CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-39497
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/shmem-helper: Fix BUG_ON() on mmap(PROT_WRITE, MAP_PRIVATE) Lack of check for copy-on-write (COW) mapping in drm_gem_shmem_mmap …

Jul 12, 2024
CVE-2024-6625
5.5 MEDIUM

The WP Total Branding – Complete branding solution for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions …

Jul 12, 2024
CVE-2024-6588
6.4 MEDIUM

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘media_url’ parameter in all versions up to, and …

Jul 12, 2024
CVE-2024-6555
5.3 MEDIUM

The WP Popups – WordPress Popup builder plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.2.0.1. This …

Jul 12, 2024
CVE-2024-5811
5.4 MEDIUM

The Simple Video Directory WordPress plugin before 1.4.4 does not sanitise and escape some of its settings, which could allow contributors and higher to perform …

Jul 12, 2024
CVE-2024-5626
6.1 MEDIUM

The Inline Related Posts WordPress plugin before 3.7.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jul 12, 2024
CVE-2024-4753
4.8 MEDIUM

The WP Secure Maintenance WordPress plugin before 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jul 12, 2024
CVE-2024-3112
4.8 MEDIUM

The Quotes and Tips by BestWebSoft WordPress plugin before 1.45 does not properly validate image files uploaded, allowing high privilege users such as admin to …

Jul 12, 2024
CVE-2024-2696
4.8 MEDIUM

The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jul 12, 2024
CVE-2024-2640
5.4 MEDIUM

The Watu Quiz WordPress plugin before 3.4.1.2 does not sanitise and escape some of its settings, which could allow users such as authors (if they've …

Jul 12, 2024
CVE-2024-2430
5.4 MEDIUM

The Website Content in Page or Post WordPress plugin before 2024.04.09 does not validate and escape some of its shortcode attributes before outputting them back …

Jul 12, 2024
CVE-2024-0974
4.8 MEDIUM

The Social Media Widget WordPress plugin before 4.0.9 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jul 12, 2024
CVE-2024-1375
4.3 MEDIUM

The Event post plugin for WordPress is vulnerable to unauthorized bulk metadata update due to a missing nonce check on the save_bulkdatas function in all …

Jul 12, 2024
CVE-2024-6392
5.4 MEDIUM

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modification due to missing capability checks on the …

Jul 11, 2024
CVE-2022-29946
6.3 MEDIUM

NATS.io NATS Server before 2.8.2 and Streaming Server before 0.24.6 could allow a remote attacker to bypass security restrictions, caused by the failure to enforce …

Jul 11, 2024
CVE-2024-6681
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in witmy my-springsecurity-plus up to 2024-07-04. Affected by this issue is some unknown functionality of …

Jul 11, 2024
CVE-2024-6485
6.4 MEDIUM

A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the …

Jul 11, 2024
CVE-2024-39553
6.5 MEDIUM

An Exposure of Resource to Wrong Sphere vulnerability in the sampling service of Juniper Networks Junos OS Evolved allows an unauthenticated network-based attacker to send …

Jul 11, 2024
CVE-2024-39550
6.5 MEDIUM

A Missing Release of Memory after Effective Lifetime vulnerability in the rtlogd process of Juniper Networks Junos OS on MX Series with SPC3 allows an …

Jul 11, 2024
CVE-2024-39543
6.5 MEDIUM

A Buffer Copy without Checking Size of Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS …

Jul 11, 2024
CVE-2024-39541
6.5 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, …

Jul 11, 2024
CVE-2024-39539
5.3 MEDIUM

A Missing Release of Memory after Effective Lifetime vulnerability in Juniper Networks Junos OS on MX Series allows an unauthenticated adjacent attacker to cause a …

Jul 11, 2024
CVE-2024-39538
6.5 MEDIUM

A Buffer Copy without Checking Size of Input vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved on ACX7000 Series allows …

Jul 11, 2024
CVE-2024-39537
6.5 MEDIUM

An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved on ACX 7000 Series allows an unauthenticated, network-based attacker …

Jul 11, 2024
CVE-2024-39536
5.3 MEDIUM

A Missing Release of Memory after Effective Lifetime vulnerability in the Periodic Packet Management Daemon (ppmd) of Juniper Networks Junos OS and Junos OS Evolved …

