CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4019
6.3 MEDIUM

A vulnerability classified as critical has been found in Byzoro Smart S80 Management Platform up to 20240411. Affected is an unknown function of the file …

Apr 20, 2024
CVE-2024-4014
6.4 MEDIUM

The hCaptcha for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cf7-hcaptcha shortcode in all versions up to, and including, …

Apr 20, 2024
CVE-2024-1730
5.4 MEDIUM

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Media Slider, Drag Drop Slider, Video Slider, Product Slider, Ecommerce Slider) plugin …

Apr 20, 2024
CVE-2024-1057
6.4 MEDIUM

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored …

Apr 20, 2024
CVE-2024-31994
6.5 MEDIUM

Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, an attacker can point the image request to an arbitrarily large file. …

Apr 19, 2024
CVE-2024-32392
4.5 MEDIUM

Cross Site Scripting vulnerability in CmSimple v.5.15 allows a remote attacker to execute arbitrary code via the functions.php component.

Apr 19, 2024
CVE-2024-31993
6.2 MEDIUM

Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the scrape_image function will retrieve an image based on a user-provided URL, …

Apr 19, 2024
CVE-2024-31992
6.5 MEDIUM

Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-controlled URL to issue a request to …

Apr 19, 2024
CVE-2024-31991
4.1 MEDIUM

Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-controlled URL to issue a request to …

Apr 19, 2024
CVE-2024-31584
5.5 MEDIUM

Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.cpp.

Apr 19, 2024
CVE-2024-1681
5.3 MEDIUM

corydolphin/flask-cors is vulnerable to log injection when the log level is set to debug. An attacker can inject fake log entries into the log file …

Apr 19, 2024
CVE-2024-3979
4.4 MEDIUM

A vulnerability, which was classified as problematic, has been found in COVESA vsomeip up to 3.4.10. Affected by this issue is some unknown functionality. The …

Apr 19, 2024
CVE-2024-2440
5.5 MEDIUM

A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on a detached repository by making a GraphQL mutation to alter …

Apr 19, 2024
CVE-2024-29991
5.0 MEDIUM

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Apr 19, 2024
CVE-2023-51797
6.7 MEDIUM

Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showwaves.c:722:24 in showwaves_filter_frame

Apr 19, 2024
CVE-2023-50007
4.0 MEDIUM

FFmpeg v.n6.1-3-g466799d4f5 allows an attacker to trigger use of a parameter of negative size in the av_samples_set_silence function in thelibavutil/samplefmt.c:260:9 component.

Apr 19, 2024
CVE-2023-27279
6.5 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a user to cause a denial of service due to missing API rate limiting. IBM X-Force ID: …

Apr 19, 2024
CVE-2022-40745
5.5 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to weaker than expected security. IBM X-Force ID: 236452.

Apr 19, 2024
CVE-2024-32206
4.6 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the component \affiche\admin\index.php of WUZHICMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Apr 19, 2024
CVE-2024-31587
6.5 MEDIUM

SecuSTATION Camera V2.5.5.3116-S50-SMA-B20160811A and lower allows an unauthenticated attacker to download device configuration files via a crafted request.

Apr 19, 2024
CVE-2024-29183
6.1 MEDIUM

OpenRASP is a RASP solution that directly integrates its protection engine into the application server by instrumentation. There exists a reflected XSS in the /login …

Apr 19, 2024
CVE-2024-29029
6.1 MEDIUM

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal …

Apr 19, 2024
CVE-2024-27752
5.4 MEDIUM

Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the Default Keyword field in the settings function.

Apr 19, 2024
CVE-2023-22869
5.5 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 244119.

Apr 19, 2024
CVE-2024-3470
5.9 MEDIUM

An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use a deploy key pertaining to an organization to …

Apr 19, 2024
CVE-2024-32478
6.9 MEDIUM

Git Credential Manager (GCM) is a secure Git credential helper. Prior to 2.5.0, the Debian package does not set root ownership on installed files. This …

Apr 19, 2024
CVE-2024-29030
5.8 MEDIUM

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/resource that allows authenticated users to enumerate the internal …

Apr 19, 2024
CVE-2024-29028
5.8 MEDIUM

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthenticated users to enumerate the internal …

Apr 19, 2024
CVE-2023-49275
6.5 MEDIUM

Wazuh is a free and open source platform used for threat prevention, detection, and response. A NULL pointer dereference was detected during fuzzing of the …

Apr 19, 2024
CVE-2024-3654
6.3 MEDIUM

An XSS vulnerability has been found in Teimas Global's Teixo, version 1.42.42-stable. This vulnerability could allow an attacker to send a specially crafted JavaScript payload …

Apr 19, 2024
CVE-2024-32683
5.3 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through 2.2.5.

Apr 19, 2024
CVE-2024-1065
5.9 MEDIUM

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel …

Apr 19, 2024
CVE-2024-0671
6.8 MEDIUM

Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd …

Apr 19, 2024
CVE-2024-2761
6.8 MEDIUM

The Genesis Blocks WordPress plugin before 3.1.3 does not properly escape data input provided to some of its blocks, allowing using with at least contributor …

Apr 19, 2024
CVE-2024-29967
4.4 MEDIUM

In Brocade SANnav before Brocade SANnav v2.31 and v2.3.0a, it was observed that Docker instances inside the appliance have insecure mount points, allowing reading and …

Apr 19, 2024
CVE-2024-29965
6.8 MEDIUM

In Brocade SANnav before v2.3.1, and v2.3.0a, it is possible to back up the appliance from the web interface or the command line interface ("SSH"). …

Apr 19, 2024
CVE-2024-29964
5.7 MEDIUM

Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files. An unprivileged attacker who gains access to the server can …

Apr 19, 2024
CVE-2024-29962
5.5 MEDIUM

Brocade SANnav OVA before v2.3.1 and v2.3.0a have an insecure file permission setting that makes files world-readable. This could allow a local user without the …

Apr 19, 2024
CVE-2024-29960
6.8 MEDIUM

In Brocade SANnav server before v2.3.1 and v2.3.0a, the SSH keys inside the OVA image are identical in the VM every time SANnav is installed. …

Apr 19, 2024
CVE-2024-3818
5.4 MEDIUM

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "Social Icons" …

Apr 19, 2024
CVE-2024-3731
6.1 MEDIUM

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, …

Apr 19, 2024
CVE-2024-3615
6.1 MEDIUM

The Media Library Folders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 8.2.0 …

Apr 19, 2024
CVE-2024-3598
6.4 MEDIUM

The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Creative Button widget in all versions up to, and including, …

Apr 19, 2024
CVE-2024-3560
6.4 MEDIUM

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id value in all versions up to, and …

Apr 19, 2024
CVE-2024-27978
6.5 MEDIUM

A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks.

Apr 19, 2024
CVE-2024-24991
6.5 MEDIUM

A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks.

Apr 19, 2024
CVE-2024-23533
6.5 MEDIUM

An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an authenticated remote attacker to read sensitive information …

Apr 19, 2024
CVE-2024-21846
5.3 MEDIUM

An unauthenticated attacker can reset the board and stop transmitter operations by sending a specially-crafted GET request to the command.cgi gateway, resulting in a denial-of-service …

Apr 18, 2024
CVE-2024-32473
4.7 MEDIUM

Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. …

Apr 18, 2024
CVE-2024-30927
6.3 MEDIUM

Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the racer-results.php component.

Apr 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.