CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-38459
7.8 HIGH

langchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an opt-in step. NOTE; this issue exists because of an incomplete fix …

Jun 16, 2024
CVE-2024-38458
8.8 HIGH

Xenforo before 2.2.16 allows code injection.

Jun 16, 2024
CVE-2024-38457
8.8 HIGH

Xenforo before 2.2.16 allows CSRF.

Jun 16, 2024
CVE-2024-38454
6.1 MEDIUM

ExpressionEngine before 7.4.11 allows XSS.

Jun 16, 2024
CVE-2024-38448
9.1 CRITICAL

htags in GNU Global through 6.6.12 allows code execution in situations where dbpath (aka -d) is untrusted, because shell metacharacters may be used.

Jun 16, 2024
CVE-2024-38443
6.2 MEDIUM

C/sorting/binary_insertion_sort.c in The Algorithms - C through e5dad3f has a segmentation fault for deep recursion, which may affect common use cases such as sorting an …

Jun 16, 2024
CVE-2024-38441
9.8 CRITICAL

Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[len] to '\0' in FPMapName in afp_mapname in etc/afpd/directory.c. 2.4.1 …

Jun 16, 2024
CVE-2024-38440
7.5 HIGH

Netatalk before 3.2.1 has an off-by-one error, and resultant heap-based buffer overflow and segmentation violation, because of incorrectly using FPLoginExt in BN_bin2bn in etc/uams/uams_dhx_pam.c. The …

Jun 16, 2024
CVE-2024-38439
9.8 CRITICAL

Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[PASSWDLEN] to '\0' in FPLoginExt in login in etc/uams/uams_pam.c. 2.4.1 …

Jun 16, 2024
CVE-2024-36397
6.1 MEDIUM

Vantiva - MediaAccess DGA2232 v19.4 - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Jun 16, 2024
CVE-2024-38428
9.1 CRITICAL

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data …

Jun 16, 2024
CVE-2024-38427
8.8 HIGH

In International Color Consortium DemoIccMAX before 85ce74e, a logic flaw in CIccTagXmlProfileSequenceId::ParseXml in IccXML/IccLibXML/IccTagXml.cpp results in unconditionally returning false.

Jun 16, 2024
CVE-2024-38395
9.8 CRITICAL

In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is not trivially …

Jun 16, 2024
CVE-2024-38394
4.3 MEDIUM

Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kernel's underlying device matching logic allow a physically proximate …

Jun 16, 2024
CVE-2024-6016
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in itsourcecode Online Laundry Management System 1.0. Affected by this issue is some unknown functionality …

Jun 15, 2024
CVE-2024-6015
6.3 MEDIUM

A vulnerability classified as critical was found in itsourcecode Online House Rental System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jun 15, 2024
CVE-2024-6014
6.3 MEDIUM

A vulnerability classified as critical has been found in itsourcecode Document Management System 1.0. Affected is an unknown function of the file edithis.php. The manipulation …

Jun 15, 2024
CVE-2024-6013
6.3 MEDIUM

A vulnerability was found in itsourcecode Online Book Store 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Jun 15, 2024
CVE-2024-6009
6.3 MEDIUM

A vulnerability has been found in itsourcecode Event Calendar 1.0 and classified as critical. Affected by this vulnerability is the function regConfirm/regDelete of the file …

Jun 15, 2024
CVE-2024-6008
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Online Book Store up to 1.0. Affected is an unknown function of the file …

Jun 15, 2024
CVE-2024-31870
3.3 LOW

IBM Db2 for i 7.2, 7.3, 7.4, and 7.5 supplies user defined table function is vulnerable to user enumeration by a local authenticated attacker, without …

Jun 15, 2024
CVE-2024-27275
7.4 HIGH

IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority requirement. A local user without administrator privilege …

Jun 15, 2024
CVE-2024-6007
6.3 MEDIUM

A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /protocol/iscgwtunnel/deleteiscgwrouteconf.php. The …

