CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-26049
4.8 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a privileged attacker to …

Jun 13, 2024
CVE-2024-26039
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier Answer: are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to execute …

Jun 13, 2024
CVE-2024-26037
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier Answer: are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to execute …

Jun 13, 2024
CVE-2024-26036
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Jun 13, 2024
CVE-2024-20784
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Jun 13, 2024
CVE-2024-20769
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Jun 13, 2024
CVE-2024-5265
6.4 MEDIUM

The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link attribute within the vc_single_image shortcode in all versions up …

Jun 13, 2024
CVE-2024-4576
5.3 MEDIUM

The component listed above contains a vulnerability that allows an attacker to traverse directories and access sensitive files, leading to unauthorized disclosure of system configuration …

Jun 13, 2024
CVE-2024-5787
6.4 MEDIUM

The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the …

Jun 13, 2024
CVE-2024-5757
6.4 MEDIUM

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url attribute within the plugin's Site Title widget …

Jun 13, 2024
CVE-2024-5661
6.0 MEDIUM

An issue has been identified in both XenServer 8 and Citrix Hypervisor 8.2 CU1 LTSR which may allow a malicious administrator of a guest VM …

Jun 13, 2024
CVE-2024-4149
4.8 MEDIUM

The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button WordPress plugin before 3.2.3 does not sanitise and …

Jun 13, 2024
CVE-2024-3032
6.1 MEDIUM

Themify Builder WordPress plugin before 7.5.8 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

Jun 13, 2024
CVE-2024-2762
5.4 MEDIUM

The FooGallery WordPress plugin before 2.4.15, foogallery-premium WordPress plugin before 2.4.15 does not validate and escape some of its Gallery settings before outputting them back …

Jun 13, 2024
CVE-2023-52890
4.5 MEDIUM

NTFS-3G before 75dcdc2 has a use-after-free in ntfs_uppercase_mbs in libntfs-3g/unistr.c. NOTE: discussion suggests that exploitation would be challenging.

Jun 13, 2024
CVE-2024-4201
4.4 MEDIUM

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all …

Jun 12, 2024
CVE-2024-1963
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.4 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting …

Jun 12, 2024
CVE-2024-1736
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior …

Jun 12, 2024
CVE-2024-1495
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.1 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting …

Jun 12, 2024
CVE-2024-36523
6.5 MEDIUM

An access control issue in Wvp GB28181 Pro 2.0 allows users to continue to access information in the application after deleting their own or administrator …

Jun 12, 2024
CVE-2024-31881
6.5 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server …

Jun 12, 2024
CVE-2023-29267
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5is vulnerable to a denial of service, under specific configurations, as …

Jun 12, 2024
CVE-2024-5559
6.1 MEDIUM

CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists that could cause denial of service, device reboot, or an attacker gaining full control …

Jun 12, 2024
CVE-2024-37629
6.1 MEDIUM

SummerNote v0.9.1 is vulnerable to Cross Site Scripting (XSS) via the Code View Function.

Jun 12, 2024
CVE-2024-28762
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted …

Jun 12, 2024
CVE-2024-24051
5.5 MEDIUM

Improper input validation of printing files in Monoprice Select Mini V2 V37.115.32 allows attackers to instruct the device's movable parts to destinations that exceed the …

Jun 12, 2024
CVE-2024-5909
5.5 MEDIUM

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to …

Jun 12, 2024
CVE-2024-5906
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in Palo Alto Networks Prisma Cloud Compute software enables a malicious administrator with add/edit permissions for identity providers to store …

Jun 12, 2024
CVE-2024-5905
4.4 MEDIUM

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low privileged Windows user to …

Jun 12, 2024
CVE-2024-5898
6.3 MEDIUM

A vulnerability was found in itsourcecode Payroll Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jun 12, 2024
CVE-2024-5560
5.3 MEDIUM

CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service of the device’s web interface when an attacker sends a specially crafted HTTP request.

Jun 12, 2024
CVE-2024-5558
6.4 MEDIUM

CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists that could cause escalation of privileges when an attacker abuses a limited admin account.

Jun 12, 2024
CVE-2024-5557
4.5 MEDIUM

CWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause exposure of SNMP credentials when an attacker has access to the controller …

Jun 12, 2024
CVE-2024-37878
6.1 MEDIUM

Cross Site Scripting vulnerability in TWCMS v.2.0.3 allows a remote attacker to execute arbitrary code via the /TWCMS-gh-pages/twcms/runtime/twcms_view/default,index.htm.php" PHP directly echoes parameters input from external …

Jun 12, 2024
CVE-2024-37040
5.4 MEDIUM

CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a user with access to the device’s web interface …

Jun 12, 2024
CVE-2024-37039
5.9 MEDIUM

CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request.

Jun 12, 2024
CVE-2024-22855
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in the User Maintenance section of ITSS iMLog v1.307 allows attackers to execute arbitrary web scripts or HTML via a …

Jun 12, 2024
CVE-2024-5897
4.3 MEDIUM

A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is an …

Jun 12, 2024
CVE-2024-5759
5.4 MEDIUM

An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized objects and launch scans without having the …

Jun 12, 2024
CVE-2024-5895
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. This issue affects the function …

Jun 12, 2024
CVE-2024-5893
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Cab Management System 1.0. This affects an unknown part of the file /cms/classes/Users.php?f=delete_client. The manipulation …

Jun 12, 2024
CVE-2024-37304
6.1 MEDIUM

NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While …

Jun 12, 2024
CVE-2024-37297
5.4 MEDIUM

WooCommerce is an open-source e-commerce platform built on WordPress. A vulnerability introduced in WooCommerce 8.8 allows for cross-site scripting. A bad actor can manipulate a …

Jun 12, 2024
CVE-2024-36691
6.3 MEDIUM

Insecure permissions in the AdminController.AjaxSave() method of PPGo_Jobs v2.8.0 allows authenticated attackers to arbitrarily modify users' account information.

Jun 12, 2024
CVE-2024-31217
5.3 MEDIUM

Strapi is an open-source content management system. Prior to version 4.22.0, a denial-of-service vulnerability is present in the media upload process causing the server to …

Jun 12, 2024
CVE-2024-2300
6.2 MEDIUM

HP Advance Mobile Applications for iOS and Android are potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices.

Jun 12, 2024
CVE-2024-5891
4.2 MEDIUM

A vulnerability was found in Quay. If an attacker can obtain the client ID for an application, they can use an OAuth token to authenticate …

Jun 12, 2024
CVE-2024-23445
6.5 MEDIUM

It was identified that if a cross-cluster API key https://www.elastic.co/guide/en/elasticsearch/reference/8.14/security-api-create-cross-cluster-api-key.html#security-api-create-cross-cluster-api-key-request-body restricts search for a given index using the query or the field_security parameter, and the …

Jun 12, 2024
CVE-2024-5313
6.5 MEDIUM

CWE-668: Exposure of the Resource Wrong Sphere vulnerability exists that exposes a SSH interface over the product network interface. This does not allow to directly …

Jun 12, 2024
CVE-2024-5056
6.5 MEDIUM

CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may prevent user to update the device firmware and prevent proper behavior of the …

Jun 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.