CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-31460
6.5 MEDIUM

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules.php` is not thoroughly checked and …

May 14, 2024
CVE-2024-31458
4.6 MEDIUM

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `form_save()` function in `graph_template_inputs.php` is not …

May 14, 2024
CVE-2024-31444
4.6 MEDIUM

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules_form_save()` function in `automation_tree_rules.php` is not …

May 14, 2024
CVE-2024-31443
5.7 MEDIUM

Cacti provides an operational monitoring and fault management framework. Prior to 1.2.27, some of the data stored in `form_save()` function in `data_queries.php` is not thoroughly …

May 14, 2024
CVE-2024-31113
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.11.

May 14, 2024
CVE-2024-30801
5.5 MEDIUM

SQL Injection vulnerability in Cloud based customer service management platform v.1.0.0 allows a local attacker to execute arbitrary code via a crafted payload to Login.asp …

May 14, 2024
CVE-2024-30268
6.1 MEDIUM

Cacti provides an operational monitoring and fault management framework. A reflected cross-site scripting vulnerability on the 1.3.x DEV branch allows attackers to obtain cookies of …

May 14, 2024
CVE-2024-30171
5.9 MEDIUM

An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of …

May 14, 2024
CVE-2024-30055
5.4 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

May 14, 2024
CVE-2024-2923
6.4 MEDIUM

The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

May 14, 2024
CVE-2024-2846
4.4 MEDIUM

The Visual Footer Credit Remover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'selector' parameter in all versions up to, and including, …

May 14, 2024
CVE-2024-2785
6.4 MEDIUM

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Age Gate widget in all versions up to, …

May 14, 2024
CVE-2024-2749
5.9 MEDIUM

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's access control mechanism fails to properly restrict access to its settings, permitting any users …

May 14, 2024
CVE-2024-2651
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 …

May 14, 2024
CVE-2024-2454
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting …

May 14, 2024
CVE-2024-2299
6.1 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability exists in the parisneo/lollms-webui application due to improper validation of uploaded files in the profile picture upload functionality. Attackers …

May 14, 2024
CVE-2024-29894
5.4 MEDIUM

Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 contain a residual cross-site scripting vulnerability caused by an incomplete …

May 14, 2024
CVE-2024-29166
5.7 MEDIUM

HDF5 through 1.14.3 contains a buffer overflow in H5O__linfo_decode, resulting in the corruption of the instruction pointer and causing denial of service or potential code …

May 14, 2024
CVE-2024-28781
5.4 MEDIUM

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4, and 8.0 through 8.0.0.1 is vulnerable to cross-site scripting. …

May 14, 2024
CVE-2024-28761
5.4 MEDIUM

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which …

May 14, 2024
CVE-2024-28760
4.3 MEDIUM

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 dashboard is vulnerable to a denial of service due to improper restrictions of resource …

May 14, 2024
CVE-2024-28759
4.3 MEDIUM

A crafted network packet may cause a buffer overrun in Wind River VxWorks 7 through 23.09.

May 14, 2024
CVE-2024-28277
6.1 MEDIUM

In Sourcecodester School Task Manager v1.0, a vulnerability was identified within the subject_name= parameter, enabling Stored Cross-Site Scripting (XSS) attacks. This vulnerability allows attackers to …

May 14, 2024
CVE-2024-28276
6.1 MEDIUM

Sourcecodester School Task Manager 1.0 is vulnerable to Cross Site Scripting (XSS) via add-task.php?task_name=.

May 14, 2024
CVE-2024-27852
6.5 MEDIUM

A privacy issue was addressed with improved client ID handling for alternative app marketplaces. This issue is fixed in iOS 17.5 and iPadOS 17.5. A …

May 14, 2024
CVE-2024-27847
5.5 MEDIUM

This issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, …

May 14, 2024
CVE-2024-27841
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An app may be …

May 14, 2024
CVE-2024-27834
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS …

May 14, 2024
CVE-2024-27827
5.5 MEDIUM

This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.5, macOS Ventura 13.6.7. An app may be able to …

May 14, 2024
CVE-2024-27821
4.7 MEDIUM

A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, watchOS 10.5. A …

May 14, 2024
CVE-2024-27816
5.5 MEDIUM

A logic issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. …

May 14, 2024
CVE-2024-27810
5.5 MEDIUM

A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, …

May 14, 2024
CVE-2024-27804
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.3, …

May 14, 2024
CVE-2024-27789
5.5 MEDIUM

A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, macOS Monterey 12.7.5, macOS Sonoma 14.4, macOS …

May 14, 2024
CVE-2024-27460
6.7 MEDIUM

A privilege escalation exists in the updater for Plantronics Hub 3.25.1 and below.

May 14, 2024
CVE-2024-27400
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: once more fix the call oder in amdgpu_ttm_move() v2 This reverts drm/amdgpu: fix ftrace …

May 14, 2024
CVE-2024-27399
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout There is a race condition between l2cap_chan_timeout() and l2cap_chan_del(). …

May 14, 2024
CVE-2024-27393
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xen-netfront: Add missing skb_mark_for_recycle Notice that skb_mark_for_recycle() is introduced later than fixes tag in commit …

May 14, 2024
CVE-2024-27282
6.6 MEDIUM

An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary …

May 14, 2024
CVE-2024-27281
4.5 MEDIUM

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as …

May 14, 2024
CVE-2024-27269
6.8 MEDIUM

IBM QRadar SIEM 7.5 could allow a privileged user to configure user management that would disclose unintended sensitive information across tenants. IBM X-Force ID: 284575.

May 14, 2024
CVE-2024-26306
5.9 MEDIUM

iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This …

May 14, 2024
CVE-2024-25662
6.1 MEDIUM

Oxygen XML Web Author v26.0.0 and older and Oxygen Content Fusion v6.1 and older are vulnerable to Cross-Site Scripting (XSS) for malicious URLs.

May 14, 2024
CVE-2024-24157
6.1 MEDIUM

Gnuboard g6 / https://github.com/gnuboard/g6 commit c2cc1f5069e00491ea48618d957332d90f6d40e4 is vulnerable to Cross Site Scripting (XSS) via board.py.

May 14, 2024
CVE-2024-23236
5.5 MEDIUM

A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to read arbitrary files.

May 14, 2024
CVE-2024-23229
5.5 MEDIUM

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.5, macOS Sonoma 14.4, macOS Ventura 13.6.5. A …

May 14, 2024
CVE-2024-22910
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in CrushFTP v.10.6.0 and v.10.5.5 allows an attacker to execute arbitrary code via a crafted payload.

May 14, 2024
CVE-2024-22345
6.2 MEDIUM

IBM TXSeries for Multiplatforms 8.2 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. IBM …

May 14, 2024
CVE-2024-22344
6.1 MEDIUM

IBM TXSeries for Multiplatforms 8.2 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in …

May 14, 2024
CVE-2024-22343
4.0 MEDIUM

IBM TXSeries for Multiplatforms 8.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: …

May 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.