CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5942
4.3 MEDIUM

The Page and Post Clone plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0 via the …

Jun 29, 2024
CVE-2024-5889
6.1 MEDIUM

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘country’ parameter in all versions …

Jun 29, 2024
CVE-2024-5598
7.5 HIGH

The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.4 via the 'fma_local_file_system' function. …

Jun 29, 2024
CVE-2024-5192
6.4 MEDIUM

The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells plugin for WordPress is …

Jun 29, 2024
CVE-2024-6405
6.1 MEDIUM

The Floating Social Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to …

Jun 29, 2024
CVE-2019-25211
9.1 CRITICAL

parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is …

Jun 29, 2024
CVE-2024-37371
9.1 CRITICAL

In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with …

Jun 28, 2024
CVE-2024-39828
6.1 MEDIUM

R74n Sandboxels 1.9 through 1.9.5 allows XSS via a message in a modified saved-game file. This was fixed in a hotfix to 1.9.5 on 2024-06-29.

Jun 28, 2024
CVE-2024-38533
6.5 MEDIUM

ZKsync Era is a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. There is possible invalid stack access due to the addresses used …

Jun 28, 2024
CVE-2024-38532
7.1 HIGH

The NXP Data Co-Processor (DCP) is a built-in hardware module for specific NXP SoCs¹ that implements a dedicated AES cryptographic engine for encryption/decryption operations. The …

Jun 28, 2024
CVE-2024-38525
7.5 HIGH

dd-trace-cpp is the Datadog distributed tracing for C++. When the library fails to extract trace context due to malformed unicode, it logs the list of …

Jun 28, 2024
CVE-2024-37370
7.5 HIGH

In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing …

Jun 28, 2024
CVE-2024-39307
3.5 LOW

Kavita is a cross platform reading server. Opening an ebook with malicious scripts inside leads to code execution inside the browsing context. Kavita doesn't sanitize …

Jun 28, 2024
CVE-2024-39302
3.7 LOW

BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker may be able to exploit the overly elevated file …

Jun 28, 2024
CVE-2024-38518
4.6 MEDIUM

BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker with a valid join link to a meeting can …

Jun 28, 2024
CVE-2024-29040
4.3 MEDIUM

This repository hosts source code implementing the Trusted Computing Group's (TCG) TPM2 Software Stack (TSS). The JSON Quote Info returned by Fapi_Quote has to be …

Jun 28, 2024
CVE-2024-5827
9.8 CRITICAL

Vanna v0.3.4 is vulnerable to SQL injection in its DuckDB integration exposed to its Flask Web APIs. Attackers can inject malicious SQL training data and …

Jun 28, 2024
CVE-2024-5712
8.1 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability was identified in the stitionai/devika application, affecting the latest version. This vulnerability allows attackers to perform unauthorized actions in …

Jun 28, 2024
CVE-2024-3995

In Helix ALM versions prior to 2024.2.0, a local command injection was identified. Reported by Bryan Riggins.

Jun 28, 2024
CVE-2024-38528
7.5 HIGH

nptd-rs is a tool for synchronizing your computer's clock, implementing the NTP and NTS protocols. There is a missing limit for accepted NTS-KE connections. This …

Jun 28, 2024
CVE-2024-5972

Rejected reason: CVE ID issued in error. This is not a valid vulnerability.

Jun 28, 2024
CVE-2024-38514
7.4 HIGH

NextChat is a cross-platform ChatGPT/Gemini UI. There is a Server-Side Request Forgery (SSRF) vulnerability due to a lack of validation of the `endpoint` GET parameter …

Jun 28, 2024
CVE-2024-38322
5.3 MEDIUM

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 agent username and password error response discrepancy exposes product to brute force enumeration. IBM X-Force ID: …

Jun 28, 2024
CVE-2024-35156
6.5 MEDIUM

IBM MQ 9.3 LTS and 9.3 CD could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in …

Jun 28, 2024
CVE-2024-35116
5.9 MEDIUM

IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, and 9.3 CD is vulnerable to a denial of service attack caused by an error …

Jun 28, 2024
CVE-2024-27629
7.8 HIGH

An issue in dc2niix before v.1.0.20240202 allows a local attacker to execute arbitrary code via the generated file name is not properly escaped and injected …

Jun 28, 2024
CVE-2024-27628
8.1 HIGH

Buffer Overflow vulnerability in DCMTK v.3.6.8 allows an attacker to execute arbitrary code via the EctEnhancedCT method component.

