CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8440
6.4 MEDIUM

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Sep 11, 2024
CVE-2024-7716
4.8 MEDIUM

The Logo Slider WordPress plugin before 3.6.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Sep 11, 2024
CVE-2024-3899
4.8 MEDIUM

The Gallery Plugin for WordPress WordPress plugin before 1.8.15 does not sanitise and escape some of its image settings, which could allow users with post-writing …

Sep 11, 2024
CVE-2024-7727
5.3 MEDIUM

The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing …

Sep 11, 2024
CVE-2024-7721
4.3 MEDIUM

The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Sep 11, 2024
CVE-2024-39808
4.6 MEDIUM

Incorrect Calculation of Buffer Size (CWE-131) in the Controller 6000 and Controller 7000 OSDP message handling, allows an attacker with physical access to Controller wiring …

Sep 11, 2024
CVE-2024-24972
6.5 MEDIUM

Buffer Copy without Checking Size of Input (CWE-120) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authorised and authenticated operator to …

Sep 11, 2024
CVE-2024-23906
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (CWE-79) in the Controller 6000 and Controller 7000 diagnostic webpage allows an attacker to modify Controller configuration …

Sep 11, 2024
CVE-2024-40659
5.5 MEDIUM

In getRegistration of RemoteProvisioningService.java, there is a possible way to permanently disable the AndroidKeyStore key generation feature by updating the attestation keys of all installed …

Sep 11, 2024
CVE-2024-40656
5.5 MEDIUM

In handleCreateConferenceComplete of ConnectionServiceWrapper.java, there is a possible way to reveal images across users due to a confused deputy. This could lead to local information …

Sep 11, 2024
CVE-2024-45597
5.3 MEDIUM

Pluto is a superset of Lua 5.4 with a focus on general-purpose programming. Scripts passing user-controlled values to http.request header values are affected. An attacker …

Sep 10, 2024
CVE-2024-8441
6.7 MEDIUM

An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin …

Sep 10, 2024
CVE-2024-8322
4.3 MEDIUM

Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.

Sep 10, 2024
CVE-2024-8321
5.8 MEDIUM

Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to isolate managed devices …

Sep 10, 2024
CVE-2024-8320
5.3 MEDIUM

Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation …

Sep 10, 2024
CVE-2024-8655
5.3 MEDIUM

A vulnerability was found in Mercury MNVR816 up to 2.0.1.0.5. It has been classified as problematic. This affects an unknown part of the file /web-static/. …

Sep 10, 2024
CVE-2024-34831
6.1 MEDIUM

cross-site scripting (XSS) vulnerability in Gibbon Core v26.0.00 allows an attacker to execute arbitrary code via the imageLink parameter in the library_manage_catalog_editProcess.php component.

Sep 10, 2024
CVE-2024-44872
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in moziloCMS v3.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a …

Sep 10, 2024
CVE-2024-43487
6.5 MEDIUM

Windows Mark of the Web Security Feature Bypass Vulnerability

Sep 10, 2024
CVE-2024-43482
6.5 MEDIUM

Microsoft Outlook for iOS Information Disclosure Vulnerability

Sep 10, 2024
CVE-2024-43466
6.5 MEDIUM

Microsoft SharePoint Server Denial of Service Vulnerability

Sep 10, 2024
CVE-2024-38258
6.5 MEDIUM

Windows Remote Desktop Licensing Service Information Disclosure Vulnerability

Sep 10, 2024
CVE-2024-38256
5.5 MEDIUM

Windows Kernel-Mode Driver Information Disclosure Vulnerability

Sep 10, 2024
CVE-2024-38254
5.5 MEDIUM

Windows Authentication Information Disclosure Vulnerability

Sep 10, 2024
CVE-2024-38235
6.5 MEDIUM

Windows Hyper-V Denial of Service Vulnerability

Sep 10, 2024
CVE-2024-38234
6.5 MEDIUM

Windows Networking Denial of Service Vulnerability

Sep 10, 2024
CVE-2024-38231
6.5 MEDIUM

Windows Remote Desktop Licensing Service Denial of Service Vulnerability

Sep 10, 2024
CVE-2024-38230
6.5 MEDIUM

Windows Standards-Based Storage Management Service Denial of Service Vulnerability

