CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5558
6.4 MEDIUM

CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists that could cause escalation of privileges when an attacker abuses a limited admin account.

Jun 12, 2024
CVE-2024-5557
4.5 MEDIUM

CWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause exposure of SNMP credentials when an attacker has access to the controller …

Jun 12, 2024
CVE-2024-37878
6.1 MEDIUM

Cross Site Scripting vulnerability in TWCMS v.2.0.3 allows a remote attacker to execute arbitrary code via the /TWCMS-gh-pages/twcms/runtime/twcms_view/default,index.htm.php" PHP directly echoes parameters input from external …

Jun 12, 2024
CVE-2024-37040
5.4 MEDIUM

CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a user with access to the device’s web interface …

Jun 12, 2024
CVE-2024-37039
5.9 MEDIUM

CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request.

Jun 12, 2024
CVE-2024-37038
7.5 HIGH

CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware …

Jun 12, 2024
CVE-2024-37037
8.1 HIGH

CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability exists that could allow an authenticated user with access to the device’s …

Jun 12, 2024
CVE-2024-37036
9.8 CRITICAL

CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass when sending a malformed POST request and particular configuration parameters are set.

Jun 12, 2024
CVE-2024-2230

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 12, 2024
CVE-2024-22855
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in the User Maintenance section of ITSS iMLog v1.307 allows attackers to execute arbitrary web scripts or HTML via a …

Jun 12, 2024
CVE-2024-5897
4.3 MEDIUM

A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is an …

Jun 12, 2024
CVE-2024-5896
7.3 HIGH

A vulnerability, which was classified as critical, was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. Affected is the function save_users of …

Jun 12, 2024
CVE-2024-5759
5.4 MEDIUM

An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized objects and launch scans without having the …

Jun 12, 2024
CVE-2024-37300
8.1 HIGH

OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. JupyterHub < 5.0, when used with `GlobusOAuthenticator`, could be …

Jun 12, 2024
CVE-2024-36761
9.8 CRITICAL

naga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs.

Jun 12, 2024
CVE-2024-1891
3.5 LOW

A stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker could inject HTML code into a web application scan …

Jun 12, 2024
CVE-2024-5895
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. This issue affects the function …

Jun 12, 2024
CVE-2024-5894
7.3 HIGH

A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects unknown code of the file manage_product.php. The manipulation of …

Jun 12, 2024
CVE-2024-5893
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Cab Management System 1.0. This affects an unknown part of the file /cms/classes/Users.php?f=delete_client. The manipulation …

Jun 12, 2024
CVE-2024-37304
6.1 MEDIUM

NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While …

Jun 12, 2024
CVE-2024-37297
5.4 MEDIUM

WooCommerce is an open-source e-commerce platform built on WordPress. A vulnerability introduced in WooCommerce 8.8 allows for cross-site scripting. A bad actor can manipulate a …

Jun 12, 2024
CVE-2024-36840
9.1 CRITICAL

SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code and obtain sensitive information via the id parameter …

Jun 12, 2024
CVE-2024-36691
6.3 MEDIUM

Insecure permissions in the AdminController.AjaxSave() method of PPGo_Jobs v2.8.0 allows authenticated attackers to arbitrarily modify users' account information.

Jun 12, 2024
CVE-2024-36265
9.8 CRITICAL

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: from 0.8.0. As this project …

Jun 12, 2024
CVE-2024-34065
7.1 HIGH

Strapi is an open-source content management system. By combining two vulnerabilities (an `Open Redirect` and `session token sent as URL query parameter`) in @strapi/plugin-users-permissions before …

Jun 12, 2024
CVE-2024-31217
5.3 MEDIUM

Strapi is an open-source content management system. Prior to version 4.22.0, a denial-of-service vulnerability is present in the media upload process causing the server to …

Jun 12, 2024
CVE-2024-2300
6.2 MEDIUM

HP Advance Mobile Applications for iOS and Android are potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices.

