CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-3873
4.3 MEDIUM

A vulnerability was found in SMI SMI-EX-5414W up to 1.0.03. It has been classified as problematic. This affects an unknown part of the component Web …

Apr 16, 2024
CVE-2024-3862
5.3 MEDIUM

The MarkStack assignment operator, part of the JavaScript engine, could access uninitialized memory if it were used in a self-assignment. This vulnerability affects Firefox < …

Apr 16, 2024
CVE-2024-3861
4.0 MEDIUM

If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free. This vulnerability affects Firefox < …

Apr 16, 2024
CVE-2024-3860
6.2 MEDIUM

An out-of-memory condition during object initialization could result in an empty shape list. If the JIT subsequently traced the object it would crash. This vulnerability …

Apr 16, 2024
CVE-2024-3859
5.9 MEDIUM

On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulnerability affects Firefox …

Apr 16, 2024
CVE-2024-3855
6.5 MEDIUM

In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability affects Firefox < 125.

Apr 16, 2024
CVE-2024-32024
6.5 MEDIUM

Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a path injection in the `common_gui.py` `add_pre_postfix` function. This vulnerability is fixed …

Apr 16, 2024
CVE-2024-32023
6.5 MEDIUM

Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a path injection in the `common_gui.py` `find_and_replace` function. This vulnerability is fixed …

Apr 16, 2024
CVE-2024-31451
5.3 MEDIUM

DocsGPT is a GPT-powered chat for documentation. DocsGPT is vulnerable to unauthenticated limited file write in routes.py. This vulnerability is fixed in 0.8.1.

Apr 16, 2024
CVE-2024-30256
6.4 MEDIUM

Open WebUI is a user-friendly WebUI for LLMs. Open-webui is vulnerable to authenticated blind server-side request forgery. This vulnerability is fixed in 0.1.117.

Apr 16, 2024
CVE-2024-3869
4.3 MEDIUM

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'woocommerce_json_search_coupons' function …

Apr 16, 2024
CVE-2024-3672
6.4 MEDIUM

The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'all-items' shortcode in all versions up to, and including, …

Apr 16, 2024
CVE-2024-3243
4.3 MEDIUM

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in …

Apr 16, 2024
CVE-2024-3367
6.5 MEDIUM

Argument injection in websphere_mq agent plugin in Checkmk 2.0.0, 2.1.0, <2.2.0p26 and <2.3.0b5 allows local attacker to inject one argument to runmqsc

Apr 16, 2024
CVE-2024-3867
6.1 MEDIUM

The archive-tainacan-collection theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in version …

Apr 16, 2024
CVE-2024-1357
6.4 MEDIUM

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aux_timeline shortcode in all versions …

Apr 16, 2024
CVE-2024-32634
6.1 MEDIUM

In huge memory get unmapped area check, code can never be reached because of a logical contradiction.

Apr 16, 2024
CVE-2024-32633
4.0 MEDIUM

An unsigned value can never be negative, so eMMC full disk test will always evaluate the same way.

Apr 16, 2024
CVE-2024-32632
6.6 MEDIUM

A value in ATCMD will be misinterpreted by printf, causing incorrect output and possibly out-of-bounds memory access

Apr 16, 2024
CVE-2024-32625
5.8 MEDIUM

In OffloadAMRWriter, a scalar field is not initialized so will contain an arbitrary value left over from earlier computations

Apr 16, 2024
CVE-2024-32557
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: …

Apr 16, 2024
CVE-2024-31784
6.1 MEDIUM

An issue in Typora v.1.8.10 and before, allows a local attacker to obtain sensitive information and execute arbitrary code via a crafted payload to the …

Apr 16, 2024
CVE-2024-31783
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Typora v.1.6.7 and before, allows a local attacker to obtain sensitive information via a crafted script during markdown file …

Apr 16, 2024
CVE-2024-31634
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Xunruicms versions 4.6.3 and before, allows remote attacker to execute arbitrary code via the Security.php file in the catalog …

Apr 16, 2024
CVE-2024-3575
6.1 MEDIUM

Cross-site Scripting (XSS) - Stored in mindsdb/mindsdb

Apr 16, 2024
CVE-2024-30567
6.3 MEDIUM

An issue in JNT Telecom JNT Liftcom UMS V1.J Core Version JM-V15 allows a remote attacker to execute arbitrary code via the Network Troubleshooting functionality.

