CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-43543
6.7 MEDIUM

Memory corruption in Audio during a playback or a recording due to race condition between allocation and deallocation of graph object.

Jun 3, 2024
CVE-2023-43537
6.5 MEDIUM

Information disclosure while handling T2LM Action Frame in WLAN Host.

Jun 3, 2024
CVE-2024-35639
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webliberty Simple Spoiler simple-spoiler.This issue affects Simple Spoiler: from n/a through <= 1.2.

Jun 3, 2024
CVE-2024-35638
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in JumpDEMAND Inc. ActiveDEMAND.This issue affects ActiveDEMAND: from n/a through 0.2.43.

Jun 3, 2024
CVE-2024-35637
4.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.3.6.

Jun 3, 2024
CVE-2024-36964
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs/9p: only translate RWX permissions for plain 9P2000 Garbage in plain 9P2000's perm bits is …

Jun 3, 2024
CVE-2024-36962
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: ks8851: Queue RX packets in IRQ handler instead of disabling BHs Currently the driver …

Jun 3, 2024
CVE-2024-36961
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: thermal/debugfs: Fix two locking issues with thermal zone debug With the current thermal zone locking …

Jun 3, 2024
CVE-2024-35640
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tomas Cordero Safety Exit allows Stored XSS.This issue affects Safety Exit: …

Jun 3, 2024
CVE-2024-31493
6.5 MEDIUM

An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 and below, version 7.0.3 and below may …

Jun 3, 2024
CVE-2024-23107
5.5 MEDIUM

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, 6.3 all …

Jun 3, 2024
CVE-2023-48789
4.3 MEDIUM

A client-side enforcement of server-side security in Fortinet FortiPortal version 6.0.0 through 6.0.14 allows attacker to improper access control via crafted HTTP requests.

Jun 3, 2024
CVE-2024-35643
5.9 MEDIUM

Cross Site Scripting (XSS) vulnerability in Xabier Miranda WP Back Button allows Stored XSS.This issue affects WP Back Button: from n/a through 1.1.3.

Jun 3, 2024
CVE-2024-35642
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bryan Hadaway Site Favicon allows Stored XSS.This issue affects Site Favicon: …

Jun 3, 2024
CVE-2024-35641
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in GregRoss Just Writing Statistics allows Stored XSS.This issue affects Just Writing …

Jun 3, 2024
CVE-2024-37031
6.1 MEDIUM

The Active Admin (aka activeadmin) framework before 3.2.2 for Ruby on Rails allows stored XSS in certain situations where users can create entities (to be …

Jun 3, 2024
CVE-2023-51436
5.9 MEDIUM

Cross-site scripting vulnerability exists in UNIVERSAL PASSPORT RX versions 1.0.0 to 1.0.8, which may allow a remote authenticated attacker with an administrative privilege to execute …

Jun 3, 2024
CVE-2023-42427
6.5 MEDIUM

Cross-site scripting vulnerability exists in UNIVERSAL PASSPORT RX versions 1.0.0 to 1.0.7, which may allow a remote authenticated attacker to execute an arbitrary script on …

Jun 3, 2024
CVE-2024-20075
6.7 MEDIUM

In eemgpu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Jun 3, 2024
CVE-2024-20074
6.6 MEDIUM

In dmc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Jun 3, 2024
CVE-2024-20073
6.6 MEDIUM

In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with …

Jun 3, 2024
CVE-2024-20072
6.6 MEDIUM

In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with …

Jun 3, 2024
CVE-2024-20071
4.4 MEDIUM

In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System …

Jun 3, 2024
CVE-2024-20070
5.1 MEDIUM

In modem, there is a possible information disclosure due to using risky cryptographic algorithm during connection establishment negotiation. This could lead to remote information disclosure, …

Jun 3, 2024
CVE-2024-20069
6.5 MEDIUM

In modem, there is a possible selection of less-secure algorithm during the VoWiFi IKE due to a missing DH downgrade check. This could lead to …

Jun 3, 2024
CVE-2024-20068
5.9 MEDIUM

In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution …

Jun 3, 2024
CVE-2024-20065
4.0 MEDIUM

In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution …

Jun 3, 2024
CVE-2024-5590
6.3 MEDIUM

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been declared as critical. This vulnerability affects unknown code of the file …

Jun 3, 2024
CVE-2024-5589
6.3 MEDIUM

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. This affects an unknown part of the file …

Jun 3, 2024
CVE-2024-5588
6.3 MEDIUM

A vulnerability was found in itsourcecode Learning Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jun 2, 2024
CVE-2024-36392
6.1 MEDIUM

MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Jun 2, 2024
CVE-2024-5587
5.3 MEDIUM

A vulnerability was found in Casdoor up to 1.335.0. It has been classified as problematic. Affected is an unknown function of the file /conf/app.conf of …

Jun 2, 2024
CVE-2024-4344
4.3 MEDIUM

The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, …

Jun 2, 2024
CVE-2024-35647
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Global Notification Bar allows Stored XSS.This issue affects Global Notification Bar: …

Jun 2, 2024
CVE-2024-35646
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Erez Hadas-Sonnenschein Smartarget Message Bar smartarget-message-bar.This issue affects Smartarget Message Bar: from n/a …

Jun 2, 2024
CVE-2024-35645
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar Random Banner random-banner allows DOM-Based XSS.This issue affects Random …

Jun 2, 2024
CVE-2024-35636
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Uploadcare Uploadcare File Uploader and Adaptive Delivery (beta) uploadcare.This issue affects Uploadcare File Uploader and Adaptive Delivery (beta): from …

Jun 1, 2024
CVE-2024-2295
6.4 MEDIUM

The Contact Form Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [xyz-cfm-form] shortcode in all versions up to, and including, …

Jun 1, 2024
CVE-2024-2506
6.4 MEDIUM

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS functionality …

Jun 1, 2024
CVE-2024-1324
5.3 MEDIUM

The QQWorld Auto Save Images plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the save_remote_images_get_auto_saved_results() function …

Jun 1, 2024
CVE-2024-5501
6.4 MEDIUM

The Supreme Modules Lite – Divi Theme, Extra Theme and Divi Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_one_id’ parameter …

Jun 1, 2024
CVE-2024-4342
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image hotspot, image accordion, off canvas, woogrid, …

Jun 1, 2024
CVE-2024-4087
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Back to Top widget in all versions …

Jun 1, 2024
CVE-2023-6382
6.4 MEDIUM

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_slide' shortcode in all versions up …

Jun 1, 2024
CVE-2024-3565
6.4 MEDIUM

The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'content_block' shortcode in all versions up to, …

Jun 1, 2024
CVE-2024-4711
6.4 MEDIUM

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ajax_load_more shortcode in versions up to, …

Jun 1, 2024
CVE-2024-2933
6.4 MEDIUM

The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Social Profiles widget in all versions up …

Jun 1, 2024
CVE-2024-34006
4.3 MEDIUM

The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered.

May 31, 2024
CVE-2024-34005
6.5 MEDIUM

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore database …

May 31, 2024
CVE-2024-34004
6.5 MEDIUM

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore wiki …

May 31, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.