CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-39704
9.8 CRITICAL

Soft Circle French-Bread Melty Blood: Actress Again: Current Code through 1.07 Rev. 1.4.0 allows a remote attacker to execute arbitrary code on a client's machine …

Jun 28, 2024
CVE-2024-37741
5.4 MEDIUM

OpenPLC 3 through 9cd8f1b allows XSS via an SVG document as a profile picture.

Jun 28, 2024
CVE-2024-5737
6.1 MEDIUM

Script afGdStream.php in AdmirorFrames Joomla! extension doesn’t specify a content type and as a result default (text/html) is used. An attacker may embed HTML tags …

Jun 28, 2024
CVE-2024-5736
7.5 HIGH

Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! extension in afGdStream.php script allows to access local files or server pages available only from localhost. …

Jun 28, 2024
CVE-2024-5735
7.5 HIGH

Full Path Disclosure vulnerability in AdmirorFrames Joomla! extension in afHelper.php script allows an unauthorised attacker to retrieve location of web root folder. This issue affects …

Jun 28, 2024
CVE-2024-5925
6.4 MEDIUM

The Theron Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up …

Jun 28, 2024
CVE-2024-5922
6.4 MEDIUM

The Scylla lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up …

Jun 28, 2024
CVE-2024-5662
6.4 MEDIUM

The Ultimate Post Kit Addons For Elementor – (Post Grid, Post Carousel, Post Slider, Category List, Post Tabs, Timeline, Post Ticker, Tag Cloud) plugin for …

Jun 28, 2024
CVE-2024-5424
6.4 MEDIUM

The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery plugin for WordPress is vulnerable to …

Jun 28, 2024
CVE-2024-30135
3.3 LOW

HCL DRYiCE AEX is potentially impacted by disclosure of sensitive information in the mobile application when a snapshot is taken.

Jun 28, 2024
CVE-2024-6288
4.7 MEDIUM

The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site …

Jun 28, 2024
CVE-2024-5796
6.4 MEDIUM

The Infinite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘project_url’ parameter in all versions up to, and including, 1.1.2 due to …

Jun 28, 2024
CVE-2024-5788
6.4 MEDIUM

The Silesia theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ attribute within the theme's Button shortcode in all versions up to, …

Jun 28, 2024
CVE-2024-39350
7.5 HIGH

A vulnerability regarding authentication bypass by spoofing is found in the RTSP functionality. This allows man-in-the-middle attackers to obtain privileges without consent via unspecified vectors. …

Jun 28, 2024
CVE-2024-39348
7.5 HIGH

Download of code without integrity check vulnerability in AirPrint functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows man-in-the-middle attackers to execute arbitrary …

Jun 28, 2024
CVE-2024-39347
5.9 MEDIUM

Incorrect default permissions vulnerability in firewall functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows man-in-the-middle attackers to access highly sensitive intranet resources …

Jun 28, 2024
CVE-2024-30111
3.3 LOW

HCL DRYiCE AEX product is impacted by Missing Root Detection vulnerability in the mobile application. The mobile app can be installed in the rooted device …

Jun 28, 2024
CVE-2024-30110
3.7 LOW

HCL DRYiCE AEX product is impacted by lack of input validation vulnerability in a particular web application. A malicious script can be injected into a …

Jun 28, 2024
CVE-2024-2795
5.3 MEDIUM

The SEO SIMPLE PACK plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.1 via META description. This makes …

Jun 28, 2024
CVE-2024-5730
6.1 MEDIUM

The Pagerank tools WordPress plugin through 1.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jun 28, 2024
CVE-2024-5729
6.1 MEDIUM

The Simple AL Slider WordPress plugin through 1.2.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jun 28, 2024
CVE-2024-5728
5.4 MEDIUM

The Animated AL List WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jun 28, 2024
CVE-2024-5727
4.7 MEDIUM

The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jun 28, 2024
CVE-2024-5570
6.5 MEDIUM

The Simple Photoswipe WordPress plugin through 0.1 does not have authorisation check when updating its settings, which could allow any authenticated users, such as subscriber …

Jun 28, 2024
CVE-2024-39352
4.9 MEDIUM

A vulnerability regarding incorrect authorization is found in the firmware upgrade functionality. This allows remote authenticated users with administrator privileges to bypass firmware integrity check …

Jun 28, 2024
CVE-2024-39351
7.2 HIGH

A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the NTP configuration. This allows remote …

