CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-50304
7.1 HIGH

IBM Engineering Requirements Management DOORS Web Access 9.7.2.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker …

Jul 18, 2024
CVE-2024-34013
7.8 HIGH

Local privilege escalation due to OS command injection vulnerability. The following products are affected: Acronis True Image (macOS) before build 41396, Acronis True Image OEM …

Jul 18, 2024
CVE-2024-31143
7.5 HIGH

An optional feature of PCI MSI called "Multiple Message" allows a device to use multiple consecutive interrupt vectors. Unlike for MSI-X, the setting up of …

Jul 18, 2024
CVE-2024-29178
8.8 HIGH

On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker …

Jul 18, 2024
CVE-2024-6504
4.3 MEDIUM

Rapid7 InsightVM Console versions below 6.6.260 suffer from a protection mechanism failure whereby an attacker with network access to the InsightVM Console can cause it …

Jul 18, 2024
CVE-2024-40898
7.5 HIGH

SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and …

Jul 18, 2024
CVE-2024-40725
5.3 MEDIUM

A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" …

Jul 18, 2024
CVE-2024-5555
6.4 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jul 18, 2024
CVE-2024-5554
6.4 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jul 18, 2024
CVE-2024-3242
8.8 HIGH

The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension validation in the validateImageContent function called …

Jul 18, 2024
CVE-2024-40764
7.5 HIGH

Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Denial of Service (DoS).

Jul 18, 2024
CVE-2024-29014
8.8 HIGH

Vulnerability in SonicWall SMA100 NetExtender Windows (32 and 64-bit) client 10.2.339 and earlier versions allows an attacker to arbitrary code execution when processing an EPC …

Jul 18, 2024
CVE-2024-41011
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: don't allow mapping the MMIO HDP page with large pages We don't get the …

Jul 18, 2024
CVE-2024-6164
9.8 CRITICAL

The Filter & Grids WordPress plugin before 2.8.33 is vulnerable to Local File Inclusion via the post_layout parameter. This makes it possible for an unauthenticated …

Jul 18, 2024
CVE-2023-6708
5.4 MEDIUM

The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG upload feature in all versions up to, and including, 2.5.7 …

Jul 18, 2024
CVE-2024-6705
5.5 MEDIUM

The RegLevel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.1 due to insufficient …

Jul 18, 2024
CVE-2024-6599
4.3 MEDIUM

The Meks Video Importer plugin for WordPress is vulnerable to unauthorized API key modification due to a missing capability check on the ajax_save_settings function in …

Jul 18, 2024
CVE-2024-6175
5.4 MEDIUM

The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Jul 18, 2024
CVE-2024-5964
6.4 MEDIUM

The Zenon Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up …

Jul 18, 2024
CVE-2024-5726
8.8 HIGH

The Timeline Event History plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1 via deserialization of untrusted …

Jul 18, 2024
CVE-2024-41184
9.8 CRITICAL

In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: this CVE Record might not be worthwhile because an empty …

Jul 18, 2024
CVE-2024-39682
6.4 MEDIUM

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.7.15.4 due …

Jul 18, 2024
CVE-2024-39681
5.4 MEDIUM

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, …

Jul 18, 2024
CVE-2024-39680
5.4 MEDIUM

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, …

Jul 18, 2024
CVE-2024-39679
4.3 MEDIUM

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, …

Jul 18, 2024
CVE-2024-39678
4.3 MEDIUM

Cooked is a recipe plugin for WordPress. The Cooked plugin is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due …

Jul 18, 2024
CVE-2024-40492
7.1 HIGH

Cross Site Scripting vulnerability in Heartbeat Chat v.15.2.1 allows a remote attacker to execute arbitrary code via the setname function.

Jul 17, 2024
CVE-2023-43971
6.1 MEDIUM

Cross Site Scripting vulnerability in ACG-faka v1.1.7 allows a remote attacker to execute arbitrary code via the encode parameter in Index.php.

