CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23559
6.1 MEDIUM

HCL DevOps Deploy / Launch is generating an obsolete HTTP header.

Apr 15, 2024
CVE-2023-45808
4.1 MEDIUM

iTop is an IT service management platform. When creating or updating an object, extkey values aren't checked to be in the current user silo. In …

Apr 15, 2024
CVE-2023-44396
6.8 MEDIUM

iTop is an IT service management platform. Dashlet edits ajax endpoints can be used to produce XSS. Fixed in iTop 2.7.10, 3.0.4, and 3.1.1.

Apr 15, 2024
CVE-2023-43790
5.7 MEDIUM

iTop is an IT service management platform. By manipulating HTTP queries, a user can inject malicious content in the fields used for the object friendlyname …

Apr 15, 2024
CVE-2023-38511
5.0 MEDIUM

iTop is an IT service management platform. Dashboard editor : can load multiple files and URL, and full path disclosure on dashboard config file. This …

Apr 15, 2024
CVE-2024-3797
6.3 MEDIUM

A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Apr 15, 2024
CVE-2024-3786
6.6 MEDIUM

Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Device Synchronizations (/admin/DeviceReplication). Exploitation of this vulnerability could allow a remote user …

Apr 15, 2024
CVE-2024-3785
6.6 MEDIUM

Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Device NAS shared section (/admin/DeviceNAS). Exploitation of this vulnerability could allow a …

Apr 15, 2024
CVE-2024-3784
6.6 MEDIUM

Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 Accounts (/admin/CloudAccounts). Exploitation of this vulnerability could allow a remote user …

Apr 15, 2024
CVE-2024-24898
6.0 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Leak Exposure. This vulnerability is associated with program files …

Apr 15, 2024
CVE-2024-24891
6.0 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Leak Exposure. This vulnerability is associated with program files …

Apr 15, 2024
CVE-2024-32129
4.7 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Freshworks Freshdesk (official).This issue affects Freshdesk (official): from n/a through 2.3.6.

Apr 15, 2024
CVE-2024-31421
4.3 MEDIUM

Missing Authorization vulnerability in supsystic Popup by Supsystic popup-by-supsystic.This issue affects Popup by Supsystic: from n/a through <= 1.10.27.

Apr 15, 2024
CVE-2024-31389
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Ertano MihanPanel.This issue affects MihanPanel: from n/a before 12.7.

Apr 15, 2024
CVE-2024-31388
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Pauple Table & Contact Form 7 Database – Tablesome.This issue affects Table & Contact Form 7 Database – Tablesome: …

Apr 15, 2024
CVE-2024-31385
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Reservation Diary ReDi Restaurant Reservation.This issue affects ReDi Restaurant Reservation: from n/a through 24.0128.

Apr 15, 2024
CVE-2024-31384
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Spa and Salon.This issue affects Spa and Salon: from n/a through 1.2.7.

Apr 15, 2024
CVE-2024-31383
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Pagelayer PopularFX.This issue affects PopularFX: from n/a through 1.2.4.

Apr 15, 2024
CVE-2024-31382
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in creativethemeshq Blocksy blocksy.This issue affects Blocksy: from n/a through <= 2.0.22.

Apr 15, 2024
CVE-2024-31381
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in RebelCode Spotlight Social Media Feeds.This issue affects Spotlight Social Media Feeds: from n/a through 1.6.10.

Apr 15, 2024
CVE-2024-31379
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Smash Balloon Social Post Feed.This issue affects Smash Balloon Social Post Feed: from n/a through 4.2.1.

Apr 15, 2024
CVE-2024-31378
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in MailMunch MailChimp Forms by MailMunch.This issue affects MailChimp Forms by MailMunch: from n/a through 3.2.1.

Apr 15, 2024
CVE-2024-31376
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Andrew Dashboard To-Do List dashboard-to-do-list.This issue affects Dashboard To-Do List: from n/a through <= 1.3.1.

Apr 15, 2024
CVE-2024-31374
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Scott Bolinger AppPresser apppresser allows Cross Site Request Forgery.This issue affects AppPresser: from n/a through <= 4.3.0.

Apr 15, 2024
CVE-2024-31373
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in E2Pdf e2pdf e2pdf.This issue affects e2pdf: from n/a through <= 1.20.27.

