CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5172
4.8 MEDIUM

The Expert Invoice WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jun 18, 2024
CVE-2024-4094
5.4 MEDIUM

The Simple Share Buttons Adder WordPress plugin before 8.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jun 18, 2024
CVE-2024-3276
4.8 MEDIUM

The Lightbox & Modal Popup WordPress Plugin WordPress plugin before 2.7.28, foobox-image-lightbox-premium WordPress plugin before 2.7.28 does not sanitise and escape some of its settings, …

Jun 18, 2024
CVE-2024-34024
6.3 MEDIUM

Observable response discrepancy issue exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, an unauthenticated remote attacker may determine …

Jun 18, 2024
CVE-2024-33622
6.5 MEDIUM

Missing authentication for critical function vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, sensitive information may be …

Jun 18, 2024
CVE-2024-0066
5.3 MEDIUM

Johan Fagerström, member of the AXIS OS Bug Bounty Program, has found that a O3C feature may expose sensitive traffic between the client (Axis device) …

Jun 18, 2024
CVE-2024-5860
4.3 MEDIUM

The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the tc_dl_delete_tickets …

Jun 18, 2024
CVE-2024-5541
5.3 MEDIUM

The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ibtana_visual_editor_register_ajax_json_endpont' …

Jun 18, 2024
CVE-2024-4375
6.4 MEDIUM

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_layer' shortcode in all versions up …

Jun 18, 2024
CVE-2024-1634
6.5 MEDIUM

The Scheduling Plugin – Online Booking for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on …

Jun 18, 2024
CVE-2024-0845
6.4 MEDIUM

The PDF Viewer for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the render function in all versions up to, and including, …

Jun 18, 2024
CVE-2024-6083
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPVibe 11.0.46. Affected is an unknown function of the file /app/uploading/upload-mp3.php of the component Media …

Jun 18, 2024
CVE-2024-6067
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Music Class Enrollment System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jun 17, 2024
CVE-2024-6066
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. Affected is an unknown function of the file payment_report.php. …

Jun 17, 2024
CVE-2024-6064
5.3 MEDIUM

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been declared as problematic. This vulnerability affects the function xmt_node_end of the file src/scene_manager/loader_xmt.c of the …

Jun 17, 2024
CVE-2024-37828
4.8 MEDIUM

A stored cross-site scripting (XSS) in Vermeg Agile Reporter v23.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Jun 17, 2024
CVE-2024-37798
5.9 MEDIUM

Cross-site scripting (XSS) vulnerability in search-appointment.php in the Admin Panel in Phpgurukul Beauty Parlour Management System 1.0 allows remote attackers to inject arbitrary web script …

Jun 17, 2024
CVE-2024-37895
5.7 MEDIUM

Lobe Chat is an open-source LLMs/AI chat framework. In affected versions if an attacker can successfully authenticate through SSO/Access Code, they can obtain the real …

Jun 17, 2024
CVE-2024-37893
5.9 MEDIUM

Firefly III is a free and open source personal finance manager. In affected versions an MFA bypass in the Firefly III OAuth flow may allow …

Jun 17, 2024
CVE-2024-37891
4.4 MEDIUM

urllib3 is a user-friendly HTTP client library for Python. When using urllib3's proxy support with `ProxyManager`, the `Proxy-Authorization` header is only sent to the configured …

Jun 17, 2024
CVE-2024-37664
5.2 MEDIUM

Redmi router RB03 v1.0.57 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack …

Jun 17, 2024
CVE-2024-37663
4.1 MEDIUM

Redmi router RB03 v1.0.57 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic …

Jun 17, 2024
CVE-2024-37662
6.3 MEDIUM

TP-LINK TL-7DR5130 v1.0.23 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the …

Jun 17, 2024
CVE-2024-37661
6.3 MEDIUM

TP-LINK TL-7DR5130 v1.0.23 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic between …

Jun 17, 2024
CVE-2024-36527
6.5 MEDIUM

puppeteer-renderer v.3.2.0 and before is vulnerable to Directory Traversal. Attackers can exploit the URL parameter using the file protocol to read sensitive information from the …

Jun 17, 2024
CVE-2018-25103
5.3 MEDIUM

There exists use-after-free vulnerabilities in lighttpd <= 1.4.50 request parsing which might read from invalid pointers to memory used in the same request, not from …

Jun 17, 2024
CVE-2024-36578
5.9 MEDIUM

akbr update 1.0.0 is vulnerable to Prototype Pollution via update/index.js.

