CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-30164
6.7 MEDIUM

Amazon AWS Client VPN has a buffer overflow that could potentially allow a local actor to execute arbitrary commands with elevated permissions. This is resolved …

May 28, 2024
CVE-2024-36472
6.5 MEDIUM

In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an …

May 28, 2024
CVE-2024-35621
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in the Edit function of Formwork before 1.13.0 allows attackers to execute arbitrary web scripts or HTML via a crafted …

May 28, 2024
CVE-2024-33849
6.5 MEDIUM

ci solution CI-Out-of-Office Manager through 6.0.0.77 uses a Hard-coded Cryptographic Key.

May 28, 2024
CVE-2024-33807
5.4 MEDIUM

A SQL injection vulnerability in /model/get_teacher_timetable.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the grade …

May 28, 2024
CVE-2024-33804
6.3 MEDIUM

A SQL injection vulnerability in /model/get_subject.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id …

May 28, 2024
CVE-2024-33803
5.4 MEDIUM

A SQL injection vulnerability in /model/get_exam.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id …

May 28, 2024
CVE-2024-33802
6.5 MEDIUM

A SQL injection vulnerability in /model/get_student_subject.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the index …

May 28, 2024
CVE-2024-4429
5.4 MEDIUM

Cross-Site Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to sensitive information disclosure.

May 28, 2024
CVE-2024-35400
5.3 MEDIUM

TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function SetPortForwardRules

May 28, 2024
CVE-2024-2451
6.4 MEDIUM

Improper fingerprint validation in the TeamViewer Client (Full & Host) prior Version 15.54 for Windows and macOS allows an attacker with administrative user rights to …

May 28, 2024
CVE-2024-5428
4.3 MEDIUM

A vulnerability classified as problematic was found in SourceCodester Simple Online Bidding System 1.0. Affected by this vulnerability is the function save_product of the file …

May 28, 2024
CVE-2024-24584
4.3 MEDIUM

Multiple out-of-bounds read vulnerabilities exist in the readMSH functionality of libigl v2.5.0. A specially crafted .msh file can lead to an out-of-bounds read. An attacker …

May 28, 2024
CVE-2024-24583
4.3 MEDIUM

Multiple out-of-bounds read vulnerabilities exist in the readMSH functionality of libigl v2.5.0. A specially crafted .msh file can lead to an out-of-bounds read. An attacker …

May 28, 2024
CVE-2024-2199
5.7 MEDIUM

A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modifying …

May 28, 2024
CVE-2024-28793
4.9 MEDIUM

IBM Engineering Workflow Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. Under certain configurations, this vulnerability allows users to embed arbitrary JavaScript code …

May 28, 2024
CVE-2023-37411
4.8 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …

May 28, 2024
CVE-2024-5410
5.4 MEDIUM

Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.

May 28, 2024
CVE-2024-28880
6.5 MEDIUM

Path traversal vulnerability in MosP kintai kanri V4.6.6 and earlier allows a remote attacker who can log in to the product to obtain sensitive information …

May 28, 2024
CVE-2024-34923
6.1 MEDIUM

In Avocent DSR2030 Appliance firmware 03.04.00.07 before 03.07.01.23, and SVIP1020 Appliance firmware 01.06.00.03 before 01.07.00.00, there is reflected cross-site scripting (XSS).

May 27, 2024
CVE-2024-35182
5.9 MEDIUM

Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructure and applications. A SQL injection vulnerability in Meshery …

May 27, 2024
CVE-2024-35181
5.9 MEDIUM

Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructure and applications. A SQL injection vulnerability in Meshery …

May 27, 2024
CVE-2024-36105
5.3 MEDIUM

dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications. Prior to versions 1.6.15, …

May 27, 2024
CVE-2024-36037
5.5 MEDIUM

Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to view the session recordings.

May 27, 2024
CVE-2024-36036
4.2 MEDIUM

Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to access sensitive information and modifying the agent configuration.