Sep 10, 2024
CVE-2024-38217
5.4 MEDIUM KEV

Windows Mark of the Web Security Feature Bypass Vulnerability

Sep 10, 2024
CVE-2024-6876
4.4 MEDIUM

Out-of-Bounds read vulnerability in OSCAT Basic Library allows an local, unprivileged attacker to access limited internal data of the PLC which may lead to a …

Sep 10, 2024
CVE-2024-45595
6.1 MEDIUM

D-Tale is a visualizer for Pandas data structures. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code …

Sep 10, 2024
CVE-2024-45591
5.3 MEDIUM

XWiki Platform is a generic wiki platform. The REST API exposes the history of any page in XWiki of which the attacker knows the name. …

Sep 10, 2024
CVE-2024-45412
5.3 MEDIUM

Yeti bridges the gap between CTI and DFIR practitioners by providing a Forensics Intelligence platform and pipeline. Remote user-controlled data tags can reach a Unicode …

Sep 10, 2024
CVE-2024-45407
6.5 MEDIUM

Sunshine is a self-hosted game stream host for Moonlight. Clients that experience a MITM attack during the pairing process may inadvertantly allow access to an …

Sep 10, 2024
CVE-2024-44815
4.6 MEDIUM

Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash Firmware W25Q64JV.

Sep 10, 2024
CVE-2024-44676
4.8 MEDIUM

eladmin v2.7 and before is vulnerable to Cross Site Scripting (XSS) which allows an attacker to execute arbitrary code via LocalStoreController. java.

Sep 10, 2024
CVE-2024-45393
6.4 MEDIUM

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account can access webhook …

Sep 10, 2024
CVE-2024-45323
4.3 MEDIUM

An improper access control vulnerability [CWE-284] in FortiEDR Manager API 6.2.0 through 6.2.2, 6.0 all versions may allow in a shared environment context an authenticated …

Sep 10, 2024
CVE-2024-43800
5.0 MEDIUM

serve-static serves static files. serve-static passes untrusted user input - even after sanitizing it - to redirect() may execute untrusted code. This issue is patched …

Sep 10, 2024
CVE-2024-43799
5.0 MEDIUM

Send is a library for streaming files from the file system as a http response. Send passes untrusted user input to SendStream.redirect() which executes untrusted …

Sep 10, 2024
CVE-2024-43796
5.0 MEDIUM

Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted …

Sep 10, 2024
CVE-2024-42423
6.1 MEDIUM

Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user …

Sep 10, 2024
CVE-2024-35282
4.2 MEDIUM

A cleartext storage of sensitive information in memory vulnerability [CWE-316] affecting FortiClient VPN iOS 7.2 all versions, 7.0 all versions, 6.4 all versions, 6.2 all …

Sep 10, 2024
CVE-2024-31490
4.3 MEDIUM

An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 all versions, FortiSandbox …

Sep 10, 2024
CVE-2024-31489
6.8 MEDIUM

AAn improper certificate validation vulnerability [CWE-295] in FortiClientWindows 7.2.0 through 7.2.2, 7.0.0 through 7.0.11, FortiClientLinux 7.2.0, 7.0.0 through 7.0.11 and FortiClientMac 7.0.0 through 7.0.11, 7.2.0 …

Sep 10, 2024
CVE-2024-27257
4.3 MEDIUM

IBM OpenPages 8.3 and 9.0 potentially exposes information about client-side source code through use of JavaScript source maps to unauthorized users.

Sep 10, 2024
CVE-2024-25074
5.9 MEDIUM

An issue was discovered in Samsung Semiconductor Mobile Processor and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, …

Sep 10, 2024
CVE-2024-25073
5.9 MEDIUM

An issue was discovered in Samsung Semiconductor Mobile Processor and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, …

Sep 10, 2024
CVE-2024-23184
5.0 MEDIUM

Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 …

Sep 10, 2024
CVE-2024-21753
5.5 MEDIUM

A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.13, 6.4.0 through 6.4.9, …

Sep 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.