CVE Database

39204+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-34031
8.8 HIGH

Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the script Handler_CFG.ashx. An authenticated attacker can exploit this issue to potentially …

May 3, 2024
CVE-2024-30306
7.8 HIGH

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read …

May 2, 2024
CVE-2024-30305
7.8 HIGH

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

May 2, 2024
CVE-2024-30304
7.8 HIGH

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

May 2, 2024
CVE-2024-30303
7.8 HIGH

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

May 2, 2024
CVE-2024-30301
7.8 HIGH

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

May 2, 2024
CVE-2024-25047
8.6 HIGH

IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2 is vulnerable to injection attacks in application logging by not sanitizing user provided data. This …

May 2, 2024
CVE-2024-4140
7.5 HIGH

An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch …

May 2, 2024
CVE-2024-34394
8.1 HIGH

libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the namespaces() function (which invokes XmlNode::get_local_namespaces()) on a grand-child …

May 2, 2024
CVE-2024-34393
8.1 HIGH

libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking a function on the result of attrs() that was …

May 2, 2024
CVE-2024-34392
8.1 HIGH

libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the namespaces() function (which invokes _wrap__xmlNode_nsDef_get()) on a grand-child …

May 2, 2024
CVE-2024-34391
8.1 HIGH

libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking a function on the result of attrs() that was …

May 2, 2024
CVE-2024-33396
8.4 HIGH

An issue in karmada-io karmada v1.9.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.

May 2, 2024
CVE-2024-4216
7.4 HIGH

pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client …

May 2, 2024
CVE-2024-4215
7.4 HIGH

pgAdmin <= 8.5 is affected by a multi-factor authentication bypass vulnerability. This vulnerability allows an attacker with knowledge of a legitimate account’s username and password …

May 2, 2024
CVE-2024-4097
7.2 HIGH

The Cost Calculator Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG upload feature in all versions up to, and including, …

May 2, 2024
CVE-2024-4033
8.8 HIGH

The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the aiovg_create_attachment_from_external_image_url function in all …

May 2, 2024
CVE-2024-3895
8.8 HIGH

The WP Datepicker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpdp_add_new_datepicker_ajax() function in all …

May 2, 2024
CVE-2024-3849
8.8 HIGH

The Click to Chat – HoliThemes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.35. This makes …

May 2, 2024
CVE-2024-3715
7.2 HIGH

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, …

May 2, 2024
CVE-2024-3500
8.8 HIGH

The ElementsKit Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.0 via the Price Menu, Hotspot, …

May 2, 2024
CVE-2024-3499
8.8 HIGH

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.0 via the generate_navigation_markup function …

May 2, 2024
CVE-2024-3047
7.2 HIGH

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.8.0 via …

May 2, 2024
CVE-2024-3045
7.2 HIGH

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and …

May 2, 2024
CVE-2024-2831
8.8 HIGH

The Calendar plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcodes in all versions up to, and including, 1.3.14 due to insufficient …

May 2, 2024
CVE-2024-2661
8.8 HIGH

The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. plugin for WordPress is vulnerable to …

May 2, 2024
CVE-2024-2417
8.8 HIGH

The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to privilege escalation due to a …

May 2, 2024
CVE-2024-2082
7.2 HIGH

The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in …

May 2, 2024
CVE-2024-25290
8.0 HIGH

An issue in Casa Systems NL1901ACV R6B032 allows a remote attacker to execute arbitrary code via the userName parameter of the add function.

May 2, 2024
CVE-2024-1945
7.1 HIGH

The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable to unauthorized loss of data due …

May 2, 2024
CVE-2024-1897
7.5 HIGH

The Grid Gallery – Photo Image Grid Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.3 …

May 2, 2024
CVE-2024-1896
7.5 HIGH

The Photo Gallery – Responsive Photo Gallery, Image Gallery, Portfolio Gallery, Logo Gallery And Team Gallery plugin for WordPress is vulnerable to PHP Object Injection …

May 2, 2024
CVE-2024-1797
8.8 HIGH

The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to SQL Injection via the 'status' and 'id' attributes of the …

May 2, 2024
CVE-2024-1567
8.2 HIGH

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type validation in the 'file_validity' function …

May 2, 2024
CVE-2024-1173
7.2 HIGH

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL …

May 2, 2024
CVE-2023-7064
7.5 HIGH

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.17.5 …

May 2, 2024
CVE-2023-6961
7.2 HIGH

The WP Meta SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Referer’ header in all versions up to, and including, 4.5.12 …

May 2, 2024
CVE-2023-6214
7.5 HIGH

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.6 …

May 2, 2024
CVE-2024-33530
7.5 HIGH

In Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make use of a lobby) leads to the disclosure of the meeting …

May 2, 2024
CVE-2024-31964
7.5 HIGH

A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit …

May 2, 2024
CVE-2024-29309
7.7 HIGH

An issue in Alfresco Content Services v.23.3.0.7 allows a remote attacker to execute arbitrary code via the Transfer Service.

May 2, 2024
CVE-2023-50685
7.5 HIGH

An issue in Hipcam Cameras RealServer v.1.0 allows a remote attacker to cause a denial of service via a crafted script to the client_port parameter.

May 2, 2024
CVE-2024-3544
7.5 HIGH

Unauthenticated attackers can perform actions, using SSH private keys, by knowing the IP address and having access to the same network of one of the …

May 2, 2024
CVE-2024-34145
8.8 HIGH

A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to …

May 2, 2024
CVE-2024-33303
8.2 HIGH

SourceCodester Product Show Room 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" under Add Users.

May 2, 2024
CVE-2024-30251
7.5 HIGH

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attacker can send a specially crafted POST (multipart/form-data) request. When …

May 2, 2024
CVE-2024-23459
7.1 HIGH

An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Mac allows a system file to be overwritten.This issue affects …

May 2, 2024
CVE-2024-33911
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar School Management Pro.This issue affects School Management Pro: from n/a …

May 2, 2024
CVE-2024-32114
8.5 HIGH

In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolokia JMX REST API and the Message REST API are …

May 2, 2024
CVE-2024-3476
8.8 HIGH

The Side Menu Lite WordPress plugin before 4.2.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in …

May 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.