Jul 11, 2024
CVE-2024-39535
6.5 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX 7000 Series …

Jul 11, 2024
CVE-2024-39533
5.8 MEDIUM

An Unimplemented or Unsupported Feature in the UI vulnerability in Juniper Networks Junos OS on QFX5000 Series and EX4600 Series allows an unauthenticated, network-based attacker …

Jul 11, 2024
CVE-2024-39532
6.3 MEDIUM

An Insertion of Sensitive Information into Log File vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high …

Jul 11, 2024
CVE-2024-6680
6.3 MEDIUM

A vulnerability classified as critical was found in witmy my-springsecurity-plus up to 2024-07-04. Affected by this vulnerability is an unknown functionality of the file /api/dept/build. …

Jul 11, 2024
CVE-2024-39905
5.3 MEDIUM

Red is a fully modular Discord bot. Due to a bug in Red's Core API, 3rd-party cogs using the `@commands.can_manage_channel()` command permission check without additional …

Jul 11, 2024
CVE-2024-39528
5.7 MEDIUM

A Use After Free vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated, network-based attacker …

Jul 11, 2024
CVE-2024-39519
6.5 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX7000 Series allows …

Jul 11, 2024
CVE-2024-39317
6.5 MEDIUM

Wagtail is an open source content management system built on Django. A bug in Wagtail's `parse_query_string` would result in it taking a long time to …

Jul 11, 2024
CVE-2024-6679
6.3 MEDIUM

A vulnerability classified as critical has been found in witmy my-springsecurity-plus up to 2024-07-04. Affected is an unknown function of the file /api/role. The manipulation …

Jul 11, 2024
CVE-2024-37151
5.3 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Mishandling of multiple fragmented packets using the same IP ID …

Jul 11, 2024
CVE-2024-6035
6.1 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410. This vulnerability allows an attacker to inject malicious JavaScript code into the chat history …

Jul 11, 2024
CVE-2024-6528
5.4 MEDIUM

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a vulnerability leading to a cross-site scripting condition where …

Jul 11, 2024
CVE-2024-38433
6.7 MEDIUM

Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton …

Jul 11, 2024
CVE-2024-6256
6.4 MEDIUM

The Feeds for YouTube (YouTube video, channel, and gallery plugin) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'youtube-feed' shortcode in …

Jul 11, 2024
CVE-2024-5257
4.9 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer …

Jul 11, 2024
CVE-2024-6138
4.8 MEDIUM

The Secure Copy Content Protection and Content Locking WordPress plugin before 4.0.9 does not sanitise and escape some of its settings, which could allow high …

Jul 11, 2024
CVE-2024-6026
5.4 MEDIUM

The Slider by 10Web WordPress plugin before 1.2.56 does not sanitise and escape some of its Slide options, which could allow authenticated users with access …

Jul 11, 2024
CVE-2024-6025
5.4 MEDIUM

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.5 does not sanitise and escape some of its Quiz settings, which could allow contributors and …

Jul 11, 2024
CVE-2024-5444
5.4 MEDIUM

The Bible Text WordPress plugin through 0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Jul 11, 2024
CVE-2024-4655
5.4 MEDIUM

The Ultimate Blocks WordPress plugin before 3.1.9 does not validate and escape some of its block options before outputting them back in a page/post where …

Jul 11, 2024
CVE-2024-6554
5.3 MEDIUM

The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and …

Jul 11, 2024
CVE-2024-0619
5.3 MEDIUM

The Payflex Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the payment_callback() function in …

Jul 11, 2024
CVE-2024-6676
6.3 MEDIUM

A vulnerability has been found in witmy my-springsecurity-plus up to 2024-07-03 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Jul 11, 2024
CVE-2024-6210
5.3 MEDIUM

The Duplicator plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 1.5.9. This makes it possible for unauthenticated attackers …

Jul 11, 2024
CVE-2024-23485
4.6 MEDIUM

Improperly Preserved Integrity of Hardware Configuration State During a Power Save/Restore Operation (CWE-1304) in the Controller 6000 and 7000 can lead to secured door locks …

Jul 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.