CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-32471
6.0 MEDIUM

Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds read vulnerability. A local authenticated malicious user with high privileges could potentially exploit this …

Jul 24, 2024
CVE-2024-6629
6.4 MEDIUM

The All-in-One Video Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video shortcode in all versions up to, and including, …

Jul 24, 2024
CVE-2024-6571
5.3 MEDIUM

The Optimize Images ALT Text (alt tag) & names for SEO using AI plugin for WordPress is vulnerable to Full Path Disclosure in all versions …

Jul 24, 2024
CVE-2024-6553
5.3 MEDIUM

The WP Meteor Website Speed Optimization Addon plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.3.This is …

Jul 24, 2024
CVE-2023-32466
5.7 MEDIUM

Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this …

Jul 24, 2024
CVE-2024-6836
4.3 MEDIUM

The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells plugin for WordPress is …

Jul 24, 2024
CVE-2024-6094
4.8 MEDIUM

The WP ULike WordPress plugin before 4.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jul 24, 2024
CVE-2024-40767
6.5 MEDIUM

In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image …

Jul 24, 2024
CVE-2024-5861
5.3 MEDIUM

The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the wpep_square_disconnect() …

Jul 24, 2024
CVE-2024-3246
6.1 MEDIUM

The LiteSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.0.1. This is due to missing …

Jul 24, 2024
CVE-2024-6755
6.5 MEDIUM

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the ‘wpw_auto_poster_quick_delete_multiple’ …

Jul 24, 2024
CVE-2024-6754
5.4 MEDIUM

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the ‘wpw_auto_poster_update_tweet_template’ function in all …

Jul 24, 2024
CVE-2024-6752
6.4 MEDIUM

The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_name’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions …

Jul 24, 2024
CVE-2024-6751
6.3 MEDIUM

The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.3.14. This is due to missing …

Jul 24, 2024
CVE-2024-41665
5.5 MEDIUM

Ampache, a web based audio/video streaming application and file manager, has a stored cross-site scripting (XSS) vulnerability in versions prior to 6.6.0. This vulnerability exists …

Jul 23, 2024
CVE-2024-41664
5.4 MEDIUM

Canarytokens help track activity and actions on a network. Prior to `sha-8ea5315`, Canarytokens.org was vulnerable to a blind SSRF in the Webhook alert feature. When …

Jul 23, 2024
CVE-2024-39702
5.9 MEDIUM

In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the string hashing function (used during string interning) allows HashDoS (Hash Denial of Service) attacks. An attacker could …

Jul 23, 2024
CVE-2024-6783
4.8 MEDIUM

A vulnerability has been discovered in Vue, that allows an attacker to perform XSS via prototype pollution. The attacker could change the prototype chain of …

Jul 23, 2024
CVE-2024-41836
5.5 MEDIUM

InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS) condition. An …

Jul 23, 2024
CVE-2024-34128
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to …

Jul 23, 2024
CVE-2024-41012
6.3 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: filelock: Remove locks reliably when fcntl/close race is detected When fcntl_setlk() races with close(), it …

Jul 23, 2024
CVE-2024-6231
5.9 MEDIUM

The Request a Quote WordPress plugin before 2.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jul 23, 2024
CVE-2024-4260
6.5 MEDIUM

The Page Builder Gutenberg Blocks WordPress plugin before 3.1.12 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow …

Jul 23, 2024
CVE-2024-1575
6.5 MEDIUM

The improper privilege management vulnerability in the Zyxel WBE660S firmware version 6.70(ACGG.3) and earlier versions could allow an authenticated user to escalate privileges and download …

Jul 23, 2024
CVE-2024-24507
6.1 MEDIUM

Cross Site Scripting vulnerability in Act-On 2023 allows a remote attacker to execute arbitrary code via the newUser parameter in the login.jsp component.