Jun 28, 2024
CVE-2024-25053
5.9 MEDIUM

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is vulnerable to improper certificate validation when using the IBM Planning Analytics Data …

Jun 28, 2024
CVE-2024-25041
5.4 MEDIUM

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is potentially vulnerable to cross site scripting (XSS). A remote attacker could execute …

Jun 28, 2024
CVE-2024-25031
6.5 MEDIUM

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 uses an inadequate account lockout setting that could allow an attacker on the network to brute …

Jun 28, 2024
CVE-2022-38383
4.0 MEDIUM

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Software Suite 1.10.12.0 through 1.10.21.0 allows web pages to be stored locally which …

Jun 28, 2024
CVE-2022-27540
7.8 HIGH

A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code …

Jun 28, 2024
CVE-2024-38374
7.5 HIGH

The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Before deserializing CycloneDX …

Jun 28, 2024
CVE-2024-38371
8.6 HIGH

authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when using the OAuth2 Device code flow. This could potentially …

Jun 28, 2024
CVE-2024-37905
8.8 HIGH

authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to gain admin user privileges. A successful exploit …

Jun 28, 2024
CVE-2024-35155
6.5 MEDIUM

IBM MQ Console 9.3 LTS and 9.3 CD could disclose could allow a remote attacker to obtain sensitive information when a detailed technical error message …

Jun 28, 2024
CVE-2024-31919
5.9 MEDIUM

IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD, in certain configurations, is vulnerable to a denial of service attack caused …

Jun 28, 2024
CVE-2024-31912
7.5 HIGH

IBM MQ 9.3 LTS and 9.3 CD could allow an authenticated user to escalate their privileges under certain configurations due to incorrect privilege assignment. IBM …

Jun 28, 2024
CVE-2024-6403
6.5 MEDIUM

A vulnerability, which was classified as critical, has been found in Tenda A301 15.13.08.12. Affected by this issue is the function formWifiBasicSet of the file …

Jun 28, 2024
CVE-2024-6402
6.5 MEDIUM

A vulnerability classified as critical was found in Tenda A301 15.13.08.12. Affected by this vulnerability is the function fromSetWirelessRepeat of the file /goform/SetOnlineDevName. The manipulation …

Jun 28, 2024
CVE-2024-38522
6.3 MEDIUM

Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. The CSP policy applied on the `tips.hushline.app` website and bundled by default in …

Jun 28, 2024
CVE-2024-38521
8.8 HIGH

Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. There is a stored XSS in the Inbox. The input is displayed using …

Jun 28, 2024
CVE-2024-35139
6.2 MEDIUM

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from the container due to incorrect default permissions. …

Jun 28, 2024
CVE-2024-35137
6.2 MEDIUM

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. …

Jun 28, 2024
CVE-2024-29039
9.0 CRITICAL

tpm2 is the source repository for the Trusted Platform Module (TPM2.0) tools. This vulnerability allows attackers to manipulate tpm2_checkquote outputs by altering the TPML_PCR_SELECTION in …

Jun 28, 2024
CVE-2024-38531
3.6 LOW

Nix is a package manager for Linux and other Unix systems that makes package management reliable and reproducible. A build process has access to and …

Jun 28, 2024
CVE-2024-29038
4.3 MEDIUM

tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by …

Jun 28, 2024
CVE-2024-3816
9.8 CRITICAL

Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to a blind SQL Injection executed using the search bar. Only a part of observed …

Jun 28, 2024
CVE-2024-3801
6.1 MEDIUM

Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in one of GET header parameters. Only a part …

Jun 28, 2024
CVE-2024-3800
6.1 MEDIUM

Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in requested file names. Only a part of observed …

Jun 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.