channel Export versions <=1.0.0 fail to restrict concurrent runs of the /export command which allows a user to consume excessive resource by running …

Aug 23, 2024
CVE-2024-6715
6.1 MEDIUM

The Ditty WordPress plugin before 3.1.46 re-introduced a previously fixed security issue (https://wpscan.com/vulnerability/80a9eb3a-2cb1-4844-9004-ba2554b2d46c/) in v3.1.39

Aug 23, 2024
CVE-2024-3282
4.8 MEDIUM

The WP Table Builder WordPress plugin through 1.5.0 does not sanitise and escape some of its Table data, which could allow high privilege users such …

Aug 23, 2024
CVE-2024-8089
6.3 MEDIUM

A vulnerability was found in SourceCodester E-Commerce System 1.0. It has been classified as critical. Affected is an unknown function of the file /ecommerce/admin/products/controller.php. The …

Aug 23, 2024
CVE-2024-8087
6.3 MEDIUM

A vulnerability was found in SourceCodester E-Commerce System 1.0 and classified as critical. This issue affects some unknown processing of the file /ecommerce/popup_Item.php. The manipulation …

Aug 22, 2024
CVE-2024-38208
6.1 MEDIUM

Microsoft Edge for Android Spoofing Vulnerability

Aug 22, 2024
CVE-2024-8083
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this issue is some unknown …

Aug 22, 2024
CVE-2024-43790
4.5 MEDIUM

Vim is an open source command line text editor. When performing a search and displaying the search-count message is disabled (:set shm+=S), the search pattern …

Aug 22, 2024
CVE-2024-8080
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Online Health Care System 1.0. Affected is an unknown function of the file search.php. The …

Aug 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.