CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23317
6.3 MEDIUM

External Control of File Name or Path (CWE-73) in the Controller 6000 and Controller 7000 allows an attacker with local access to the Controller to …

Jul 11, 2024
CVE-2024-22387
6.8 MEDIUM

External Control of Critical State Data (CWE-642) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated user to modify device I/O …

Jul 11, 2024
CVE-2016-15039
6.3 MEDIUM

A vulnerability classified as critical was found in mhuertos phpLDAPadmin up to 665dbc2690ebeb5392d38f1fece0a654225a0b38. Affected by this vulnerability is the function makeHttpRequest of the file htdocs/js/ajax_functions.js. …

Jul 11, 2024
CVE-2024-6652
6.3 MEDIUM

A vulnerability was found in itsourcecode Gym Management System 1.0. It has been classified as critical. This affects an unknown part of the file manage_member.php. …

Jul 10, 2024
CVE-2024-39561
5.8 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX4600 and SRX5000 Series allows …

Jul 10, 2024
CVE-2024-39560
6.5 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a logically …

Jul 10, 2024
CVE-2024-39559
5.9 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS Evolved may allow a network-based unauthenticated attacker to …

Jul 10, 2024
CVE-2024-39558
6.5 MEDIUM

An Unchecked Return Value vulnerability in the Routing Protocol Daemon (rpd) on Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows a logically …

Jul 10, 2024
CVE-2024-39557
6.5 MEDIUM

An Uncontrolled Resource Consumption vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS Evolved allows an unauthenticated, adjacent attacker to …

Jul 10, 2024
CVE-2024-39556
6.4 MEDIUM

A Stack-Based Buffer Overflow vulnerability in Juniper Networks Junos OS and Juniper Networks Junos OS Evolved may allow a local, low-privileged attacker with access to …

Jul 10, 2024
CVE-2024-39554
5.9 MEDIUM

A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Juniper Networks …

Jul 10, 2024
CVE-2024-39517
6.5 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Layer 2 Address Learning Daemon (l2ald) on Juniper Networks Junos OS and Junos OS …

Jul 10, 2024
CVE-2024-39514
6.5 MEDIUM

An Improper Check or Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos and Junos OS Evolved allows an …

Jul 10, 2024
CVE-2024-39513
5.5 MEDIUM

An Improper Input Validation vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved allows a local, low-privileged attacker to cause a …

Jul 10, 2024
CVE-2024-39512
6.6 MEDIUM

An Improper Physical Access Control vulnerability in the console port control of Juniper Networks Junos OS Evolved allows an attacker with physical access to the …

Jul 10, 2024
CVE-2024-39511
5.5 MEDIUM

An Improper Input Validation vulnerability in the 802.1X Authentication (dot1x) Daemon of Juniper Networks Junos OS allows a local, low-privileged attacker with access to the …

Jul 10, 2024
CVE-2024-6150
4.3 MEDIUM

A non-admin user can cause short-term disruption in Target VM availability in Citrix Provisioning

Jul 10, 2024
CVE-2024-6149
6.1 MEDIUM

Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5

Jul 10, 2024
CVE-2024-38353
5.3 MEDIUM

CodiMD allows realtime collaborative markdown notes on all platforms. CodiMD before 2.5.4 is missing authentication and access control vulnerability allowing an unauthenticated attacker to gain …

Jul 10, 2024
CVE-2024-25076
6.8 MEDIUM

An issue was discovered on Renesas SmartBond DA14691, DA14695, DA14697, and DA14699 devices. The bootrom function responsible for validating the Flash Product Header directly uses …

Jul 10, 2024
CVE-2024-6649
4.3 MEDIUM

A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is the …

Jul 10, 2024
CVE-2024-5913
6.1 MEDIUM

An improper input validation vulnerability in Palo Alto Networks PAN-OS software enables an attacker with the ability to tamper with the physical file system to …

Jul 10, 2024
CVE-2024-5911
4.9 MEDIUM

An arbitrary file upload vulnerability in Palo Alto Networks Panorama software enables an authenticated read-write administrator with access to the web interface to disrupt system …

