CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-3352
4.3 MEDIUM

The Smush plugin for WordPress is vulnerable to unauthorized deletion of the resmush list due to a missing capability check on the delete_resmush_list() function. This …

Jun 21, 2024
CVE-2024-6214
6.3 MEDIUM

A vulnerability was found in SourceCodester Food Ordering Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Jun 21, 2024
CVE-2024-38359
6.5 MEDIUM

The Lightning Network Daemon (lnd) - is a complete implementation of a Lightning Network node. A parsing vulnerability in lnd's onion processing logic and lead …

Jun 20, 2024
CVE-2024-37183
5.7 MEDIUM

Plain text credentials and session ID can be captured with a network sniffer.

Jun 20, 2024
CVE-2024-36071
6.3 MEDIUM

Samsung Magician 8.0.0 on Windows allows an admin to escalate privileges by tampering with the directory and DLL files used during the installation process. This …

Jun 20, 2024
CVE-2024-31586
6.1 MEDIUM

A Cross Site Scripting (XSS) vulnerability exists in Computer Laboratory Management System version 1.0. This vulnerability allows a remote attacker to execute arbitrary code via …

Jun 20, 2024
CVE-2024-30848
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in SilverSky E-mail service version 5.0.3126 allows remote attackers to inject arbitrary web script or HTML via the version parameter.

Jun 20, 2024
CVE-2024-6154
6.7 MEDIUM

Parallels Desktop Toolgate Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An …

Jun 20, 2024
CVE-2024-38093
4.3 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Jun 20, 2024
CVE-2024-38082
4.7 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Jun 20, 2024
CVE-2024-37897
5.4 MEDIUM

SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azure Blob. SFTPGo WebAdmin and WebClient support …

Jun 20, 2024
CVE-2024-37674
5.5 MEDIUM

Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new …

Jun 20, 2024
CVE-2024-37352
4.5 MEDIUM

There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06 that allows attackers with system administrator permissions …

Jun 20, 2024
CVE-2024-37351
4.5 MEDIUM

There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can interfere …

Jun 20, 2024
CVE-2024-37350
6.5 MEDIUM

There is a cross-site scripting vulnerability in the policy management UI of Absolute Secure Access prior to version 13.06. Attackers can interfere with a system …

Jun 20, 2024
CVE-2024-37349
4.5 MEDIUM

There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can interfere …

Jun 20, 2024
CVE-2024-37348
4.5 MEDIUM

There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can interfere …

Jun 20, 2024
CVE-2024-37347
4.5 MEDIUM

There is a cross-site scripting vulnerability in the pool configuration component of the management UI of Absolute Secure Access prior to 13.06. Attackers with system …

Jun 20, 2024
CVE-2024-37346
4.9 MEDIUM

There is an insufficient input validation vulnerability in the Warehouse component of Absolute Secure Access prior to 13.06. Attackers with system administrator permissions can impair …

Jun 20, 2024
CVE-2024-37345
5.3 MEDIUM

There is a cross-site scripting vulnerability in the Secure Access administrative UI of Absolute Secure Access prior to version 13.06. Attackers can pass a limited-length …

Jun 20, 2024
CVE-2024-37344
4.5 MEDIUM

There is a cross-site scripting vulnerability in the Policy management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can …

Jun 20, 2024
CVE-2024-37343
4.8 MEDIUM

There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.06. Attackers with valid tunnel credentials …

Jun 20, 2024
CVE-2024-33335
6.3 MEDIUM

SQL Injection vulnerability in H3C technology company SeaSQL DWS V2.0 allows a remote attacker to execute arbitrary code via a crafted file.

Jun 20, 2024
CVE-2024-28397
5.3 MEDIUM

An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a crafted API call.

Jun 20, 2024
CVE-2022-41324
6.5 MEDIUM

Northern.tech Mender 3.3.x before 3.3.2 and 3.4.x before 3.4.0 has Incorrect Access Control and allows low-privileged users default read access to some sensitive device information.