May 27, 2024
CVE-2024-35238
5.3 MEDIUM

Minder by Stacklok is an open source software supply chain security platform. Minder prior to version 0.0.51 is vulnerable to a denial-of-service (DoS) attack which …

May 27, 2024
CVE-2024-27310
5.3 MEDIUM

Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP input.

May 27, 2024
CVE-2024-35236
4.8 MEDIUM

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.10.0, opening an ebook with malicious scripts inside leads to code execution inside the …

May 27, 2024
CVE-2024-35229
5.3 MEDIUM

ZKsync Era is a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. Prior to version 1.3.10, there is a very specific pattern `f(a(),b()); …

May 27, 2024
CVE-2022-4969
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in bwoodsend rockhopper up to 0.1.2. Affected by this issue is the function count_rows of …

May 27, 2024
CVE-2024-32978
6.6 MEDIUM

Kaminari is a paginator for web app frameworks and object relational mappings. A security vulnerability involving insecure file permissions has been identified in the Kaminari …

May 27, 2024
CVE-2024-5406
6.3 MEDIUM

A vulnerability had been discovered in WinNMP 19.02 consisting of an XSS attack via index page in from, subject, text and hash parameters. This vulnerability …

May 27, 2024
CVE-2024-5405
6.3 MEDIUM

A vulnerability had been discovered in WinNMP 19.02 consisting of an XSS attack via /tools/redis.php page in the k, hash, key and p parameters. This …

May 27, 2024
CVE-2024-36383
5.3 MEDIUM

An issue was discovered in Logpoint SAML Authentication before 6.0.3. An attacker can place a crafted filename in the state field of a SAML SSO-URL …

May 27, 2024
CVE-2024-4534
6.1 MEDIUM

The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

May 27, 2024
CVE-2024-4533
6.5 MEDIUM

The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admin users to …

May 27, 2024
CVE-2024-4532
6.4 MEDIUM

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

May 27, 2024
CVE-2024-4530
6.3 MEDIUM

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

May 27, 2024
CVE-2024-4529
5.0 MEDIUM

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

May 27, 2024
CVE-2024-3939
5.4 MEDIUM

The Ditty WordPress plugin before 3.1.36 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 27, 2024
CVE-2024-3933
5.3 MEDIUM

In Eclipse OpenJ9 release versions prior to 0.44.0 and after 0.13.0, when running with JVM option -Xgc:concurrentScavenge, the sequence generated for System.arrayCopy on the IBM …

May 27, 2024
CVE-2024-35297
4.7 MEDIUM

Cross-site scripting vulnerability exists in WP Booking versions prior to 2.4.5. If this vulnerability is exploited, an arbitrary script may be executed on the web …

May 27, 2024
CVE-2024-35291
6.1 MEDIUM

Cross-site scripting vulnerability exists in Splunk Config Explorer versions prior to 1.7.16. If this vulnerability is exploited, an arbitrary script may be executed on the …

May 27, 2024
CVE-2024-36384
6.1 MEDIUM

Pointsharp Cryptshare Server before 7.0.0 has an XSS issue that is related to notification messages.

May 27, 2024
CVE-2024-5397
6.3 MEDIUM

A vulnerability classified as critical was found in itsourcecode Online Student Enrollment System 1.0. Affected by this vulnerability is an unknown functionality of the file …

May 27, 2024
CVE-2024-5396
6.3 MEDIUM

A vulnerability classified as critical has been found in itsourcecode Online Student Enrollment System 1.0. Affected is an unknown function of the file newfaculty.php. The …

May 27, 2024
CVE-2024-5395
6.3 MEDIUM

A vulnerability was found in itsourcecode Online Student Enrollment System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

May 27, 2024
CVE-2024-5394
6.3 MEDIUM

A vulnerability was found in itsourcecode Online Student Enrollment System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

May 27, 2024
CVE-2024-5393
6.3 MEDIUM

A vulnerability was found in itsourcecode Online Student Enrollment System 1.0. It has been classified as critical. This affects an unknown part of the file …

May 27, 2024
CVE-2024-5392
6.3 MEDIUM

A vulnerability was found in itsourcecode Online Student Enrollment System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

May 27, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.