CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-38443
6.2 MEDIUM

C/sorting/binary_insertion_sort.c in The Algorithms - C through e5dad3f has a segmentation fault for deep recursion, which may affect common use cases such as sorting an …

Jun 16, 2024
CVE-2024-36397
6.1 MEDIUM

Vantiva - MediaAccess DGA2232 v19.4 - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Jun 16, 2024
CVE-2024-38394
4.3 MEDIUM

Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kernel's underlying device matching logic allow a physically proximate …

Jun 16, 2024
CVE-2024-6016
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in itsourcecode Online Laundry Management System 1.0. Affected by this issue is some unknown functionality …

Jun 15, 2024
CVE-2024-6015
6.3 MEDIUM

A vulnerability classified as critical was found in itsourcecode Online House Rental System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jun 15, 2024
CVE-2024-6014
6.3 MEDIUM

A vulnerability classified as critical has been found in itsourcecode Document Management System 1.0. Affected is an unknown function of the file edithis.php. The manipulation …

Jun 15, 2024
CVE-2024-6013
6.3 MEDIUM

A vulnerability was found in itsourcecode Online Book Store 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Jun 15, 2024
CVE-2024-6009
6.3 MEDIUM

A vulnerability has been found in itsourcecode Event Calendar 1.0 and classified as critical. Affected by this vulnerability is the function regConfirm/regDelete of the file …

Jun 15, 2024
CVE-2024-6008
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Online Book Store up to 1.0. Affected is an unknown function of the file …

Jun 15, 2024
CVE-2024-6007
6.3 MEDIUM

A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /protocol/iscgwtunnel/deleteiscgwrouteconf.php. The …

Jun 15, 2024
CVE-2024-5611
6.4 MEDIUM

The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘label_years’ attribute within the Countdown widget in all versions …

Jun 15, 2024
CVE-2024-5858
4.3 MEDIUM

The AI Infographic Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the qcld_openai_title_generate_desc AJAX action …

Jun 15, 2024
CVE-2024-4551
6.4 MEDIUM

The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and …

Jun 15, 2024
CVE-2024-4095
6.4 MEDIUM

The Collapse-O-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'expand' and 'expandsub' shortcode in all versions up to, and including, …

Jun 15, 2024
CVE-2024-2695
6.4 MEDIUM

The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortcode in all versions up to, and including, 4.6.13 …

Jun 15, 2024
CVE-2024-1399
6.4 MEDIUM

The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all …

Jun 15, 2024
CVE-2024-5868
6.5 MEDIUM

The WooCommerce - Social Login plugin for WordPress is vulnerable to Email Verification in all versions up to, and including, 2.6.2 via the use of …

Jun 15, 2024
CVE-2024-5263
6.4 MEDIUM

The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Motion Text and Table widgets in all versions up to, …

Jun 15, 2024
CVE-2024-4479
6.4 MEDIUM

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sg_general_toggle_tab_enable and sg_accordion_style attributes within the plugin's JKit - Tabs …

Jun 15, 2024
CVE-2024-3815
5.5 MEDIUM

The Newspaper theme for WordPress is vulnerable to Stored Cross-Site Scripting via attachment meta in the archive page in all versions up to, and including, …

Jun 15, 2024
CVE-2024-3814
5.5 MEDIUM

The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'single' module in all versions up to, and including, 4.8 …

Jun 15, 2024
CVE-2024-21988
5.3 MEDIUM

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible to disclosure of sensitive information via complex MiTM attacks due to a vulnerability …

Jun 14, 2024
CVE-2024-37889
6.5 MEDIUM

MyFinances is a web application for managing finances. MyFinances has a way to access other customer invoices while signed in as a user. This method …

Jun 14, 2024
CVE-2024-37888
6.1 MEDIUM

The Open Link is a CKEditor plugin, extending context menu with a possibility to open link in a new tab. The vulnerability allowed to execute …

Jun 14, 2024
CVE-2024-36599
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

Jun 14, 2024
CVE-2024-5659
6.5 MEDIUM

Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fault(MNRF/Assert). This …

Jun 14, 2024
CVE-2024-37886
5.4 MEDIUM

user_oidc app is an OpenID Connect user backend for Nextcloud. An attacker could potentially trick the app into accepting a request that is not signed …

Jun 14, 2024
CVE-2024-37883
4.3 MEDIUM

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A user with access to …

Jun 14, 2024
CVE-2024-37317
4.6 MEDIUM

The Nextcloud Notes app is a distraction free notes taking app for Nextcloud. If an attacker managed to share a folder called `Notes/` with a …

Jun 14, 2024
CVE-2024-37316
4.6 MEDIUM

Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachment data leading to a bad redirect for participants …

Jun 14, 2024
CVE-2024-33373
6.3 MEDIUM

An issue in the LB-LINK BL-W1210M v2.0 router allows attackers to bypass password complexity requirements and set single digit passwords for authentication. This vulnerability can …

Jun 14, 2024
CVE-2024-37312
6.3 MEDIUM

user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access control on the ID4me endpoint allows an attacker to register an account eventually …

Jun 14, 2024
CVE-2024-36656
6.1 MEDIUM

In MintHCM 4.0.3, a registered user can execute arbitrary JavaScript code and achieve a reflected Cross-site Scripting (XSS) attack.

Jun 14, 2024
CVE-2024-23442
6.1 MEDIUM

An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously …

Jun 14, 2024
CVE-2024-5731
6.8 MEDIUM

A vulnerability in the IPS Manager, Central Manager, and Local Manager communication workflow allows an attacker to control the destination of a request by manipulating …

Jun 14, 2024
CVE-2024-2023
4.3 MEDIUM

The Folders and Folders Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0 in Folders and 3.0.2 …

Jun 14, 2024
CVE-2023-51376
4.3 MEDIUM

Missing Authorization vulnerability in Brainstorm Force ProjectHuddle Client Site.This issue affects ProjectHuddle Client Site: from n/a through 1.0.34.

Jun 14, 2024
CVE-2024-34012
4.4 MEDIUM

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.24135.272.

Jun 14, 2024
CVE-2024-4863
6.4 MEDIUM

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘titleFont’ parameter …

Jun 14, 2024
CVE-2024-37182
4.7 MEDIUM

Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over …

Jun 14, 2024
CVE-2024-25142
5.5 MEDIUM

Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow. Airflow did not return "Cache-Control" header for dynamic content, which in case of …

Jun 14, 2024
CVE-2024-5465
5.9 MEDIUM

Function vulnerabilities in the Calendar module Impact: Successful exploitation of this vulnerability will affect availability.

Jun 14, 2024
CVE-2024-5464
4.0 MEDIUM

Vulnerability of insufficient permission verification in the NearLink module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jun 14, 2024
CVE-2024-36501
5.6 MEDIUM

Memory management vulnerability in the boottime module Impact: Successful exploitation of this vulnerability can affect integrity.

Jun 14, 2024
CVE-2024-36499
6.8 MEDIUM

Vulnerability of unauthorized screenshot capturing in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jun 14, 2024
CVE-2024-5994
6.4 MEDIUM

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom JS option in versions up to, …

Jun 14, 2024
CVE-2024-5155
6.1 MEDIUM

The Inquiry cart WordPress plugin through 3.4.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Jun 14, 2024
CVE-2024-4751
4.3 MEDIUM

The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Jun 14, 2024
CVE-2024-4480
6.1 MEDIUM

The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its email settings, which could allow attackers to …

Jun 14, 2024
CVE-2024-4271
4.6 MEDIUM

The SVGator WordPress plugin through 1.2.6 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious …

Jun 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.