CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-36987
4.3 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, an authenticated, low-privileged user who does not hold the …

Jul 1, 2024
CVE-2024-36986
6.3 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, an authenticated user could run risky commands …

Jul 1, 2024
CVE-2024-20399
6.0 MEDIUM KEV

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root …

Jul 1, 2024
CVE-2024-36422
6.1 MEDIUM

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting …

Jul 1, 2024
CVE-2024-6375
5.4 MEDIUM

A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading …

Jul 1, 2024
CVE-2024-34696
4.5 MEDIUM

GeoServer is an open source server that allows users to share and edit geospatial data. Starting in version 2.10.0 and prior to versions 2.24.4 and …

Jul 1, 2024
CVE-2024-21482
6.8 MEDIUM

Memory corruption during the secure boot process, when the `bootm` command is used, it bypasses the authentication of the kernel/rootfs image.

Jul 1, 2024
CVE-2024-21466
6.5 MEDIUM

Information disclosure while parsing sub-IE length during new IE generation.

Jul 1, 2024
CVE-2024-21458
6.5 MEDIUM

Information disclosure while handling SA query action frame.

Jul 1, 2024
CVE-2024-21457
6.5 MEDIUM

INformation disclosure while handling Multi-link IE in beacon frame.

Jul 1, 2024
CVE-2024-21456
6.5 MEDIUM

Information Disclosure while parsing beacon frame in STA.

Jul 1, 2024
CVE-2024-6050
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation vulnerability in SOKRATES-software SOWA OPAC allows a Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into …

Jul 1, 2024
CVE-2024-38953
6.1 MEDIUM

phpok 6.4.003 contains a Cross Site Scripting (XSS) vulnerability in the ok_f() method under the framework/api/upload_control.php file.

Jul 1, 2024
CVE-2024-39853
6.5 MEDIUM

adolph_dudu ratio-swiper 0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39018
6.3 MEDIUM

harvey-woo cat5th/key-serializer v0.2.5 was discovered to contain a prototype pollution via the function "query". This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39002
6.3 MEDIUM

rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function util.clone. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39001
6.3 MEDIUM

ag-grid-enterprise v31.3.2 was discovered to contain a prototype pollution via the component _ModuleSupport.jsonApply. This vulnerability allows attackers to execute arbitrary code or cause a Denial …

Jul 1, 2024
CVE-2024-39000
6.5 MEDIUM

adolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-38997
6.5 MEDIUM

adolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function extendDefaults. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-38990
6.3 MEDIUM

Tada5hi sp-common v0.5.4 was discovered to contain a prototype pollution via the function mergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-38987
6.3 MEDIUM

aofl cli-lib v3.14.0 was discovered to contain a prototype pollution via the component defaultsDeep. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39430
5.1 MEDIUM

In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jul 1, 2024
CVE-2024-39429
5.1 MEDIUM

In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jul 1, 2024
CVE-2024-39428
6.8 MEDIUM

In trusty service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jul 1, 2024
CVE-2024-39427
5.1 MEDIUM

In trusty service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jul 1, 2024
CVE-2024-6130
4.8 MEDIUM

The Form Maker by 10Web WordPress plugin before 1.15.26 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jul 1, 2024
CVE-2024-4934
5.5 MEDIUM

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 does not validate and escape some of its Quiz fields before outputting them back in …

Jul 1, 2024
CVE-2024-3122
4.9 MEDIUM

CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remote attackers with administrator privilege to read arbitrary file …

Jul 1, 2024
CVE-2024-38480
4.0 MEDIUM

"Piccoma" App for Android and iOS versions prior to 6.20.0 uses a hard-coded API key for an external service, which may allow a local attacker …

Jul 1, 2024
CVE-2024-20081
6.7 MEDIUM

In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with …

Jul 1, 2024
CVE-2024-20079
6.7 MEDIUM

In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with …

Jul 1, 2024
CVE-2024-6419
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Medicine Tracker System 1.0. This vulnerability affects unknown code of the file /classes/Master.php?f=save_medicine. The manipulation of …

Jul 1, 2024
CVE-2024-6417
6.3 MEDIUM

A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Jun 30, 2024
CVE-2024-6416
6.3 MEDIUM

A vulnerability was found in SeaCMS 12.9. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /js/player/dmplayer/dmku/?ac=edit. …

Jun 30, 2024
CVE-2024-28794
5.4 MEDIUM

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …

Jun 30, 2024
CVE-2023-50964
5.4 MEDIUM

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …

Jun 30, 2024
CVE-2024-31898
5.4 MEDIUM

IBM InfoSphere Information Server 11.7 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references. IBM …

Jun 30, 2024
CVE-2024-28797
6.4 MEDIUM

IBM InfoSphere Information Server 11.7 is vulnerable stored to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …

Jun 30, 2024
CVE-2023-50953
5.4 MEDIUM

IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could …

Jun 30, 2024
CVE-2023-50952
5.4 MEDIUM

IBM InfoSphere Information Server 11.7 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, …

Jun 30, 2024
CVE-2024-35119
5.3 MEDIUM

IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in a stack …

Jun 30, 2024
CVE-2024-31902
4.3 MEDIUM

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a …

Jun 30, 2024
CVE-2023-50954
4.3 MEDIUM

IBM InfoSphere Information Server 11.7 returns sensitive information in URL information that could be used in further attacks against the system. IBM X-Force ID: 275776.

Jun 30, 2024
CVE-2024-5062
6.1 MEDIUM

A reflected Cross-Site Scripting (XSS) vulnerability was identified in zenml-io/zenml version 0.57.1. The vulnerability exists due to improper neutralization of input during web page generation, …

Jun 30, 2024
CVE-2024-28795
5.4 MEDIUM

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …

Jun 30, 2024
CVE-2024-6414
5.3 MEDIUM

A vulnerability classified as problematic has been found in Parsec Automation TrakSYS 11.x.x. Affected is an unknown function of the file TS/export/contentpage of the component …

Jun 30, 2024
CVE-2023-4017
6.1 MEDIUM

The Goya theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘attra-color’, 'attra-size', and 'product-cata' parameters in versions up to, and including, 1.0.8.7 …

Jun 29, 2024
CVE-2024-5819
6.4 MEDIUM

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to DOM-based Stored Cross-Site Scripting via HTML data …

Jun 29, 2024
CVE-2024-6363
6.4 MEDIUM

The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's stock_ticker shortcode in all versions up to, and including, 3.24.4 …

Jun 29, 2024
CVE-2024-5790
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attribute within the plugin's Gradient Heading widget in …

Jun 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.