CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-34905
7.5 HIGH

FlyFish v3.0.0 was discovered to contain a buffer overflow via the password parameter on the login page. This vulnerability allows attackers to cause a Denial …

May 16, 2024
CVE-2024-34582
6.1 MEDIUM

Sunhillo SureLine through 8.10.0 on RICI 5000 devices allows cgi/usrPasswd.cgi userid_change XSS within the Forgot Password feature.

May 16, 2024
CVE-2024-31142
7.5 HIGH

Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intended to be used. XSA-434 (Speculative …

May 16, 2024
CVE-2024-20389
7.8 HIGH

A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attacker to read and write …

May 16, 2024
CVE-2024-20326
7.8 HIGH

A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attacker to read and write …

May 16, 2024
CVE-2023-46842
6.5 MEDIUM

Unlike 32-bit PV guests, HVM guests may switch freely between 64-bit and other modes. This in particular means that they may set registers used to …

May 16, 2024
CVE-2024-4999

A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote attacker to execute arbitrary commands with elevated privileges.This issue …

May 16, 2024
CVE-2024-4760
6.3 MEDIUM

A voltage glitch during the startup of EEFC NVM controllers on Microchip SAM E70/S70/V70/V71, SAM G55, SAM 4C/4S/4N/4E, and SAM 3S/3N/3U microcontrollers allows access to …

May 16, 2024
CVE-2024-4993
6.3 MEDIUM

Vulnerability in SiAdmin 1.1 that allows XSS via the /show.php query parameter. This vulnerability could allow a remote attacker to send a specially crafted URL …

May 16, 2024
CVE-2024-4992
9.8 CRITICAL

Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_kuliah/aksi_kuliah.php parameter in nim. This vulnerability could allow a remote attacker to send a specially …

May 16, 2024
CVE-2024-4991
9.8 CRITICAL

Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_pass/aksi_pass.php parameter in nama_lengkap. This vulnerability could allow a remote attacker to send a specially …

May 16, 2024
CVE-2024-4826
9.8 CRITICAL

SQL injection vulnerability in Simple PHP Shopping Cart affecting version 0.9. This vulnerability could allow an attacker to retrieve all the information stored in the …

May 16, 2024
CVE-2024-4580
6.4 MEDIUM

The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters …

May 16, 2024
CVE-2024-30314
7.8 HIGH

Dreamweaver Desktop versions 21.3 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that …

May 16, 2024
CVE-2024-30292
7.8 HIGH

Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

May 16, 2024
CVE-2024-30291
7.8 HIGH

Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

May 16, 2024
CVE-2024-30290
7.8 HIGH

Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

May 16, 2024
CVE-2024-30289
7.8 HIGH

Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

May 16, 2024
CVE-2024-30288
7.8 HIGH

Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

May 16, 2024
CVE-2024-30287
5.5 MEDIUM

Adobe Framemaker versions 2020.5, 2022.3 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

May 16, 2024
CVE-2024-30286
5.5 MEDIUM

Adobe Framemaker versions 2020.5, 2022.3 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

May 16, 2024
CVE-2024-30283
5.5 MEDIUM

Adobe Framemaker versions 2020.5, 2022.3 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

May 16, 2024
CVE-2024-4838
7.5 HIGH

The ConvertPlus plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.26 via deserialization of untrusted input from …

May 16, 2024
CVE-2024-4634
6.4 MEDIUM

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hfe_svg_mime_types’ function in versions up to, and including, …

May 16, 2024
CVE-2024-4617
6.4 MEDIUM

The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in versions up …

May 16, 2024
CVE-2024-4400
6.4 MEDIUM

The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plguin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown …

May 16, 2024
CVE-2024-4385
6.4 MEDIUM

The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 1.8.16 due to insufficient …

May 16, 2024
CVE-2024-4288
6.4 MEDIUM

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in versions …

May 16, 2024
CVE-2024-35302
5.4 MEDIUM

In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible

May 16, 2024
CVE-2024-35301
5.5 MEDIUM

In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token

May 16, 2024
CVE-2024-35300
3.5 LOW

In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible

May 16, 2024
CVE-2024-35299
5.9 MEDIUM

In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation

May 16, 2024
CVE-2024-4975
3.5 LOW

A vulnerability, which was classified as problematic, has been found in code-projects Simple Chat System 1.0. This issue affects some unknown processing of the component …

May 16, 2024
CVE-2024-4974
3.5 LOW

A vulnerability, which was classified as problematic, was found in code-projects Simple Chat System 1.0. Affected is an unknown function of the file /register.php. The …

May 16, 2024
CVE-2024-4973
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Simple Chat System 1.0. This vulnerability affects unknown code of the file /register.php. The manipulation of …

May 16, 2024
CVE-2024-4352
8.8 HIGH

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability …

May 16, 2024
CVE-2024-4351
8.8 HIGH

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability …

May 16, 2024
CVE-2024-4222
7.3 HIGH

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability …

May 16, 2024
CVE-2024-4972
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Simple Chat System 1.0. This affects an unknown part of the file /login.php. The manipulation …

May 16, 2024
CVE-2024-4968
3.5 LOW

A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality …

May 16, 2024
CVE-2024-4967
6.3 MEDIUM

A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

May 16, 2024
CVE-2024-4642

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 16, 2024
CVE-2024-4391
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Event Calendar widget in all versions up to, …

May 16, 2024
CVE-2024-4326
9.8 CRITICAL

A vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulnerability stems from insufficient protection of the `/apply_settings` and …

May 16, 2024
CVE-2024-4322
7.5 HIGH

A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `/list_personalities` endpoint. By manipulating the `category` parameter, an attacker can traverse the directory …

May 16, 2024
CVE-2024-4321
7.5 HIGH

A Local File Inclusion (LFI) vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically within the functionality for uploading chat history. The vulnerability arises due to improper …

May 16, 2024
CVE-2024-4263
5.4 MEDIUM

A broken access control vulnerability exists in mlflow/mlflow versions before 2.10.1, where low privilege users with only EDIT permissions on an experiment can delete any …

May 16, 2024
CVE-2024-4223
9.8 CRITICAL

The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check …

May 16, 2024
CVE-2024-4181
8.8 HIGH

A command injection vulnerability exists in the RunGptLLM class of the llama_index library, version 0.9.47, used by the RunGpt framework from JinaAI to connect to …

May 16, 2024
CVE-2024-4078
9.8 CRITICAL

A vulnerability in the parisneo/lollms, specifically in the `/unInstall_binding` endpoint, allows for arbitrary code execution due to insufficient sanitization of user input. The issue arises …

May 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.