CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4566
7.1 HIGH

The ShopLentor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_dismiss function in all versions …

May 21, 2024
CVE-2024-4290
7.1 HIGH

The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 21, 2024
CVE-2024-34710
7.1 HIGH

Wiki.js is al wiki app built on Node.js. Client side template injection was discovered, that could allow an attacker to inject malicious JavaScript into the …

May 20, 2024
CVE-2024-29000
7.9 HIGH

The SolarWinds Platform was determined to be affected by a reflected cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is …

May 20, 2024
CVE-2024-35579
7.7 HIGH

Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formSetIptv.

May 20, 2024
CVE-2024-35578
8.0 HIGH

Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv.

May 20, 2024
CVE-2024-34949
8.2 HIGH

SQL injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function OrderLogic::getOrderList function, exploited at the /admin/order/lists.html endpoint.

May 20, 2024
CVE-2024-34193
7.5 HIGH

smanga 3.2.7 does not filter the file parameter at the PHP/get file flow.php interface, resulting in a path traversal vulnerability that can cause arbitrary file …

May 20, 2024
CVE-2024-31714
7.5 HIGH

Buffer Overflow vulnerability in Waxlab wax v.0.9-3 and before allows an attacker to cause a denial of service via the Lua library component.

May 20, 2024
CVE-2024-29651
8.1 HIGH

A Prototype Pollution issue in API Dev Tools json-schema-ref-parser v.11.0.0 and v.11.1.0 allows a remote attacker to execute arbitrary code via the bundle()`, `parse()`, `resolve()`, …

May 20, 2024
CVE-2024-24293
8.8 HIGH

A Prototype Pollution issue in MiguelCastillo @bit/loader v.10.0.3 allows an attacker to execute arbitrary code via the M function e argument in index.js.

May 20, 2024
CVE-2023-49335
8.3 HIGH

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while getting file server details.

May 20, 2024
CVE-2023-49334
8.3 HIGH

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while exporting a full summary report.

May 20, 2024
CVE-2023-49333
8.3 HIGH

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the dashboard graph feature.

May 20, 2024
CVE-2023-49332
8.3 HIGH

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while adding file shares.

May 20, 2024
CVE-2023-49331
8.3 HIGH

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the aggregate reports search option.

May 20, 2024
CVE-2024-34948
7.5 HIGH

An issue in Quanxun Huiju Network Technology(Beijing) Co.,Ltd IK-Q3000 3.7.10 x64 Build202401261655 allows attackers to cause a Denial of Service (DoS) when attempting to make …

May 20, 2024
CVE-2024-0401
7.2 HIGH

ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary operating system commands by …

May 20, 2024
CVE-2024-4151
8.1 HIGH

An Improper Access Control vulnerability exists in lunary-ai/lunary version 1.2.2, where users can view and update any prompts in any projects due to insufficient access …

May 20, 2024
CVE-2024-3482
8.7 HIGH

A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Enterprise Security Manager and ArcSight Platform. The vulnerability could be remotely exploited.

May 20, 2024
CVE-2024-34953
7.5 HIGH

An issue in taurusxin ncmdump v1.3.2 allows attackers to cause a Denial of Service (DoS) via memory exhaustion by supplying a crafted .ncm file

May 20, 2024
CVE-2024-2835
8.7 HIGH

A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Enterprise Security Manager and ArcSight Platform. The vulnerability could be remotely exploited.

May 20, 2024
CVE-2024-4287
7.2 HIGH

In mintplex-labs/anything-llm, a vulnerability exists due to improper input validation in the workspace update process. Specifically, the application fails to validate or format JSON data …

May 20, 2024
CVE-2024-27312
8.1 HIGH

Zohocorp ManageEngine PAM360 version 6601 is vulnerable to authorization vulnerability which allows a low-privileged user to perform admin actions. Note: This vulnerability affects only the …

May 20, 2024
CVE-2023-49330
8.3 HIGH

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while getting aggregate report data.

