CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-34421
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsurface BlogLentor allows Stored XSS.This issue affects BlogLentor: from n/a through 1.0.8.

May 14, 2024
CVE-2024-34420
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in talspotim Comments Evolved for WordPress allows Stored XSS.This issue affects Comments Evolved for …

May 14, 2024
CVE-2024-34419
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nathan Vonnahme Configure Login Timeout allows Stored XSS.This issue affects Configure Login Timeout: …

May 14, 2024
CVE-2024-34418
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tech9logy Creators WPCS ( WordPress Custom Search ) allows Stored XSS.This issue affects …

May 14, 2024
CVE-2024-34417
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Toidicode.Com (thanhtaivtt) Viet Nam Affiliate allows Stored XSS.This issue affects Viet Nam Affiliate: …

May 14, 2024
CVE-2024-34415
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress Thim Elementor Kit allows Stored XSS.This issue affects Thim Elementor Kit: from …

May 14, 2024
CVE-2024-34354
6.5 MEDIUM

CMSaaSStarter is a SaaS template/boilerplate built with SvelteKit, Tailwind, and Supabase. Any forks of the CMSaaSStarter template before commit 7904d416d2c72ec75f42fbf51e9e64fa74062ee6 are impacted. The issue is …

May 14, 2024
CVE-2024-34353
5.5 MEDIUM

The matrix-sdk-crypto crate, part of the Matrix Rust SDK project, is an implementation of a Matrix end-to-end encryption state machine in Rust. In Matrix, the …

May 14, 2024
CVE-2024-34352
6.5 MEDIUM

1Panel is an open source Linux server operation and maintenance management panel. Prior to v1.10.3-lts, there are many command injections in the project, and some …

May 14, 2024
CVE-2024-34349
4.8 MEDIUM

Sylius is an open source eCommerce platform. Prior to 1.12.16 and 1.13.1, there is a possibility to execute javascript code in the Admin panel. In …

May 14, 2024
CVE-2024-34245
6.5 MEDIUM

An arbitrary file read vulnerability in DedeCMS v5.7.114 allows authenticated attackers to read arbitrary files by specifying any path in makehtml_js_action.php.

May 14, 2024
CVE-2024-34230
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected …

May 14, 2024
CVE-2024-34225
6.1 MEDIUM

Cross Site Scripting vulnerability in php-lms/admin/?page=system_info in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or …

May 14, 2024
CVE-2024-34223
4.3 MEDIUM

Insecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource Management System 1.0 allow attackers to approve or reject leave ticket.

May 14, 2024
CVE-2024-34222
5.9 MEDIUM

Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter.

May 14, 2024
CVE-2024-34206
6.5 MEDIUM

TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter.

May 14, 2024
CVE-2024-34202
6.5 MEDIUM

TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setMacFilterRules function.

May 14, 2024
CVE-2024-34081
6.6 MEDIUM

MantisBT (Mantis Bug Tracker) is an open source issue tracker. Improper escaping of a custom field's name allows an attacker to inject HTML and, if …

May 14, 2024
CVE-2024-34080
5.3 MEDIUM

MantisBT (Mantis Bug Tracker) is an open source issue tracker. If an issue references a note that belongs to another issue that the user doesn't …

May 14, 2024
CVE-2024-34074
6.1 MEDIUM

Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument and it allowed redirect to untrusted external …

May 14, 2024
CVE-2024-33956
4.3 MEDIUM

Missing Authorization vulnerability in ThemeLocation Custom WooCommerce Checkout Fields Editor.This issue affects Custom WooCommerce Checkout Fields Editor: from n/a through 1.3.0.

May 14, 2024
CVE-2024-33955
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme Freesia Freesia Empire allows Stored XSS.This issue affects Freesia Empire: from n/a …

May 14, 2024
CVE-2024-33954
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atanas Yonkov Pliska allows Stored XSS.This issue affects Pliska: from n/a through 0.3.5.

