CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6142
8.8 HIGH

Actiontec WCB6200Q uh_tcp_recv_content Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Actiontec WCB6200Q routers. …

Jun 19, 2024
CVE-2024-5970
6.4 MEDIUM

The MaxGalleria plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's maxgallery_thumb shortcode in all versions up to, and including, 6.4.4 due …

Jun 18, 2024
CVE-2024-6129
3.7 LOW

A vulnerability, which was classified as problematic, was found in spa-cartcms 1.9.0.6. Affected is an unknown function of the file /login of the component Username …

Jun 18, 2024
CVE-2024-6128
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in spa-cartcms 1.9.0.6. This issue affects some unknown processing of the file /checkout of the …

Jun 18, 2024
CVE-2024-38277
5.4 MEDIUM

A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between …

Jun 18, 2024
CVE-2024-38276
8.8 HIGH

Incorrect CSRF token checks resulted in multiple CSRF risks.

Jun 18, 2024
CVE-2024-38275
7.5 HIGH

The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to …

Jun 18, 2024
CVE-2024-38274
6.1 MEDIUM

Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt.

Jun 18, 2024
CVE-2024-38273
5.4 MEDIUM

Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.

Jun 18, 2024
CVE-2024-37821
8.8 HIGH

An arbitrary file upload vulnerability in the Upload Template function of Dolibarr ERP CRM up to v19.0.1 allows attackers to execute arbitrary code via uploading …

Jun 18, 2024
CVE-2024-36977
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: Wait unconditionally after issuing EndXfer command Currently all controller IP/revisions except DWC3_usb3 >= …

Jun 18, 2024
CVE-2024-36976
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Revert "media: v4l2-ctrls: show all owned controls in log_status" This reverts commit 9801b5b28c6929139d6fceeee8d739cc67bb2739. This patch …

Jun 18, 2024
CVE-2024-36975
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Do not use WARN when encode fails When asn1_encode_sequence() fails, WARN is not …

Jun 18, 2024
CVE-2024-36974
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/sched: taprio: always validate TCA_TAPRIO_ATTR_PRIOMAP If one TCA_TAPRIO_ATTR_PRIOMAP attribute has been provided, taprio_parse_mqprio_opt() must validate …

Jun 18, 2024
CVE-2024-37791
6.0 MEDIUM

DuxCMS3 v3.1.3 was discovered to contain a SQL injection vulnerability via the keyword parameter at /article/Content/index?class_id.

Jun 18, 2024
CVE-2024-22002
7.8 HIGH

CORSAIR iCUE 5.9.105 with iCUE Murals on Windows allows unprivileged users to insert DLL files in the cuepkg-1.2.6 subdirectory of the installation directory.

Jun 18, 2024
CVE-2022-23829
8.2 HIGH

A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native System Management Mode …

Jun 18, 2024
CVE-2024-38351
5.4 MEDIUM

Pocketbase is an open source web backend written in go. In affected versions a malicious user may be able to compromise other user accounts. In …

Jun 18, 2024
CVE-2024-38348
8.8 HIGH

CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Staff Info module via the searvalu parameter.

Jun 18, 2024
CVE-2024-38347
8.8 HIGH

CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Room Information module via the id parameter.

Jun 18, 2024
CVE-2024-37904
5.7 MEDIUM

Minder is an open source Software Supply Chain Security Platform. Minder's Git provider is vulnerable to a denial of service from a maliciously configured GitHub …

Jun 18, 2024
CVE-2024-37803
5.4 MEDIUM

Multiple stored cross-site scripting (XSS) vulnerabilities in CodeProjects Health Care hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a …

Jun 18, 2024
CVE-2024-37802
8.8 HIGH

CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Patient Info module via the searvalu parameter.

Jun 18, 2024
CVE-2024-37800
6.1 MEDIUM

CodeProjects Restaurant Reservation System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Date parameter at index.php.

Jun 18, 2024
CVE-2024-37799
5.4 MEDIUM

CodeProjects Restaurant Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the reserv_id parameter at view_reservations.php.

