CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-26785
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix protection fault in iommufd_test_syz_conv_iova Syzkaller reported the following bug: general protection fault, probably …

Apr 4, 2024
CVE-2024-26784
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pmdomain: arm: Fix NULL dereference on scmi_perf_domain removal On unloading of the scmi_perf_domain module got …

Apr 4, 2024
CVE-2024-26783
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/vmscan: fix a bug calling wakeup_kswapd() with a wrong zone index With numa balancing on, …

Apr 4, 2024
CVE-2024-26782
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix double-free on socket dismantle when MPTCP server accepts an incoming connection, it clones …

Apr 4, 2024
CVE-2024-26781
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix possible deadlock in subflow diag Syzbot and Eric reported a lockdep splat in …

Apr 4, 2024
CVE-2024-26780
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix task hung while purging oob_skb in GC. syzbot reported a task hung; at …

Apr 4, 2024
CVE-2024-26750
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: af_unix: Drop oob_skb ref before purging queue in GC. syzbot reported another task hung in …

Apr 4, 2024
CVE-2024-26746
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Ensure safe user copy of completion record If CONFIG_HARDENED_USERCOPY is enabled, copying completion …

Apr 4, 2024
CVE-2024-26745
4.4 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries/iommu: IOMMU table is not initialized for kdump over SR-IOV When kdump kernel tries to …

Apr 4, 2024
CVE-2024-20800
5.4 MEDIUM

Adobe Experience Manager versions 6.5.19 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to …

Apr 4, 2024
CVE-2023-36645
9.1 CRITICAL

SQL injection vulnerability in ITB-GmbH TradePro v9.5, allows remote attackers to run SQL queries via oordershow component in customer function.

Apr 4, 2024
CVE-2023-36644
7.5 HIGH

Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all order confirmations from the online shop via the printmail plugin.

Apr 4, 2024
CVE-2023-36643
7.5 HIGH

Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all orders from the online shop via oordershow component in customer function.

Apr 4, 2024
CVE-2024-30565
8.8 HIGH

An issue was discovered in SeaCMS version 12.9, allows remote attackers to execute arbitrary code via admin notify.php.

Apr 4, 2024
CVE-2024-29008
6.4 MEDIUM

A problem has been identified in the CloudStack additional VM configuration (extraconfig) feature which can be misused by anyone who has privilege to deploy a …

Apr 4, 2024
CVE-2024-29007
7.3 HIGH

The CloudStack management server and secondary storage VM could be tricked into making requests to restricted or random resources by means of following 301 HTTP …

Apr 4, 2024
CVE-2024-29006
9.8 CRITICAL

By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it as the source IP of an API request. This could lead …

Apr 4, 2024
CVE-2024-25503
4.7 MEDIUM

Cross Site Scripting (XSS) vulnerability in Advanced REST Client v.17.0.9 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted …

Apr 4, 2024
CVE-2020-25730
8.2 HIGH

Cross Site Scripting (XSS) vulnerability in ZoneMinder before version 1.34.21, allows remote attackers execute arbitrary code, escalate privileges, and obtain sensitive information via PHP_SELF component …

Apr 4, 2024
CVE-2024-29375
9.8 CRITICAL

CSV Injection vulnerability in Addactis IBNRS v.3.10.3.107 allows a remote attacker to execute arbitrary code via a crafted .ibnrs file to the Project Description, Identifiers, …

Apr 4, 2024
CVE-2023-25200
4.7 MEDIUM

An HTML injection vulnerability exists in the MT Safeline X-Ray X3310 webserver version NXG 19.05 that enables a remote attacker to render malicious HTML and …

Apr 4, 2024
CVE-2023-25199
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in the MT Safeline X-Ray X3310 webserver version NXG 19.05 that enables a remote attacker to execute JavaScript …

Apr 4, 2024
CVE-2024-28520
6.5 MEDIUM

File Upload vulnerability in Byzoro Networks Smart multi-service security gateway intelligent management platform version S210, allows an attacker to obtain sensitive information via the uploadfile.php …

Apr 4, 2024
CVE-2024-1418
5.3 MEDIUM

The CGC Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2 via the REST API. …

Apr 4, 2024
CVE-2024-31025
7.5 HIGH

SQL Injection vulnerability in ECshop 4.x allows an attacker to obtain sensitive information via the file/article.php component.