Jun 15, 2024
CVE-2024-6006
3.5 LOW

A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of …

Jun 15, 2024
CVE-2024-6005
3.5 LOW

A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Jun 15, 2024
CVE-2024-5611
6.4 MEDIUM

The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘label_years’ attribute within the Countdown widget in all versions …

Jun 15, 2024
CVE-2024-5858
4.3 MEDIUM

The AI Infographic Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the qcld_openai_title_generate_desc AJAX action …

Jun 15, 2024
CVE-2024-4551
6.4 MEDIUM

The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and …

Jun 15, 2024
CVE-2024-4258
9.8 CRITICAL

The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and …

Jun 15, 2024
CVE-2024-4095
6.4 MEDIUM

The Collapse-O-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'expand' and 'expandsub' shortcode in all versions up to, and including, …

Jun 15, 2024
CVE-2024-3105
9.9 CRITICAL

The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, …

Jun 15, 2024
CVE-2024-2695
6.4 MEDIUM

The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortcode in all versions up to, and including, 4.6.13 …

Jun 15, 2024
CVE-2024-1399
6.4 MEDIUM

The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all …

Jun 15, 2024
CVE-2024-6000
7.1 HIGH

The FooEvents for WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper capability setting on the 'display_ticket_themes_page' function in …

Jun 15, 2024
CVE-2024-5871
9.8 CRITICAL

The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of …

Jun 15, 2024
CVE-2024-5868
6.5 MEDIUM

The WooCommerce - Social Login plugin for WordPress is vulnerable to Email Verification in all versions up to, and including, 2.6.2 via the use of …

Jun 15, 2024
CVE-2024-5263
6.4 MEDIUM

The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Motion Text and Table widgets in all versions up to, …

Jun 15, 2024
CVE-2024-4479
6.4 MEDIUM

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sg_general_toggle_tab_enable and sg_accordion_style attributes within the plugin's JKit - Tabs …

Jun 15, 2024
CVE-2024-3815
5.5 MEDIUM

The Newspaper theme for WordPress is vulnerable to Stored Cross-Site Scripting via attachment meta in the archive page in all versions up to, and including, …

Jun 15, 2024
CVE-2024-3814
5.5 MEDIUM

The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'single' module in all versions up to, and including, 4.8 …

Jun 15, 2024
CVE-2024-3813
8.8 HIGH

The tagDiv Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8 via the 'td_block_title' shortcode 'block_template_id' …

Jun 15, 2024
CVE-2024-2544
7.4 HIGH

The Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on all …

Jun 15, 2024
CVE-2023-6696
8.1 HIGH

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing …

Jun 15, 2024
CVE-2024-6003
7.3 HIGH

A vulnerability was found in Guangdong Baolun Electronics IP Network Broadcasting Service Platform 2.0. It has been classified as critical. Affected is an unknown function …

Jun 14, 2024
CVE-2024-30120
2.9 LOW

HCL DRYiCE Optibot Reset Station is impacted by an Unused Parameter in the web application.

Jun 14, 2024
CVE-2024-30119
3.7 LOW

HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header. This could allow an attacker to intercept or manipulate data during …

Jun 14, 2024
CVE-2024-21988
5.3 MEDIUM

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible to disclosure of sensitive information via complex MiTM attacks due to a vulnerability …

Jun 14, 2024
CVE-2024-37889
6.5 MEDIUM

MyFinances is a web application for managing finances. MyFinances has a way to access other customer invoices while signed in as a user. This method …

Jun 14, 2024
CVE-2024-37831
9.8 CRITICAL

Itsourcecode Payroll Management System 1.0 is vulnerable to SQL Injection in payroll_items.php via the ID parameter.

Jun 14, 2024
CVE-2024-36600
8.4 HIGH

Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a crafted ISO 9660 image file.

Jun 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.