CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23669
6.5 MEDIUM

An improper authorization in Fortinet FortiWebManager version 7.2.0 and 7.0.0 through 7.0.4 and 6.3.0 and 6.2.3 through 6.2.4 and 6.0.2 allows attacker to execute unauthorized …

Jun 5, 2024
CVE-2024-5222
6.4 MEDIUM

The Responsive Addons – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Jun 5, 2024
CVE-2024-4088
4.3 MEDIUM

The Gutenberg Blocks and Page Layouts – Attire Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Jun 5, 2024
CVE-2024-2368
4.3 MEDIUM

The Mollie Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.13. This is due to missing …

Jun 5, 2024
CVE-2024-1164
6.4 MEDIUM

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's contact form widget error message and redirect URL …

Jun 5, 2024
CVE-2024-4886
4.3 MEDIUM

The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in the request

Jun 5, 2024
CVE-2024-1161
6.4 MEDIUM

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Attributes for blocks in all versions up …

Jun 5, 2024
CVE-2024-5149
6.5 MEDIUM

The BuddyForms plugin for WordPress is vulnerable to Email Verification Bypass in all versions up to, and including, 2.8.9 via the use of an insufficiently …

Jun 5, 2024
CVE-2024-34055
6.5 MEDIUM

Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.

Jun 5, 2024
CVE-2024-5483
5.3 MEDIUM

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.8 due to …

Jun 5, 2024
CVE-2024-5317
6.4 MEDIUM

The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'np1' parameter in all versions up to, and including, 8.3.4 due to …

Jun 5, 2024
CVE-2024-5636
6.3 MEDIUM

A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Jun 5, 2024
CVE-2024-5635
6.3 MEDIUM

A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Jun 4, 2024
CVE-2024-36121
5.9 MEDIUM

netty-incubator-codec-ohttp is the OHTTP implementation for netty. BoringSSLAEADContext keeps track of how many OHTTP responses have been sent and uses this sequence number to calculate …

Jun 4, 2024
CVE-2024-30889
5.4 MEDIUM

Cross Site Scripting vulnerability in audimex audimexEE v.15.1.2 and fixed in 15.1.3.9 allows a remote attacker to execute arbitrary code via the service, method, widget_type, …

Jun 4, 2024
CVE-2022-28658
5.5 MEDIUM

Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing

Jun 4, 2024
CVE-2022-28656
5.5 MEDIUM

is_closing_session() allows users to consume RAM in the Apport process

Jun 4, 2024
CVE-2022-28654
5.5 MEDIUM

is_closing_session() allows users to fill up apport.log

Jun 4, 2024
CVE-2022-28652
5.5 MEDIUM

~/.config/apport/settings parsing is vulnerable to "billion laughs" attack

Jun 4, 2024
CVE-2024-4220
4.3 MEDIUM

Prior to 23.1, an information disclosure vulnerability exists within BeyondInsight which can allow an attacker to enumerate usernames.

Jun 4, 2024
CVE-2024-4219
4.8 MEDIUM

Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, resulting in a server-side request forgery vulnerability.

Jun 4, 2024
CVE-2024-34364
5.7 MEDIUM

Envoy is a cloud-native, open source edge and service proxy. Envoy exposed an out-of-memory (OOM) vector from the mirror response, since async HTTP client will …

Jun 4, 2024
CVE-2024-34362
5.9 MEDIUM

Envoy is a cloud-native, open source edge and service proxy. There is a use-after-free in `HttpConnectionManager` (HCM) with `EnvoyQuicServerStream` that can crash Envoy. An attacker …

Jun 4, 2024
CVE-2024-32975
5.9 MEDIUM

Envoy is a cloud-native, open source edge and service proxy. There is a crash at `QuicheDataReader::PeekVarInt62Length()`. It is caused by integer underflow in the `QuicStreamSequencerBuffer::PeekRegion()` …

Jun 4, 2024
CVE-2024-32974
5.9 MEDIUM

Envoy is a cloud-native, open source edge and service proxy. A crash was observed in `EnvoyQuicServerStream::OnInitialHeadersComplete()` with following call stack. It is a use-after-free caused …

