CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-47509
6.5 MEDIUM

An Allocation of Resources Without Limits or Throttling vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved allows an authenticated, network-based …

Oct 11, 2024
CVE-2024-47508
6.5 MEDIUM

An Allocation of Resources Without Limits or Throttling vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved allows an authenticated, network-based …

Oct 11, 2024
CVE-2024-47507
5.8 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows …

Oct 11, 2024
CVE-2024-47506
5.9 MEDIUM

A Deadlock vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a …

Oct 11, 2024
CVE-2024-47505
6.5 MEDIUM

An Allocation of Resources Without Limits or Throttling vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved allows an authenticated, network-based …

Oct 11, 2024
CVE-2024-47503
6.5 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX4600 and SRX5000 Series …

Oct 11, 2024
CVE-2024-47501
5.5 MEDIUM

A NULL Pointer Dereference vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on MX304, MX with MPC10/11/LC9600, and EX9200 with EX9200-15C …

Oct 11, 2024
CVE-2024-47498
6.5 MEDIUM

An Unimplemented or Unsupported Feature in UI vulnerability in the CLI of Juniper Networks Junos OS Evolved on QFX5000 Series allows an unauthenticated, adjacent attacker …

Oct 11, 2024
CVE-2024-47496
5.5 MEDIUM

A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS allows a local, low-privileged attacker to cause a Denial-of-Service …

Oct 11, 2024
CVE-2024-47495
6.7 MEDIUM

An Authorization Bypass Through User-Controlled Key vulnerability allows a locally authenticated attacker with shell access to gain full control of the device when Dual Routing …

Oct 11, 2024
CVE-2024-47494
5.9 MEDIUM

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the AgentD process of Juniper Networks Junos OS allows an attacker who is already causing impact to …

Oct 11, 2024
CVE-2024-47493
6.5 MEDIUM

A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of the Juniper Networks Junos OS on the MX Series …

Oct 11, 2024
CVE-2024-47491
5.9 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, …

Oct 11, 2024
CVE-2024-47489
5.8 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of the Juniper Networks Junos OS Evolved on ACX Series devices allows …

Oct 11, 2024
CVE-2024-39544
5.0 MEDIUM

An Incorrect Default Permissions vulnerability in the command line interface (CLI) of Juniper Networks Junos OS Evolved allows a low privileged local attacker to view …

Oct 11, 2024
CVE-2024-39534
5.4 MEDIUM

An Incorrect Comparison vulnerability in the local address verification API of Juniper Networks Junos OS Evolved allows an unauthenticated network-adjacent attacker to create sessions or …

Oct 11, 2024
CVE-2024-39527
5.5 MEDIUM

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the command-line interface (CLI) of Juniper Networks Junos OS on SRX Series devices allows …

Oct 11, 2024
CVE-2024-39526
6.5 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS on MX Series with MPC10/MPC11/LC9600 line cards, EX9200 with EX9200-15C …

Oct 11, 2024
CVE-2024-45397
5.9 MEDIUM

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When an HTTP request using TLS/1.3 early data on top of TCP Fast …

Oct 11, 2024
CVE-2024-8530
5.9 MEDIUM

CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause exposure of private data when an already generated “logcaptures” archive is accessed directly by …

Oct 11, 2024
CVE-2024-6657
6.5 MEDIUM

A denial of service may be caused to a single peripheral device in a BLE network when multiple central devices continuously connect and disconnect to …

Oct 11, 2024
CVE-2024-9855
4.7 MEDIUM

A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been declared as critical. Affected by this vulnerability is the function uploadFile of …

Oct 11, 2024
CVE-2024-9616
6.1 MEDIUM

The BlockMeister – Block Pattern Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on …

Oct 11, 2024
CVE-2024-9611
6.1 MEDIUM

The Increase upload file size & Maximum Execution Time limit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg …

Oct 11, 2024
CVE-2024-9610
6.1 MEDIUM

The Language Switcher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in …

Oct 11, 2024
CVE-2024-9587
5.4 MEDIUM

The Linkz.ai plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_linkz' function in versions up …

Oct 11, 2024
CVE-2024-9586
6.5 MEDIUM

The Linkz.ai plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'check_auth' and 'check_logout' functions in …

Oct 11, 2024
CVE-2024-9543
6.4 MEDIUM

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skipto' shortcode in all versions up to, …

Oct 11, 2024
CVE-2024-9538
4.3 MEDIUM

The ShopLentor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.8 via the 'render' function in includes/addons/wl_faq.php. …

Oct 11, 2024
CVE-2024-9507
4.9 MEDIUM

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable …

Oct 11, 2024
CVE-2024-9436
6.1 MEDIUM

The PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of …

Oct 11, 2024
CVE-2024-9346
6.1 MEDIUM

The Embed videos and respect privacy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'v' parameter in all versions up to, and …

Oct 11, 2024
CVE-2024-9232
6.1 MEDIUM

The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without …

Oct 11, 2024
CVE-2024-9221
6.1 MEDIUM

The Tainacan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all …

Oct 11, 2024
CVE-2024-9211
6.1 MEDIUM

The FULL – Cliente plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on …

Oct 11, 2024
CVE-2024-9051
6.4 MEDIUM

The WP Ultimate Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpupg-grid-with-filters shortcode in all versions up to, and …

Oct 11, 2024
CVE-2024-8913
4.3 MEDIUM

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in …

Oct 11, 2024
CVE-2024-7514
6.5 MEDIUM

The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient file path validation during the comments …

Oct 11, 2024
CVE-2024-6971
4.4 MEDIUM

A path traversal vulnerability exists in the parisneo/lollms-webui repository, specifically in the `lollms_file_system.py` file. The functions `add_rag_database`, `toggle_mount_rag_database`, and `vectorize_folder` do not implement security measures …

Oct 11, 2024
CVE-2024-5005
4.3 MEDIUM

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all …

Oct 11, 2024
CVE-2024-48987
6.6 MEDIUM

Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exacerbated by .env files, available from …

Oct 11, 2024
CVE-2024-45315
5.5 MEDIUM

The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard …

Oct 11, 2024
CVE-2023-42133
6.7 MEDIUM

PAX Android based POS devices allow for escalation of privilege via improperly configured scripts. An attacker must have shell access with system account privileges in …

Oct 11, 2024
CVE-2024-9817
6.3 MEDIUM

A vulnerability was found in code-projects Blood Bank System 1.0. It has been classified as critical. This affects an unknown part of the file /update.php. …

Oct 10, 2024
CVE-2024-47872
5.4 MEDIUM

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **Cross-Site Scripting (XSS)** on any Gradio server that allows file uploads. Authenticated …

Oct 10, 2024
CVE-2024-9816
4.7 MEDIUM

A vulnerability was found in Codezips Tourist Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Oct 10, 2024
CVE-2024-9815
4.7 MEDIUM

A vulnerability has been found in Codezips Tourist Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Oct 10, 2024
CVE-2024-47168
4.3 MEDIUM

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves data exposure due to the enable_monitoring flag not properly disabling monitoring when …

Oct 10, 2024
CVE-2024-47166
5.3 MEDIUM

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **one-level read path traversal** in the `/custom_component` endpoint. Attackers can exploit …

Oct 10, 2024
CVE-2024-47165
5.4 MEDIUM

Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **CORS origin validation accepting a null origin**. When a Gradio server …

Oct 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.