CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5589
6.3 MEDIUM

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. This affects an unknown part of the file …

Jun 3, 2024
CVE-2024-5588
6.3 MEDIUM

A vulnerability was found in itsourcecode Learning Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jun 2, 2024
CVE-2024-36392
6.1 MEDIUM

MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Jun 2, 2024
CVE-2024-36391
9.1 CRITICAL

MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic

Jun 2, 2024
CVE-2024-36390
7.5 HIGH

MileSight DeviceHub - CWE-20 Improper Input Validation may allow Denial of Service

Jun 2, 2024
CVE-2024-36389
9.8 CRITICAL

MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass

Jun 2, 2024
CVE-2024-36388
10.0 CRITICAL

MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function

Jun 2, 2024
CVE-2024-27776
9.8 CRITICAL

MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') may allow Unauthenticated RCE

Jun 2, 2024
CVE-2024-2178
7.5 HIGH

A path traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'copy_to_custom_personas' endpoint in the 'lollms_personalities_infos.py' file. This vulnerability allows attackers to read arbitrary files …

Jun 2, 2024
CVE-2024-5587
5.3 MEDIUM

A vulnerability was found in Casdoor up to 1.335.0. It has been classified as problematic. Affected is an unknown function of the file /conf/app.conf of …

Jun 2, 2024
CVE-2024-4344
4.3 MEDIUM

The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, …

Jun 2, 2024
CVE-2024-35647
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Global Notification Bar allows Stored XSS.This issue affects Global Notification Bar: …

Jun 2, 2024
CVE-2024-35646
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Erez Hadas-Sonnenschein Smartarget Message Bar smartarget-message-bar.This issue affects Smartarget Message Bar: from n/a …

Jun 2, 2024
CVE-2024-35645
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar Random Banner random-banner allows DOM-Based XSS.This issue affects Random …

Jun 2, 2024
CVE-2024-4148
7.5 HIGH

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary application, version 1.2.10. An attacker can exploit this vulnerability by maliciously manipulating regular …

Jun 1, 2024
CVE-2024-5348
8.8 HIGH

The Elements For Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.1 via the 'beforeafter_layout' attribute …

Jun 1, 2024
CVE-2024-3821
7.3 HIGH

The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability …

Jun 1, 2024
CVE-2024-3820
10.0 CRITICAL

The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to SQL Injection via the 'id_key' parameter of …

Jun 1, 2024
CVE-2024-3200
9.9 CRITICAL

The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'slug' attribute of the 'wpforo' shortcode in all versions up to, and …

Jun 1, 2024
CVE-2024-35636
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Uploadcare Uploadcare File Uploader and Adaptive Delivery (beta) uploadcare.This issue affects Uploadcare File Uploader and Adaptive Delivery (beta): from …

Jun 1, 2024
CVE-2024-4958
7.1 HIGH

The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due …

Jun 1, 2024
CVE-2024-2295
6.4 MEDIUM

The Contact Form Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [xyz-cfm-form] shortcode in all versions up to, and including, …

Jun 1, 2024
CVE-2024-2506
6.4 MEDIUM

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS functionality …

Jun 1, 2024
CVE-2024-1324
5.3 MEDIUM

The QQWorld Auto Save Images plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the save_remote_images_get_auto_saved_results() function …

Jun 1, 2024
CVE-2024-5501
6.4 MEDIUM

The Supreme Modules Lite – Divi Theme, Extra Theme and Divi Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_one_id’ parameter …

Jun 1, 2024
CVE-2024-4342
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image hotspot, image accordion, off canvas, woogrid, …

Jun 1, 2024
CVE-2024-4087
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Back to Top widget in all versions …

Jun 1, 2024
CVE-2023-6382
6.4 MEDIUM

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_slide' shortcode in all versions up …

Jun 1, 2024
CVE-2024-3565
6.4 MEDIUM

The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'content_block' shortcode in all versions up to, …

Jun 1, 2024
CVE-2024-3564
8.8 HIGH

The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the …

Jun 1, 2024
CVE-2024-4711
6.4 MEDIUM

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ajax_load_more shortcode in versions up to, …

Jun 1, 2024
CVE-2024-2933
6.4 MEDIUM

The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Social Profiles widget in all versions up …

Jun 1, 2024
CVE-2024-5138
8.1 HIGH

The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. …

May 31, 2024
CVE-2024-34009
7.5 HIGH

Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not affect other pages where ReCAPTCHA …

May 31, 2024
CVE-2024-34008
8.8 HIGH

Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk.

May 31, 2024
CVE-2024-34007
8.8 HIGH

The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.

May 31, 2024
CVE-2024-34006
4.3 MEDIUM

The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered.

May 31, 2024
CVE-2024-34005
6.5 MEDIUM

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore database …

May 31, 2024
CVE-2024-34004
6.5 MEDIUM

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore wiki …

May 31, 2024
CVE-2024-34003
5.9 MEDIUM

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore workshop …

May 31, 2024
CVE-2024-34002
6.5 MEDIUM

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore feedback …

May 31, 2024
CVE-2024-36845
4.3 MEDIUM

An invalid pointer in the modbus_receive() function of libmodbus v3.1.6 allows attackers to cause a Denial of Service (DoS) via a crafted message sent to …

May 31, 2024
CVE-2024-36844
7.5 HIGH

libmodbus v3.1.6 was discovered to contain a use-after-free via the ctx->backend pointer. This vulnerability allows attackers to cause a Denial of Service (DoS) via a …

May 31, 2024
CVE-2024-36843
7.5 HIGH

libmodbus v3.1.6 was discovered to contain a heap overflow via the modbus_mapping_free() function.

May 31, 2024
CVE-2024-34001
8.4 HIGH

Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk.

May 31, 2024
CVE-2024-34000
4.3 MEDIUM

ID numbers displayed in the lesson overview report required additional sanitizing to prevent a stored XSS risk.

May 31, 2024
CVE-2024-33999
9.8 CRITICAL

The referrer URL used by MFA required additional sanitizing, rather than being used directly.

May 31, 2024
CVE-2024-33998
5.4 MEDIUM

Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features.

May 31, 2024
CVE-2024-33997
6.1 MEDIUM

Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation.

May 31, 2024
CVE-2024-33996
6.2 MEDIUM

Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not …

May 31, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.