CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-34690
5.4 MEDIUM

SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of privileges. On successful exploitation …

Jun 11, 2024
CVE-2024-34686
6.1 MEDIUM

Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script. When a …

Jun 11, 2024
CVE-2024-34683
6.5 MEDIUM

An authenticated attacker can upload malicious file to SAP Document Builder service. When the victim accesses this file, the attacker is allowed to access, modify, …

Jun 11, 2024
CVE-2024-33001
6.5 MEDIUM

SAP NetWeaver and ABAP platform allows an attacker to impede performance for legitimate users by crashing or flooding the service. An impact of this Denial …

Jun 11, 2024
CVE-2024-2473
5.3 MEDIUM

The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.15.2. This is due to …

Jun 11, 2024
CVE-2024-28164
5.3 MEDIUM

SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensitive information about the server which would otherwise be restricted causing …

Jun 11, 2024
CVE-2024-0653
4.4 MEDIUM

The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.6.1 due …

Jun 11, 2024
CVE-2024-0627
6.4 MEDIUM

The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom field name column in all versions up to, …

Jun 11, 2024
CVE-2023-6748
4.3 MEDIUM

The Custom Field Template plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.1 via the 'cft' shortcode. …

Jun 11, 2024
CVE-2023-6745
6.4 MEDIUM

The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cpt' shortcode in all versions up to, and including, …

Jun 11, 2024
CVE-2024-37178
5.0 MEDIUM

SAP Financial Consolidation does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. These endpoints are exposed over the network. The vulnerability can …

Jun 11, 2024
CVE-2024-22244
4.3 MEDIUM

Open Redirect in Harbor <=v2.8.4, <=v2.9.2, and <=v2.10.0 may redirect a user to a malicious site.

Jun 10, 2024
CVE-2022-37020
6.8 MEDIUM

Potential vulnerabilities have been identified in the system BIOS for certain HP PC products, which might allow escalation of privileges and code execution. HP is …

Jun 10, 2024
CVE-2022-37019
6.8 MEDIUM

Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is …

Jun 10, 2024
CVE-2024-37169
5.3 MEDIUM

@jmondi/url-to-png is a self-hosted URL to PNG utility. Versions prior to 2.0.3 are vulnerable to arbitrary file read if a threat actor uses the Playright's …

Jun 10, 2024
CVE-2024-37168
5.3 MEDIUM

@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to versions 1.10.9, 1.9.15, and 1.8.22, there are two separate …

Jun 10, 2024
CVE-2024-36473
5.3 MEDIUM

Trend Micro VPN Proxy One Pro, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite or create attack but is limited to local …

Jun 10, 2024
CVE-2024-36419
4.3 MEDIUM

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A vulnerability in versions prior to 8.6.1 allows for Host Header Injection when directly accessing …

Jun 10, 2024
CVE-2024-36359
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 could allow an attacker to escalate privileges on affected installations. …

Jun 10, 2024
CVE-2024-36307
4.7 MEDIUM

A security agent link following vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive …

Jun 10, 2024
CVE-2024-36306
6.1 MEDIUM

A link following vulnerability in the Trend Micro Apex One and Apex One as a Service Damage Cleanup Engine could allow a local attacker to …

Jun 10, 2024
CVE-2024-33850
4.3 MEDIUM

Pexip Infinity before 34.1 has Improper Access Control for persons in a waiting room. They can see the conference roster list, and perform certain actions …

Jun 10, 2024
CVE-2024-27885
6.3 MEDIUM

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7. An app …

Jun 10, 2024
CVE-2024-27850
6.5 MEDIUM

This issue was addressed with improvements to the noise injection algorithm. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma …

Jun 10, 2024
CVE-2024-27844
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in Safari 17.5, macOS Sonoma 14.5, visionOS 1.2. A website's permission dialog may persist …

Jun 10, 2024
CVE-2024-27840
6.3 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey …

Jun 10, 2024
CVE-2024-27838
6.5 MEDIUM

The issue was addressed by adding additional logic. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, …

Jun 10, 2024
CVE-2024-27830
6.5 MEDIUM

This issue was addressed through improved state management. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, …

Jun 10, 2024
CVE-2024-27812
6.5 MEDIUM

A logic issue was addressed with improved file handling. This issue is fixed in visionOS 1.2. Processing web content may lead to a denial-of-service.

