CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-22443
7.2 HIGH

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful …

Jul 24, 2024
CVE-2024-7067
6.3 MEDIUM

A vulnerability was found in kirilkirkov Ecommerce-Laravel-Bootstrap up to 1f1097a3448ce8ec53e034ea0f70b8e2a0e64a87. It has been rated as critical. Affected by this issue is the function getCartProductsIds of …

Jul 24, 2024
CVE-2024-6327
9.9 CRITICAL

In Progress® Telerik® Report Server versions prior to 2024 Q2 (10.1.24.709), a remote code execution attack is possible through an insecure deserialization vulnerability.

Jul 24, 2024
CVE-2024-6096
8.8 HIGH

In Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an insecure type resolution vulnerability.

Jul 24, 2024
CVE-2023-45249
9.8 CRITICAL KEV

Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) …

Jul 24, 2024
CVE-2024-5818
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored DOM-based Cross-Site Scripting via the plugin's Magazine Grid/Slider widget in all versions …

Jul 24, 2024
CVE-2024-3896
6.4 MEDIUM

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the Gallery title field in …

Jul 24, 2024
CVE-2024-7066
7.3 HIGH

A vulnerability was found in F-logic DataCube3 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file …

Jul 24, 2024
CVE-2024-6896
6.4 MEDIUM

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up …

Jul 24, 2024
CVE-2024-7065
4.3 MEDIUM

A vulnerability was found in Spina CMS up to 2.18.0. It has been classified as problematic. Affected is an unknown function of the file /admin/pages/. …

Jul 24, 2024
CVE-2024-6930
6.4 MEDIUM

The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute within the plugin's bookingform shortcode in all versions …

Jul 24, 2024
CVE-2024-6874
4.3 MEDIUM

libcurl's URL API function [curl_url_get()](https://curl.se/libcurl/c/curl_url_get.html) offers punycode conversions, to and from IDN. Asking to convert a name that is exactly 256 bytes, libcurl ends up …

Jul 24, 2024
CVE-2024-6197
7.5 HIGH

libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing …

Jul 24, 2024
CVE-2024-3454
3.5 LOW

An implementation issue in the Connectivity Standards Alliance Matter 1.2 protocol as used in the connectedhomeip SDK allows a third party to disclose information about …

Jul 24, 2024
CVE-2024-3297
6.5 MEDIUM

An issue in the Certificate Authenticated Session Establishment (CASE) protocol for establishing secure sessions between two devices, as implemented in the Matter protocol versions before …

Jul 24, 2024
CVE-2024-39676
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot. This issue affects Apache Pinot: from 0.1 before 1.0.0. Users are recommended to …

Jul 24, 2024
CVE-2023-48362
8.8 HIGH

XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system …

Jul 24, 2024
CVE-2023-32471
6.0 MEDIUM

Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds read vulnerability. A local authenticated malicious user with high privileges could potentially exploit this …

Jul 24, 2024
CVE-2024-6629
6.4 MEDIUM

The All-in-One Video Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video shortcode in all versions up to, and including, …

Jul 24, 2024
CVE-2024-6571
5.3 MEDIUM

The Optimize Images ALT Text (alt tag) & names for SEO using AI plugin for WordPress is vulnerable to Full Path Disclosure in all versions …

Jul 24, 2024
CVE-2024-6553
5.3 MEDIUM

The WP Meteor Website Speed Optimization Addon plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.3.This is …

Jul 24, 2024
CVE-2023-32466
5.7 MEDIUM

Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this …

Jul 24, 2024
CVE-2024-6836
4.3 MEDIUM

The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells plugin for WordPress is …

Jul 24, 2024
CVE-2024-6094
4.8 MEDIUM

The WP ULike WordPress plugin before 4.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jul 24, 2024
CVE-2024-40767
6.5 MEDIUM

In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image …

Jul 24, 2024
CVE-2024-5861
5.3 MEDIUM

The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the wpep_square_disconnect() …

