CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5695
9.8 CRITICAL

If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered, and in rarer …

Jun 11, 2024
CVE-2024-5694
7.5 HIGH

An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section of the heap. This vulnerability affects …

Jun 11, 2024
CVE-2024-5693
6.1 MEDIUM

Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. This …

Jun 11, 2024
CVE-2024-5692
6.5 MEDIUM

On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such …

Jun 11, 2024
CVE-2024-5691
4.7 MEDIUM

By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions …

Jun 11, 2024
CVE-2024-5690
4.3 MEDIUM

By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects …

Jun 11, 2024
CVE-2024-5689
4.3 MEDIUM

In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button that appeared, and …

Jun 11, 2024
CVE-2024-5688
8.1 HIGH

If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Firefox < 127, Firefox …

Jun 11, 2024
CVE-2024-5687
5.3 MEDIUM

If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. …

Jun 11, 2024
CVE-2024-2462

Allow attackers to intercept or falsify data exchanges between the client and the server

Jun 11, 2024
CVE-2024-2461

If exploited an attacker could traverse the file system to access files or directories that would otherwise be inaccessible

Jun 11, 2024
CVE-2024-36266
9.3 CRITICAL

A vulnerability has been identified in PowerSys (All versions < V3.11). The affected application insufficiently protects responses to authentication requests. This could allow a local …

Jun 11, 2024
CVE-2024-35303
7.8 HIGH

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0012), Tecnomatix Plant Simulation V2404 (All versions < V2404.0001). The affected applications …

Jun 11, 2024
CVE-2024-35292
8.2 HIGH

A vulnerability has been identified in SIMATIC S7-200 SMART CPU CR40 (6ES7288-1CR40-0AA0) (All versions), SIMATIC S7-200 SMART CPU CR60 (6ES7288-1CR60-0AA0) (All versions), SIMATIC S7-200 SMART …

Jun 11, 2024
CVE-2024-35212
6.2 MEDIUM

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected application lacks input validation due to which an attacker …

Jun 11, 2024
CVE-2024-35211
5.5 MEDIUM

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server, after a successful login, sets the session …

Jun 11, 2024
CVE-2024-35210
5.1 MEDIUM

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is not enforcing HSTS. This could allow …

Jun 11, 2024
CVE-2024-35209
6.2 MEDIUM

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is allowing HTTP methods like PUT and …

Jun 11, 2024
CVE-2024-35208
6.3 MEDIUM

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server stored the password in cleartext. This could …

Jun 11, 2024
CVE-2024-35207
7.8 HIGH

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The web interface of the affected devices are vulnerable to Cross-Site …

Jun 11, 2024
CVE-2024-35206
7.7 HIGH

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected application does not expire the session. This could allow …

Jun 11, 2024
CVE-2024-33500
5.9 MEDIUM

A vulnerability has been identified in Mendix Applications using Mendix 10 (All versions < V10.11.0), Mendix Applications using Mendix 10 (V10.6) (All versions < V10.6.9), …

Jun 11, 2024
CVE-2023-50763
4.9 MEDIUM

A vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.3), SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0) (All versions < V2.3), SIMATIC CP …

Jun 11, 2024
CVE-2023-38533
3.3 LOW

A vulnerability has been identified in TIA Administrator (All versions < V3 SP2). The affected component creates temporary download files in a directory with insecure …

Jun 11, 2024
CVE-2024-5829
3.5 LOW

A vulnerability classified as problematic was found in smallweigit Avue up to 3.4.4. Affected by this vulnerability is an unknown functionality of the component avueUeditor. …

Jun 11, 2024
CVE-2024-35685
5.3 MEDIUM

Missing Authorization vulnerability in Anders Norén Radcliffe 2.This issue affects Radcliffe 2: from n/a through 2.0.17.

Jun 11, 2024
CVE-2024-34813
5.3 MEDIUM

Missing Authorization vulnerability in Moreconvert Team MC Woocommerce Wishlist smart-wishlist-for-more-convert.This issue affects MC Woocommerce Wishlist: from n/a through <= 1.7.8.

Jun 11, 2024
CVE-2023-52179
5.4 MEDIUM

Missing Authorization vulnerability in WebCodingPlace Product Expiry for WooCommerce.This issue affects Product Expiry for WooCommerce: from n/a through 2.5.

Jun 11, 2024
CVE-2024-5825

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 11, 2024
CVE-2024-5584
6.4 MEDIUM

The WordPress Online Booking and Scheduling Plugin – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Color Profile parameter in all …

Jun 11, 2024
CVE-2024-5398

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 11, 2024
CVE-2024-4387

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 11, 2024
CVE-2024-4206

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 11, 2024
CVE-2024-4155

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 11, 2024
CVE-2024-35716
6.5 MEDIUM

Missing Authorization vulnerability in Copymatic Copymatic – AI Content Writer & Generator.This issue affects Copymatic – AI Content Writer & Generator: from n/a through 1.9.

Jun 11, 2024
CVE-2024-35692
5.3 MEDIUM

Missing Authorization vulnerability in Termly Cookie Consent.This issue affects Cookie Consent: from n/a through 3.2.

Jun 11, 2024
CVE-2024-34824
4.3 MEDIUM

Missing Authorization vulnerability in ThemeBoy SportsPress – Sports Club & League Manager.This issue affects SportsPress – Sports Club & League Manager: from n/a through 2.7.20.

Jun 11, 2024
CVE-2024-24704
5.4 MEDIUM

Missing Authorization vulnerability in AddonMaster Load More Anything.This issue affects Load More Anything: from n/a through 3.3.3.

Jun 11, 2024
CVE-2023-52217
4.3 MEDIUM

Missing Authorization vulnerability in weDevs WooCommerce Conversion Tracking.This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.11.

Jun 11, 2024
CVE-2023-52186
5.3 MEDIUM

Missing Authorization vulnerability in Woo WooCommerce Product Vendors.This issue affects WooCommerce Product Vendors: from n/a through 2.2.2.

Jun 11, 2024
CVE-2023-33922
4.3 MEDIUM

Missing Authorization vulnerability in Elementor Elementor Website Builder.This issue affects Elementor Website Builder: from n/a through 3.13.2.

Jun 11, 2024
CVE-2023-28775
5.3 MEDIUM

Missing Authorization vulnerability in Yoast Yoast SEO Premium.This issue affects Yoast SEO Premium: from n/a through 20.4.

Jun 11, 2024
CVE-2023-25799
8.3 HIGH

Missing Authorization vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.1.8.

Jun 11, 2024
CVE-2024-5531
6.4 MEDIUM

The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flickr widget in all versions up to, and including, 2.2.8 due …

Jun 11, 2024
CVE-2024-4266
5.3 MEDIUM

The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up …

Jun 11, 2024
CVE-2020-11843
6.5 MEDIUM

This allows the information exposure to unauthorized users. This issue affects NetIQ Access Manager using version 4.5 or before

Jun 11, 2024
CVE-2024-3549
9.9 CRITICAL

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSortPostType' parameter in all versions up to, …

Jun 11, 2024
CVE-2024-4319
5.3 MEDIUM

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'vsz_cf7_export_to_excel' …

Jun 11, 2024
CVE-2024-3723
5.3 MEDIUM

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.2 via the …

Jun 11, 2024
CVE-2024-31402
4.3 MEDIUM

Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker to delete the data of Shared To-Dos.

Jun 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.