Jun 10, 2024
CVE-2024-27807
4.3 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5. An app may …

Jun 10, 2024
CVE-2024-27806
5.5 MEDIUM

This issue was addressed with improved environment sanitization. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey …

Jun 10, 2024
CVE-2024-27805
5.5 MEDIUM

An issue was addressed with improved validation of environment variables. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, …

Jun 10, 2024
CVE-2024-27800
6.5 MEDIUM

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS …

Jun 10, 2024
CVE-2024-23282
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, …

Jun 10, 2024
CVE-2024-23251
4.6 MEDIUM

An authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS …

Jun 10, 2024
CVE-2024-36417
5.7 MEDIUM

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, an unverified IFrame can be added some some inputs, …

Jun 10, 2024
CVE-2024-27792
5.5 MEDIUM

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sonoma 14.4. An app may be able …

Jun 10, 2024
CVE-2024-22279
5.9 MEDIUM

Improper handling of requests in Routing Release > v0.273.0 and <= v0.297.0 allows an unauthenticated attacker to degrade the service availability of the Cloud Foundry …

Jun 10, 2024
CVE-2023-40389
5.5 MEDIUM

The issue was addressed with improved restriction of data container access. This issue is fixed in macOS Ventura 13.6.5, macOS Monterey 12.7.4. An app may …

Jun 10, 2024
CVE-2022-32933
5.3 MEDIUM

An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Monterey 12.5. A website may be able to …

Jun 10, 2024
CVE-2024-31612
6.5 MEDIUM

Emlog pro2.3 is vulnerable to Cross Site Request Forgery (CSRF) via twitter.php which can be used with a XSS vulnerability to access administrator information.

Jun 10, 2024
CVE-2024-3850
5.4 MEDIUM

Uniview NVR301-04S2-P4 is vulnerable to reflected cross-site scripting attack (XSS). An attacker could send a user a URL that if clicked on could execute malicious …

Jun 10, 2024
CVE-2024-35747
5.3 MEDIUM

Improper Restriction of Excessive Authentication Attempts vulnerability in wpdevart Contact Form Builder, Contact Widget allows Functionality Bypass.This issue affects Contact Form Builder, Contact Widget: from …

Jun 10, 2024
CVE-2024-35728
5.3 MEDIUM

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Themeisle PPOM for WooCommerce allows Code Inclusion.This issue affects PPOM …

Jun 10, 2024
CVE-2024-35712
4.9 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Jordy Meow Database Cleaner allows Relative Path Traversal.This issue affects Database Cleaner: …

Jun 10, 2024
CVE-2024-35680
5.3 MEDIUM

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in YITHEMES YITH WooCommerce Product Add-Ons yith-woocommerce-product-add-ons.This issue affects YITH WooCommerce Product …

Jun 10, 2024
CVE-2024-35650
4.9 MEDIUM

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Melapress MelaPress Login Security melapress-login-security.This issue affects MelaPress Login …

Jun 10, 2024
CVE-2024-35474
6.5 MEDIUM

A Directory Traversal vulnerability in iceice666 ResourcePack Server before v1.0.8 allows a remote attacker to disclose files on the server, via setPath in ResourcePackFileServer.kt.

Jun 10, 2024
CVE-2024-31613
5.4 MEDIUM

BOSSCMS v3.10 is vulnerable to Cross Site Request Forgery (CSRF) in name="head_code" or name="foot_code."

Jun 10, 2024
CVE-2024-36531
5.7 MEDIUM

nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admin/extensions/upload.php component.

Jun 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.