CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5264
5.9 MEDIUM

Network Transfer with AES KHT in Thales Luna EFT 2.1 and above allows a user with administrative console access to access backups taken via offline …

May 23, 2024
CVE-2024-35223
5.3 MEDIUM

Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. Dapr sends the app token of the invoker app instead of …

May 23, 2024
CVE-2024-4706
6.4 MEDIUM

The WordPress + Microsoft Office 365 / Azure AD | LOGIN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pintra' shortcode …

May 23, 2024
CVE-2024-5241
4.7 MEDIUM

A vulnerability was found in Huashi Private Cloud CDN Live Streaming Acceleration Server up to 20240520. It has been classified as critical. Affected is an …

May 23, 2024
CVE-2024-5240
6.3 MEDIUM

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. This issue affects some unknown processing of the file …

May 23, 2024
CVE-2024-4043
6.4 MEDIUM

The WP Ultimate Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpupg-text' shortcode in all versions up to, and …

May 23, 2024
CVE-2024-3648
6.4 MEDIUM

The ShareThis Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sharethis-inline-button' shortcode in all versions up to, and including, …

May 23, 2024
CVE-2024-36013
6.8 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect() Extend a critical section to prevent chan from early …

May 23, 2024
CVE-2024-36011
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HCI: Fix potential null-ptr-deref Fix potential null-ptr-deref in hci_le_big_sync_established_evt().

May 23, 2024
CVE-2024-2874
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions before 16.10.6, version 16.11 before 16.11.3, and 17.0 before 17.0.1. A runner registered with …

May 23, 2024
CVE-2024-5239
6.3 MEDIUM

A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file …

May 23, 2024
CVE-2024-5238
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file …

May 23, 2024
CVE-2024-5237
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Campcodes Complete Web-Based School Management System 1.0. Affected by this issue is some unknown …

May 23, 2024
CVE-2024-5177
6.4 MEDIUM

The Hash Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' parameter within multiple widgets in all versions up to, and …

May 23, 2024
CVE-2024-3918
4.8 MEDIUM

The Pet Manager WordPress plugin through 1.4 does not sanitise and escape some of its Pet settings, which could allow high privilege users such as …

May 23, 2024
CVE-2024-3917
6.1 MEDIUM

The Pet Manager WordPress plugin through 1.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

May 23, 2024
CVE-2024-3711
4.3 MEDIUM

The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized plugin setting update due to a missing capability check on the functions action_request_disable, …

May 23, 2024
CVE-2024-3626
4.3 MEDIUM

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access of data …

May 23, 2024
CVE-2024-5236
6.3 MEDIUM

A vulnerability classified as critical was found in Campcodes Complete Web-Based School Management System 1.0. Affected by this vulnerability is an unknown functionality of the …

May 23, 2024
CVE-2024-5235
6.3 MEDIUM

A vulnerability classified as critical has been found in Campcodes Complete Web-Based School Management System 1.0. Affected is an unknown function of the file /view/teacher_salary_invoice.php. …

May 23, 2024
CVE-2024-5234
6.3 MEDIUM

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as critical. This issue affects some unknown processing of …

May 23, 2024
CVE-2024-5233
6.3 MEDIUM

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the …

May 23, 2024
CVE-2023-6325
5.3 MEDIUM

The RomethemeForm For Elementor plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the export_entries, …

May 23, 2024
CVE-2024-5232
6.3 MEDIUM

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as critical. This affects an unknown part of the …

May 23, 2024
CVE-2024-4431
6.4 MEDIUM

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and …

May 23, 2024
CVE-2024-5231
6.3 MEDIUM

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of …

May 23, 2024
CVE-2024-4895
4.7 MEDIUM

The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the CSV import …

May 23, 2024
CVE-2024-5230
5.3 MEDIUM

A vulnerability has been found in EnvaySoft FleetCart up to 4.1.1 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation …

May 23, 2024
CVE-2024-4783
6.4 MEDIUM

The jQuery T(-) Countdown Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's tminus shortcode in all versions up to, and …

May 23, 2024
CVE-2024-4486
6.4 MEDIUM

The Awesome Contact Form7 for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'AEP Contact Form 7' widget in all versions …

May 23, 2024
CVE-2024-3201
6.4 MEDIUM

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pp_link' shortcode in all versions up to, and …

May 23, 2024
CVE-2024-3065
4.4 MEDIUM

The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all …

May 23, 2024
CVE-2024-1855
5.3 MEDIUM

The WPCafe – Restaurant Menu, Online Ordering for WooCommerce, Pickup / Delivery and Table Reservation plugin for WordPress is vulnerable to Server-Side Request Forgery in …

May 23, 2024
CVE-2023-6844
5.0 MEDIUM

The iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to and including 5.0 due to …

May 23, 2024
CVE-2024-22026
6.7 MEDIUM

A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitrary commands on the appliance.

May 22, 2024
CVE-2023-46807
6.7 MEDIUM

An SQL Injection vulnerability in web component of EPMM before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify data in the …

May 22, 2024
CVE-2023-46806
6.7 MEDIUM

An SQL Injection vulnerability in a web component of EPMM versions before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify data …

May 22, 2024
CVE-2024-31895
4.3 MEDIUM

IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user information using an expired access token. IBM X-Force ID: …

May 22, 2024
CVE-2024-31894
4.3 MEDIUM

IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user information using an expired access token. IBM X-Force ID: …

May 22, 2024
CVE-2024-35627
6.1 MEDIUM

tileserver-gl up to v4.4.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /data/v3/?key.

May 22, 2024
CVE-2024-31904
6.5 MEDIUM

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 integration nodes could allow an authenticated user to cause a denial of service due …

May 22, 2024
CVE-2024-31893
4.3 MEDIUM

IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive calendar information using an expired access token. IBM X-Force ID: …

May 22, 2024
CVE-2024-25737
5.4 MEDIUM

A Server-Side Request Forgery (SSRF) vulnerability in the /Cover/Show route (showAction in CoverController.php) in Open Library Foundation VuFind 2.4 through 9.1 before 9.1.1 allows remote …

May 22, 2024
CVE-2024-31617
5.3 MEDIUM

OpenLiteSpeed before 1.8.1 mishandles chunked encoding.

May 22, 2024
CVE-2024-29421
6.2 MEDIUM

xmedcon 0.23.0 and fixed in v.0.24.0 is vulnerable to Buffer Overflow via libs/dicom/basic.c which allows an attacker to execute arbitrary code.

May 22, 2024
CVE-2024-21791
4.7 MEDIUM

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection in lockout history option. Note: Non-admin users cannot exploit this vulnerability.

May 22, 2024
CVE-2024-5166
6.5 MEDIUM

An Insecure Direct Object Reference in Google Cloud's Looker allowed metadata exposure across authenticated Looker users sharing the same LookML model.

May 22, 2024
CVE-2024-4563
6.1 MEDIUM

The Progress MOVEit Automation configuration export function prior to 2024.0.0 uses a cryptographic method with insufficient bit length.

May 22, 2024
CVE-2024-20363
5.8 MEDIUM

Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated, remote attacker to …

May 22, 2024
CVE-2024-20361
5.8 MEDIUM

A vulnerability in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker …

May 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.