CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-41821
5.0 MEDIUM

A an improper export vulnerability was reported in the Motorola Setup application that could allow a local attacker to read sensitive user information.

May 3, 2024
CVE-2023-41820
5.0 MEDIUM

An implicit intent vulnerability was reported in the Motorola Ready For application that could allow a local attacker to read information about connected Bluetooth audio …

May 3, 2024
CVE-2023-41819
6.1 MEDIUM

A PendingIntent hijacking vulnerability was reported in the Motorola Face Unlock application that could allow a local attacker to access unauthorized content providers.

May 3, 2024
CVE-2023-41818
5.0 MEDIUM

An improper use of the SD card for sensitive data vulnerability was reported in the Motorola Device Help application that could allow a local attacker …

May 3, 2024
CVE-2023-41817
2.8 LOW

An improper export vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read unauthorized information.

May 3, 2024
CVE-2023-41816
5.0 MEDIUM

An improper export vulnerability was reported in the Motorola Services Main application that could allow a local attacker to write to a local database.

May 3, 2024
CVE-2024-33787
8.2 HIGH

Hengan Weighing Management Information Query Platform 2019-2021 53.25 was discovered to contain a SQL injection vulnerability via the tuser_Number parameter at search_user.aspx.

May 3, 2024
CVE-2024-33786
9.8 CRITICAL

An arbitrary file upload vulnerability in Zhongcheng Kexin Ticketing Management Platform 20.04 allows attackers to execute arbitrary code via uploading a crafted file.

May 3, 2024
CVE-2024-2410
7.6 HIGH

The JsonToBinaryStream() function is part of the protocol buffers C++ implementation and is used to parse JSON from a stream. If the input is broken …

May 3, 2024
CVE-2024-4466
9.8 CRITICAL

SQL injection vulnerability in Gescen on the centrosdigitales.net platform. This vulnerability allows an attacker to send a specially crafted SQL query to the pass parameter …

May 3, 2024
CVE-2024-4461
7.8 HIGH

Unquoted path or search item vulnerability in SugarSync versions prior to 4.1.3 for Windows. This misconfiguration could allow an unauthorized local user to inject arbitrary …

May 3, 2024
CVE-2024-34073
7.8 HIGH

sagemaker-python-sdk is a library for training and deploying machine learning models on Amazon SageMaker. In affected versions the capture_dependencies function in `sagemaker.serve.save_retrive.version_1_0_0.save.utils` module allows for …

May 3, 2024
CVE-2024-34072
7.8 HIGH

sagemaker-python-sdk is a library for training and deploying machine learning models on Amazon SageMaker. The sagemaker.base_deserializers.NumpyDeserializer module before v2.218.0 allows potentially unsafe deserialization when untrusted …

May 3, 2024
CVE-2024-34063
2.5 LOW

vodozemac is an implementation of Olm and Megolm in pure Rust. Versions 0.5.0 and 0.5.1 of vodozemac have degraded secret zeroization capabilities, due to changes …

May 3, 2024
CVE-2024-34062
4.8 MEDIUM

tqdm is an open source progress bar for Python and CLI. Any optional non-boolean CLI arguments (e.g. `--delim`, `--buf-size`, `--manpath`) are passed through python's `eval`, …

May 3, 2024
CVE-2024-32986
9.6 CRITICAL

PWAsForFirefox is a tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox. Due to improper sanitization of web app properties (such …

May 3, 2024
CVE-2024-33937
4.3 MEDIUM

Missing Authorization vulnerability in Nico Martin Progressive WordPress (PWA).This issue affects Progressive WordPress (PWA): from n/a through 2.1.13.

May 3, 2024
CVE-2024-33931
6.5 MEDIUM

Missing Authorization vulnerability in ilGhera JW Player for WordPress.This issue affects JW Player for WordPress: from n/a through 2.3.3.

May 3, 2024
CVE-2024-33929
5.3 MEDIUM

Missing Authorization vulnerability in wpWax Directorist.This issue affects Directorist: from n/a through 7.8.6.

May 3, 2024
CVE-2024-33925
4.3 MEDIUM

Missing Authorization vulnerability in Adrian Mörchen Embed Google Fonts.This issue affects Embed Google Fonts: from n/a through 3.1.0.

May 3, 2024
CVE-2024-33923
6.3 MEDIUM

Missing Authorization vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager : from n/a through 4.69.

May 3, 2024
CVE-2024-33921
4.3 MEDIUM

Broken Access Control vulnerability in ReviewX.This issue affects ReviewX: from n/a through 1.6.21.

May 3, 2024
CVE-2024-33920
5.3 MEDIUM

Missing Authorization vulnerability in Kama Democracy Poll.This issue affects Democracy Poll: from n/a through 6.0.3.

May 3, 2024
CVE-2024-33919
6.5 MEDIUM

Missing Authorization vulnerability in Rometheme RomethemeKit For Elementor.This issue affects RomethemeKit For Elementor: from n/a through 1.4.1.

