CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-39488
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: arm64: asm-bug: Add .align 2 to the end of __BUG_ENTRY When CONFIG_DEBUG_BUGVERBOSE=n, we fail to …

Jul 10, 2024
CVE-2023-6813
6.1 MEDIUM

The Login by Auth0 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wle’ parameter in all versions up to, and including, 4.6.0 …

Jul 10, 2024
CVE-2024-36453
6.1 MEDIUM

Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions prior to 1.820. If this vulnerability is exploited, an arbitrary …

Jul 10, 2024
CVE-2024-36450
5.4 MEDIUM

Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exploited, an arbitrary script may be executed on the …

Jul 10, 2024
CVE-2024-6410
4.3 MEDIUM

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Jul 10, 2024
CVE-2024-39330
4.3 MEDIUM

An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. Derived classes of the django.core.files.storage.Storage base class, when they override generate_filename() without …

Jul 10, 2024
CVE-2024-39329
5.3 MEDIUM

An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. The django.contrib.auth.backends.ModelBackend.authenticate() method allows remote attackers to enumerate users via a timing …

Jul 10, 2024
CVE-2024-6550
5.3 MEDIUM

The Gravity Forms: Multiple Form Instances plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.1.1. This is …

Jul 10, 2024
CVE-2024-38301
6.7 MEDIUM

Dell Alienware Command Center, version 5.7.3.0 and prior, contains an improper access control vulnerability. A low privileged attacker could potentially exploit this vulnerability, leading to …

Jul 10, 2024
CVE-2023-32472
5.7 MEDIUM

Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this …

Jul 10, 2024
CVE-2023-32467
5.7 MEDIUM

Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this …

Jul 10, 2024
CVE-2024-5677
4.3 MEDIUM

The Featured Image Generator plugin for WordPress is vulnerable to unauthorized image upload due to a missing capability check on the fig_save_after_generate_image function in all …

Jul 10, 2024
CVE-2024-4866
6.4 MEDIUM

The UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere Elementor Shortcode) plugin for WordPress is vulnerable to Stored …

Jul 10, 2024
CVE-2024-25023
5.5 MEDIUM

IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 stores potentially sensitive information in log files that could …

Jul 10, 2024
CVE-2024-22377
5.3 MEDIUM

The deploy directory in PingFederate runtime nodes is reachable to unauthorized users.

Jul 9, 2024
CVE-2024-39901
4.2 MEDIUM

OpenSearch Observability is collection of plugins and applications that visualize data-driven events. An issue in the OpenSearch observability plugins allows unintended access to private tenant …

Jul 9, 2024
CVE-2024-39900
5.4 MEDIUM

OpenSearch Dashboards Reports allows ‘Report Owner’ export and share reports from OpenSearch Dashboards. An issue in the OpenSearch reporting plugin allows unintended access to private …

Jul 9, 2024
CVE-2024-38963
6.1 MEDIUM

Nopcommerce 4.70.1 is vulnerable to Cross Site Scripting (XSS) via the combined "AddProductReview.Title" and "AddProductReview.ReviewText" parameter(s) (Reviews) when creating a new review.

Jul 9, 2024
CVE-2024-21993
5.7 MEDIUM

SnapCenter versions prior to 5.0p1 are susceptible to a vulnerability which could allow an authenticated attacker to discover plaintext credentials.

Jul 9, 2024
CVE-2024-39181
6.5 MEDIUM

Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 was discovered to contain a buffer overflow via the ApCliSsid parameter in thegenerate_conf_router() function. This vulnerability allows attackers …

Jul 9, 2024
CVE-2024-39072
5.5 MEDIUM

AMTT Hotel Broadband Operation System (HiBOS) v3.0.3.151204 is vulnerable to SQL injection via manager/conference/calendar_remind.php.

