CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-39660
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jordy Meow Photo Engine allows Stored XSS.This issue affects Photo Engine: …

Aug 1, 2024
CVE-2024-39659
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Lester ‘GaMerZ’ Chan WP-PostRatings allows Stored XSS.This issue affects WP-PostRatings: from …

Aug 1, 2024
CVE-2024-39655
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LiquidPoll LiquidPoll – Advanced Polls for Creators and Brands.This issue affects …

Aug 1, 2024
CVE-2024-39649
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite.This issue affects Essential Addons for Elementor: from …

Aug 1, 2024
CVE-2024-39648
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themewinter Eventin allows Stored XSS.This issue affects Eventin: from n/a through …

Aug 1, 2024
CVE-2024-39637
5.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in pixelcurve Edubin edubin.This issue affects Edubin: from n/a through <= 9.2.0.

Aug 1, 2024
CVE-2024-32931
5.7 MEDIUM

Under certain circumstances the exacqVision Web Service can expose authentication token details within communications.

Aug 1, 2024
CVE-2024-32865
6.4 MEDIUM

Under certain circumstances the exacqVision Server will not properly validate TLS certificates provided by connected devices.

Aug 1, 2024
CVE-2024-32862
6.8 MEDIUM

Under certain circumstances the ExacqVision Web Services does not provide sufficient protection from untrusted domains.

Aug 1, 2024
CVE-2024-7367
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in SourceCodester Simple Realtime Quiz System 1.0. This affects an unknown part of the file /ajax.php?action=save_user. …

Aug 1, 2024
CVE-2024-39630
5.5 MEDIUM

Deserialization of Untrusted Data vulnerability in MotoPress Timetable and Event Schedule allows Object Injection.This issue affects Timetable and Event Schedule: from n/a through 2.4.13.

Aug 1, 2024
CVE-2024-38791
4.9 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot allows Server Side Request Forgery.This issue affects AI Engine: ChatGPT Chatbot: from n/a …

Aug 1, 2024
CVE-2024-38772
6.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetWidgets for Elementor and WooCommerce allows PHP Local File Inclusion.This issue …

Aug 1, 2024
CVE-2024-38768
4.3 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Webangon The Pack Elementor addons allows PHP Local File Inclusion, Path Traversal.This …

Aug 1, 2024
CVE-2024-32864
6.4 MEDIUM

Under certain circumstances exacqVision Web Services will not enforce secure web communications (HTTPS)

Aug 1, 2024
CVE-2024-32863
6.8 MEDIUM

Under certain circumstances the exacqVision Web Services may be susceptible to Cross-Site Request Forgery (CSRF)

Aug 1, 2024
CVE-2024-7365
6.3 MEDIUM

A vulnerability was found in SourceCodester Tracking Monitoring Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Aug 1, 2024
CVE-2024-7364
6.3 MEDIUM

A vulnerability has been found in SourceCodester Tracking Monitoring Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Aug 1, 2024
CVE-2024-7363
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Tracking Monitoring Management System 1.0. Affected is an unknown function of the file /manage_person.php. …

Aug 1, 2024
CVE-2024-7362
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Tracking Monitoring Management System 1.0. This issue affects some unknown processing of the …

Aug 1, 2024
CVE-2024-4353
4.8 MEDIUM

Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in the generate dashboard board instance functionality. The Name input field does …

Aug 1, 2024
CVE-2024-7361
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Tracking Monitoring Management System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=save_establishment. The manipulation …

Aug 1, 2024
CVE-2024-7360
4.3 MEDIUM

A vulnerability classified as problematic has been found in SourceCodester Tracking Monitoring Management System 1.0. This affects an unknown part of the file /ajax.php. The …

Aug 1, 2024
CVE-2024-7211
4.7 MEDIUM

The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulnerability, permitting an attacker to control the redirection path …

Aug 1, 2024
CVE-2024-41962
4.6 MEDIUM

Bostr is an nostr relay aggregator proxy that acts like a regular nostr relay. bostr let everyone in even having authorized_keys being set when noscraper …

Aug 1, 2024
CVE-2024-41946
5.3 MEDIUM

REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions …

Aug 1, 2024
CVE-2024-41162
4.1 MEDIUM

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow the modification of local channels by a …

Aug 1, 2024
CVE-2024-41144
5.5 MEDIUM

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly validate synced posts, when shared channels are enabled, …

Aug 1, 2024
CVE-2024-41123
5.3 MEDIUM

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific …

Aug 1, 2024
CVE-2024-39839
4.3 MEDIUM

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when …

Aug 1, 2024
CVE-2024-39832
6.8 MEDIUM

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly safeguard an error handling which allows a malicious …

Aug 1, 2024
CVE-2024-6923
5.5 MEDIUM

There is a MEDIUM severity vulnerability affecting CPython. The email module didn’t properly quote newlines for email headers when serializing an email message allowing for …

Aug 1, 2024
CVE-2024-7357
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-600 up to 2.18. It has been rated as critical. This issue affects the …

Aug 1, 2024
CVE-2024-2455
6.4 MEDIUM

The Element Pack - Addon for Elementor Page Builder WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget wrapper link …

Aug 1, 2024
CVE-2024-6346
6.4 MEDIUM

The Gutenberg Blocks, Page Builder – ComboBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the redirectURL parameter of the Date Countdown widget, …

Aug 1, 2024
CVE-2024-38490
5.8 MEDIUM

Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting …

Aug 1, 2024
CVE-2024-38481
4.8 MEDIUM

Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Read Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting …

Aug 1, 2024
CVE-2024-28972
5.9 MEDIUM

Dell InsightIQ, Verion 5.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading …

Aug 1, 2024
CVE-2024-25948
4.8 MEDIUM

Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting …

Aug 1, 2024
CVE-2024-7302
6.4 MEDIUM

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 3gp2 file uploads in all versions up …

Aug 1, 2024
CVE-2024-5678
4.7 MEDIUM

Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature.

Aug 1, 2024
CVE-2024-5331
4.3 MEDIUM

The Breakdance plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 1.7.2. This makes it possible for …

Aug 1, 2024
CVE-2024-5330
6.4 MEDIUM

The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the breakdance_css_file_paths_cache parameter in all versions up to, and including, 1.7.2 due to …

Aug 1, 2024
CVE-2024-25947
4.8 MEDIUM

Dell iDRAC Service Module version 5.3.0.0 and prior, contain an Out of bound Read Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting …

Aug 1, 2024
CVE-2024-6496
6.5 MEDIUM

The Light Poll WordPress plugin through 1.0.0 does not have CSRF checks when deleting polls, which could allow attackers to make logged in users perform …

Aug 1, 2024
CVE-2024-4090
4.8 MEDIUM

The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.7.2 does not sanitise and escape some …

Aug 1, 2024
CVE-2024-2872
4.8 MEDIUM

The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to …

Aug 1, 2024
CVE-2024-2843
6.5 MEDIUM

The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin …

Aug 1, 2024
CVE-2024-1747
6.5 MEDIUM

The WooCommerce Customers Manager WordPress plugin before 30.2 does not have authorisation and CSRF in various AJAX actions, allowing any authenticated users, such as subscriber, …

Aug 1, 2024
CVE-2024-2090
6.4 MEDIUM

The Remote Content Shortcode plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.5 via the remote_content shortcode. …

Aug 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.