CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4376
6.4 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fancy Text widget in all versions up to, …

May 31, 2024
CVE-2024-4205
4.3 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_template_content() function …

May 31, 2024
CVE-2024-36246
9.8 CRITICAL

Missing authorization vulnerability exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a result, …

May 31, 2024
CVE-2024-23847
5.9 MEDIUM

Incorrect default permissions issue exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a …

May 31, 2024
CVE-2024-2793
7.2 HIGH

The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Stored Cross-Site Scripting via comments in all versions up …

May 31, 2024
CVE-2024-37032
8.8 HIGH

Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the …

May 31, 2024
CVE-2024-5418
6.4 MEDIUM

The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slitems' attribute within the plugin's De Product Tab & Slide …

May 31, 2024
CVE-2024-5345
8.8 HIGH

The Responsive Owl Carousel for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2.0 via the …

May 31, 2024
CVE-2024-32850
9.8 CRITICAL

Improper neutralization of special elements used in a command ('Command Injection') exists in SkyBridge MB-A100/MB-A110 firmware Ver. 4.2.2 and earlier and SkyBridge BASIC MB-A130 firmware …

May 31, 2024
CVE-2024-37018
9.1 CRITICAL

The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the path that is taken by discovery packets.

May 31, 2024
CVE-2024-37017
8.1 HIGH

asdcplib (aka AS-DCP Lib) 2.13.1 has a heap-based buffer over-read in ASDCP::TimedText::MXFReader::h__Reader::MD_to_TimedText_TDesc in AS_DCP_TimedText.cpp in libasdcp.so.

May 31, 2024
CVE-2024-5499
8.8 HIGH

Out of bounds write in Streams API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary code inside a sandbox via …

May 30, 2024
CVE-2024-5498
8.8 HIGH

Use after free in Presentation API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

May 30, 2024
CVE-2024-5497
8.8 HIGH

Out of bounds memory access in Browser UI in Google Chrome prior to 125.0.6422.141 allowed a remote attacker who convinced a user to engage in …

May 30, 2024
CVE-2024-5496
8.8 HIGH

Use after free in Media Session in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary code inside a sandbox via a …

May 30, 2024
CVE-2024-5495
8.8 HIGH

Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

May 30, 2024
CVE-2024-5494
8.8 HIGH

Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

May 30, 2024
CVE-2024-5493
8.8 HIGH

Heap buffer overflow in WebRTC in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

May 30, 2024
CVE-2024-36119
1.8 LOW

Statamic is a, Laravel + Git powered CMS designed for building websites. In affected versions users registering via the `user:register_form` tag will have their password …

May 30, 2024
CVE-2024-1298
6.0 MEDIUM

EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A …

May 30, 2024
CVE-2024-5271
7.8 HIGH

Fuji Electric Monitouch V-SFT is vulnerable to an out-of-bounds write because of a type confusion, which could result in arbitrary code execution.

May 30, 2024
CVE-2024-35189
6.5 MEDIUM

Fides is an open-source privacy engineering platform. The Fides webserver has a number of endpoints that retrieve `ConnectionConfiguration` records and their associated `secrets` which _can_ …

May 30, 2024
CVE-2024-34171
7.8 HIGH

Fuji Electric Monitouch V-SFT is vulnerable to a stack-based buffer overflow, which could allow an attacker to execute arbitrary code.

May 30, 2024
CVE-2024-32877
4.2 MEDIUM

Yii 2 is a PHP application framework. During internal penetration testing of a product based on Yii2, users discovered a Cross-site Scripting (XSS) vulnerability within …

May 30, 2024
CVE-2024-35228
5.5 MEDIUM

Wagtail is an open source content management system built on Django. Due to an improperly applied permission check in the `wagtail.contrib.settings` module, a user with …

May 30, 2024
CVE-2024-35469
9.8 CRITICAL

A SQL injection vulnerability in /hrm/user/ in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.

May 30, 2024
CVE-2024-35468
5.4 MEDIUM

A SQL injection vulnerability in /hrm/index.php in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.

