CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-34230
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected …

May 14, 2024
CVE-2024-34225
6.1 MEDIUM

Cross Site Scripting vulnerability in php-lms/admin/?page=system_info in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or …

May 14, 2024
CVE-2024-34223
4.3 MEDIUM

Insecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource Management System 1.0 allow attackers to approve or reject leave ticket.

May 14, 2024
CVE-2024-34222
5.9 MEDIUM

Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter.

May 14, 2024
CVE-2024-34206
6.5 MEDIUM

TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter.

May 14, 2024
CVE-2024-34202
6.5 MEDIUM

TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setMacFilterRules function.

May 14, 2024
CVE-2024-34081
6.6 MEDIUM

MantisBT (Mantis Bug Tracker) is an open source issue tracker. Improper escaping of a custom field's name allows an attacker to inject HTML and, if …

May 14, 2024
CVE-2024-34080
5.3 MEDIUM

MantisBT (Mantis Bug Tracker) is an open source issue tracker. If an issue references a note that belongs to another issue that the user doesn't …

May 14, 2024
CVE-2024-34074
6.1 MEDIUM

Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument and it allowed redirect to untrusted external …

May 14, 2024
CVE-2024-33956
4.3 MEDIUM

Missing Authorization vulnerability in ThemeLocation Custom WooCommerce Checkout Fields Editor.This issue affects Custom WooCommerce Checkout Fields Editor: from n/a through 1.3.0.

May 14, 2024
CVE-2024-33955
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme Freesia Freesia Empire allows Stored XSS.This issue affects Freesia Empire: from n/a …

May 14, 2024
CVE-2024-33954
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atanas Yonkov Pliska allows Stored XSS.This issue affects Pliska: from n/a through 0.3.5.

May 14, 2024
CVE-2024-33953
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt van Andel Adventure Journal allows Stored XSS.This issue affects Adventure Journal: from …

May 14, 2024
CVE-2024-33952
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Tadlock Unique allows Stored XSS.This issue affects Unique: from n/a through 0.3.0.

May 14, 2024
CVE-2024-33951
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adam DeHaven Perfect Pullquotes allows Stored XSS.This issue affects Perfect Pullquotes: from n/a …

May 14, 2024
CVE-2024-33950
5.9 MEDIUM

Administrator Cross Site Scripting (XSS) in Archives Calendar Widget <= 1.0.15 versions.

May 14, 2024
CVE-2024-33942
4.3 MEDIUM

Missing Authorization vulnerability in Eric Alli Google Typography.This issue affects Google Typography: from n/a through 1.1.2.

May 14, 2024
CVE-2024-33938
6.5 MEDIUM

Missing Authorization vulnerability in codename065 Sliding Widgets allows Cross-Site Scripting (XSS).This issue affects Sliding Widgets: from n/a through 1.5.0.

May 14, 2024
CVE-2024-33876
5.7 MEDIUM

HDF5 Library through 1.14.3 has a heap buffer overflow in H5S__point_deserialize in H5Spoint.c.

May 14, 2024
CVE-2024-33875
5.7 MEDIUM

HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5O__layout_encode in H5Olayout.c, resulting in the corruption of the instruction pointer.

May 14, 2024
CVE-2024-33819
4.6 MEDIUM

Globitel KSA SpeechLog v8.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Save Query function.

May 14, 2024
CVE-2024-33774
6.5 MEDIUM

A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanSetup_Wizard allows remote authenticated users to trigger a denial of service (DoS) through …

May 14, 2024
CVE-2024-33773
6.5 MEDIUM

A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanGuestSetup allows remote authenticated users to trigger a denial of service (DoS) through …

May 14, 2024
CVE-2024-33772
5.7 MEDIUM

A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formTcpipSetup allows remote authenticated users to trigger a denial of service (DoS) through …

May 14, 2024
CVE-2024-33771
6.5 MEDIUM

A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via goform/formWPS, allows remote authenticated users to trigger a denial of service (DoS) through …

May 14, 2024
CVE-2024-33454
6.5 MEDIUM

Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the Bluetooth stack component.