Jun 28, 2024
CVE-2024-39349
9.8 CRITICAL

A vulnerability regarding buffer copy without checking size of input ('Classic Buffer Overflow') is found in the libjansson component and it does not affect the …

Jun 28, 2024
CVE-2024-30109
3.7 LOW

HCL DRYiCE AEX is impacted by a lack of clickjacking protection in the AEX web application. An attacker can use multiple transparent or opaque layers …

Jun 28, 2024
CVE-2023-47803
5.3 MEDIUM

A vulnerability regarding improper limitation of a pathname to a restricted directory ('Path Traversal') is found in the Language Settings functionality. This allows remote attackers …

Jun 28, 2024
CVE-2023-47802
7.2 HIGH

A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the IP block functionality. This allows …

Jun 28, 2024
CVE-2024-37282
8.1 HIGH

It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subsequently used to create …

Jun 28, 2024
CVE-2024-6296
6.4 MEDIUM

The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-caption’ parameter in all versions up to, …

Jun 28, 2024
CVE-2024-5864
4.3 MEDIUM

The Easy Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the eafl_reset_settings AJAX action …

Jun 28, 2024
CVE-2024-5863
5.4 MEDIUM

The Easy Image Collage plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the ajax_image_collage() function in …

Jun 28, 2024
CVE-2024-37137
3.8 LOW

Dell Key Trust Platform, v3.0.6 and prior, contains Use of a Cryptographic Primitive with a Risky Implementation vulnerability. A local privileged attacker could potentially exploit …

Jun 28, 2024
CVE-2024-39708
7.0 HIGH

An issue was discovered in the Agent in Delinea Privilege Manager (formerly Thycotic Privilege Manager) before 12.0.1096 on Windows. Sometimes, a non-administrator user can copy …

Jun 28, 2024
CVE-2024-6071
10.0 CRITICAL

PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to execute arbitrary OS commands on the server.

Jun 27, 2024
CVE-2016-20022
8.4 HIGH

In the Linux kernel before 4.8, usb_parse_endpoint in drivers/usb/core/config.c does not validate the wMaxPacketSize field of an endpoint descriptor. NOTE: This vulnerability only affects products …

Jun 27, 2024
CVE-2024-4395
7.8 HIGH

The XPC service within the audit functionality of Jamf Compliance Editor before version 1.3.1 on macOS can lead to local privilege escalation.

Jun 27, 2024
CVE-2024-39705
9.8 CRITICAL

NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, …

Jun 27, 2024
CVE-2024-36059
9.4 CRITICAL

Directory Traversal vulnerability in Kalkitech ASE ASE61850 IEDSmart upto and including version 2.3.5 allows attackers to read/write arbitrary files via the IEC61850 File Transfer protocol.

Jun 27, 2024
CVE-2023-52892
7.5 HIGH

In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are incorrectly allowed to …

Jun 27, 2024
CVE-2024-5642
6.5 MEDIUM

CPython 3.9 and earlier doesn't disallow configuring an empty list ("[]") for SSLContext.set_npn_protocols() which is an invalid value for the underlying OpenSSL API. This results …

Jun 27, 2024
CVE-2024-39209
6.3 MEDIUM

luci-app-sms-tool v1.9-6 was discovered to contain a command injection vulnerability via the score parameter.

Jun 27, 2024
CVE-2024-39134
7.5 HIGH

A Stack Buffer Overflow vulnerability in zziplibv 0.13.77 allows attackers to cause a denial of service via the __zzip_fetch_disk_trailer() function at /zzip/zip.c.

Jun 27, 2024
CVE-2024-39132
6.5 MEDIUM

A NULL Pointer Dereference vulnerability in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the function VerifyCommandLine() at /src/DumpTS.cpp.

Jun 27, 2024
CVE-2024-36755
6.8 MEDIUM

D-Link DIR-1950 up to v1.11B03 does not validate SSL certificates when requesting the latest firmware version and downloading URL. This can allow attackers to downgrade …

Jun 27, 2024
CVE-2024-36075
6.5 MEDIUM

The CoSoSys Endpoint Protector through 5.9.3 and Unify agent through 7.0.6 is susceptible to an arbitrary code execution vulnerability due to the way an archive …

Jun 27, 2024
CVE-2024-36074
7.2 HIGH

Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the Endpoint Protector and Unify agent in …

Jun 27, 2024
CVE-2024-36073
7.2 HIGH

Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the shadowing component of the Endpoint Protector …

Jun 27, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.