Apr 15, 2024
CVE-2024-30546
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Pixelite Login With Ajax.This issue affects Login With Ajax: from n/a through 4.1.

Apr 15, 2024
CVE-2024-30219
6.8 MEDIUM

Active debug code vulnerability exists in PLANEX COMMUNICATIONS wireless LAN routers. If a logged-in user who knows how to use the debug function accesses the …

Apr 15, 2024
CVE-2024-28957
5.3 MEDIUM

Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series. If this vulnerability is exploited, a remote unauthenticated attacker may interfere communications by …

Apr 15, 2024
CVE-2024-28894
5.3 MEDIUM

Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 headers exists in Cente middleware TCP/IP Network Series, which may allow …

Apr 15, 2024
CVE-2024-26023
4.2 MEDIUM

OS command injection vulnerability in BUFFALO wireless LAN routers allows a logged-in user to execute arbitrary OS commands.

Apr 15, 2024
CVE-2024-31940
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in RedNao Extra Product Options Builder for WooCommerce.This issue affects Extra Product Options Builder for WooCommerce: from n/a through 1.2.104.

Apr 15, 2024
CVE-2024-31938
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Themeinwp NewsXpress.This issue affects NewsXpress: from n/a through 1.0.7.

Apr 15, 2024
CVE-2024-31933
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.35.

Apr 15, 2024
CVE-2024-31923
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in PluginOps Feather Login Page.This issue affects Feather Login Page: from n/a through 1.1.5.

Apr 15, 2024
CVE-2024-31922
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Anton Aleksandrov WordPress Hosting Benchmark tool.This issue affects WordPress Hosting Benchmark tool: from n/a through 1.3.6.

Apr 15, 2024
CVE-2024-31921
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Etoile Web Design Ultimate Product Catalogue.This issue affects Ultimate Product Catalogue: from n/a through 5.2.15.

Apr 15, 2024
CVE-2024-31920
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Tyche Softwares Currency per Product for WooCommerce.This issue affects Currency per Product for WooCommerce: from n/a through 1.6.0.

Apr 15, 2024
CVE-2024-31434
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Stefano Lissa & The Newsletter Team Newsletter.This issue affects Newsletter: from n/a through 8.0.6.

Apr 15, 2024
CVE-2024-31433
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in StellarWP The Events Calendar the-events-calendar.This issue affects The Events Calendar: from n/a through <= 6.3.0.

Apr 15, 2024
CVE-2024-31432
5.3 MEDIUM

Missing Authorization vulnerability in StellarWP Restrict Content.This issue affects Restrict Content: from n/a through 3.2.8.

Apr 15, 2024
CVE-2024-31431
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Tyche Softwares Product Input Fields for WooCommerce.This issue affects Product Input Fields for WooCommerce: from n/a through 1.7.0.

Apr 15, 2024
CVE-2024-31429
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Blossom Themes Sarada Lite.This issue affects Sarada Lite: from n/a through 1.1.2.

Apr 15, 2024
CVE-2024-31428
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme The Conference.This issue affects The Conference: from n/a through 1.2.0.

Apr 15, 2024
CVE-2024-31427
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Marker.Io Marker.Io.This issue affects Marker.Io : from n/a through 1.1.8.

Apr 15, 2024
CVE-2024-31426
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Data443 Inline Related Posts.This issue affects Inline Related Posts: from n/a through 3.3.1.

Apr 15, 2024
CVE-2024-31425
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in TMS Amelia.This issue affects Amelia: from n/a through 1.0.95.

Apr 15, 2024
CVE-2024-31422
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Philippe Bernard Favicon.This issue affects Favicon: from n/a through 1.3.29.

Apr 15, 2024
CVE-2024-22439
6.9 MEDIUM

A potential security vulnerability has been identified in HPE FlexFabric and FlexNetwork series products. This vulnerability could be exploited to gain privileged access to switches …

Apr 15, 2024
CVE-2024-32437
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in impleCode eCommerce Product Catalog.This issue affects eCommerce Product Catalog: from n/a through 3.3.28.

Apr 15, 2024
CVE-2024-32436
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Codemenschen Gift Vouchers.This issue affects Gift Vouchers: from n/a through 4.4.0.

Apr 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.