Jul 17, 2024
CVE-2024-40402
6.3 MEDIUM

A SQL injection vulnerability was found in 'ajax.php' of Sourcecodester Simple Library Management System 1.0. This vulnerability stems from insufficient user input validation of the …

Jul 17, 2024
CVE-2024-40119
8.8 HIGH

Nepstech Wifi Router xpon (terminal) model NTPL-Xpon1GFEVN v.1.0 Firmware V2.0.1 contains a Cross-Site Request Forgery (CSRF) vulnerability in the password change function, which allows remote …

Jul 17, 2024
CVE-2024-39126
5.4 MEDIUM

Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents.

Jul 17, 2024
CVE-2024-39125
5.4 MEDIUM

Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header.

Jul 17, 2024
CVE-2024-39124
5.4 MEDIUM

In Roundup before 2.4.0, classhelpers (_generic.help.html) allow XSS.

Jul 17, 2024
CVE-2024-32981
5.4 MEDIUM

Silverstripe framework is the PHP framework forming the base for the Silverstripe CMS. In affected versions a bad actor with access to edit content in …

Jul 17, 2024
CVE-2024-29885
4.3 MEDIUM

silverstripe/reports is an API for creating backend reports in the Silverstripe Framework. In affected versions reports can be accessed by their direct URL by any …

Jul 17, 2024
CVE-2024-40420

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2024-36694. Reason: This record is a duplicate of CVE-2024-36694. Notes: All CVE users should reference CVE-2024-36694 …

Jul 17, 2024
CVE-2024-28796
6.4 MEDIUM

IBM ClearQuest (CQ) 9.1 through 9.1.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

Jul 17, 2024
CVE-2024-40641
7.4 HIGH

Nuclei is a fast and customizable vulnerability scanner based on simple YAML based DSL. In affected versions it a way to execute code template without …

Jul 17, 2024
CVE-2024-40640
2.9 LOW

vodozemac is an open source implementation of Olm and Megolm in pure Rust. Versions before 0.7.0 of vodozemac use a non-constant time base64 implementation for …

Jul 17, 2024
CVE-2024-40639

Rejected reason: This CVE is a duplicate of another CVE.

Jul 17, 2024
CVE-2024-40636
5.3 MEDIUM

Steeltoe is an open source project that provides a collection of libraries that helps users build production-grade cloud-native applications using externalized configuration, service discovery, distributed …

Jul 17, 2024
CVE-2024-40633
5.3 MEDIUM

Sylius is an Open Source eCommerce Framework on Symfony. A security vulnerability was discovered in the `/api/v2/shop/adjustments/{id}` endpoint, which retrieves order adjustments based on incremental …

Jul 17, 2024
CVE-2024-38447
8.1 HIGH

NATO NCI ANET 3.4.1 allows Insecure Direct Object Reference via a modified ID field in a request for a private draft report (that belongs to …

Jul 17, 2024
CVE-2023-42010
3.1 LOW

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 could disclose sensitive information in the HTTP response using man in the …

Jul 17, 2024
CVE-2024-38870
3.5 LOW

Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and OpManager Enterprise Edition versions before 128104, from 128151 before 128238, from 128247 before 128250 are vulnerable to …

Jul 17, 2024
CVE-2024-38446
6.5 MEDIUM

NATO NCI ANET 3.4.1 mishandles report ownership. A user can create a report and, despite the restrictions imposed by the UI, change the author of …

Jul 17, 2024
CVE-2024-20435
8.8 HIGH

A vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, local attacker to execute arbitrary commands and elevate privileges …

Jul 17, 2024
CVE-2024-20429
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco AsyncOS for Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary system commands …

Jul 17, 2024
CVE-2024-20419
10.0 CRITICAL

A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of …

Jul 17, 2024
CVE-2024-20416
6.5 MEDIUM

A vulnerability in the upload module of Cisco RV340 and RV345 Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to execute arbitrary …

Jul 17, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.