CVE Database

39204+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-1358
8.8 HIGH

The Elementor Addon Elements plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.12.12 via the render function. This …

Mar 13, 2024
CVE-2024-1311
8.8 HIGH

The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeImages function in …

Mar 13, 2024
CVE-2024-1203
8.8 HIGH

The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress is vulnerable to SQL Injection …

Mar 13, 2024
CVE-2024-0683
7.3 HIGH

The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions in all versions up to, …

Mar 13, 2024
CVE-2024-0368
8.6 HIGH

The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, …

Mar 13, 2024
CVE-2024-0161
7.2 HIGH

Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit …

Mar 13, 2024
CVE-2023-5663
8.8 HIGH

The News Announcement Scroll plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.0.0 due to …

Mar 13, 2024
CVE-2024-25155
7.2 HIGH

In FileCatalyst Direct 3.8.8 and earlier through 3.8.6, the web server does not properly sanitize illegal characters in a URL which is then displayed on …

Mar 13, 2024
CVE-2024-2247
8.8 HIGH

JFrog Artifactory versions below 7.77.7, 7.82.1, are vulnerable to DOM-based cross-site scripting due to improper handling of the import override mechanism.

Mar 13, 2024
CVE-2024-28684
8.8 HIGH

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/module_main.php

Mar 13, 2024
CVE-2024-28675
8.8 HIGH

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/diy_edit.php

Mar 13, 2024
CVE-2024-28665
8.8 HIGH

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article_add.php

Mar 13, 2024
CVE-2024-28432
8.8 HIGH

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article_edit.php.

Mar 13, 2024
CVE-2024-28431
8.8 HIGH

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_del.php.

Mar 13, 2024
CVE-2024-2415
7.8 HIGH

Command injection vulnerability in Movistar 4G router affecting version ES_WLD71-T1_v2.0.201820. This vulnerability allows an authenticated user to execute commands inside the router by making a …

Mar 13, 2024
CVE-2024-2414
8.8 HIGH

The primary channel is unprotected on Movistar 4G router affecting E version S_WLD71-T1_v2.0.201820. This device has the 'adb' service open on port 5555 and provides …

Mar 13, 2024
CVE-2024-2123
7.2 HIGH

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Mar 13, 2024
CVE-2015-10123
8.8 HIGH

An unautheticated remote attacker could send specifically crafted packets to a affected device. If an authenticated user then views that data in a specific page …

Mar 13, 2024
CVE-2024-26529
7.5 HIGH

An issue in mz-automation libiec61850 v.1.5.3 and before, allows a remote attacker to cause a denial of service (DoS) via the mmsServer_handleDeleteNamedVariableListRequest function of src/mms/iso_mms/server/mms_named_variable_list_service.c.

Mar 13, 2024
CVE-2024-2400
8.8 HIGH

Use after free in Performance Manager in Google Chrome prior to 122.0.6261.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Mar 13, 2024
CVE-2023-7072
7.5 HIGH

The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.68 …

Mar 12, 2024
CVE-2024-2395
7.3 HIGH

The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.14. This is due to …

Mar 12, 2024
CVE-2024-0386
7.2 HIGH

The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Referer' HTTP header in all versions up to, and including, 1.6.21 due …

Mar 12, 2024
CVE-2024-28236
7.7 HIGH

Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Vela pipelines can use variable substitution combined with insensitive fields …

Mar 12, 2024
CVE-2024-24092
7.8 HIGH

SQL Injection vulnerability in Code-projects.org Scholars Tracking System 1.0 allows attackers to run arbitrary code via login.php.

Mar 12, 2024
CVE-2024-23300
7.8 HIGH

A use-after-free issue was addressed with improved memory management. This issue is fixed in GarageBand 10.4.11. Processing a maliciously crafted file may lead to unexpected …

Mar 12, 2024
CVE-2024-28186
7.1 HIGH

FreeScout is an open source help desk and shared inbox built with PHP. A vulnerability has been identified in the Free Scout Application, which exposes …

Mar 12, 2024
CVE-2024-28121
8.8 HIGH

stimulus_reflex is a system to extend the capabilities of both Rails and Stimulus by intercepting user interactions and passing them to Rails over real-time websockets. …

Mar 12, 2024
CVE-2024-28114
8.1 HIGH

Peering Manager is a BGP session management tool. There is a Server Side Template Injection vulnerability that leads to Remote Code Execution in Peering Manager …

Mar 12, 2024
CVE-2023-5410
8.2 HIGH

A potential security vulnerability has been reported in the system BIOS of certain HP PC products, which might allow memory tampering. HP is releasing mitigation …

Mar 12, 2024
CVE-2024-27894
8.5 HIGH

The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the function's implementation is referenced by a URL. The supported …

Mar 12, 2024
CVE-2024-27317
8.4 HIGH

In Pulsar Functions Worker, authenticated users can upload functions in jar or nar files. These files, essentially zip files, are extracted by the Functions Worker. …

Mar 12, 2024
CVE-2024-27135
8.5 HIGH

Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function worker, outside of …

Mar 12, 2024
CVE-2022-34321
8.2 HIGH

Improper Authentication vulnerability in Apache Pulsar Proxy allows an attacker to connect to the /proxy-stats endpoint without authentication. The vulnerable endpoint exposes detailed statistics about …

Mar 12, 2024
CVE-2024-1138
8.8 HIGH

The FTL Server component of TIBCO Software Inc.'s TIBCO FTL - Enterprise Edition contains a vulnerability that allows a low privileged attacker with network access …

Mar 12, 2024
CVE-2024-28340
7.5 HIGH

An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without …

Mar 12, 2024
CVE-2024-28338
8.0 HIGH

A login bypass in TOTOLINK A8000RU V7.1cu.643_B20200521 allows attackers to login to Administrator accounts via providing a crafted session cookie.

Mar 12, 2024
CVE-2024-26204
7.5 HIGH

Outlook for Android Information Disclosure Vulnerability

Mar 12, 2024
CVE-2024-26203
7.3 HIGH

Azure Data Studio Elevation of Privilege Vulnerability

Mar 12, 2024
CVE-2024-26199
7.8 HIGH

Microsoft Office Elevation of Privilege Vulnerability

Mar 12, 2024
CVE-2024-26198
8.8 HIGH

Microsoft Exchange Server Remote Code Execution Vulnerability

Mar 12, 2024
CVE-2024-26190
7.5 HIGH

Microsoft QUIC Denial of Service Vulnerability

Mar 12, 2024
CVE-2024-26182
7.8 HIGH

Windows Kernel Elevation of Privilege Vulnerability

Mar 12, 2024
CVE-2024-26178
7.8 HIGH

Windows Kernel Elevation of Privilege Vulnerability

Mar 12, 2024
CVE-2024-26176
7.8 HIGH

Windows Kernel Elevation of Privilege Vulnerability

Mar 12, 2024
CVE-2024-26173
7.8 HIGH

Windows Kernel Elevation of Privilege Vulnerability

Mar 12, 2024
CVE-2024-26170
7.8 HIGH

Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability

Mar 12, 2024
CVE-2024-26169
7.8 HIGH KEV

Windows Error Reporting Service Elevation of Privilege Vulnerability

Mar 12, 2024
CVE-2024-26166
8.8 HIGH

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

Mar 12, 2024
CVE-2024-26165
8.8 HIGH

Visual Studio Code Elevation of Privilege Vulnerability

Mar 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.