CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-26923
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix garbage collector racing against connect() Garbage collector does not take into account the …

Apr 25, 2024
CVE-2024-23527
7.5 HIGH

An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information …

Apr 25, 2024
CVE-2024-20313
7.4 HIGH

A vulnerability in the OSPF version 2 (OSPFv2) feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause an affected device …

Apr 24, 2024
CVE-2023-20249
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) Software could allow an authenticated, remote attacker to conduct a cross-site scripting …

Apr 24, 2024
CVE-2023-20248
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) Software could allow an authenticated, remote attacker to conduct a cross-site scripting …

Apr 24, 2024
CVE-2024-4127
8.8 HIGH

A vulnerability was found in Tenda W15E 15.11.0.14. It has been classified as critical. Affected is the function guestWifiRuleRefresh. The manipulation of the argument qosGuestDownstream …

Apr 24, 2024
CVE-2024-4126
8.8 HIGH

A vulnerability was found in Tenda W15E 15.11.0.14 and classified as critical. This issue affects the function formSetSysTime of the file /goform/SetSysTimeCfg. The manipulation of …

Apr 24, 2024
CVE-2024-32879
4.9 MEDIUM

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.4.1, due to default case-insensitive collation in MySQL or MariaDB databases, third-party authentication user …

Apr 24, 2024
CVE-2024-20358
6.0 MEDIUM

A vulnerability in the Cisco Adaptive Security Appliance (ASA) restore functionality that is available in Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software …

Apr 24, 2024
CVE-2024-20356
8.7 HIGH

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker with Administrator-level privileges to perform command …

Apr 24, 2024
CVE-2024-20295
8.8 HIGH

A vulnerability in the CLI of the Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to perform command injection attacks on the …

Apr 24, 2024
CVE-2024-4141
2.9 LOW

Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid character code in a Type 1 font. The root problem was a bounds …

Apr 24, 2024
CVE-2024-4125
8.8 HIGH

A vulnerability has been found in Tenda W15E 15.11.0.14 and classified as critical. This vulnerability affects the function formSetStaticRoute of the file /goform/setStaticRoute. The manipulation …

Apr 24, 2024
CVE-2024-4124
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda W15E 15.11.0.14. This affects the function formSetRemoteWebManage of the file /goform/SetRemoteWebManage. The manipulation of …

Apr 24, 2024
CVE-2024-4123
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda W15E 15.11.0.14. Affected by this issue is the function formSetPortMapping of the file …

Apr 24, 2024
CVE-2024-32876
8.5 HIGH

NewPipe is an Android app for video streaming written in Java. It supports exporting and importing backups, as a way to let users move their …

Apr 24, 2024
CVE-2024-20359
6.0 MEDIUM KEV

A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security …

Apr 24, 2024
CVE-2024-20353
8.6 HIGH KEV

A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow …

Apr 24, 2024
CVE-2024-4122
8.8 HIGH

A vulnerability classified as critical was found in Tenda W15E 15.11.0.14. Affected by this vulnerability is the function formSetDebugCfg of the file /goform/setDebugCfg. The manipulation …

Apr 24, 2024
CVE-2024-4121
8.8 HIGH

A vulnerability classified as critical has been found in Tenda W15E 15.11.0.14. Affected is the function formQOSRuleDel. The manipulation of the argument qosIndex leads to …

Apr 24, 2024
CVE-2024-4120
8.8 HIGH

A vulnerability was found in Tenda W15E 15.11.0.14. It has been rated as critical. This issue affects the function formIPMacBindModify of the file /goform/modifyIpMacBind. The …

Apr 24, 2024
CVE-2024-0151
6.5 MEDIUM

Insufficient argument checking in Secure state Entry functions in software using Cortex-M Security Extensions (CMSE), that has been compiled using toolchains that implement 'Arm v8-M …

Apr 24, 2024
CVE-2024-4119
8.8 HIGH

A vulnerability was found in Tenda W15E 15.11.0.14. It has been declared as critical. This vulnerability affects the function formIPMacBindDel of the file /goform/delIpMacBind. The …

Apr 24, 2024
CVE-2024-4118
8.8 HIGH

A vulnerability was found in Tenda W15E 15.11.0.14. It has been classified as critical. This affects the function formIPMacBindAdd of the file /goform/addIpMacBind. The manipulation …

Apr 24, 2024
CVE-2024-3371
7.1 HIGH

MongoDB Compass may accept and use insufficiently validated input from an untrusted external source. This may cause unintended application behavior, including data disclosure and enabling …

Apr 24, 2024
CVE-2024-27791
7.1 HIGH

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, …

Apr 24, 2024
CVE-2024-23271
6.5 MEDIUM

A logic issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, …

Apr 24, 2024
CVE-2024-23228
3.3 LOW

This issue was addressed through improved state management. This issue is fixed in iOS 17.3 and iPadOS 17.3. Locked Notes content may have been unexpectedly …

Apr 24, 2024
CVE-2023-51477
9.8 CRITICAL

Improper Authentication vulnerability in BUDDYBOSS DMCC BuddyBoss Theme allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BuddyBoss Theme: from n/a through 2.4.60.