Jul 9, 2024
CVE-2024-39031
5.4 MEDIUM

In Silverpeas Core <= 6.3.5, in Mes Agendas, a user can create new events and add them to their calendar. Additionally, users can invite others …

Jul 9, 2024
CVE-2024-38959
6.1 MEDIUM

Cross Site Scripting vulnerability in Creativeitem Academy LMS Learning Management System v.6.8.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via …

Jul 9, 2024
CVE-2024-37865
5.9 MEDIUM

An issue in S3Browser v.11.4.5 and v.10.9.9 and fixed in v.11.5.7 allows a remote attacker to obtain sensitive information via the S3 compatible storage component.

Jul 9, 2024
CVE-2024-34721
5.5 MEDIUM

In ensureFileColumns of MediaProvider.java, there is a possible disclosure of files owned by another user due to improper input validation. This could lead to local …

Jul 9, 2024
CVE-2024-31314
5.5 MEDIUM

In multiple functions of ShortcutService.java, there is a possible persistent DOS due to resource exhaustion. This could lead to local denial of service with no …

Jul 9, 2024
CVE-2024-31312
5.5 MEDIUM

In multiple locations, there is a possible information leak due to a missing permission check. This could lead to local information disclosure exposing played media …

Jul 9, 2024
CVE-2024-27386
6.7 MEDIUM

A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 and Exynos 1480 related to no input validation check on tag_len …

Jul 9, 2024
CVE-2024-27385
6.7 MEDIUM

A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 and Exynos 1480 related to no input validation check on tag_len …

Jul 9, 2024
CVE-2024-40750
5.3 MEDIUM

Linksys Velop Pro 6E 1.0.8 MX6200_1.0.8.215731 and 7 1.0.10.215314 devices send cleartext Wi-Fi passwords over the public Internet during app-based installation.

Jul 9, 2024
CVE-2024-37830
6.1 MEDIUM

An issue in Outline <= v0.76.1 allows attackers to redirect a victim user to a malicious site via intercepting and changing the state cookie.

Jul 9, 2024
CVE-2024-34140
5.5 MEDIUM

Bridge versions 14.0.4, 13.0.7, 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Jul 9, 2024
CVE-2024-28068
5.3 MEDIUM

A vulnerability was discovered in SS in Samsung Mobile Processor, Wearable Processor, and Modems with versions Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos …

Jul 9, 2024
CVE-2024-27363
6.0 MEDIUM

A vulnerability was discovered in Samsung Mobile Processor Exynos 850, Exynos 9610, Exynos 980, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, and Exynos W930 …

Jul 9, 2024
CVE-2024-27361
5.1 MEDIUM

A vulnerability was discovered in Samsung Mobile Processor Exynos 980, Exynos 990, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, and Exynos 2400 …

Jul 9, 2024
CVE-2024-40038
5.3 MEDIUM

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userScore_deal.php?mudi=rev

Jul 9, 2024
CVE-2024-40035
5.9 MEDIUM

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userLevel_deal.php?mudi=add.

Jul 9, 2024
CVE-2024-39899
5.3 MEDIUM

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. In v1.5, PrivateBin introduced the YOURLS server-side proxy. The idea was …

Jul 9, 2024
CVE-2024-39897
4.3 MEDIUM

zot is an OCI image registry. Prior to 2.1.0, the cache driver `GetBlob()` allows read access to any blob without access control check. If a …

Jul 9, 2024
CVE-2024-40742
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the circuit …

Jul 9, 2024
CVE-2024-40741
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the circuit …

Jul 9, 2024
CVE-2024-40740
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Jul 9, 2024
CVE-2024-40739
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Jul 9, 2024
CVE-2024-40738
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Jul 9, 2024
CVE-2024-40737
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Jul 9, 2024
CVE-2024-40736
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Jul 9, 2024
CVE-2024-40735
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Jul 9, 2024
CVE-2024-40734
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Jul 9, 2024
CVE-2024-40733
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Jul 9, 2024
CVE-2024-40732
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Jul 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.