CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4783
6.4 MEDIUM

The jQuery T(-) Countdown Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's tminus shortcode in all versions up to, and …

May 23, 2024
CVE-2024-4486
6.4 MEDIUM

The Awesome Contact Form7 for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'AEP Contact Form 7' widget in all versions …

May 23, 2024
CVE-2024-3201
6.4 MEDIUM

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pp_link' shortcode in all versions up to, and …

May 23, 2024
CVE-2024-3065
4.4 MEDIUM

The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all …

May 23, 2024
CVE-2024-1855
5.3 MEDIUM

The WPCafe – Restaurant Menu, Online Ordering for WooCommerce, Pickup / Delivery and Table Reservation plugin for WordPress is vulnerable to Server-Side Request Forgery in …

May 23, 2024
CVE-2023-6844
5.0 MEDIUM

The iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to and including 5.0 due to …

May 23, 2024
CVE-2024-3708

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 23, 2024
CVE-2024-29853
7.8 HIGH

An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local privilege escalation.

May 22, 2024
CVE-2024-29852
2.7 LOW

Veeam Backup Enterprise Manager allows high-privileged users to read backup session logs.

May 22, 2024
CVE-2024-29851
7.2 HIGH

Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account.

May 22, 2024
CVE-2024-29850
8.8 HIGH

Veeam Backup Enterprise Manager allows account takeover via NTLM relay.

May 22, 2024
CVE-2024-29849
9.8 CRITICAL

Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.

May 22, 2024
CVE-2024-22026
6.7 MEDIUM

A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitrary commands on the appliance.

May 22, 2024
CVE-2023-46807
6.7 MEDIUM

An SQL Injection vulnerability in web component of EPMM before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify data in the …

May 22, 2024
CVE-2023-46806
6.7 MEDIUM

An SQL Injection vulnerability in a web component of EPMM versions before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify data …

May 22, 2024
CVE-2024-4454
7.8 HIGH

WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of WithSecure Elements Endpoint …

May 22, 2024
CVE-2024-4453
7.8 HIGH

GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction …

May 22, 2024
CVE-2024-4267
9.8 CRITICAL

A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically within the 'open_file' module, version 9.5. The vulnerability arises due to improper neutralization of …

May 22, 2024
CVE-2024-31895
4.3 MEDIUM

IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user information using an expired access token. IBM X-Force ID: …

May 22, 2024
CVE-2024-31894
4.3 MEDIUM

IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user information using an expired access token. IBM X-Force ID: …

May 22, 2024
CVE-2024-27264
7.4 HIGH

IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. …

May 22, 2024
CVE-2023-51637
9.8 CRITICAL

Sante PACS Server PG Patient Query SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

May 22, 2024
CVE-2023-51636
7.8 HIGH

Avira Prime Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avira Prime. An attacker must …

May 22, 2024
CVE-2024-35627
6.1 MEDIUM

tileserver-gl up to v4.4.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /data/v3/?key.

May 22, 2024
CVE-2024-31904
6.5 MEDIUM

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 integration nodes could allow an authenticated user to cause a denial of service due …

May 22, 2024
CVE-2024-31893
4.3 MEDIUM

IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive calendar information using an expired access token. IBM X-Force ID: …

May 22, 2024
CVE-2024-25738
9.1 CRITICAL

A Server-Side Request Forgery (SSRF) vulnerability in the /Upgrade/FixConfig route in Open Library Foundation VuFind 2.0 through 9.1 before 9.1.1 allows a remote attacker to …

May 22, 2024
CVE-2024-25737
5.4 MEDIUM

A Server-Side Request Forgery (SSRF) vulnerability in the /Cover/Show route (showAction in CoverController.php) in Open Library Foundation VuFind 2.4 through 9.1 before 9.1.1 allows remote …

May 22, 2024
CVE-2024-31617
5.3 MEDIUM

OpenLiteSpeed before 1.8.1 mishandles chunked encoding.

May 22, 2024
CVE-2024-29421
6.2 MEDIUM

xmedcon 0.23.0 and fixed in v.0.24.0 is vulnerable to Buffer Overflow via libs/dicom/basic.c which allows an attacker to execute arbitrary code.

May 22, 2024
CVE-2024-21791
4.7 MEDIUM

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection in lockout history option. Note: Non-admin users cannot exploit this vulnerability.

May 22, 2024
CVE-2024-20360
8.8 HIGH

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks …

May 22, 2024
CVE-2024-5166
6.5 MEDIUM

An Insecure Direct Object Reference in Google Cloud's Looker allowed metadata exposure across authenticated Looker users sharing the same LookML model.

May 22, 2024
CVE-2024-4563
6.1 MEDIUM

The Progress MOVEit Automation configuration export function prior to 2024.0.0 uses a cryptographic method with insufficient bit length.

May 22, 2024
CVE-2024-36077
8.8 HIGH

Qlik Sense Enterprise for Windows before 14.187.4 allows a remote attacker to elevate their privilege due to improper validation. The attacker can elevate their privilege …

May 22, 2024
CVE-2024-20363
5.8 MEDIUM

Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated, remote attacker to …

May 22, 2024
CVE-2024-20361
5.8 MEDIUM

A vulnerability in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker …

May 22, 2024
CVE-2024-20355
5.0 MEDIUM

A vulnerability in the implementation of SAML 2.0 single sign-on (SSO) for remote access VPN services in Cisco Adaptive Security Appliance (ASA) Software and Cisco …

May 22, 2024
CVE-2024-20293
5.8 MEDIUM

A vulnerability in the activation of an access control list (ACL) on Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software …

May 22, 2024
CVE-2024-20261
5.8 MEDIUM

A vulnerability in the file policy feature that is used to inspect encrypted archive files of Cisco Firepower Threat Defense (FTD) Software could allow an …

May 22, 2024
CVE-2023-20239

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 22, 2024
CVE-2024-5160
8.8 HIGH

Heap buffer overflow in Dawn in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory write via a …

May 22, 2024
CVE-2024-5159
8.8 HIGH

Heap buffer overflow in ANGLE in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory read via a …

May 22, 2024
CVE-2024-5158
8.1 HIGH

Type Confusion in V8 in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to potentially perform arbitrary read/write via a crafted HTML page. (Chromium …

May 22, 2024
CVE-2024-5157
8.8 HIGH

Use after free in Scheduling in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

May 22, 2024
CVE-2024-35362
5.4 MEDIUM

Ecshop 3.6 is vulnerable to Cross Site Scripting (XSS) via ecshop/article_cat.php.

May 22, 2024
CVE-2024-34448
8.8 HIGH

Ghost before 5.82.0 allows CSV Injection during a member CSV export.

May 22, 2024
CVE-2024-33228
8.4 HIGH

An issue in the component segwindrvx64.sys of Insyde Software Corp SEG Windows Driver v100.00.07.02 allows attackers to escalate privileges and execute arbitrary code via sending …

May 22, 2024
CVE-2024-33227
8.8 HIGH

An issue in the component ddcdrv.sys of Nicomsoft WinI2C/DDC v3.7.4.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

May 22, 2024
CVE-2024-33226
9.9 CRITICAL

An issue in the component Access64.sys of Wistron Corporation TBT Force Power Control v1.0.0.0 allows attackers to escalate privileges and execute arbitrary code via sending …

May 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.