CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6489
5.3 MEDIUM

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_google_api_key function …

Jul 20, 2024
CVE-2024-40347
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in Hyland Alfresco Platform 23.2.1-r96 allows attackers to execute arbitrary code in the context of a user's browser via …

Jul 20, 2024
CVE-2024-3934
6.5 MEDIUM

The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to Path Traversal in versions 7.3.0 to 7.5.1 via the mercadopagoDownloadLog function. This makes …

Jul 20, 2024
CVE-2024-6560
5.3 MEDIUM

The Addonify – Quick View For WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.16. This …

Jul 20, 2024
CVE-2024-2337
6.4 MEDIUM

The Easy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'testimonials_grid ' shortcode in all versions up to, and including, …

Jul 20, 2024
CVE-2024-5804
4.3 MEDIUM

The Conditional Fields for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.13. This is …

Jul 20, 2024
CVE-2024-41599
6.1 MEDIUM

Cross Site Scripting vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the file upload method

Jul 19, 2024
CVE-2024-41597
4.2 MEDIUM

Cross Site Request Forgery vulnerability in ProcessWire v.3.0.229 allows a remote attacker to execute arbitrary code via a crafted HTML file to the comments functionality.

Jul 19, 2024
CVE-2024-41124
6.3 MEDIUM

Puncia is the Official CLI utility for Subdomain Center & Exploit Observer. `API_URLS` is utilizing HTTP instead of HTTPS for communication that can lead to …

Jul 19, 2024
CVE-2024-39123
5.4 MEDIUM

In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization performed by the clean_string function. …

Jul 19, 2024
CVE-2024-29080
6.5 MEDIUM

Potential vulnerabilities have been identified in the HP Display Control software component within the HP Application Enabling Software Driver which might allow escalation of privilege.

Jul 19, 2024
CVE-2024-24970
6.5 MEDIUM

Potential vulnerabilities have been identified in the HP Display Control software component within the HP Application Enabling Software Driver which might allow escalation of privilege.

Jul 19, 2024
CVE-2024-37066
6.8 MEDIUM

A command injection vulnerability exists in Wyze V4 Pro firmware versions before 4.50.4.9222, which allows attackers to execute arbitrary commands over Bluetooth as root during …

Jul 19, 2024
CVE-2024-6916
5.9 MEDIUM

A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a terminal using the '--show-inputs-only' flag.

Jul 19, 2024
CVE-2024-5977
5.4 MEDIUM

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Jul 19, 2024
CVE-2024-6906
6.3 MEDIUM

A vulnerability was found in SourceCodester Record Management System 1.0 and classified as critical. This issue affects some unknown processing of the file add_leave_non_user.php. The …

Jul 19, 2024
CVE-2024-6905
6.3 MEDIUM

A vulnerability has been found in SourceCodester Record Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file view_info_user.php. The …

Jul 19, 2024
CVE-2024-6904
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Record Management System 1.0. This affects an unknown part of the file sort2_user.php. The …

Jul 19, 2024
CVE-2024-39457
5.4 MEDIUM

Cybozu Garoon 6.0.0 to 6.0.1 contains a cross-site scripting vulnerability in PDF preview. If this vulnerability is exploited, an arbitrary script may be executed on …

Jul 19, 2024
CVE-2024-6903
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Record Management System 1.0. Affected by this issue is some unknown functionality of …

Jul 19, 2024
CVE-2024-6902
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Record Management System 1.0. Affected by this vulnerability is an unknown functionality of the file sort_user.php. …

Jul 19, 2024
CVE-2024-6799
4.3 MEDIUM

The YITH Essential Kit for WooCommerce #1 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Jul 19, 2024
CVE-2024-6901
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Record Management System 1.0. Affected is an unknown function of the file entry.php. The manipulation …

Jul 19, 2024
CVE-2024-6900
6.3 MEDIUM

A vulnerability was found in SourceCodester Record Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Jul 19, 2024
CVE-2024-5604
5.9 MEDIUM

The Bug Library WordPress plugin before 2.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jul 19, 2024
CVE-2023-7268
6.5 MEDIUM

The ArtPlacer Widget WordPress plugin before 2.21.2 does not have authorisation check in place when deleting widgets, allowing ay authenticated users, such as subscriber, to …