Jun 17, 2024
CVE-2024-36574
6.3 MEDIUM

A Prototype Pollution issue in flatten-json 1.0.1 allows an attacker to execute arbitrary code via module.exports.unflattenJSON (flatten-json/index.js:42)

Jun 17, 2024
CVE-2024-38470
6.1 MEDIUM

zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /own.php.

Jun 17, 2024
CVE-2024-38469
6.3 MEDIUM

zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /pay.php.

Jun 17, 2024
CVE-2024-37625
6.1 MEDIUM

zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /index.php.

Jun 17, 2024
CVE-2024-37624
6.1 MEDIUM

Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /chajian/inputChajian.php. component.

Jun 17, 2024
CVE-2024-37623
6.1 MEDIUM

Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /kaoqin/tpl_kaoqin_locationchange.html component.

Jun 17, 2024
CVE-2024-37622
6.1 MEDIUM

Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the num parameter at /flow/flow.php.

Jun 17, 2024
CVE-2024-37620
6.1 MEDIUM

PHPVOD v4.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /view/admin/view.php.

Jun 17, 2024
CVE-2024-37619
6.1 MEDIUM

StrongShop v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the spec_group_id parameter at /spec/index.blade.php.

Jun 17, 2024
CVE-2024-6055
4.7 MEDIUM

Improper removal of sensitive information in data source export feature in Devolutions Remote Desktop Manager 2024.1.32.0 and earlier on Windows allows an attacker that obtains …

Jun 17, 2024
CVE-2024-5741
6.5 MEDIUM

Stored XSS in inventory tree rendering in Checkmk before 2.3.0p7, 2.2.0p28, 2.1.0p45 and 2.0.0 (EOL)

Jun 17, 2024
CVE-2024-36289
5.3 MEDIUM

Reusing a nonce, key pair in encryption issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. If …

Jun 17, 2024
CVE-2024-36279
5.3 MEDIUM

Reliance on obfuscation or encryption of security-relevant inputs without integrity checking issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for …

Jun 17, 2024
CVE-2024-36277
5.3 MEDIUM

Improper verification of cryptographic signature issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. The affected app …

Jun 17, 2024
CVE-2024-4305
6.8 MEDIUM

The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.1.0 does not validate and escape some of its block options before outputting …

Jun 17, 2024
CVE-2024-3236
5.4 MEDIUM

The Popup Builder WordPress plugin before 1.1.33 does not sanitise and escape some of its Notification fields, which could allow users such as contributor and …

Jun 17, 2024
CVE-2024-6044
6.5 MEDIUM

Certain models of D-Link wireless routers have a path traversal vulnerability. Unauthenticated attackers on the same local area network can read arbitrary system files by …

Jun 17, 2024
CVE-2024-6041
6.3 MEDIUM

A vulnerability was found in itsourcecode Gym Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jun 16, 2024
CVE-2024-6039
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Feng Office 3.11.1.2. Affected is an unknown function of the component Workspaces. The manipulation of …

Jun 16, 2024
CVE-2023-27636
5.4 MEDIUM

Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.

Jun 16, 2024
CVE-2024-38465
5.3 MEDIUM

Shenzhen Guoxin Synthesis image system before 8.3.0 allows username enumeration because of the response discrepancy of incorrect versus error.

Jun 16, 2024
CVE-2024-38460
4.9 MEDIUM

In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL …

Jun 16, 2024
CVE-2024-38454
6.1 MEDIUM

ExpressionEngine before 7.4.11 allows XSS.

Jun 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.