CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-31211
5.5 MEDIUM

WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows for code execution via its `__destruct()` magic method. …

Apr 4, 2024
CVE-2024-31210
7.6 HIGH

WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted …

Apr 4, 2024
CVE-2024-31206
8.2 HIGH

dectalk-tts is a Node package to interact with the aeiou Dectalk web API. In `[email protected]`, network requests to the third-party API are sent over HTTP, …

Apr 4, 2024
CVE-2024-27981
9.8 CRITICAL

A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.0.28 and earlier) allows a malicious actor with …

Apr 4, 2024
CVE-2024-21894
9.8 CRITICAL

A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially …

Apr 4, 2024
CVE-2024-3316
6.3 MEDIUM

A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Apr 4, 2024
CVE-2024-29981
4.3 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Apr 4, 2024
CVE-2024-29049
4.1 MEDIUM

Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability

Apr 4, 2024
CVE-2024-3315
6.3 MEDIUM

A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Apr 4, 2024
CVE-2024-3314
6.3 MEDIUM

A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Users.php. …

Apr 4, 2024
CVE-2024-3311
6.3 MEDIUM

A vulnerability was found in Dreamer CMS up to 4.1.3.0. It has been declared as critical. Affected by this vulnerability is the function ZipUtils.unZipFiles of …

Apr 4, 2024
CVE-2024-31204
6.1 MEDIUM

mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identified in mailcow affecting versions prior to 2024-04. This …

Apr 4, 2024
CVE-2024-30270
6.2 MEDIUM

mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identified in mailcow affecting versions prior to 2024-04. This …

Apr 4, 2024
CVE-2024-30264
8.1 HIGH

Typebot is an open-source chatbot builder. A reflected cross-site scripting (XSS) in the sign-in page of typebot.io prior to version 2.24.0 may allow an attacker …

Apr 4, 2024
CVE-2023-45288
7.5 HIGH

An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state …

Apr 4, 2024
CVE-2024-30255
5.3 MEDIUM

Envoy is a cloud-native, open source edge and service proxy. The HTTP/2 protocol stack in Envoy versions prior to 1.29.3, 1.28.2, 1.27.4, and 1.26.8 are …

Apr 4, 2024
CVE-2024-29387
8.8 HIGH

projeqtor up to 11.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /view/print.php.

Apr 4, 2024
CVE-2024-29386
5.4 MEDIUM

projeqtor up to 11.2.0 was discovered to contain a SQL injection vulnerability via the component /view/criticalResourceExport.php.

Apr 4, 2024
CVE-2024-27316
7.5 HIGH

HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not …

Apr 4, 2024
CVE-2024-24795
6.3 MEDIUM

HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an …

Apr 4, 2024
CVE-2024-22053
8.2 HIGH

A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially …

Apr 4, 2024
CVE-2024-22052
7.5 HIGH

A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send …

Apr 4, 2024
CVE-2024-22023
5.3 MEDIUM

An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated attacker to …

Apr 4, 2024
CVE-2023-38709
7.3 HIGH

Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through …

Apr 4, 2024
CVE-2024-30254
5.8 MEDIUM

MesonLSP is an unofficial, unendorsed language server for meson written in C++. A vulnerability in versions prior to 4.1.4 allows overwriting arbitrary files if the …

Apr 4, 2024
CVE-2024-30252
2.6 LOW

Livemarks is a browser extension that provides RSS feed bookmark folders. Versions of Livemarks prior to 3.7 are vulnerable to cross-site request forgery. A malicious …

Apr 4, 2024
CVE-2024-30249
8.6 HIGH

Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.0.0.CR1-20240330.101522-15` impacts publicly accessible software depending on the affected versions …

Apr 4, 2024
CVE-2024-29193
6.1 MEDIUM

gotortc is a camera streaming application. Versions 1.8.5 and prior are vulnerable to DOM-based cross-site scripting. The index page (`index.html`) shows the available streams by …

Apr 4, 2024
CVE-2024-25007
7.1 HIGH

Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application log where Improper Neutralization of Formula Elements in …

Apr 4, 2024
CVE-2024-2660
6.4 MEDIUM

Vault and Vault Enterprise TLS certificates auth method did not correctly validate OCSP responses when one or more OCSP sources were configured. This vulnerability, CVE-2024-2660, …

Apr 4, 2024
CVE-2024-29192
8.8 HIGH

gotortc is a camera streaming application. Versions 1.8.5 and prior are vulnerable to Cross-Site Request Forgery. The `/api/config` endpoint allows one to modify the existing …

Apr 4, 2024
CVE-2024-28787
8.7 HIGH

IBM Security Verify Access 10.0.0 through 10.0.7 and IBM Application Gateway 20.01 through 24.03 could allow a remote attacker to obtain highly sensitive private information …

Apr 4, 2024
CVE-2024-27268
5.9 MEDIUM

IBM WebSphere Application Server Liberty 18.0.0.2 through 24.0.0.4 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker …

Apr 4, 2024
CVE-2024-25709
6.1 MEDIUM

There is a stored Cross‑Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.2 and below that may allow a remote, authenticated attacker to …

Apr 4, 2024
CVE-2024-25708
4.8 MEDIUM

There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 10.9.1 and below that may allow a remote, …

Apr 4, 2024
CVE-2024-25706
6.1 MEDIUM

There is an HTML injection vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL …

Apr 4, 2024
CVE-2024-25705
5.4 MEDIUM

There is a cross‑site scripting (XSS) vulnerability in Esri Portal for ArcGIS Experience Builder versions 11.1 and below on Windows and Linux that allows a …

Apr 4, 2024
CVE-2024-25704

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because this item is scheduled to be patched at a …

Apr 4, 2024
CVE-2024-25703

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because this item is scheduled to be patched at a …

Apr 4, 2024
CVE-2024-25700
4.8 MEDIUM

There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 11.1 and below that may allow a remote, …

Apr 4, 2024
CVE-2024-25699
8.5 HIGH

There is a difficult‑to‑exploit improper authentication issue in the Home application for Esri Portal for ArcGIS versions 11.2 and below on Windows and Linux, and …

Apr 4, 2024
CVE-2024-25698
6.1 MEDIUM

There is a reflected cross site scripting vulnerability in the home application in Esri Portal for ArcGIS 11.1 and below on Windows and Linux that …

Apr 4, 2024
CVE-2024-25697
5.4 MEDIUM

There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.1 and below that may allow a remote, authenticated attacker to create a …

Apr 4, 2024
CVE-2024-25696
4.8 MEDIUM

There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.0 and below that may allow a remote, authenticated attacker to create a …

Apr 4, 2024
CVE-2024-25695
7.2 HIGH

There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.2 and below that may allow a remote, authenticated attacker to provide input …

Apr 4, 2024
CVE-2024-25693
9.9 CRITICAL

There is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote, authenticated attacker to traverse the file …

Apr 4, 2024
CVE-2024-25692
5.4 MEDIUM

There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.1 and below that may in some cases allow a remote, unauthenticated attacker …

Apr 4, 2024
CVE-2024-25690
4.7 MEDIUM

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.1 and below that may allow a remote, unauthenticated attacker to create a …

Apr 4, 2024
CVE-2024-30263
7.7 HIGH

macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Users with edit rights can access restricted PDF attachments using the PDF Viewer macro, …

Apr 4, 2024
CVE-2023-3454
8.6 HIGH

Remote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to execute arbitrary code and use this …

Apr 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.