Jun 20, 2024
CVE-2024-6195
6.3 MEDIUM

A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Jun 20, 2024
CVE-2024-6194
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System 1.0. Affected is an unknown function of the file editmeasurement.php. The …

Jun 20, 2024
CVE-2024-6188
5.3 MEDIUM

A vulnerability was found in Parsec Automation TrackSYS 11.x.x and classified as problematic. This issue affects some unknown processing of the file /TS/export/pagedefinition. The manipulation …

Jun 20, 2024
CVE-2024-5156
6.4 MEDIUM

The Flatsome theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.18.7 due to …

Jun 20, 2024
CVE-2024-6187
6.3 MEDIUM

A vulnerability has been found in Ruijie RG-UAC 1.0 and classified as critical. This vulnerability affects unknown code of the file /view/vpn/autovpn/sub_commit.php. The manipulation of …

Jun 20, 2024
CVE-2024-6186
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Ruijie RG-UAC 1.0. This affects an unknown part of the file /view/userAuthentication/SSO/commit.php. The manipulation of …

Jun 20, 2024
CVE-2023-49112
6.5 MEDIUM

Kiuwan provides an API endpoint /saas/rest/v1/info/application to get information about any application, providing only its name via the "application" parameter. This endpoint lacks proper access …

Jun 20, 2024
CVE-2023-49111
6.5 MEDIUM

For Kiuwan installations with SSO (single sign-on) enabled, an unauthenticated reflected cross-site scripting attack can be performed on the login page "login.html". This is possible …

Jun 20, 2024
CVE-2024-6185
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC 1.0. Affected by this issue is the function get_ip_addr_details of the file …

Jun 20, 2024
CVE-2024-6184
6.3 MEDIUM

A vulnerability classified as critical was found in Ruijie RG-UAC 1.0. Affected by this vulnerability is an unknown functionality of the file /view/systemConfig/reboot/reboot_commit.php. The manipulation …

Jun 20, 2024
CVE-2024-6183
4.3 MEDIUM

A vulnerability classified as problematic has been found in EZ-Suite EZ-Partner 5. Affected is an unknown function of the component Forgot Password Handler. The manipulation …

Jun 20, 2024
CVE-2022-48770
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Guard against accessing NULL pt_regs in bpf_get_task_stack() task_pt_regs() can return NULL on powerpc for …

Jun 20, 2024
CVE-2022-48769
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: efi: runtime: avoid EFIv2 runtime services on Apple x86 machines Aditya reports [0] that his …

Jun 20, 2024
CVE-2022-48768
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tracing/histogram: Fix a potential memory leak for kstrdup() kfree() is missing on an error path …

Jun 20, 2024
CVE-2022-48767
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ceph: properly put ceph_string reference after async create attempt The reference acquired by try_prep_async_create is …

Jun 20, 2024
CVE-2022-48766
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wrap dcn301_calculate_wm_and_dlg for FPU. Mirrors the logic for dcn30. Cue lots of WARNs and …

Jun 20, 2024
CVE-2022-48765
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: LAPIC: Also cancel preemption timer during SET_LAPIC The below warning is splatting during guest …

Jun 20, 2024
CVE-2022-48764
5.3 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Free kvm_cpuid_entry2 array on post-KVM_RUN KVM_SET_CPUID{,2} Free the "struct kvm_cpuid_entry2" array on successful …

Jun 20, 2024
CVE-2022-48763
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Forcibly leave nested virt when SMM state is toggled Forcibly leave nested virtualization …

Jun 20, 2024
CVE-2022-48762
6.2 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: arm64: extable: fix load_unaligned_zeropad() reg indices In ex_handler_load_unaligned_zeropad() we erroneously extract the data and addr …

Jun 20, 2024
CVE-2022-48761
5.3 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: xhci-plat: fix crash when suspend if remote wake enable Crashed at i.mx8qm platform when …

Jun 20, 2024
CVE-2022-48758
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: bnx2fc: Flush destroy_work queue before calling bnx2fc_interface_put() The bnx2fc_destroy() functions are removing the interface …

Jun 20, 2024
CVE-2022-48756
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/msm/dsi: invalid parameter check in msm_dsi_phy_enable The function performs a check on the "phy" input …

Jun 20, 2024
CVE-2022-48755
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: powerpc64/bpf: Limit 'ldbrx' to processors compliant with ISA v2.06 Johan reported the below crash with …

Jun 20, 2024
CVE-2022-48753
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: block: fix memory leak in disk_register_independent_access_ranges kobject_init_and_add() takes reference even when it fails. According to …

Jun 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.