CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-35234
4.2 MEDIUM

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch, an attacker can execute …

Jul 3, 2024
CVE-2024-33871
8.8 HIGH

An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. …

Jul 3, 2024
CVE-2024-33870
6.3 MEDIUM

An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory …

Jul 3, 2024
CVE-2024-33869
5.3 MEDIUM

An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction …

Jul 3, 2024
CVE-2024-29511
7.5 HIGH

Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages …

Jul 3, 2024
CVE-2024-29510
6.3 MEDIUM

Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.

Jul 3, 2024
CVE-2024-29507
5.4 MEDIUM

Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.

Jul 3, 2024
CVE-2024-5887

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 3, 2024
CVE-2024-5821
6.2 MEDIUM

The vulnerability allows an attacker to access sensitive files on the server by confusing the agent with incorrect file names. When a user requests the …

Jul 3, 2024
CVE-2024-35227
7.5 HIGH

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch, Oneboxing against a carefully …

Jul 3, 2024
CVE-2024-31223
5.3 MEDIUM

Fides is an open-source privacy engineering platform, and `SERVER_SIDE_FIDES_API_URL` is a server-side configuration environment variable used by the Fides Privacy Center to communicate with the …

Jul 3, 2024
CVE-2024-29509
8.8 HIGH

Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the middle.

Jul 3, 2024
CVE-2024-29508
3.3 LOW

Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.

Jul 3, 2024
CVE-2024-29506
8.8 HIGH

Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name.

Jul 3, 2024
CVE-2023-52169
8.2 HIGH

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The …

Jul 3, 2024
CVE-2023-52168
8.4 HIGH

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite two bytes at multiple …

Jul 3, 2024
CVE-2024-3332
6.5 MEDIUM

A malicious BLE device can send a specific order of packet sequence to cause a DoS attack on the victim BLE device

Jul 3, 2024
CVE-2024-39844
9.8 CRITICAL

In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.

Jul 3, 2024
CVE-2024-39248
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in SimpCMS v0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title …

Jul 3, 2024
CVE-2024-6126
3.2 LOW

A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any process when enabling the pam_env's user_readenv option, which …

Jul 3, 2024
CVE-2024-6052
6.5 MEDIUM

Stored XSS in Checkmk before versions 2.3.0p8, 2.2.0p29, 2.1.0p45, and 2.0.0 (EOL) allows users to execute arbitrary scripts by injecting HTML elements

Jul 3, 2024
CVE-2024-39223
9.8 CRITICAL

An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the HostKeyCallback function to ssh.InsecureIgnoreHostKey

Jul 3, 2024
CVE-2024-39220
6.5 MEDIUM

BAS-IP AV-01D, AV-01MD, AV-01MFD, AV-01ED, AV-01KD, AV-01BD, AV-01KBD, AV-02D, AV-02IDE, AV-02IDR, AV-02IPD, AV-02FDE, AV-02FDR, AV-03D, AV-03BD, AV-04AFD, AV-04ASD, AV-04FD, AV-04SD, AV-05FD, AV-05SD, AA-07BD, AA-07BDI, BA-04BD, …

Jul 3, 2024
CVE-2024-6471
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Online Tours & Travels Management 1.0. This affects an unknown part of the file sms_setting.php. …

Jul 3, 2024
CVE-2024-37726
6.8 MEDIUM

Insecure Permissions vulnerability in Micro-Star International Co., Ltd MSI Center v.2.0.36.0 allows a local attacker to escalate privileges via the Export System Info function in …

Jul 3, 2024
CVE-2024-32937
8.1 HIGH

An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1.0.11.79. A specially crafted network packet can lead …

Jul 3, 2024
CVE-2024-6470
2.7 LOW

A vulnerability was found in playSMS 1.4.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /index.php?app=main&inc=feature_inboxgroup&op=list …

Jul 3, 2024
CVE-2024-5672
7.2 HIGH

A high privileged remote attacker can execute arbitrary system commands via GET requests due to improper neutralization of special elements used in an OS command.

Jul 3, 2024
CVE-2024-6427
7.5 HIGH

Uncontrolled Resource Consumption vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can use the "message" parameter to inject a payload with dangerous JavaScript code, …

Jul 3, 2024
CVE-2024-6426
8.1 HIGH

Information exposure vulnerability in MESbook 20221021.03 version, the exploitation of which could allow a local attacker, with user privileges, to access different resources by changing …

Jul 3, 2024
CVE-2024-6469
2.7 LOW

A vulnerability was found in playSMS 1.4.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php?app=main&inc=feature_firewall&op=firewall_list …

Jul 3, 2024
CVE-2024-6428
5.3 MEDIUM

Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when creating a new user which allows …

Jul 3, 2024
CVE-2024-39830
8.1 HIGH

Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled, fail to use constant time …

Jul 3, 2024
CVE-2024-39807
3.1 LOW

Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an attacker monitoring webhook events to …

Jul 3, 2024
CVE-2024-39361
3.1 LOW

Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a RemoteId for their posts which …

Jul 3, 2024
CVE-2024-39353
2.7 LOW

Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to sanitize the RemoteClusterFrame payloads before audit logging them which allows a high privileged attacker with access …

Jul 3, 2024
CVE-2024-36257
2.7 LOW

Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server A requesting …

Jul 3, 2024
CVE-2024-6340
6.4 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and …

Jul 3, 2024
CVE-2024-6263
6.4 MEDIUM

The WP Lightbox 2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 3.0.6.6 …

Jul 3, 2024
CVE-2024-4482
6.4 MEDIUM

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jul 3, 2024
CVE-2024-38453
7.5 HIGH

The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of …

Jul 3, 2024
CVE-2024-37082
9.1 CRITICAL

When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTP requests that bypass mTLS …

Jul 3, 2024
CVE-2024-2376
8.8 HIGH

The WPQA Builder WordPress plugin before 6.1.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

Jul 3, 2024
CVE-2024-2375
5.4 MEDIUM

The WPQA Builder WordPress plugin before 6.1.1 does not sanitise and escape some of its Slider settings, which could allow high privilege users such as …

Jul 3, 2024
CVE-2024-2235
4.3 MEDIUM

The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make users vote on any polls, …

Jul 3, 2024
CVE-2024-2234
5.4 MEDIUM

The Himer WordPress theme before 2.1.1 does not sanitise and escape some of its Post settings, which could allow high privilege users such as Contributor …

Jul 3, 2024
CVE-2024-2233
4.3 MEDIUM

The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted …

Jul 3, 2024
CVE-2024-2231
6.5 MEDIUM

The allows any authenticated user to join a private group due to a missing authorization check on a function

Jul 3, 2024
CVE-2024-2040
4.3 MEDIUM

The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make users join private groups via …

Jul 3, 2024
CVE-2024-4543
4.3 MEDIUM

The Snippet Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.1.4. This is due to missing …

Jul 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.