May 3, 2024
CVE-2024-33915
4.3 MEDIUM

Missing Authorization vulnerability in Bowo Debug Log Manager.This issue affects Debug Log Manager: from n/a through 2.3.1.

May 3, 2024
CVE-2024-33914
4.3 MEDIUM

Missing Authorization vulnerability in Exclusive Addons Exclusive Addons Elementor.This issue affects Exclusive Addons Elementor: from n/a through 2.6.9.1.

May 3, 2024
CVE-2024-23914
5.7 MEDIUM

Use of Externally-Controlled Format String vulnerability in Merge DICOM Toolkit C/C++ on Windows. When MC_Open_Association() function is used to open DICOM Association and gets DICOM …

May 3, 2024
CVE-2024-23913
4.0 MEDIUM

Use of Out-of-range Pointer Offset vulnerability in Merge DICOM Toolkit C/C++ on Windows. When deprecated MC_XML_To_Message() function is used to read a malformed DICOM XML …

May 3, 2024
CVE-2024-23912
4.0 MEDIUM

Out-of-bounds Read vulnerability in Merge DICOM Toolkit C/C++ on Windows. When MC_Open_File() function is used to read a malformed DICOM data, it might result in …

May 3, 2024
CVE-2023-35701
6.6 MEDIUM

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Hive. The vulnerability affects the Hive JDBC driver component and it can potentially lead …

May 3, 2024
CVE-2024-33941
5.3 MEDIUM

Missing Authorization vulnerability in Avirtum iPanorama 360 WordPress Virtual Tour Builder.This issue affects iPanorama 360 WordPress Virtual Tour Builder: from n/a through 1.8.1.

May 3, 2024
CVE-2024-33927
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team GIPHY Giphypress allows Stored XSS.This issue affects Giphypress: from n/a through 1.6.2.

May 3, 2024
CVE-2024-33926
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Karl Kiesinger GWP-Histats allows Stored XSS.This issue affects GWP-Histats: from n/a through 1.0.

May 3, 2024
CVE-2024-33924
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Realtyna Realtyna Organic IDX plugin allows Reflected XSS.This issue affects Realtyna Organic IDX …

May 3, 2024
CVE-2024-33918
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maxim K AJAX Login and Registration modal popup + inline form allows Stored …

May 3, 2024
CVE-2024-33916
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MachoThemes CPO Companion allows Stored XSS.This issue affects CPO Companion: from n/a through …

May 3, 2024
CVE-2024-32831
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lorna Timbah (webgrrrl) Accessibility Widget allows Stored XSS.This issue affects Accessibility Widget: from …

May 3, 2024
CVE-2024-32810
7.6 HIGH

Missing Authorization vulnerability in ShortPixel ShortPixel Critical CSS.This issue affects ShortPixel Critical CSS: from n/a through 1.0.2.

May 3, 2024
CVE-2024-28072
5.7 MEDIUM

A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly.

May 3, 2024
CVE-2024-24710
4.3 MEDIUM

Missing Authorization vulnerability in SlickRemix Feed Them Social.This issue affects Feed Them Social: from n/a through 4.2.0.

May 3, 2024
CVE-2023-44472
4.3 MEDIUM

Missing Authorization vulnerability in ThemeFuse Unyson.This issue affects Unyson: from n/a through 2.7.28.

May 3, 2024
CVE-2023-25457
5.3 MEDIUM

Missing Authorization vulnerability in Richteam Slider Carousel – Responsive Image Slider.This issue affects Slider Carousel – Responsive Image Slider: from n/a through 1.5.1.

May 3, 2024
CVE-2024-33947
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic allows Reflected XSS.This issue affects RegistrationMagic: from n/a through 5.3.2.0.

May 3, 2024
CVE-2024-33946
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPify s.R.O. WPify Woo Czech allows Reflected XSS.This issue affects WPify Woo Czech: …

May 3, 2024
CVE-2024-33945
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in solverwp.Com Eleblog – Elementor Blog And Magazine Addons allows Stored XSS.This issue affects …

May 3, 2024
CVE-2024-33943
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyKite Ultimate Under Construction allows Stored XSS.This issue affects Ultimate Under Construction: from …

May 3, 2024
CVE-2024-33940
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ashan Jay EventON allows Stored XSS.This issue affects EventON: from n/a through 2.2.14.

May 3, 2024
CVE-2024-33936
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Twinpictures Print-O-Matic allows Stored XSS.This issue affects Print-O-Matic: from n/a through 2.1.10.

May 3, 2024
CVE-2024-33935
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pascal Bajorat PB MailCrypt allows Stored XSS.This issue affects PB MailCrypt: from n/a …

May 3, 2024
CVE-2024-33934
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kailey Lampert Mini Loops allows Stored XSS.This issue affects Mini Loops: from n/a …

May 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.