May 20, 2024
CVE-2024-36001
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix the pre-flush when appending to a file in writethrough mode In netfs_perform_write(), when …

May 20, 2024
CVE-2024-35979
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: raid1: fix use-after-free for original bio in raid1_write_request() r1_bio->bios[] is used to record new bios …

May 20, 2024
CVE-2024-35967
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: Fix not validating setsockopt user input syzbot reported sco_sock_setsockopt() is copying data without …

May 20, 2024
CVE-2024-35966
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: Fix not validating setsockopt user input syzbot reported rfcomm_sock_setsockopt_old() is copying data without …

May 20, 2024
CVE-2024-35965
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix not validating setsockopt user input Check user input length before copying data.

May 20, 2024
CVE-2024-35964
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix not validating setsockopt user input Check user input length before copying data.

May 20, 2024
CVE-2024-35963
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sock: Fix not validating setsockopt user input Check user input length before copying data.

May 20, 2024
CVE-2024-35955
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: kprobes: Fix possible use-after-free issue on kprobe registration When unloading a module, its state is …

May 20, 2024
CVE-2024-35949
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: btrfs: make sure that WRITTEN is set on all metadata blocks We previously would call …

May 20, 2024
CVE-2024-35948
8.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: bcachefs: Check for journal entries overruning end of sb clean section Fix a missing bounds …

May 20, 2024
CVE-2024-5135
7.3 HIGH

A vulnerability was found in PHPGurukul Directory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

May 20, 2024
CVE-2024-3761
7.5 HIGH

In lunary-ai/lunary version 1.2.2, the DELETE endpoint located at `packages/backend/src/api/v1/datasets` is vulnerable to unauthorized dataset deletion due to missing authorization and authentication mechanisms. This vulnerability …

May 20, 2024
CVE-2024-1968
7.5 HIGH

In scrapy/scrapy, an issue was identified where the Authorization header is not removed during redirects that only change the scheme (e.g., HTTPS to HTTP) but …

May 20, 2024
CVE-2024-5122
7.3 HIGH

A vulnerability was found in SourceCodester Event Registration System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

May 20, 2024
CVE-2024-5118
7.3 HIGH

A vulnerability has been found in SourceCodester Event Registration System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/login.php. The …

May 20, 2024
CVE-2024-5117
7.3 HIGH

A vulnerability, which was classified as critical, was found in SourceCodester Event Registration System 1.0. This affects an unknown part of the file portal.php. The …

May 20, 2024
CVE-2024-5116
7.3 HIGH

A vulnerability, which was classified as critical, has been found in SourceCodester Online Examination System 1.0. Affected by this issue is some unknown functionality of …

May 20, 2024
CVE-2024-36076
8.8 HIGH

Cross-Site WebSocket Hijacking in SysReptor from version 2024.28 to version 2024.30 causes attackers to escalate privileges and obtain sensitive information when a logged-in SysReptor user …

May 19, 2024
CVE-2024-36070
7.5 HIGH

tine before 2023.11.8, when an LDAP backend is used, allows anonymous remote attackers to obtain sensitive authentication information via setup.php because of getRegistryData in Setup/Frontend/Json.php. …

May 19, 2024
CVE-2024-35939
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: dma-direct: Leak pages on dma_set_decrypted() failure On TDX it is possible for the untrusted host …

May 19, 2024
CVE-2024-35937
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: check A-MSDU format more carefully If it looks like there's another subframe in …

May 19, 2024
CVE-2024-35932
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/vc4: don't check if plane->state->fb == state->fb Currently, when using non-blocking commits, we can see …

May 19, 2024
CVE-2024-35929
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: rcu/nocb: Fix WARN_ON_ONCE() in the rcu_nocb_bypass_lock() For the kernels built with CONFIG_RCU_NOCB_CPU_DEFAULT_ALL=y and CONFIG_RCU_LAZY=y, the …

May 19, 2024
CVE-2024-35921
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix oops when HEVC init fails The stateless HEVC decoder saves the …

May 19, 2024
CVE-2024-35919
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: adding lock to protect encoder context list Add a lock for the …

May 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.