CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6024
8.8 HIGH

The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when deleting groups or emails, which could allow attackers to make a …

Jul 12, 2024
CVE-2024-6023
8.8 HIGH

The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when adding emails, which could allow attackers to make a logged in …

Jul 12, 2024
CVE-2024-6022
8.8 HIGH

The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged …

Jul 12, 2024
CVE-2024-5811
5.4 MEDIUM

The Simple Video Directory WordPress plugin before 1.4.4 does not sanitise and escape some of its settings, which could allow contributors and higher to perform …

Jul 12, 2024
CVE-2024-5626
6.1 MEDIUM

The Inline Related Posts WordPress plugin before 3.7.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jul 12, 2024
CVE-2024-4753
4.8 MEDIUM

The WP Secure Maintenance WordPress plugin before 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jul 12, 2024
CVE-2024-3112
4.8 MEDIUM

The Quotes and Tips by BestWebSoft WordPress plugin before 1.45 does not properly validate image files uploaded, allowing high privilege users such as admin to …

Jul 12, 2024
CVE-2024-2696
4.8 MEDIUM

The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jul 12, 2024
CVE-2024-2640
5.4 MEDIUM

The Watu Quiz WordPress plugin before 3.4.1.2 does not sanitise and escape some of its settings, which could allow users such as authors (if they've …

Jul 12, 2024
CVE-2024-2430
5.4 MEDIUM

The Website Content in Page or Post WordPress plugin before 2024.04.09 does not validate and escape some of its shortcode attributes before outputting them back …

Jul 12, 2024
CVE-2024-0974
4.8 MEDIUM

The Social Media Widget WordPress plugin before 4.0.9 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jul 12, 2024
CVE-2024-6677
7.8 HIGH

Privilege escalation in uberAgent

Jul 12, 2024
CVE-2024-1375
4.3 MEDIUM

The Event post plugin for WordPress is vulnerable to unauthorized bulk metadata update due to a missing nonce check on the save_bulkdatas function in all …

Jul 12, 2024
CVE-2024-6396
9.8 CRITICAL

A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host server and exfiltrate arbitrary data. …

Jul 12, 2024
CVE-2024-6392
5.4 MEDIUM

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modification due to missing capability checks on the …

Jul 11, 2024
CVE-2024-6468
7.5 HIGH

Vault and Vault Enterprise did not properly handle requests originating from unauthorized IP addresses when the TCP listener option, proxy_protocol_behavior, was set to deny_unauthorized. When …

Jul 11, 2024
CVE-2024-36435
9.8 CRITICAL

An issue was discovered on Supermicro BMC firmware in select X11, X12, H12, B12, X13, H13, and B13 motherboards (and CMM6 modules). An unauthenticated user …

Jul 11, 2024
CVE-2022-29946
6.3 MEDIUM

NATS.io NATS Server before 2.8.2 and Streaming Server before 0.24.6 could allow a remote attacker to bypass security restrictions, caused by the failure to enforce …

Jul 11, 2024
CVE-2024-6531

Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such, the …

Jul 11, 2024
CVE-2024-6681
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in witmy my-springsecurity-plus up to 2024-07-04. Affected by this issue is some unknown functionality of …

Jul 11, 2024
CVE-2024-6485
6.4 MEDIUM

A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the …

Jul 11, 2024
CVE-2024-6484

Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such, the …

Jul 11, 2024
CVE-2024-39553
6.5 MEDIUM

An Exposure of Resource to Wrong Sphere vulnerability in the sampling service of Juniper Networks Junos OS Evolved allows an unauthenticated network-based attacker to send …

Jul 11, 2024
CVE-2024-39552
7.5 HIGH

An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows a network …

Jul 11, 2024
CVE-2024-39551
7.5 HIGH

An Uncontrolled Resource Consumption vulnerability in the H.323 ALG (Application Layer Gateway) of Juniper Networks Junos OS on SRX Series and MX Series with SPC3 …

Jul 11, 2024
CVE-2024-39550
6.5 MEDIUM

A Missing Release of Memory after Effective Lifetime vulnerability in the rtlogd process of Juniper Networks Junos OS on MX Series with SPC3 allows an …