Apr 4, 2024
CVE-2024-2919
6.4 MEDIUM

The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the CountUp Widget in all …

Apr 4, 2024
CVE-2024-2830
6.4 MEDIUM

The WordPress Tag and Category Manager – AI Autotagger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'st_tag_cloud' shortcode in all …

Apr 4, 2024
CVE-2024-2008
8.8 HIGH

The Modal Popup Box – Popup Builder, Show Offers And News in Popup plugin for WordPress is vulnerable to PHP Object Injection in all versions …

Apr 4, 2024
CVE-2024-3274
5.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DNS-320L, DNS-320LW and DNS-327L up to 20240403 and classified as problematic. Affected by …

Apr 4, 2024
CVE-2024-3030
4.4 MEDIUM

The Announce from the Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.5.2 …

Apr 4, 2024
CVE-2024-3022
7.2 HIGH

The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient filename validation in the 'bookingpress_process_upload' function in all versions up to, …

Apr 4, 2024
CVE-2024-2868
6.4 MEDIUM

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored …

Apr 4, 2024
CVE-2024-2803
6.4 MEDIUM

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget in all versions up to, and including, 3.0.6 …

Apr 4, 2024
CVE-2024-2692
9.0 CRITICAL

SiYuan version 3.0.3 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to Server Side XSS.

Apr 4, 2024
CVE-2024-3273
7.3 HIGH KEV

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected …

Apr 4, 2024
CVE-2024-3272
9.8 CRITICAL KEV

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to …

Apr 4, 2024
CVE-2024-29225
4.3 MEDIUM

ELECOM wireless LAN routers allow a network-adjacent unauthenticated attacker to obtain the configuration file containing sensitive information by sending a specially crafted request.

Apr 4, 2024
CVE-2024-29167
7.2 HIGH

SVR-116 firmware version 1.6.0.30028871 allows a remote authenticated attacker with an administrative privilege to execute arbitrary OS commands by sending a specially crafted request to …

Apr 4, 2024
CVE-2024-26258
7.1 HIGH

OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with credentials to execute arbitrary OS commands by sending a specially crafted …

Apr 4, 2024
CVE-2024-25568
8.8 HIGH

OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent unauthenticated attacker to execute arbitrary OS commands by sending a specially crafted request …

Apr 4, 2024
CVE-2024-3270
3.8 LOW

A vulnerability classified as problematic was found in ThingsBoard up to 3.6.2. This vulnerability affects unknown code of the component AdvancedFeature. The manipulation leads to …

Apr 3, 2024
CVE-2024-30265
7.5 HIGH

Collabora Online is a collaborative online office suite based on LibreOffice technology. Any deployment of voilà dashboard allow local file inclusion. Any file on a …

Apr 3, 2024
CVE-2024-2689
4.4 MEDIUM

Denial of Service in Temporal Server prior to version 1.20.5, 1.21.6, and 1.22.7 allows an authenticated user who has permissions to interact with workflows and …

Apr 3, 2024
CVE-2024-29413
5.4 MEDIUM

Cross Site Scripting vulnerability in Webasyst v.2.9.9 allows a remote attacker to run arbitrary code via the Instant messenger field in the Contact info function.

Apr 3, 2024
CVE-2024-28870
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OISF and the Suricata community. When parsing …

Apr 3, 2024
CVE-2024-27705
7.6 HIGH

Cross Site Scripting vulnerability in Leantime v3.0.6 allows attackers to execute arbitrary code via upload of crafted PDF file to the files/browse endpoint.

Apr 3, 2024
CVE-2023-52043
8.1 HIGH

An issue in D-Link COVR 1100, 1102, 1103 AC1200 Dual-Band Whole-Home Mesh Wi-Fi System (Hardware Rev B1) truncates Wireless Access Point Passwords (WPA-PSK) allowing an …

Apr 3, 2024
CVE-2024-27706
6.1 MEDIUM

Cross Site Scripting vulnerability in Huly Platform v.0.6.202 allows attackers to execute arbitrary code via upload of crafted SVG file to issues.

Apr 3, 2024
CVE-2024-3181
3.1 LOW

Concrete CMS version 9 prior to 9.2.8 and previous versions prior to 8.5.16 are vulnerable to Stored XSS in the Search Field. Prior to the …

Apr 3, 2024
CVE-2024-3180
3.1 LOW

Concrete CMS version 9 below 9.2.8 and previous versions below 8.5.16 is vulnerable to Stored XSS in blocks of type file. Stored XSS could be …

Apr 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.