CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-37888
6.1 MEDIUM

The Open Link is a CKEditor plugin, extending context menu with a possibility to open link in a new tab. The vulnerability allowed to execute …

Jun 14, 2024
CVE-2024-36599
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

Jun 14, 2024
CVE-2024-36598
8.1 HIGH

An arbitrary file upload vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary code via uploading a crafted image file.

Jun 14, 2024
CVE-2024-36597
8.8 HIGH

Aegon Life v1.0 was discovered to contain a SQL injection vulnerability via the client_id parameter at clientStatus.php.

Jun 14, 2024
CVE-2024-24320
8.8 HIGH

Directory Traversal vulnerability in Mgt-commerce CloudPanel v.2.0.0 thru v.2.4.0 allows a remote attacker to obtain sensitive information and execute arbitrary code via the service parameter …

Jun 14, 2024
CVE-2024-5659
6.5 MEDIUM

Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fault(MNRF/Assert). This …

Jun 14, 2024
CVE-2024-37369
8.8 HIGH

A privilege escalation vulnerability exists in the affected product. The vulnerability allows low-privilege users to edit scripts, bypassing Access Control Lists, and potentially gaining further …

Jun 14, 2024
CVE-2024-37887
3.5 LOW

Nextcloud Server is a self hosted personal cloud system. Private shared calendar events' recurrence exceptions can be read by sharees. It is recommended that the …

Jun 14, 2024
CVE-2024-37886
5.4 MEDIUM

user_oidc app is an OpenID Connect user backend for Nextcloud. An attacker could potentially trick the app into accepting a request that is not signed …

Jun 14, 2024
CVE-2024-37885
3.8 LOW

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. A code injection in Nextcloud Desktop Client for macOS …

Jun 14, 2024
CVE-2024-37884
3.5 LOW

Nextcloud Server is a self hosted personal cloud system. A malicious user was able to send delete requests for old versions of files they only …

Jun 14, 2024
CVE-2024-37883
4.3 MEDIUM

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A user with access to …

Jun 14, 2024
CVE-2024-37882
8.1 HIGH

Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share permissions could reshare the item with more permissions. It …

Jun 14, 2024
CVE-2024-37645
8.8 HIGH

TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow vulnerability via the submit-url parameter at /formSysLog .

Jun 14, 2024
CVE-2024-37643
8.8 HIGH

TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow vulnerability via the submit-url parameter at /formPasswordAuth .

Jun 14, 2024
CVE-2024-37642
9.1 CRITICAL

TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a command injection vulnerability via the ipv4_ping, ipv6_ping parameter at /formSystemCheck .

Jun 14, 2024
CVE-2024-37641
8.8 HIGH

TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow via the submit-url parameter at /formNewSchedule

Jun 14, 2024
CVE-2024-37317
4.6 MEDIUM

The Nextcloud Notes app is a distraction free notes taking app for Nextcloud. If an attacker managed to share a folder called `Notes/` with a …

Jun 14, 2024
CVE-2024-37316
4.6 MEDIUM

Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachment data leading to a bad redirect for participants …

Jun 14, 2024
CVE-2024-37315
3.5 LOW

Nextcloud Server is a self hosted personal cloud system. An attacker with read-only access to a file is able to restore older versions of a …

Jun 14, 2024
CVE-2024-33373
6.3 MEDIUM

An issue in the LB-LINK BL-W1210M v2.0 router allows attackers to bypass password complexity requirements and set single digit passwords for authentication. This vulnerability can …

Jun 14, 2024
CVE-2024-37644
8.8 HIGH

TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.

Jun 14, 2024
CVE-2024-37368
7.5 HIGH

A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with FTView to send …

Jun 14, 2024
CVE-2024-37367
7.5 HIGH

A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system with FTView to …

Jun 14, 2024
CVE-2024-37314
3.5 LOW

Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommended that the Nextcloud Server is …

Jun 14, 2024
CVE-2024-37313
7.3 HIGH

Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second factor of 2FA after successfully providing …

Jun 14, 2024
CVE-2024-37312
6.3 MEDIUM

user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access control on the ID4me endpoint allows an attacker to register an account eventually …

Jun 14, 2024
CVE-2024-36656
6.1 MEDIUM

In MintHCM 4.0.3, a registered user can execute arbitrary JavaScript code and achieve a reflected Cross-site Scripting (XSS) attack.

Jun 14, 2024
CVE-2024-34694
8.1 HIGH

LNbits is a Lightning wallet and accounts system. Paying invoices in Eclair that do not get settled within the internal timeout (about 30s) lead to …

Jun 14, 2024
CVE-2024-34539
9.4 CRITICAL

Hardcoded credentials in TerraMaster TOS firmware through 5.1 allow a remote attacker to successfully login to the mail or webmail server. These credentials can also …

Jun 14, 2024
CVE-2024-33377
8.1 HIGH

LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attackers can cause victim users to perform arbitrary operations via …

Jun 14, 2024
CVE-2024-33375
9.8 CRITICAL

LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.

Jun 14, 2024
CVE-2024-33374
9.8 CRITICAL

Incorrect access control in the UART/Serial interface on the LB-LINK BL-W1210M v2.0 router allows attackers to access the root terminal without authentication.

Jun 14, 2024
CVE-2024-23442
6.1 MEDIUM

An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously …

Jun 14, 2024
CVE-2024-5731
6.8 MEDIUM

A vulnerability in the IPS Manager, Central Manager, and Local Manager communication workflow allows an attacker to control the destination of a request by manipulating …

Jun 14, 2024
CVE-2024-5671
9.8 CRITICAL

Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitrary code execution and access to the vulnerable Trellix IPS …

Jun 14, 2024
CVE-2024-37640
8.8 HIGH

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWiFiEasyGuestCfg.

Jun 14, 2024
CVE-2024-37639
8.8 HIGH

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via eport in the function setIpPortFilterRules.

Jun 14, 2024
CVE-2024-37637
9.8 CRITICAL

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWizardCfg.

Jun 14, 2024
CVE-2024-2024
8.8 HIGH

The Folders Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_folders_file_upload' function in all versions …

Jun 14, 2024
CVE-2024-2023
4.3 MEDIUM

The Folders and Folders Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0 in Folders and 3.0.2 …

Jun 14, 2024
CVE-2024-36459

A CRLF cross-site scripting vulnerability has been identified in certain configurations of the SiteMinder Web Agent for IIS Web Server and SiteMinder Web Agent for …

Jun 14, 2024
CVE-2023-51376
4.3 MEDIUM

Missing Authorization vulnerability in Brainstorm Force ProjectHuddle Client Site.This issue affects ProjectHuddle Client Site: from n/a through 1.0.34.

Jun 14, 2024
CVE-2024-5685
7.6 HIGH

Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue …

Jun 14, 2024
CVE-2024-3912
9.8 CRITICAL

Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on …

Jun 14, 2024
CVE-2024-34012
4.4 MEDIUM

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.24135.272.

Jun 14, 2024
CVE-2024-2472
9.1 CRITICAL

The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the …

Jun 14, 2024
CVE-2024-5996

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 14, 2024
CVE-2024-4863
6.4 MEDIUM

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘titleFont’ parameter …

Jun 14, 2024
CVE-2024-37182
4.7 MEDIUM

Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over …

Jun 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.