CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-2130
6.4 MEDIUM

The CWW Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Module2 widget in all versions up to, and including, 1.2.7 due …

Mar 12, 2024
CVE-2024-2031
6.4 MEDIUM

The Video Conferencing with Zoom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zoom_recordings_by_meeting' shortcode in all versions up to, and …

Mar 12, 2024
CVE-2024-28112
6.1 MEDIUM

Peering Manager is a BGP session management tool. Affected versions of Peering Manager are subject to a potential stored Cross-Site Scripting (XSS) attack in the …

Mar 12, 2024
CVE-2023-30968
6.8 MEDIUM

One of Gotham Gaia services was found to be vulnerable to a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker to bypass …

Mar 12, 2024
CVE-2024-28098
6.4 MEDIUM

The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, such as retention, TTL, and offloading settings. These management operations …

Mar 12, 2024
CVE-2024-1765
5.9 MEDIUM

Cloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server …

Mar 12, 2024
CVE-2024-1137
4.3 MEDIUM

The Proxy and Client components of TIBCO Software Inc.'s TIBCO ActiveSpaces - Enterprise Edition contain a vulnerability that theoretically allows an Active Spaces client to …

Mar 12, 2024
CVE-2024-2182
6.5 MEDIUM

A flaw was found in the Open Virtual Network (OVN). In OVN clusters where BFD is used between hypervisors for high availability, an attacker can …

Mar 12, 2024
CVE-2024-28339
5.4 MEDIUM

An information leak in the debuginfo.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without …

Mar 12, 2024
CVE-2024-26201
6.6 MEDIUM

Microsoft Intune Linux Agent Elevation of Privilege Vulnerability

Mar 12, 2024
CVE-2024-26197
6.5 MEDIUM

Windows Standards-Based Storage Management Service Denial of Service Vulnerability

Mar 12, 2024
CVE-2024-26185
6.5 MEDIUM

Windows Compressed Folder Tampering Vulnerability

Mar 12, 2024
CVE-2024-26181
5.5 MEDIUM

Windows Kernel Denial of Service Vulnerability

Mar 12, 2024
CVE-2024-26177
5.5 MEDIUM

Windows Kernel Information Disclosure Vulnerability

Mar 12, 2024
CVE-2024-26174
5.5 MEDIUM

Windows Kernel Information Disclosure Vulnerability

Mar 12, 2024
CVE-2024-26160
5.5 MEDIUM

Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability

Mar 12, 2024
CVE-2024-21448
5.0 MEDIUM

Microsoft Teams for Android Information Disclosure Vulnerability

Mar 12, 2024
CVE-2024-21430
5.7 MEDIUM

Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability

Mar 12, 2024
CVE-2024-21429
6.8 MEDIUM

Windows USB Hub Driver Remote Code Execution Vulnerability

Mar 12, 2024
CVE-2024-21408
5.5 MEDIUM

Windows Hyper-V Denial of Service Vulnerability

Mar 12, 2024
CVE-2024-20671
5.5 MEDIUM

Microsoft Defender Security Feature Bypass Vulnerability

Mar 12, 2024
CVE-2024-1304
6.3 MEDIUM

Cross-site scripting vulnerability in Badger Meter Monitool that affects versions up to 4.6.3 and earlier. This vulnerability allows a remote attacker to send a specially …

Mar 12, 2024
CVE-2024-1303
6.5 MEDIUM

Incorrectly limiting the path to a restricted directory vulnerability in Badger Meter Monitool that affects versions up to 4.6.3 and earlier. This vulnerability allows an …

Mar 12, 2024
CVE-2024-2394
4.7 MEDIUM

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Mar 12, 2024
CVE-2024-21761
4.3 MEDIUM

An improper authorization vulnerability [CWE-285] in FortiPortal version 7.2.0, and versions 7.0.6 and below reports may allow a user to download other organizations reports via …

Mar 12, 2024
CVE-2024-1227
6.5 MEDIUM

An open redirect vulnerability, the exploitation of which could allow an attacker to create a custom URL and redirect a legitimate page to a malicious …

