CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-45400
6.1 MEDIUM

ckeditor-plugin-openlink is a plugin for the CKEditor JavaScript text editor that extends the context menu with a possibility to open a link in a new …

Sep 6, 2024
CVE-2024-42495
6.5 MEDIUM

Credentials to access device configuration were transmitted using an unencrypted protocol. These credentials would allow read-only access to network configuration information and terminal configuration data.

Sep 5, 2024
CVE-2024-39278
4.2 MEDIUM

Credentials to access device configuration information stored unencrypted in flash memory. These credentials would allow read-only access to network configuration information and terminal configuration data.

Sep 5, 2024
CVE-2024-45157
5.1 MEDIUM

An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used. Unlike previously documented, enabling …

Sep 5, 2024
CVE-2024-42491
5.7 MEDIUM

Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.24.3, 20.9.3, and 21.4.3 of Asterisk and versions 18.9-cert12 and 20.7-cert2 of certified-asterisk, if …

Sep 5, 2024
CVE-2024-44728
6.1 MEDIUM

Sourcecodehero Event Management System 1.0 allows Stored Cross-Site Scripting via parameters Full Name, Address, Email, and contact# in /clientdetails/admin/regester.php.

Sep 5, 2024
CVE-2024-45589
5.9 MEDIUM

RapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts and allows a remote attacker to cause a denial of service via …

Sep 5, 2024
CVE-2024-45176
6.1 MEDIUM

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper input validation, the C-MOR web interface is vulnerable to reflected cross-site scripting …

Sep 5, 2024
CVE-2024-45098
6.8 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.

Sep 5, 2024
CVE-2024-45097
5.9 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.

Sep 5, 2024
CVE-2024-45096
6.5 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user with access to the package to obtain sensitive information through a directory listing.

Sep 5, 2024
CVE-2023-51712
4.7 MEDIUM

An issue was discovered in Trusted Firmware-M through 2.0.0. The lack of argument verification in the logging subsystem allows attackers to read sensitive data via …

Sep 5, 2024
CVE-2024-8445
5.7 MEDIUM

The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while …

Sep 5, 2024
CVE-2024-8473
6.3 MEDIUM

Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of …

Sep 5, 2024
CVE-2024-8472
6.3 MEDIUM

Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of …

Sep 5, 2024
CVE-2024-8471
6.3 MEDIUM

Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of …

Sep 5, 2024
CVE-2024-8461
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in D-Link DNS-320 2.02b01. This affects an unknown part of the file /cgi-bin/discovery.cgi of the component …

Sep 5, 2024
CVE-2024-7605
4.3 MEDIUM

The HelloAsso plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ha_ajax' function in all versions …

Sep 5, 2024
CVE-2024-7381
5.3 MEDIUM

The Geo Controller plugin for WordPress is vulnerable to unauthorized shortcode execution due to missing authorization and capability checks on the ajax__shortcode_cache function in all …

Sep 5, 2024
CVE-2024-7380
4.3 MEDIUM

The Geo Controller plugin for WordPress is vulnerable to unauthorized menu creation/deletion due to missing capability checks on the ajax__geolocate_menu and ajax__geolocate_remove_menu functions in all …

Sep 5, 2024
CVE-2024-5957
6.3 MEDIUM

This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.

Sep 5, 2024
CVE-2024-5956
6.5 MEDIUM

This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the vulnerable Trellix IPS Manager with garbage data in response …

Sep 5, 2024
CVE-2022-4529
5.3 MEDIUM

The Security, Antivirus, Firewall – S.A.F plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.3.5. This is due …

Sep 5, 2024
CVE-2022-3556
4.4 MEDIUM

The Cab fare calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vehicle title setting in versions up to, and including, 1.1.6 …

Sep 5, 2024
CVE-2024-6929
6.4 MEDIUM

The Dynamic Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘dfiFeatured’ parameter in all versions up to, and including, 3.7.0 …

Sep 5, 2024
CVE-2024-6894
6.4 MEDIUM

The RD Station plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.3.2 due to insufficient input sanitization …

Sep 5, 2024
CVE-2024-6332
6.5 MEDIUM

The Booking for Appointments and Events Calendar – Amelia Premium and Lite plugins for WordPress are vulnerable to unauthorized access of data due to a …

Sep 5, 2024
CVE-2024-8363
6.4 MEDIUM

The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's STI Buttons shortcode in all versions up to, and …

Sep 5, 2024
CVE-2024-5309
5.4 MEDIUM

The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a …

Sep 5, 2024
CVE-2024-45107
5.5 MEDIUM

Acrobat Reader versions 20.005.30636, 24.002.20964, 24.001.30123, 24.002.20991 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. …

Sep 5, 2024
CVE-2024-6835
5.3 MEDIUM

The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.5.6 via the …

Sep 5, 2024
CVE-2024-6846
5.3 MEDIUM

The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and …

Sep 5, 2024
CVE-2024-45429
6.1 MEDIUM

Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5 and earlier. If an attacker with …

Sep 4, 2024
CVE-2024-20506
6.1 MEDIUM

A vulnerability in the ClamD service module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions, all …

Sep 4, 2024
CVE-2024-20505
4.0 MEDIUM

A vulnerability in the PDF parsing module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions, all …

Sep 4, 2024
CVE-2024-45399
4.3 MEDIUM

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In Indico prior to version 3.3.4, corresponding to Flask-Multipass prior …

Sep 4, 2024
CVE-2024-45172
6.8 MEDIUM

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to missing protection mechanisms, the C-MOR web interface is vulnerable to cross-site …

Sep 4, 2024
CVE-2024-45008
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Input: MT - limit max slots syzbot is reporting too large allocation at input_mt_init_slots(), for …

Sep 4, 2024
CVE-2024-45007
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: char: xillybus: Don't destroy workqueue from work item running on it Triggered by a kref …

Sep 4, 2024
CVE-2024-45006
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xhci: Fix Panther point NULL pointer deref at full-speed re-enumeration re-enumerating full-speed devices after a …

Sep 4, 2024
CVE-2024-45005
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: fix validity interception issue when gisa is switched off We might run into …

Sep 4, 2024
CVE-2024-45004
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: dcp: fix leak of blob encryption key Trusted keys unseal the key blob …

Sep 4, 2024
CVE-2024-45003
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vfs: Don't evict inode under the inode lru traversing context The inode reclaiming process(See function …

Sep 4, 2024
CVE-2024-45002
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: rtla/osnoise: Prevent NULL dereference in error handling If the "tool->data" allocation fails then there is …

Sep 4, 2024
CVE-2024-45001
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix RX buf alloc_size alignment and atomic op panic The MANA driver's RX …

Sep 4, 2024
CVE-2024-45000
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs/netfs/fscache_cookie: add missing "n_accesses" check This fixes a NULL pointer dereference bug due to a …

Sep 4, 2024
CVE-2024-44996
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vsock: fix recursive ->recvmsg calls After a vsock socket has been added to a BPF …

Sep 4, 2024
CVE-2024-44995
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix a deadlock problem when config TC during resetting When config TC during …

Sep 4, 2024
CVE-2024-44994
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iommu: Restore lost return in iommu_report_device_fault() When iommu_report_device_fault gets called with a partial fault it …

Sep 4, 2024
CVE-2024-44992
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: smb/client: avoid possible NULL dereference in cifs_free_subrequest() Clang static checker (scan-build) warning: cifsglob.h:line 890, column …

Sep 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.