Jun 4, 2024
CVE-2024-23326
5.9 MEDIUM

Envoy is a cloud-native, open source edge and service proxy. A theoretical request smuggling vulnerability exists through Envoy if a server can be tricked into …

Jun 4, 2024
CVE-2024-32464
6.1 MEDIUM

Action Text brings rich text content and editing to Rails. Instances of ActionText::Attachable::ContentAttachment included within a rich_text_area tag could potentially contain unsanitized HTML. This vulnerability …

Jun 4, 2024
CVE-2024-30528
5.4 MEDIUM

Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar.This issue affects Spiffy Calendar: from n/a through 4.9.10.

Jun 4, 2024
CVE-2024-30525
5.3 MEDIUM

Missing Authorization vulnerability in moveaddons Move Addons for Elementor.This issue affects Move Addons for Elementor: from n/a through 1.2.9.

Jun 4, 2024
CVE-2024-28103
5.4 MEDIUM

Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served on responses with an …

Jun 4, 2024
CVE-2024-35670
5.3 MEDIUM

Broken Authentication vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.93.

Jun 4, 2024
CVE-2024-34759
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in VideoWhisper Picture Gallery allows Stored XSS.This issue affects Picture Gallery: from …

Jun 4, 2024
CVE-2024-30484
4.3 MEDIUM

Missing Authorization vulnerability in RT Easy Builder – Advanced addons for Elementor.This issue affects RT Easy Builder – Advanced addons for Elementor: from n/a through …

Jun 4, 2024
CVE-2024-29152
5.9 MEDIUM

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos …

Jun 4, 2024
CVE-2024-35653
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder visualcomposer.This issue affects Visual Composer Website Builder: …

Jun 4, 2024
CVE-2024-35651
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Spiffy Plugins WP Flow Plus allows Stored XSS.This issue affects WP …

Jun 4, 2024
CVE-2024-35649
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pdfcrowd Save as PDF plugin by Pdfcrowd allows Stored XSS.This issue …

Jun 4, 2024
CVE-2024-28999
6.4 MEDIUM

The SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console.

Jun 4, 2024
CVE-2024-0756
5.4 MEDIUM

The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 lacks validation of URLs when adding iframes, allowing attackers to inject an iFrame in …

Jun 4, 2024
CVE-2024-35782
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Codeless Cowidgets – Elementor Addons allows Stored XSS.This issue affects Cowidgets …

Jun 4, 2024
CVE-2024-35666
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themesflat Themesflat Addons For Elementor allows Stored XSS.This issue affects Themesflat …

Jun 4, 2024
CVE-2024-35655
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brave Brave brave-popup-builder allows DOM-Based XSS.This issue affects Brave: from n/a through <= …

Jun 4, 2024
CVE-2024-35654
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CyberChimps Responsive allows Stored XSS.This issue affects Responsive: from n/a through …

Jun 4, 2024
CVE-2024-35634
4.9 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wow-Company Woocommerce – Recent Purchases allows PHP Local File Inclusion.This issue affects …

Jun 4, 2024
CVE-2024-34384
6.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SinaExtra Sina Extension for Elementor allows PHP Local File Inclusion.This issue affects …

Jun 4, 2024
CVE-2024-36801
5.9 MEDIUM

A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the lgid parameter in Download.php.

Jun 4, 2024
CVE-2024-33541
6.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BetterAddons Better Elementor Addons allows PHP Local File Inclusion.This issue affects Better …

Jun 4, 2024
CVE-2023-52176
5.3 MEDIUM

Authentication Bypass by Spoofing vulnerability in miniorange Malware Scanner allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Malware Scanner: from n/a through 4.7.1.

Jun 4, 2024
CVE-2023-51667
5.3 MEDIUM

Authentication Bypass by Spoofing vulnerability in FeedbackWP Rate my Post – WP Rating System allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Rate …

Jun 4, 2024
CVE-2023-51544
5.3 MEDIUM

Improper Control of Interaction Frequency vulnerability in Metagauss RegistrationMagic allows Functionality Misuse.This issue affects RegistrationMagic: from n/a through 5.2.5.0.

Jun 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.