Apr 24, 2024
CVE-2023-51472
9.8 CRITICAL

Improper Authentication vulnerability in Mestres do WP Checkout Mestres WP allows Privilege Escalation.This issue affects Checkout Mestres WP: from n/a through 7.1.9.7.

Apr 24, 2024
CVE-2023-51471
8.2 HIGH

Improper Authentication vulnerability in Mestres do WP Checkout Mestres WP allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Checkout Mestres WP: from n/a …

Apr 24, 2024
CVE-2024-4117
8.8 HIGH

A vulnerability was found in Tenda W15E 15.11.0.14 and classified as critical. Affected by this issue is the function formDelPortMapping of the file /goform/DelPortMapping. The …

Apr 24, 2024
CVE-2024-4116
8.8 HIGH

A vulnerability has been found in Tenda W15E 15.11.0.14 and classified as critical. Affected by this vulnerability is the function formDelDhcpRule of the file /goform/DelDhcpRule. …

Apr 24, 2024
CVE-2024-4115
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda W15E 15.11.0.14. Affected is the function formAddDnsForward of the file /goform/AddDnsForward. The manipulation of …

Apr 24, 2024
CVE-2024-32678
5.3 MEDIUM

Missing Authorization vulnerability in TrackShip TrackShip for WooCommerce.This issue affects TrackShip for WooCommerce: from n/a through 1.7.5.

Apr 24, 2024
CVE-2024-32677
5.3 MEDIUM

Missing Authorization vulnerability in LoginPress LoginPress Pro.This issue affects LoginPress Pro: from n/a before 3.0.0.

Apr 24, 2024
CVE-2024-32675
6.5 MEDIUM

Missing Authorization vulnerability in Xfinity Soft Order Limit for WooCommerce.This issue affects Order Limit for WooCommerce: from n/a through 2.0.0.

Apr 24, 2024
CVE-2024-32432
4.3 MEDIUM

Missing Authorization vulnerability in Ovic Team Ovic Addon Toolkit.This issue affects Ovic Addon Toolkit: from n/a through 2.6.1.

Apr 24, 2024
CVE-2024-32078
4.1 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Foliovision FV Flowplayer Video Player.This issue affects FV Flowplayer Video Player: from n/a through 7.5.44.7212.

Apr 24, 2024
CVE-2023-51425
9.8 CRITICAL

Improper Privilege Management vulnerability in Jacques Malgrange Rencontre – Dating Site allows Privilege Escalation.This issue affects Rencontre – Dating Site: from n/a through 3.10.1.

Apr 24, 2024
CVE-2023-51405
8.2 HIGH

Improper Authentication vulnerability in Repute Infosystems BookingPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BookingPress: from n/a through 1.0.74.

Apr 24, 2024
CVE-2023-48763
5.3 MEDIUM

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in Crocoblock JetFormBuilder allows Code Injection.This issue affects JetFormBuilder: from n/a through …

Apr 24, 2024
CVE-2023-47774
5.4 MEDIUM

Improper Restriction of Rendered UI Layers or Frames vulnerability in Automattic Jetpack allows Clickjacking.This issue affects Jetpack: from n/a before 12.7.

Apr 24, 2024
CVE-2023-47504
6.5 MEDIUM

Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elementor Website Builder: from n/a through 3.16.4.

Apr 24, 2024
CVE-2023-32127
5.3 MEDIUM

Missing Authorization vulnerability in Daniel Powney Multi Rating allows Functionality Misuse.This issue affects Multi Rating: from n/a through 5.0.6.

Apr 24, 2024
CVE-2023-31090
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Upload a Web Shell to …

Apr 24, 2024
CVE-2023-25790
5.3 MEDIUM

Improper Authentication, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xtemos WoodMart allows Cross-Site Scripting (XSS).This issue affects WoodMart: from n/a …

Apr 24, 2024
CVE-2024-4114
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda TX9 22.03.02.10. This issue affects the function sub_42C014 of the file /goform/PowerSaveSet. The …

Apr 24, 2024
CVE-2024-4113
8.8 HIGH

A vulnerability classified as critical was found in Tenda TX9 22.03.02.10. This vulnerability affects the function sub_42D4DC of the file /goform/SetSysTimeCfg. The manipulation of the …

Apr 24, 2024
CVE-2024-4112
8.8 HIGH

A vulnerability classified as critical has been found in Tenda TX9 22.03.02.10. This affects the function sub_42CB94 of the file /goform/SetVirtualServerCfg. The manipulation of the …

Apr 24, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.