Jul 19, 2024
CVE-2024-6899
6.3 MEDIUM

A vulnerability was found in SourceCodester Record Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file view_info.php. …

Jul 19, 2024
CVE-2024-21583
4.1 MEDIUM

Versions of the package github.com/gitpod-io/gitpod/components/server/go/pkg/lib before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/components/ws-proxy/pkg/proxy before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/install/installer/pkg/components/auth before main-gha.27122; versions of the package …

Jul 19, 2024
CVE-2024-38156
6.1 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Jul 19, 2024
CVE-2024-5997
4.3 MEDIUM

The Duplica – Duplicate Posts, Pages, Custom Posts or Users plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Jul 18, 2024
CVE-2024-6455
5.3 MEDIUM

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.0 due to a missing capability …

Jul 18, 2024
CVE-2024-39090
6.1 MEDIUM

The PHPGurukul Online Shopping Portal Project version 2.0 contains a vulnerability that allows Cross-Site Request Forgery (CSRF) to lead to Stored Cross-Site Scripting (XSS). An …

Jul 18, 2024
CVE-2024-30126
4.7 MEDIUM

HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which can allow an attacker to create a malicious website that embeds the target …

Jul 18, 2024
CVE-2024-5321
6.1 MEDIUM

A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read container logs and NT AUTHORITY\Authenticated Users may …

Jul 18, 2024
CVE-2024-5625
6.5 MEDIUM

Improper Restriction of XML External Entity Reference vulnerability in PruvaSoft Informatics Apinizer Management Console allows Data Serialization External Entities Blowup.This issue affects Apinizer Management Console: …

Jul 18, 2024
CVE-2024-30125
6.2 MEDIUM

HCL BigFix Compliance server can respond with an HTTP status of 500, indicating a server-side error that may cause the server process to die.

Jul 18, 2024
CVE-2024-5620
6.5 MEDIUM

Authentication Bypass Using an Alternate Path or Channel vulnerability in PruvaSoft Informatics Apinizer Management Console allows Authentication Bypass.This issue affects Apinizer Management Console: before 2024.05.1.

Jul 18, 2024
CVE-2024-40648
5.4 MEDIUM

matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. The `UserIdentity::is_verified()` method in the matrix-sdk-crypto crate before version 0.7.2 doesn't take into account …

Jul 18, 2024
CVE-2024-40647
5.3 MEDIUM

sentry-sdk is the official Python SDK for Sentry.io. A bug in Sentry's Python SDK < 2.8.0 allows the environment variables to be passed to subprocesses …

Jul 18, 2024
CVE-2024-40644
6.8 MEDIUM

gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. `gix-path` can be tricked into running another `git.exe` placed in an untrusted location …

Jul 18, 2024
CVE-2023-40704
6.8 MEDIUM

The product does not require unique and complex passwords to be created during installation. Using Philips's default password could jeopardize the PACS system if the …

Jul 18, 2024
CVE-2024-38302
6.8 MEDIUM

Dell Data Lakehouse, version(s) 1.0.0.0, contain(s) a Missing Encryption of Sensitive Data vulnerability in the DDAE (Starburst). A low privileged attacker with adjacent network access …

Jul 18, 2024
CVE-2024-30473
4.9 MEDIUM

Dell ECS, versions prior to 3.8.1, contain a privilege elevation vulnerability in user management. A remote high privileged attacker could potentially exploit this vulnerability, gaining …

Jul 18, 2024
CVE-2024-6504
4.3 MEDIUM

Rapid7 InsightVM Console versions below 6.6.260 suffer from a protection mechanism failure whereby an attacker with network access to the InsightVM Console can cause it …

Jul 18, 2024
CVE-2024-40725
5.3 MEDIUM

A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" …

Jul 18, 2024
CVE-2024-5555
6.4 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jul 18, 2024
CVE-2024-5554
6.4 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jul 18, 2024
CVE-2023-6708
5.4 MEDIUM

The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG upload feature in all versions up to, and including, 2.5.7 …

Jul 18, 2024
CVE-2024-6705
5.5 MEDIUM

The RegLevel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.1 due to insufficient …

Jul 18, 2024
CVE-2024-6599
4.3 MEDIUM

The Meks Video Importer plugin for WordPress is vulnerable to unauthorized API key modification due to a missing capability check on the ajax_save_settings function in …

Jul 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.