Apr 16, 2024
CVE-2024-2260
4.2 MEDIUM

A session fixation vulnerability exists in the zenml-io/zenml application, where JWT tokens used for user authentication are not invalidated upon logout. This flaw allows an …

Apr 16, 2024
CVE-2024-1666
5.3 MEDIUM

In lunary-ai/lunary version 1.0.0, an authorization flaw exists that allows unauthorized radar creation. The vulnerability stems from the lack of server-side checks to verify if …

Apr 16, 2024
CVE-2024-1183
6.5 MEDIUM

An SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to scan and identify open ports within an internal network. By manipulating …

Apr 16, 2024
CVE-2024-27794
6.1 MEDIUM

Claris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to an improperly handled parameter in the FileMaker WebDirect login …

Apr 15, 2024
CVE-2020-22540
5.4 MEDIUM

Stored Cross-Site Scripting (XSS) vulnerability in Codoforum v4.9, allows attackers to execute arbitrary code and obtain sensitive information via crafted payload to Category name component.

Apr 15, 2024
CVE-2024-31651
6.1 MEDIUM

A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Apr 15, 2024
CVE-2024-31652
6.1 MEDIUM

A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Apr 15, 2024
CVE-2024-31649
5.4 MEDIUM

A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Apr 15, 2024
CVE-2024-31648
6.1 MEDIUM

Cross Site Scripting (XSS) in Insurance Management System v1.0, allows remote attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Apr 15, 2024
CVE-2024-23561
4.3 MEDIUM

HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfuscation of sensitive values.

Apr 15, 2024
CVE-2024-23558
6.3 MEDIUM

HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

Apr 15, 2024
CVE-2024-3804
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Vesystem Cloud Desktop up to 20240408. This issue affects some unknown processing of the …

Apr 15, 2024
CVE-2024-32036
5.3 MEDIUM

ImageSharp is a 2D graphics API. A data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker …

Apr 15, 2024
CVE-2024-32035
5.3 MEDIUM

ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory …

Apr 15, 2024
CVE-2024-31990
4.8 MEDIUM

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The API server does not enforce project sourceNamespaces which allows attackers to use the …

Apr 15, 2024
CVE-2024-31497
5.9 MEDIUM

In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick …

Apr 15, 2024
CVE-2024-30840
6.5 MEDIUM

A Stack Overflow vulnerability in Tenda AC15 v15.03.05.18 allows attackers to cause a denial of service via the LISTEN parameter in the fromDhcpListClient function.

Apr 15, 2024
CVE-2024-23560
4.4 MEDIUM

HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type.

Apr 15, 2024
CVE-2023-45503
5.3 MEDIUM

SQL Injection vulnerability in Macrob7 Macs CMS 1.1.4f, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain …

Apr 15, 2024
CVE-2024-3803
6.3 MEDIUM

A vulnerability classified as critical was found in Vesystem Cloud Desktop up to 20240408. This vulnerability affects unknown code of the file /Public/webuploader/0.1.5/server/fileupload.php. The manipulation …

Apr 15, 2024
CVE-2024-24487
6.8 MEDIUM

An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to cause a denial of service via crafted UDP packets using the …

Apr 15, 2024
CVE-2024-31219
4.3 MEDIUM

Discourse-reactions is a plugin that allows user to add their reactions to the post. When whispers are enabled on a site via `whispers_allowed_groups` and reactions …

Apr 15, 2024
CVE-2024-23594
6.4 MEDIUM

A buffer overflow vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from …

Apr 15, 2024
CVE-2024-23593
6.7 MEDIUM

A vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from 2012 to …

Apr 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.