CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-34003
5.9 MEDIUM

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore workshop …

May 31, 2024
CVE-2024-34002
6.5 MEDIUM

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore feedback …

May 31, 2024
CVE-2024-36845
4.3 MEDIUM

An invalid pointer in the modbus_receive() function of libmodbus v3.1.6 allows attackers to cause a Denial of Service (DoS) via a crafted message sent to …

May 31, 2024
CVE-2024-34000
4.3 MEDIUM

ID numbers displayed in the lesson overview report required additional sanitizing to prevent a stored XSS risk.

May 31, 2024
CVE-2024-33998
5.4 MEDIUM

Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features.

May 31, 2024
CVE-2024-33997
6.1 MEDIUM

Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation.

May 31, 2024
CVE-2024-33996
6.2 MEDIUM

Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not …

May 31, 2024
CVE-2024-22060
4.9 MEDIUM

An unrestricted file upload vulnerability in web component of Ivanti Neurons for ITSM allows a remote, authenticated, high privileged user to write arbitrary files into …

May 31, 2024
CVE-2021-44534
6.5 MEDIUM

Insufficient user input filtering leads to arbitrary file read by non-authenticated attacker, which results in sensitive information disclosure.

May 31, 2024
CVE-2022-25038
6.1 MEDIUM

wanEditor v4.7.11 was discovered to contain a cross-site scripting (XSS) vulnerability via the video upload function.

May 31, 2024
CVE-2022-25037
5.4 MEDIUM

An issue in wanEditor v4.7.11 and fixed in v.4.7.12 and v.5 was discovered to contain a cross-site scripting (XSS) vulnerability via the image upload function.

May 31, 2024
CVE-2023-7073
6.4 MEDIUM

The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.7 via …

May 31, 2024
CVE-2024-31908
6.4 MEDIUM

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web …

May 31, 2024
CVE-2024-31907
5.4 MEDIUM

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

May 31, 2024
CVE-2024-31889
5.4 MEDIUM

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

May 31, 2024
CVE-2024-22338
4.0 MEDIUM

IBM Security Verify Access OIDC Provider 22.09 through 23.03 could disclose sensitive information to a local user due to hazardous input validation. IBM X-Force ID: …

May 31, 2024
CVE-2024-5347
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'arrow' attribute within the plugin's Post Navigation widget in …

May 31, 2024
CVE-2024-5041
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ha-ia-content-button’ parameter in all versions up to, and including, …

May 31, 2024
CVE-2024-4160
6.4 MEDIUM

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' shortcode in all versions up to, and including, 3.2.90 …

May 31, 2024
CVE-2024-5524
5.3 MEDIUM

Information exposure vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows unregistered users to access all internal links of the application without providing any credentials.

May 31, 2024
CVE-2024-5427
6.4 MEDIUM

The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's …

May 31, 2024
CVE-2024-4379
5.4 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Global Tooltip widget in all versions up to, …

May 31, 2024
CVE-2024-4376
6.4 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fancy Text widget in all versions up to, …

May 31, 2024
CVE-2024-4205
4.3 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_template_content() function …

May 31, 2024
CVE-2024-23847
5.9 MEDIUM

Incorrect default permissions issue exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a …

May 31, 2024
CVE-2024-5418
6.4 MEDIUM

The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slitems' attribute within the plugin's De Product Tab & Slide …

May 31, 2024
CVE-2024-1298
6.0 MEDIUM

EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A …

May 30, 2024
CVE-2024-35189
6.5 MEDIUM

Fides is an open-source privacy engineering platform. The Fides webserver has a number of endpoints that retrieve `ConnectionConfiguration` records and their associated `secrets` which _can_ …

May 30, 2024
CVE-2024-32877
4.2 MEDIUM

Yii 2 is a PHP application framework. During internal penetration testing of a product based on Yii2, users discovered a Cross-site Scripting (XSS) vulnerability within …

May 30, 2024
CVE-2024-35228
5.5 MEDIUM

Wagtail is an open source content management system built on Django. Due to an improperly applied permission check in the `wagtail.contrib.settings` module, a user with …

May 30, 2024
CVE-2024-35468
5.4 MEDIUM

A SQL injection vulnerability in /hrm/index.php in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.

May 30, 2024
CVE-2024-35429
6.5 MEDIUM

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via eventRecord.

May 30, 2024
CVE-2024-35352
6.1 MEDIUM

A vulnerability has been discovered in Diño Physics School Assistant version 2.3. This vulnerability impacts unidentified code within the file /classes/Users.php?f=save. Manipulating the parameter middlename …

May 30, 2024
CVE-2024-35351
5.4 MEDIUM

A vulnerability has been discovered in Diño Physics School Assistant version 2.3. This vulnerability impacts unidentified code within the file /classes/SystemSettings.php?f=update_settings. Manipulating the parameter name …

May 30, 2024
CVE-2024-5518
6.3 MEDIUM

A vulnerability classified as critical has been found in itsourcecode Online Discussion Forum 1.0. This affects an unknown part of the file change_profile_picture.php. The manipulation …

May 30, 2024
CVE-2024-36959
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pinctrl: devicetree: fix refcount leak in pinctrl_dt_to_map() If we fail to allocate propname buffer, we …

May 30, 2024
CVE-2024-36958
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix nfsd4_encode_fattr4() crasher Ensure that args.acl is initialized early. It is used in an …

May 30, 2024
CVE-2024-36957
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: avoid off-by-one read from userspace We try to access count + 1 byte from …

May 30, 2024
CVE-2024-36956
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: thermal/debugfs: Free all thermal zone debug memory on zone removal Because thermal_debug_tz_remove() does not free …

May 30, 2024
CVE-2024-36954
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tipc: fix a possible memleak in tipc_buf_append __skb_linearize() doesn't free the skb when it fails, …

May 30, 2024
CVE-2024-36953
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-v2: Check for non-NULL vCPU in vgic_v2_parse_attr() vgic_v2_parse_attr() is responsible for finding the …

May 30, 2024
CVE-2024-36952
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Move NPIV's transport unregistration to after resource clean up There are cases after …

May 30, 2024
CVE-2024-36951
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: range check cp bad op exception interrupts Due to a CP interrupt bug, bad …

May 30, 2024
CVE-2024-36950
4.4 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: firewire: ohci: mask bus reset interrupts between ISR and bottom half In the FireWire OHCI …

May 30, 2024
CVE-2024-36949
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: amd/amdkfd: sync all devices to wait all processes being evicted If there are more than …

May 30, 2024
CVE-2024-36948
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe/xe_migrate: Cast to output precision before multiplying operands Addressing potential overflow in result of multiplication …

May 30, 2024
CVE-2024-36947
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: qibfs: fix dentry leak simple_recursive_removal() drops the pinning references to all positives in subtree. For …

May 30, 2024
CVE-2024-36946
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: phonet: fix rtm_phonet_notify() skb allocation fill_route() stores three components in the skb: - struct rtmsg …

May 30, 2024
CVE-2024-36945
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix neighbour and rtable leak in smc_ib_find_route() In smc_ib_find_route(), the neighbour found by neigh_lookup() …

May 30, 2024
CVE-2024-36944
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Reapply "drm/qxl: simplify qxl_fence_wait" This reverts commit 07ed11afb68d94eadd4ffc082b97c2331307c5ea. Stephen Rostedt reports: "I went to run …

May 30, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.