May 14, 2024
CVE-2024-33433
4.8 MEDIUM

Cross Site Scripting vulnerability in TOTOLINK X2000R before v1.0.0-B20231213.1013 allows a remote attacker to execute arbitrary code via the Guest Access Control parameter in the …

May 14, 2024
CVE-2024-33263
4.0 MEDIUM

QuickJS commit 3b45d15 was discovered to contain an Assertion Failure via JS_FreeRuntime(JSRuntime *) at quickjs.c.

May 14, 2024
CVE-2024-32999
6.8 MEDIUM

Cracking vulnerability in the OS security module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32998
5.9 MEDIUM

NULL pointer access vulnerability in the clock module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32996
6.2 MEDIUM

Privilege escalation vulnerability in the account module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32995
6.2 MEDIUM

Denial of service (DoS) vulnerability in the AMS module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32993
5.6 MEDIUM

Out-of-bounds access vulnerability in the memory module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32990
6.1 MEDIUM

Permission verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32985
5.9 MEDIUM

Stellar-core is a reference implementation for the peer-to-peer agent that manages the Stellar network. Prior to 20.4.0, core nodes could be randomly crashed due to …

May 14, 2024
CVE-2024-32874
6.8 MEDIUM

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Below 0.13.2 Release, when uploading a file or retrieving the …

May 14, 2024
CVE-2024-32776
6.5 MEDIUM

Missing Authorization vulnerability in AppPresser Team AppPresser.This issue affects AppPresser: from n/a through 4.3.0.

May 14, 2024
CVE-2024-32730
6.5 MEDIUM

SAP Enable Now Manager does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker with …

May 14, 2024
CVE-2024-32719
5.3 MEDIUM

Missing Authorization vulnerability in WP Club Manager WP Club Manager wp-club-manager.This issue affects WP Club Manager: from n/a through <= 2.2.11.

May 14, 2024
CVE-2024-32717
6.5 MEDIUM

Missing Authorization vulnerability in WPDeveloper SchedulePress.This issue affects SchedulePress: from n/a through 5.0.8.

May 14, 2024
CVE-2024-32672
5.3 MEDIUM

A Segmentation Fault issue discovered in Samsung Open Source Escargot JavaScript engine allows remote attackers to cause a denial of service via crafted input. This …

May 14, 2024
CVE-2024-32669
5.3 MEDIUM

Improper Input Validation vulnerability in Samsung Open Source escargot JavaScript engine allows Overflow Buffers. However, it occurs in the test code and does not include …

May 14, 2024
CVE-2024-32610
5.7 MEDIUM

HDF5 Library through 1.14.3 has a SEGV in H5T_close_real in H5T.c, resulting in a corrupted instruction pointer.

May 14, 2024
CVE-2024-32607
5.7 MEDIUM

HDF5 Library through 1.14.3 has a SEGV in H5A__close in H5Aint.c, resulting in the corruption of the instruction pointer.

May 14, 2024
CVE-2024-32606
5.7 MEDIUM

HDF5 Library through 1.14.3 may attempt to dereference uninitialized values in h5tools_str_sprint in tools/lib/h5tools_str.c (called from h5tools_dump_simple_data in tools/lib/h5tools_dump.c).

May 14, 2024
CVE-2024-32476
6.5 MEDIUM

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. There is a Denial of Service (DoS) vulnerability via OOM using jq in ignoreDifferences. …

May 14, 2024
CVE-2024-32100
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.11.

May 14, 2024
CVE-2024-31953
6.7 MEDIUM

An issue was discovered in Samsung Magician 8.0.0 on macOS. Because it is possible to tamper with the directory and executable files used during the …

May 14, 2024
CVE-2024-31952
6.7 MEDIUM

An issue was discovered in Samsung Magician 8.0.0 on macOS. Because symlinks are used during the installation process, an attacker can escalate privileges via arbitrary …

May 14, 2024
CVE-2024-31803
6.2 MEDIUM

Buffer Overflow vulnerability in emp-ot v.0.2.4 allows a remote attacker to execute arbitrary code via the FerretCOT<T>::read_pre_data128_from_file function.

May 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.