Jun 18, 2024
CVE-2024-21685
6.5 MEDIUM

This High severity Information Disclosure vulnerability was introduced in versions 9.4.0, 9.12.0, and 9.15.0 of Jira Core Data Center. This Information Disclosure vulnerability, with a …

Jun 18, 2024
CVE-2024-5275
7.8 HIGH

A hard-coded password in the FileCatalyst TransferAgent can be found which can be used to unlock the keystore from which contents may be read out, …

Jun 18, 2024
CVE-2024-6116
7.3 HIGH

A vulnerability, which was classified as critical, has been found in itsourcecode Simple Online Hotel Reservation System 1.0. Affected by this issue is some unknown …

Jun 18, 2024
CVE-2023-47726
7.1 HIGH

IBM QRadar Suite Software 1.10.12.0 through 1.10.21.0 and IBM Cloud Pak for Security 1.10.12.0 through 1.10.21.0 could allow an authenticated user to execute certain arbitrary …

Jun 18, 2024
CVE-2024-6115
7.3 HIGH

A vulnerability classified as critical was found in itsourcecode Simple Online Hotel Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the …

Jun 18, 2024
CVE-2024-6114
7.3 HIGH

A vulnerability classified as critical has been found in itsourcecode Monbela Tourist Inn Online Reservation System up to 1.0. Affected is an unknown function of …

Jun 18, 2024
CVE-2024-6112
7.3 HIGH

A vulnerability classified as critical was found in itsourcecode Pool of Bethesda Online Reservation System 1.0. This vulnerability affects unknown code of the file index.php. …

Jun 18, 2024
CVE-2024-6111
7.3 HIGH

A vulnerability classified as critical has been found in itsourcecode Pool of Bethesda Online Reservation System 1.0. This affects an unknown part of the file …

Jun 18, 2024
CVE-2024-6110
7.3 HIGH

A vulnerability was found in itsourcecode Magbanua Beach Resort Online Reservation System up to 1.0. It has been rated as critical. Affected by this issue …

Jun 18, 2024
CVE-2024-6109
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jun 18, 2024
CVE-2024-5967
2.7 LOW

A vulnerability was found in Keycloak. The LDAP testing endpoint allows changing the Connection URL independently without re-entering the currently configured LDAP bind credentials. This …

Jun 18, 2024
CVE-2024-38507
3.5 LOW

In JetBrains Hub before 2024.2.34646 stored XSS via project description was possible

Jun 18, 2024
CVE-2024-38506
6.3 MEDIUM

In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows

Jun 18, 2024
CVE-2024-38505
5.3 MEDIUM

In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site

Jun 18, 2024
CVE-2024-38504
4.3 MEDIUM

In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles

Jun 18, 2024
CVE-2024-6108
4.3 MEDIUM

A vulnerability was found in Genexis Tilgin Home Gateway 322_AS0500-03_05_13_05. It has been classified as problematic. Affected is an unknown function of the file /vood/cgi-bin/vood_view.cgi?act=index&lang=EN# …

Jun 18, 2024
CVE-2024-5953
5.7 MEDIUM

A denial of service vulnerability was found in the 389-ds-base LDAP server. This issue may allow an authenticated user to cause a server denial of …

Jun 18, 2024
CVE-2024-5899
3.3 LOW

When Bazel Plugin in intellij imports a project (either using "import project" or "Auto import") the dialog for trusting the project is not displayed. This …

Jun 18, 2024
CVE-2024-5533
6.4 MEDIUM

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.25.1 due to insufficient input sanitization and …

Jun 18, 2024
CVE-2024-5172
4.8 MEDIUM

The Expert Invoice WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jun 18, 2024
CVE-2024-4094
5.4 MEDIUM

The Simple Share Buttons Adder WordPress plugin before 8.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jun 18, 2024
CVE-2024-3276
4.8 MEDIUM

The Lightbox & Modal Popup WordPress Plugin WordPress plugin before 2.7.28, foobox-image-lightbox-premium WordPress plugin before 2.7.28 does not sanitise and escape some of its settings, …

Jun 18, 2024
CVE-2024-37081
7.8 HIGH

The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues …

Jun 18, 2024
CVE-2024-37080
9.8 CRITICAL

vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this …

Jun 18, 2024
CVE-2024-37079
9.8 CRITICAL KEV

vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this …

Jun 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.