Mar 12, 2024
CVE-2023-41842
6.7 MEDIUM

A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute unauthorized code or commands via specially crafted command …

Mar 12, 2024
CVE-2024-2393
6.3 MEDIUM

A vulnerability was found in SourceCodester CRUD without Page Reload 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Mar 12, 2024
CVE-2024-2049
6.5 MEDIUM

Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose limited information from the …

Mar 12, 2024
CVE-2024-21483
4.6 MEDIUM

A vulnerability has been identified in SENTRON 7KM PAC3120 AC/DC (7KM3120-0BA01-1DA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( …

Mar 12, 2024
CVE-2023-45793
5.5 MEDIUM

A vulnerability has been identified in Siveillance Control (All versions >= V2.8 < V3.1.1). The affected product does not properly check the list of access …

Mar 12, 2024
CVE-2023-4731
4.3 MEDIUM

The LadiApp plugn for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the init_endpoint() function hooked via 'init' in …

Mar 12, 2024
CVE-2023-4729
4.3 MEDIUM

The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the publish_lp() function hooked via an AJAX …

Mar 12, 2024
CVE-2023-4728
4.3 MEDIUM

The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the publish_lp() function hooked via an …

Mar 12, 2024
CVE-2023-4629
4.3 MEDIUM

The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the save_config() function in versions up to, …

Mar 12, 2024
CVE-2023-4628
4.3 MEDIUM

The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the ladiflow_save_hook() function in versions up to, …

Mar 12, 2024
CVE-2023-4627
4.3 MEDIUM

The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_config() function in versions up …

Mar 12, 2024
CVE-2023-4626
4.3 MEDIUM

The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ladiflow_save_hook() function in versions up …

Mar 12, 2024
CVE-2024-2371
6.2 MEDIUM

Information exposure vulnerability in Korenix JetI/O 6550 affecting firmware version F208 Build:0817. The SNMP protocol uses plaintext to transfer data, allowing an attacker to intercept …

Mar 12, 2024
CVE-2024-27279
6.5 MEDIUM

Directory traversal vulnerability exists in a-blog cms Ver.3.1.x series Ver.3.1.9 and earlier, Ver.3.0.x series Ver.3.0.30 and earlier, Ver.2.11.x series Ver.2.11.59 and earlier, Ver.2.10.x series Ver.2.10.51 …

Mar 12, 2024
CVE-2024-26005
4.8 MEDIUM

An unauthenticated remote attacker can gain service level privileges through an incomplete cleanup during service restart after a DoS.

Mar 12, 2024
CVE-2024-26000
5.9 MEDIUM

An unauthenticated remote attacker can read memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not …

Mar 12, 2024
CVE-2024-25997
5.3 MEDIUM

An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file is affected.

Mar 12, 2024
CVE-2024-25996
5.3 MEDIUM

An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is limited to the service user.

Mar 12, 2024
CVE-2024-25994
5.3 MEDIUM

An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload destination is fixed and is write only.

Mar 12, 2024
CVE-2024-1328
6.4 MEDIUM

The Newsletter2Go plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ parameter in all versions up to, and including, 4.0.14 due to …

Mar 12, 2024
CVE-2024-0906
5.3 MEDIUM

The f(x) Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.1 via the API. This …

Mar 12, 2024
CVE-2024-24964
6.3 MEDIUM

Improper access control vulnerability exists in the resident process of SKYSEA Client View versions from Ver.11.220 prior to Ver.19.2. If this vulnerability is exploited, an …

Mar 12, 2024
CVE-2024-21584
6.1 MEDIUM

Pleasanter 1.3.49.0 and earlier contains a cross-site scripting vulnerability. If an attacker tricks the user to access the product with a specially crafted URL and …

Mar 12, 2024
CVE-2023-49453
6.1 MEDIUM

Reflected cross-site scripting (XSS) vulnerability in Racktables v0.22.0 and before, allows local attackers to execute arbitrary code and obtain sensitive information via the search component …

Mar 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.