Jul 11, 2024
CVE-2024-39549
7.5 HIGH

A Missing Release of Memory after Effective Lifetime vulnerability in the routing process daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows …

Jul 11, 2024
CVE-2024-39548
7.5 HIGH

An Uncontrolled Resource Consumption vulnerability in the aftmand process of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to consume memory resources, resulting …

Jul 11, 2024
CVE-2024-39546
7.3 HIGH

A Missing Authorization vulnerability in the Socket Intercept (SI) command file interface of Juniper Networks Junos OS Evolved allows an authenticated, low-privilege local attacker to …

Jul 11, 2024
CVE-2024-39545
7.5 HIGH

An Improper Check for Unusual or Exceptional Conditions vulnerability in the the IKE daemon (iked) of Juniper Networks Junos OS on SRX Series, MX Series …

Jul 11, 2024
CVE-2024-39543
6.5 MEDIUM

A Buffer Copy without Checking Size of Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS …

Jul 11, 2024
CVE-2024-39542
7.5 HIGH

An Improper Validation of Syntactic Correctness of Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series with MPC10/11 …

Jul 11, 2024
CVE-2024-39541
6.5 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, …

Jul 11, 2024
CVE-2024-39540
7.5 HIGH

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on SRX Series, and MX …

Jul 11, 2024
CVE-2024-39539
5.3 MEDIUM

A Missing Release of Memory after Effective Lifetime vulnerability in Juniper Networks Junos OS on MX Series allows an unauthenticated adjacent attacker to cause a …

Jul 11, 2024
CVE-2024-39538
6.5 MEDIUM

A Buffer Copy without Checking Size of Input vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved on ACX7000 Series allows …

Jul 11, 2024
CVE-2024-39537
6.5 MEDIUM

An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved on ACX 7000 Series allows an unauthenticated, network-based attacker …

Jul 11, 2024
CVE-2024-39536
5.3 MEDIUM

A Missing Release of Memory after Effective Lifetime vulnerability in the Periodic Packet Management Daemon (ppmd) of Juniper Networks Junos OS and Junos OS Evolved …

Jul 11, 2024
CVE-2024-39535
6.5 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX 7000 Series …

Jul 11, 2024
CVE-2024-39533
5.8 MEDIUM

An Unimplemented or Unsupported Feature in the UI vulnerability in Juniper Networks Junos OS on QFX5000 Series and EX4600 Series allows an unauthenticated, network-based attacker …

Jul 11, 2024
CVE-2024-39532
6.3 MEDIUM

An Insertion of Sensitive Information into Log File vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high …

Jul 11, 2024
CVE-2024-39531
7.5 HIGH

An Improper Handling of Values vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX 7000 Series allows a network-based, …

Jul 11, 2024
CVE-2024-6680
6.3 MEDIUM

A vulnerability classified as critical was found in witmy my-springsecurity-plus up to 2024-07-04. Affected by this vulnerability is an unknown functionality of the file /api/dept/build. …

Jul 11, 2024
CVE-2024-39905
5.3 MEDIUM

Red is a fully modular Discord bot. Due to a bug in Red's Core API, 3rd-party cogs using the `@commands.can_manage_channel()` command permission check without additional …

Jul 11, 2024
CVE-2024-39904
8.8 HIGH

VNote is a note-taking platform. Prior to 3.18.1, a code execution vulnerability existed in VNote, which allowed an attacker to execute arbitrary programs on the …

Jul 11, 2024
CVE-2024-39530
7.5 HIGH

An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis management daemon (chassisd) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker …

Jul 11, 2024
CVE-2024-39529
7.5 HIGH

A Use of Externally-Controlled Format String vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based …

Jul 11, 2024
CVE-2024-39528
5.7 MEDIUM

A Use After Free vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated, network-based attacker …

Jul 11, 2024
CVE-2024-39524
7.8 HIGH

An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their …

Jul 11, 2024
CVE-2024-39523
7.8 HIGH

An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their …

Jul 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.