May 30, 2024
CVE-2024-35433
8.1 HIGH

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Incorrect Access Control. An authenticated user, without the permissions of managing users, can create a new admin user.

May 30, 2024
CVE-2024-2422
8.8 HIGH

LenelS2 NetBox access control and event monitoring system was discovered to contain an authenticated RCE in versions prior to and including 5.6.1, which allows an …

May 30, 2024
CVE-2024-2421
9.8 CRITICAL

LenelS2 NetBox access control and event monitoring system was discovered to contain an unauthenticated RCE in versions prior to and including 5.6.1, which allows an …

May 30, 2024
CVE-2024-2420
9.8 CRITICAL

LenelS2 NetBox access control and event monitoring system was discovered to contain Hardcoded Credentials in versions prior to and including 5.6.1 which allows an attacker …

May 30, 2024
CVE-2024-5537

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 30, 2024
CVE-2024-36118
3.5 LOW

MeterSphere is a test management and interface testing tool. In affected versions users without workspace permissions can view functional test cases of other workspaces beyond …

May 30, 2024
CVE-2024-35431
7.5 HIGH

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. NOTE: Third parties have …

May 30, 2024
CVE-2024-35429
6.5 MEDIUM

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via eventRecord.

May 30, 2024
CVE-2024-35428
7.1 HIGH

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via BaseMediaFile. An authenticated user can delete local files from the server which can lead to …

May 30, 2024
CVE-2024-35359
9.8 CRITICAL

A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=view_item. Manipulating the argument …

May 30, 2024
CVE-2024-35353
9.8 CRITICAL

A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Users.php?f=save. Manipulating the argument …

May 30, 2024
CVE-2024-35352
6.1 MEDIUM

A vulnerability has been discovered in Diño Physics School Assistant version 2.3. This vulnerability impacts unidentified code within the file /classes/Users.php?f=save. Manipulating the parameter middlename …

May 30, 2024
CVE-2024-35351
5.4 MEDIUM

A vulnerability has been discovered in Diño Physics School Assistant version 2.3. This vulnerability impacts unidentified code within the file /classes/SystemSettings.php?f=update_settings. Manipulating the parameter name …

May 30, 2024
CVE-2024-35350
9.8 CRITICAL

A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /admin/?page=borrow/view_borrow. Manipulating the argument …

May 30, 2024
CVE-2024-35349
9.8 CRITICAL

A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /admin/category/view_category.php. Manipulating the argument …

May 30, 2024
CVE-2024-5519
7.3 HIGH

A vulnerability classified as critical was found in ItsourceCode Learning Management System Project In PHP 1.0. This vulnerability affects unknown code of the file login.php. …

May 30, 2024
CVE-2024-5518
6.3 MEDIUM

A vulnerability classified as critical has been found in itsourcecode Online Discussion Forum 1.0. This affects an unknown part of the file change_profile_picture.php. The manipulation …

May 30, 2024
CVE-2024-3301
8.5 HIGH

An unsafe .NET object deserialization vulnerability in DELMIA Apriso Release 2019 through Release 2024 could lead to post-authentication remote code execution.

May 30, 2024
CVE-2024-3300
9.0 CRITICAL

An unsafe .NET object deserialization vulnerability in DELMIA Apriso Release 2019 through Release 2024 could lead to pre-authentication remote code execution.

May 30, 2024
CVE-2024-36959
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pinctrl: devicetree: fix refcount leak in pinctrl_dt_to_map() If we fail to allocate propname buffer, we …

May 30, 2024
CVE-2024-36958
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix nfsd4_encode_fattr4() crasher Ensure that args.acl is initialized early. It is used in an …

May 30, 2024
CVE-2024-36957
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: avoid off-by-one read from userspace We try to access count + 1 byte from …

May 30, 2024
CVE-2024-36956
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: thermal/debugfs: Free all thermal zone debug memory on zone removal Because thermal_debug_tz_remove() does not free …

May 30, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.