May 14, 2024
CVE-2024-33953
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt van Andel Adventure Journal allows Stored XSS.This issue affects Adventure Journal: from …

May 14, 2024
CVE-2024-33952
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Tadlock Unique allows Stored XSS.This issue affects Unique: from n/a through 0.3.0.

May 14, 2024
CVE-2024-33951
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adam DeHaven Perfect Pullquotes allows Stored XSS.This issue affects Perfect Pullquotes: from n/a …

May 14, 2024
CVE-2024-33950
5.9 MEDIUM

Administrator Cross Site Scripting (XSS) in Archives Calendar Widget <= 1.0.15 versions.

May 14, 2024
CVE-2024-33942
4.3 MEDIUM

Missing Authorization vulnerability in Eric Alli Google Typography.This issue affects Google Typography: from n/a through 1.1.2.

May 14, 2024
CVE-2024-33938
6.5 MEDIUM

Missing Authorization vulnerability in codename065 Sliding Widgets allows Cross-Site Scripting (XSS).This issue affects Sliding Widgets: from n/a through 1.5.0.

May 14, 2024
CVE-2024-33876
5.7 MEDIUM

HDF5 Library through 1.14.3 has a heap buffer overflow in H5S__point_deserialize in H5Spoint.c.

May 14, 2024
CVE-2024-33875
5.7 MEDIUM

HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5O__layout_encode in H5Olayout.c, resulting in the corruption of the instruction pointer.

May 14, 2024
CVE-2024-33819
4.6 MEDIUM

Globitel KSA SpeechLog v8.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Save Query function.

May 14, 2024
CVE-2024-33774
6.5 MEDIUM

A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanSetup_Wizard allows remote authenticated users to trigger a denial of service (DoS) through …

May 14, 2024
CVE-2024-33773
6.5 MEDIUM

A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanGuestSetup allows remote authenticated users to trigger a denial of service (DoS) through …

May 14, 2024
CVE-2024-33772
5.7 MEDIUM

A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formTcpipSetup allows remote authenticated users to trigger a denial of service (DoS) through …

May 14, 2024
CVE-2024-33771
6.5 MEDIUM

A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via goform/formWPS, allows remote authenticated users to trigger a denial of service (DoS) through …

May 14, 2024
CVE-2024-33454
6.5 MEDIUM

Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the Bluetooth stack component.

May 14, 2024
CVE-2024-33433
4.8 MEDIUM

Cross Site Scripting vulnerability in TOTOLINK X2000R before v1.0.0-B20231213.1013 allows a remote attacker to execute arbitrary code via the Guest Access Control parameter in the …

May 14, 2024
CVE-2024-33263
4.0 MEDIUM

QuickJS commit 3b45d15 was discovered to contain an Assertion Failure via JS_FreeRuntime(JSRuntime *) at quickjs.c.

May 14, 2024
CVE-2024-32999
6.8 MEDIUM

Cracking vulnerability in the OS security module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32998
5.9 MEDIUM

NULL pointer access vulnerability in the clock module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32996
6.2 MEDIUM

Privilege escalation vulnerability in the account module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32995
6.2 MEDIUM

Denial of service (DoS) vulnerability in the AMS module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32993
5.6 MEDIUM

Out-of-bounds access vulnerability in the memory module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32990
6.1 MEDIUM

Permission verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32985
5.9 MEDIUM

Stellar-core is a reference implementation for the peer-to-peer agent that manages the Stellar network. Prior to 20.4.0, core nodes could be randomly crashed due to …

May 14, 2024
CVE-2024-32874
6.8 MEDIUM

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Below 0.13.2 Release, when uploading a file or retrieving the …

May 14, 2024
CVE-2024-32776
6.5 MEDIUM

Missing Authorization vulnerability in AppPresser Team AppPresser.This issue affects AppPresser: from n/a through 4.3.0.

May 14, 2024
CVE-2024-32730
6.5 MEDIUM

SAP Enable Now Manager does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker with …

May 14, 2024
CVE-2024-32719
5.3 MEDIUM

Missing Authorization vulnerability in WP Club Manager WP Club Manager wp-club-manager.This issue affects WP Club Manager: from n/a through <= 2.2.11.

May 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.