Jul 24, 2024
CVE-2024-3246
6.1 MEDIUM

The LiteSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.0.1. This is due to missing …

Jul 24, 2024
CVE-2024-7027
7.3 HIGH

The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 4.9.3. This is due to insufficient …

Jul 24, 2024
CVE-2024-6756
8.8 HIGH

The Social Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpw_auto_poster_get_image_path' function in all …

Jul 24, 2024
CVE-2024-6755
6.5 MEDIUM

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the ‘wpw_auto_poster_quick_delete_multiple’ …

Jul 24, 2024
CVE-2024-6754
5.4 MEDIUM

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the ‘wpw_auto_poster_update_tweet_template’ function in all …

Jul 24, 2024
CVE-2024-6753
7.2 HIGH

The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mapTypes’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions …

Jul 24, 2024
CVE-2024-6752
6.4 MEDIUM

The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_name’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions …

Jul 24, 2024
CVE-2024-6751
6.3 MEDIUM

The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.3.14. This is due to missing …

Jul 24, 2024
CVE-2024-6750
7.3 HIGH

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple …

Jul 24, 2024
CVE-2024-41656
7.1 HIGH

Sentry is an error tracking and performance monitoring platform. Starting in version 10.0.0 and prior to version 24.7.1, an unsanitized payload sent by an Integration …

Jul 23, 2024
CVE-2024-38176
8.1 HIGH

An improper restriction of excessive authentication attempts in GroupMe allows a unauthenticated attacker to elevate privileges over a network.

Jul 23, 2024
CVE-2024-38164
9.6 CRITICAL

An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on …

Jul 23, 2024
CVE-2024-0981
7.1 HIGH

Okta Browser Plugin versions 6.5.0 through 6.31.0 (Chrome/Edge/Firefox/Safari) are vulnerable to cross-site scripting. This issue occurs when the plugin prompts the user to save these …

Jul 23, 2024
CVE-2024-41668
8.3 HIGH

The cBioPortal for Cancer Genomics provides visualization, analysis, and download of large-scale cancer genomics data sets. When running a publicly exposed proxy endpoint without authentication, …

Jul 23, 2024
CVE-2024-41665
5.5 MEDIUM

Ampache, a web based audio/video streaming application and file manager, has a stored cross-site scripting (XSS) vulnerability in versions prior to 6.6.0. This vulnerability exists …

Jul 23, 2024
CVE-2020-11640
8.8 HIGH

AdvaBuild uses a command queue to launch certain operations. An attacker who gains access to the command queue can use it to launch an attack …

Jul 23, 2024
CVE-2020-11639
7.8 HIGH

An attacker could exploit the vulnerability by injecting garbage data or specially crafted data. Depending on the data injected each process might be affected differently. …

Jul 23, 2024
CVE-2024-41664
5.4 MEDIUM

Canarytokens help track activity and actions on a network. Prior to `sha-8ea5315`, Canarytokens.org was vulnerable to a blind SSRF in the Webhook alert feature. When …

Jul 23, 2024
CVE-2024-41178
7.5 HIGH

Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and earlier on all platforms using AWS WebIdentityTokens. On …

Jul 23, 2024
CVE-2024-6714
8.8 HIGH

An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege.

Jul 23, 2024
CVE-2024-41663
3.5 LOW

Canarytokens help track activity and actions on a network. A Cross-Site Scripting vulnerability was identified in the "Cloned Website" Canarytoken, whereby the Canarytoken's creator can …

Jul 23, 2024
CVE-2024-39702
5.9 MEDIUM

In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the string hashing function (used during string interning) allows HashDoS (Hash Denial of Service) attacks. An attacker could …

Jul 23, 2024
CVE-2024-6783
4.8 MEDIUM

A vulnerability has been discovered in Vue, that allows an attacker to perform XSS via prototype pollution. The attacker could change the prototype chain of …

Jul 23, 2024
CVE-2024-4076
7.5 HIGH

Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result in an assertion failure. This issue …

Jul 23, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.