Jul 22, 2024
CVE-2024-6638
5.5 MEDIUM

An integer overflow vulnerability due to improper input validation when reading TDMS files in LabVIEW may result in an infinite loop. Successful exploitation requires an …

Jul 22, 2024
CVE-2024-6122
5.5 MEDIUM

An incorrect permission in the installation directory for the shared NI SystemLink Server KeyValueDatabase service may result in information disclosure via local access. This affects …

Jul 22, 2024
CVE-2024-41880
5.3 MEDIUM

In veilid-core in Veilid before 0.3.4, the protocol's ping function can be misused in a way that decreases the effectiveness of safety and private routes.

Jul 22, 2024
CVE-2024-40075
4.3 MEDIUM

Laravel v11.x was discovered to contain an XML External Entity (XXE) vulnerability.

Jul 22, 2024
CVE-2024-37380
5.3 MEDIUM

A misconfiguration on UniFi U6+ Access Point could cause an incorrect VLAN traffic forwarding to APs meshed to UniFi U6+ Access Point. Affected Products: UniFi …

Jul 22, 2024
CVE-2024-41130
5.4 MEDIUM

llama.cpp provides LLM inference in C/C++. Prior to b3427, llama.cpp contains a null pointer dereference in gguf_init_from_file. This vulnerability is fixed in b3427.

Jul 22, 2024
CVE-2024-39688
6.5 MEDIUM

Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is concatenated with other folders and used to open a …

Jul 22, 2024
CVE-2024-41825
4.6 MEDIUM

In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab

Jul 22, 2024
CVE-2024-41824
6.4 MEDIUM

In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases

Jul 22, 2024
CVE-2024-41132
5.3 MEDIUM

ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory …

Jul 22, 2024
CVE-2024-41129
4.4 MEDIUM

The ops library is a Python framework for developing and testing Kubernetes and machine charms. The issue here is that ops passes the secret content …

Jul 22, 2024
CVE-2024-29073
5.3 MEDIUM

An vulnerability in the handling of Latex exists in Ankitects Anki 24.04. When Latex is sanitized to prevent unsafe commands, the verbatim package, which comes …

Jul 22, 2024
CVE-2024-41315
6.8 MEDIUM

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.

Jul 22, 2024
CVE-2024-41314
6.8 MEDIUM

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function.

Jul 22, 2024
CVE-2024-39902
4.8 MEDIUM

Tuleap is an open source suite to improve management of software developments and collaboration. Prior to Tuleap Community Edition 15.10.99.128 and Tuleap Enterprise Edition 15.10-6 …

Jul 22, 2024
CVE-2024-39601
6.5 MEDIUM

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base system (All versions < V1.4.0). Affected devices allow a remote …

Jul 22, 2024
CVE-2024-38759
5.4 MEDIUM

Deserialization of Untrusted Data vulnerability in WP MEDIA SAS Search & Replace search-and-replace.This issue affects Search & Replace: from n/a through 3.2.2.

Jul 22, 2024
CVE-2024-38730
4.9 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Noor alam Magical Addons For Elementor.This issue affects Magical Addons For Elementor: from n/a through 1.1.41.

Jul 22, 2024
CVE-2024-38723
6.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Bernhard Kux JSON Content Importer.This issue affects JSON Content Importer: from n/a through 1.5.6.

Jul 22, 2024
CVE-2024-38701
4.3 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 2.0.4.

Jul 22, 2024
CVE-2024-6542
6.5 MEDIUM

Improper neutralization of livestatus command delimiters in mknotifyd in Checkmk <= 2.0.0p39, < 2.1.0p47, < 2.2.0p32 and < 2.3.0p11 allows arbitrary livestatus command execution.

Jul 22, 2024
CVE-2024-38503
5.4 MEDIUM

When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to …

Jul 22, 2024
CVE-2024-37244
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ninja Team Ninja Beaver Add-ons for Beaver Builder allows Stored XSS.This …

Jul 22, 2024
CVE-2024-37239
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Branda branda-white-labeling.This issue affects Branda: from …

Jul 22, 2024
CVE-2024-37229
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AuburnForest Blogmentor – Blog Layouts for Elementor allows Stored XSS.This issue …

Jul 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.