CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6175
5.4 MEDIUM

The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Jul 18, 2024
CVE-2024-5964
6.4 MEDIUM

The Zenon Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up …

Jul 18, 2024
CVE-2024-39682
6.4 MEDIUM

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.7.15.4 due …

Jul 18, 2024
CVE-2024-39681
5.4 MEDIUM

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, …

Jul 18, 2024
CVE-2024-39680
5.4 MEDIUM

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, …

Jul 18, 2024
CVE-2024-39679
4.3 MEDIUM

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, …

Jul 18, 2024
CVE-2024-39678
4.3 MEDIUM

Cooked is a recipe plugin for WordPress. The Cooked plugin is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due …

Jul 18, 2024
CVE-2023-43971
6.1 MEDIUM

Cross Site Scripting vulnerability in ACG-faka v1.1.7 allows a remote attacker to execute arbitrary code via the encode parameter in Index.php.

Jul 17, 2024
CVE-2024-40402
6.3 MEDIUM

A SQL injection vulnerability was found in 'ajax.php' of Sourcecodester Simple Library Management System 1.0. This vulnerability stems from insufficient user input validation of the …

Jul 17, 2024
CVE-2024-39126
5.4 MEDIUM

Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents.

Jul 17, 2024
CVE-2024-39125
5.4 MEDIUM

Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header.

Jul 17, 2024
CVE-2024-39124
5.4 MEDIUM

In Roundup before 2.4.0, classhelpers (_generic.help.html) allow XSS.

Jul 17, 2024
CVE-2024-32981
5.4 MEDIUM

Silverstripe framework is the PHP framework forming the base for the Silverstripe CMS. In affected versions a bad actor with access to edit content in …

Jul 17, 2024
CVE-2024-29885
4.3 MEDIUM

silverstripe/reports is an API for creating backend reports in the Silverstripe Framework. In affected versions reports can be accessed by their direct URL by any …

Jul 17, 2024
CVE-2024-28796
6.4 MEDIUM

IBM ClearQuest (CQ) 9.1 through 9.1.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

Jul 17, 2024
CVE-2024-40636
5.3 MEDIUM

Steeltoe is an open source project that provides a collection of libraries that helps users build production-grade cloud-native applications using externalized configuration, service discovery, distributed …

Jul 17, 2024
CVE-2024-40633
5.3 MEDIUM

Sylius is an Open Source eCommerce Framework on Symfony. A security vulnerability was discovered in the `/api/v2/shop/adjustments/{id}` endpoint, which retrieves order adjustments based on incremental …

Jul 17, 2024
CVE-2024-38446
6.5 MEDIUM

NATO NCI ANET 3.4.1 mishandles report ownership. A user can create a report and, despite the restrictions imposed by the UI, change the author of …

Jul 17, 2024
CVE-2024-20429
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco AsyncOS for Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary system commands …

Jul 17, 2024
CVE-2024-20416
6.5 MEDIUM

A vulnerability in the upload module of Cisco RV340 and RV345 Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to execute arbitrary …

Jul 17, 2024
CVE-2024-20400
4.7 MEDIUM

A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote attacker to redirect a user to a malicious web …

Jul 17, 2024
CVE-2024-20396
5.3 MEDIUM

A vulnerability in the protocol handlers of Cisco Webex App could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability exists …

Jul 17, 2024
CVE-2024-20395
6.4 MEDIUM

A vulnerability in the media retrieval functionality of Cisco Webex App could allow an unauthenticated, adjacent attacker to gain access to sensitive session information. This …

Jul 17, 2024
CVE-2024-20296
4.7 MEDIUM

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to upload arbitrary files to an …

Jul 17, 2024
CVE-2024-6830
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Simple Inventory Management System 1.0. Affected is an unknown function of the file action.php …

Jul 17, 2024
CVE-2024-6833
5.9 MEDIUM

A vulnerability in Zowe CLI allows local, privileged actors to store previously entered secure credentials in a plaintext file as part of an auto-init operation.

Jul 17, 2024
CVE-2024-29120
5.9 MEDIUM

In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use …

Jul 17, 2024
CVE-2024-27311
5.5 MEDIUM

Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to directory traversal vulnerability which allows the user to upload new files to the server …

Jul 17, 2024
CVE-2024-40617
6.5 MEDIUM

Path traversal vulnerability exists in FUJITSU Network Edgiot GW1500 (M2M-GW for FENICS). If a remote authenticated attacker with User Class privilege sends a specially crafted …

Jul 17, 2024
CVE-2024-31979
4.3 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Apache StreamPipes during installation process of pipeline elements. Previously, StreamPipes allowed users to configure custom endpoints from which to …

Jul 17, 2024
CVE-2024-29737
4.7 MEDIUM

In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, …

Jul 17, 2024
CVE-2023-52291
4.7 MEDIUM

In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, …

Jul 17, 2024
CVE-2024-5703
4.3 MEDIUM

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized API access due …

Jul 17, 2024
CVE-2024-5582
6.4 MEDIUM

The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' attribute within the …

Jul 17, 2024
CVE-2024-39863
5.4 MEDIUM

Apache Airflow versions before 2.9.3 have a vulnerability that allows an authenticated attacker to inject a malicious link when installing a provider. Users are recommended …

Jul 17, 2024
CVE-2024-6669
5.5 MEDIUM

The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and …

Jul 17, 2024
CVE-2024-6033
4.3 MEDIUM

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized data importation due to a missing capability check on …

Jul 17, 2024
CVE-2024-5255
6.4 MEDIUM

The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_dual_color shortcode in all versions up to, and …

Jul 17, 2024
CVE-2024-5254
6.4 MEDIUM

The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_info_banner shortcode in all versions up to, and …

Jul 17, 2024
CVE-2024-5253
6.4 MEDIUM

The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ult_team shortcode in all versions up to, and …

Jul 17, 2024
CVE-2024-5252
6.4 MEDIUM

The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_info_table shortcode in all versions up to, and …

Jul 17, 2024
CVE-2024-5251
6.4 MEDIUM

The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_pricing shortcode in all versions up to, and …

Jul 17, 2024
CVE-2024-41010
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix too early release of tcx_entry Pedro Pinto and later independently also Hyunwoo Kim …

Jul 17, 2024
CVE-2024-41009
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix overrunning reservations in ringbuf The BPF ring buffer internally is implemented as a …

Jul 17, 2024
CVE-2024-6803
5.5 MEDIUM

A vulnerability has been found in itsourcecode Document Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Jul 17, 2024
CVE-2024-6535
5.3 MEDIUM

A flaw was found in Skupper. When Skupper is initialized with the console-enabled and with console-auth set to Openshift, it configures the openshift oauth-proxy with …

Jul 17, 2024
CVE-2024-6802
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Computer Laboratory Management System 1.0. Affected is an unknown function of the file /lms/classes/Master.php?f=save_record. …

Jul 17, 2024
CVE-2024-6801
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Online Student Management System 1.0. This issue affects some unknown processing of the …

Jul 17, 2024
CVE-2024-5500
6.5 MEDIUM

Inappropriate implementation in Sign-In in Google Chrome prior to 1.3.36.351 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security …

Jul 16, 2024
CVE-2024-40637
4.2 MEDIUM

dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications. When a user installs …

Jul 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.