Jun 12, 2024
CVE-2024-29181
2.3 LOW

Strapi is an open-source content management system. Prior to version 4.19.1, a super admin can create a collection where an item in the collection has …

Jun 12, 2024
CVE-2024-28964
7.8 HIGH

Dell Common Event Enabler, version 8.9.10.0 and prior, contain an insecure deserialization vulnerability in CAVATools. A local unauthenticated attacker could potentially exploit this vulnerability, leading …

Jun 12, 2024
CVE-2024-5891
4.2 MEDIUM

A vulnerability was found in Quay. If an attacker can obtain the client ID for an application, they can use an OAuth token to authenticate …

Jun 12, 2024
CVE-2024-36699

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not …

Jun 12, 2024
CVE-2024-36264
9.8 CRITICAL

** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submarine.auth.default.secret`, a default value will be …

Jun 12, 2024
CVE-2024-36263
8.1 HIGH

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Submarine Server Core. This issue …

Jun 12, 2024
CVE-2024-23445
6.5 MEDIUM

It was identified that if a cross-cluster API key https://www.elastic.co/guide/en/elasticsearch/reference/8.14/security-api-create-cross-cluster-api-key.html#security-api-create-cross-cluster-api-key-request-body restricts search for a given index using the query or the field_security parameter, and the …

Jun 12, 2024
CVE-2024-1659
9.8 CRITICAL

Arbitrary File Upload vulnerability in MegaBIP software allows attacker to upload any file to the server (including a PHP code file) without an authentication. This …

Jun 12, 2024
CVE-2024-1577
9.8 CRITICAL

Remote Code Execution vulnerability in MegaBIP software allows to execute arbitrary code on the server without requiring authentication by saving crafted by the attacker PHP …

Jun 12, 2024
CVE-2024-1576
9.8 CRITICAL

SQL Injection vulnerability in MegaBIP software allows attacker to obtain site administrator privileges, including access to the administration panel and the ability to change the …

Jun 12, 2024
CVE-2024-5313
6.5 MEDIUM

CWE-668: Exposure of the Resource Wrong Sphere vulnerability exists that exposes a SSH interface over the product network interface. This does not allow to directly …

Jun 12, 2024
CVE-2024-25949
8.8 HIGH

Dell OS10 Networking Switches, versions10.5.6.x, 10.5.5.x, 10.5.4.x and 10.5.3.x ,contain an improper authorization vulnerability. A remote authenticated attacker could potentially exploit this vulnerability leading to …

Jun 12, 2024
CVE-2024-5211
7.2 HIGH

A path traversal vulnerability in mintplex-labs/anything-llm allowed a manager to bypass the `normalizePath()` function, intended to defend against path traversal attacks. This vulnerability enables the …

Jun 12, 2024
CVE-2024-5056
6.5 MEDIUM

CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may prevent user to update the device firmware and prevent proper behavior of the …

Jun 12, 2024
CVE-2024-5674
6.5 MEDIUM

The Newsletter - API v1 and v2 addon plugin for WordPress is vulnerable to unauthorized subscribers management due to PHP type juggling issue on the …

Jun 12, 2024
CVE-2024-4898
9.8 CRITICAL

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due to a missing authorization checks on …

Jun 12, 2024
CVE-2024-3492
6.4 MEDIUM

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event', 'location', and 'event_category' …

Jun 12, 2024
CVE-2024-1766
4.4 MEDIUM

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.2.86 …

Jun 12, 2024
CVE-2024-4845
8.8 HIGH

The Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘options[list_id]’ parameter in all versions up to, and including, 5.7.22 due to …

Jun 12, 2024
CVE-2024-2092
5.4 MEDIUM

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Twitter Widget in all versions up to, and including, …

Jun 12, 2024
CVE-2023-51524
4.3 MEDIUM

Missing Authorization vulnerability in weForms.This issue affects weForms: from n/a through 1.6.18.

Jun 12, 2024
CVE-2023-51413
5.3 MEDIUM

Missing Authorization vulnerability in Piotnet Forms.This issue affects Piotnet Forms: from n/a through 1.0.29.

Jun 12, 2024
CVE-2023-48280
7.5 HIGH

Missing Authorization vulnerability in Consensu.IO Consensu.Io.This issue affects Consensu.Io: from n/a through 1.0.1.

Jun 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.