Jul 10, 2024
CVE-2024-5492
6.1 MEDIUM

Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway

Jul 10, 2024
CVE-2024-37147
4.3 MEDIUM

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can …

Jul 10, 2024
CVE-2024-27095
5.4 MEDIUM

Decidim is a participatory democracy framework. The admin panel is subject to potential XSS attach in case the attacker manages to modify some records being …

Jul 10, 2024
CVE-2024-27090
5.3 MEDIUM

Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. If an …

Jul 10, 2024
CVE-2024-6647
4.7 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Croogo up to 4.0.7. This affects an unknown part of the …

Jul 10, 2024
CVE-2024-6646
5.3 MEDIUM

A vulnerability was found in Netgear WN604 up to 20240710. It has been rated as problematic. Affected by this issue is some unknown functionality of …

Jul 10, 2024
CVE-2024-37504
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team FileBird Document Library.This issue affects FileBird Document Library: from n/a through 2.0.6.

Jul 10, 2024
CVE-2024-37498
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pauple Table & Contact Form 7 Database – Tablesome.This issue affects Table & Contact Form …

Jul 10, 2024
CVE-2024-37270
5.3 MEDIUM

Insertion of Sensitive Information into Log File vulnerability in TrustedLogin TrustedLogin Vendor.This issue affects TrustedLogin Vendor: from n/a before 1.1.1.

Jul 10, 2024
CVE-2024-37205
5.3 MEDIUM

Insertion of Sensitive Information into Log File vulnerability in SERVIT Software Solutions.This issue affects affiliate-toolkit: from n/a through 3.4.4.

Jul 10, 2024
CVE-2024-6645
6.3 MEDIUM

A vulnerability was found in WuKongOpenSource Wukong_nocode up to 20230807. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jul 10, 2024
CVE-2024-6644
6.3 MEDIUM

A vulnerability was found in zmops ArgusDBM up to 0.1.0. It has been classified as critical. Affected is the function getDefaultClassLoader of the file CalculateAlarm.java …

Jul 10, 2024
CVE-2024-5178
4.9 MEDIUM

ServiceNow has addressed a sensitive file read vulnerability that was identified in the Washington DC, Vancouver, and Utah Now Platform releases. This vulnerability could allow …

Jul 10, 2024
CVE-2024-40417
6.5 MEDIUM

A vulnerability was found in Tenda AX1806 1.0.0.1. Affected by this issue is the function formSetRebootTimer of the file /goform/SetIpMacBind. The manipulation of the argument …

Jul 10, 2024
CVE-2024-40412
6.8 MEDIUM

Tenda AX12 v1.0 v22.03.01.46 contains a stack overflow in the deviceList parameter of the sub_42E410 function.

Jul 10, 2024
CVE-2024-20456
6.7 MEDIUM

A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Cisco Secure …

Jul 10, 2024
CVE-2023-35006
5.4 MEDIUM

IBM Security QRadar EDR 3.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in …

Jul 10, 2024
CVE-2023-33860
5.3 MEDIUM

IBM Security QRadar EDR 3.12 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie …

Jul 10, 2024
CVE-2023-33859
5.3 MEDIUM

IBM Security QRadar EDR 3.12 could disclose sensitive information due to an observable login response discrepancy. IBM X-Force ID: 257697.

Jul 10, 2024
CVE-2024-40336
6.1 MEDIUM

idccms v1.35 is vulnerable to Cross Site Scripting (XSS) within the 'Image Advertising Management.'

Jul 10, 2024
CVE-2024-40328
6.3 MEDIUM

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/memberOnline_deal.php?mudi=del&dataType=&dataID=6

Jul 10, 2024
CVE-2024-6556
5.3 MEDIUM

The SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, …

Jul 10, 2024
CVE-2024-5664
6.4 MEDIUM

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' …

Jul 10, 2024
CVE-2024-39493
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: qat - Fix ADF_DEV_RESET_SYNC memory leak Using completion_done to determine whether the caller has …

Jul 10, 2024
CVE-2024-39491
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: cs35l56: Fix lifetime of cs_dsp instance The cs_dsp instance is initialized in the …

Jul 10, 2024
CVE-2024-39490
6.2 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix missing sk_buff release in seg6_input_core The seg6_input() function is responsible for adding …

Jul 10, 2024
CVE-2024-39489
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix memleak in seg6_hmac_init_algo seg6_hmac_init_algo returns without cleaning up the previous allocations if …

Jul 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.