CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0762
7.5 HIGH

Potential buffer overflow in unsafe UEFI variable handling in Phoenix SecureCore™ for select Intel platforms This issue affects: Phoenix SecureCore™ for Intel Kaby Lake: from …

May 14, 2024
CVE-2023-35841
7.8 HIGH

Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects WinFlash …

May 14, 2024
CVE-2024-4791
7.5 HIGH

A vulnerability classified as critical was found in Contemporary Control System BASrouter BACnet BASRT-B 2.7.2. This vulnerability affects unknown code of the component Application Protocol …

May 14, 2024
CVE-2024-4747
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Propovoice Propovoice CRM allows Stored XSS.This issue affects Propovoice CRM: from n/a through …

May 14, 2024
CVE-2024-4712
7.8 HIGH

An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This specific flaw exists within the image-handler …

May 14, 2024
CVE-2024-4605
8.8 HIGH

The Breakdance plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.7.1 via post meta data. This is …

May 14, 2024
CVE-2024-4545
7.7 HIGH

All versions of EnterpriseDB Postgres Advanced Server (EPAS) from 15.0 prior to 15.7.0 and from 16.0 prior to 16.3.0 may allow users using edbldr to …

May 14, 2024
CVE-2024-4441
8.1 HIGH

The XML Sitemap & Google News plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.8 via the …

May 14, 2024
CVE-2024-4423
7.2 HIGH

The access control in CemiPark software does not properly validate user-entered data, which allows the authentication bypass. An attacker who has network access to the …

May 14, 2024
CVE-2024-4397
8.8 HIGH

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_post_materials' function …

May 14, 2024
CVE-2024-4129
8.8 HIGH

Improper Authentication vulnerability in Snow Software AB Snow License Manager on Windows allows a networked attacker to perform an Authentication Bypass if Active Directory Authentication …

May 14, 2024
CVE-2024-4068
7.5 HIGH

The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In …

May 14, 2024
CVE-2024-4044
7.8 HIGH

A deserialization of untrusted data vulnerability exists in common code used by FlexLogger and InstrumentStudio that may result in remote code execution. Successful exploitation requires …

May 14, 2024
CVE-2024-3954
8.8 HIGH

The Ditty plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.1.38 via deserialization of untrusted input when adding a …

May 14, 2024
CVE-2024-3940
8.8 HIGH

The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

May 14, 2024
CVE-2024-3903
7.1 HIGH

The Add Custom CSS and JS WordPress plugin through 1.20 does not have CSRF check in some places, and is missing sanitisation as well as …

May 14, 2024
CVE-2024-3828
8.8 HIGH

The Spectra Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.5. This is due to the plugin …

May 14, 2024
CVE-2024-3809
8.8 HIGH

The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.9 via the 'slideshow_type' …

May 14, 2024
CVE-2024-3808
8.8 HIGH

The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.0 via the 'porto_portfolios' …

May 14, 2024
CVE-2024-3807
8.8 HIGH

The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via 'porto_page_header_shortcode_type', 'slideshow_type' and 'post_layout' post …

May 14, 2024
CVE-2024-3727
8.3 HIGH

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing …

May 14, 2024
CVE-2024-3460
7.4 HIGH

In KioWare for Windows (versions all through 8.34) it is possible to exit this software and use other already opened applications utilizing a short time …

May 14, 2024
CVE-2024-3459
8.4 HIGH

KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened in an external …

May 14, 2024
CVE-2024-3055
8.8 HIGH

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions …

May 14, 2024
CVE-2024-3037
7.8 HIGH

An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first …

May 14, 2024
CVE-2024-35205
7.8 HIGH

The WPS Office (aka cn.wps.moffice_eng) application before 17.0.0 for Android fails to properly sanitize file names before processing them through external application interactions, leading to …

May 14, 2024
CVE-2024-35204
8.4 HIGH

Veritas System Recovery before 23.3_Hotfix has incorrect permissions for the Veritas System Recovery folder, and thus low-privileged users can conduct attacks.

May 14, 2024
CVE-2024-35050
8.8 HIGH

An issue in SurveyKing v1.3.1 allows attackers to escalate privileges via re-using the session ID of a user that was deleted by an Admin.

May 14, 2024
CVE-2024-34974
8.2 HIGH

Tenda AC18 v15.03.05.19 is vulnerable to Buffer Overflow in the formSetPPTPServer function via the endIp parameter.

May 14, 2024
CVE-2024-34944
8.8 HIGH

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the list1 parameter at ip/goform/DhcpListClient.

May 14, 2024
CVE-2024-34942
8.8 HIGH

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter at ip/goform/exeCommand.

May 14, 2024
CVE-2024-34921
8.8 HIGH

TOTOLINK X5000R v9.1.0cu.2350_B20230313 was discovered to contain a command injection via the disconnectVPN function.

May 14, 2024
CVE-2024-34818
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress.This issue affects WebinarPress: from n/a through 1.33.17.

May 14, 2024
CVE-2024-34707
7.5 HIGH

Nautobot is a Network Source of Truth and Network Automation Platform. A Nautobot user with admin privileges can modify the `BANNER_TOP`, `BANNER_BOTTOM`, and `BANNER_LOGIN` configuration …

May 14, 2024
CVE-2024-34697
7.6 HIGH

FreeScout is a free, self-hosted help desk and shared mailbox. A stored HTML Injection vulnerability has been identified in the Email Receival Module of the …

May 14, 2024
CVE-2024-34559
7.5 HIGH

Insertion of Sensitive Information into Log File vulnerability in Ghost Foundation Ghost.This issue affects Ghost: from n/a through 1.4.0.

May 14, 2024
CVE-2024-34459
7.5 HIGH

An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result in a buffer …

May 14, 2024
CVE-2024-34431
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP-etracker WP etracker allows Reflected XSS.This issue affects WP etracker: from n/a through …

May 14, 2024
CVE-2024-34360
8.2 HIGH

go-spacemesh is a Go implementation of the Spacemesh protocol full node. Nodes can publish activations transactions (ATXs) which reference the incorrect previous ATX of the …

May 14, 2024
CVE-2024-34351
7.5 HIGH

Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server …

May 14, 2024
CVE-2024-34350
7.5 HIGH

Next.js is a React framework that can provide building blocks to create web applications. Prior to 13.5.1, an inconsistent interpretation of a crafted HTTP request …

May 14, 2024
CVE-2024-34345
8.1 HIGH

The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML External entity injections were possible, when running the provided …

May 14, 2024
CVE-2024-34338
7.2 HIGH

Tenda O3V2 with firmware versions V1.0.0.10 and V1.0.0.12 was discovered to contain a Blind Command Injection via dest parameter in /goform/getTraceroute. This vulnerability allows attackers …

May 14, 2024
CVE-2024-34310
8.8 HIGH

Jin Fang Times Content Management System v3.2.3 was discovered to contain a SQL injection vulnerability via the id parameter.

May 14, 2024
CVE-2024-34308
8.8 HIGH

TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the function urldecode.

May 14, 2024
CVE-2024-34231
7.1 HIGH

A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected …

May 14, 2024
CVE-2024-34224
7.3 HIGH

Cross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or …

May 14, 2024
CVE-2024-34221
8.8 HIGH

Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation.

May 14, 2024
CVE-2024-34220
7.5 HIGH

Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the 'leave' parameter.

May 14, 2024
CVE-2024-34219
8.6 HIGH

TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allows attackers to log in through telnet.

May 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.