CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-3377
4.3 MEDIUM

A vulnerability classified as problematic was found in SourceCodester Computer Laboratory Management System 1.0. This vulnerability affects unknown code of the file /classes/SystemSettings.php?f=update_settings. The manipulation …

Apr 6, 2024
CVE-2024-3369
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Car Rental 1.0. Affected by this issue is some unknown functionality of the …

Apr 6, 2024
CVE-2024-2296
5.5 MEDIUM

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions …

Apr 6, 2024
CVE-2024-2132
6.4 MEDIUM

The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Widget in all versions up to, and …

Apr 6, 2024
CVE-2024-2458
6.4 MEDIUM

The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, …

Apr 6, 2024
CVE-2024-1428
6.4 MEDIUM

The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to …

Apr 6, 2024
CVE-2024-0837
6.4 MEDIUM

The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to …

Apr 6, 2024
CVE-2024-2949
6.4 MEDIUM

The Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce …

Apr 6, 2024
CVE-2024-2471
6.4 MEDIUM

The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image attachment fields (such as 'Title', 'Alt Text', 'Custom URL', 'Custom Class', and …

Apr 6, 2024
CVE-2024-2444
4.8 MEDIUM

The Inline Related Posts WordPress plugin before 3.5.0 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Apr 6, 2024
CVE-2024-3216
5.3 MEDIUM

The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Apr 6, 2024
CVE-2024-2950
5.3 MEDIUM

The BoldGrid Easy SEO – Simple and Effective SEO plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.6.14 …

Apr 6, 2024
CVE-2024-2656
4.4 MEDIUM

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Apr 6, 2024
CVE-2024-3245
6.4 MEDIUM

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress …

Apr 6, 2024
CVE-2024-1994
4.3 MEDIUM

The Image Watermark plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the watermark_action_ajax() function in all …

Apr 6, 2024
CVE-2024-27910
5.3 MEDIUM

A vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to reboot the printer without authentication.

Apr 5, 2024
CVE-2024-27909
4.9 MEDIUM

A denial of service vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in a system reboot.

Apr 5, 2024
CVE-2024-27908
4.9 MEDIUM

A buffer overflow vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in denial of service.

Apr 5, 2024
CVE-2024-23592
6.3 MEDIUM

An authentication bypass vulnerability was reported in Lenovo devices with Synaptics fingerprint readers that could allow an attacker with physical access to replay fingerprints and …

Apr 5, 2024
CVE-2023-5912
6.7 MEDIUM

A potential memory leakage vulnerability was reported in some Lenovo Notebook products that may allow a local attacker with elevated privileges to write to NVRAM …

Apr 5, 2024
CVE-2023-4605
6.5 MEDIUM

A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoint to retrieve system event information.

Apr 5, 2024
CVE-2023-25494
6.7 MEDIUM

A potential vulnerability were reported in the BIOS of some Desktop, Smart Edge, and ThinkStation products that could allow a local attacker with elevated privileges …

Apr 5, 2024
CVE-2023-25493
6.7 MEDIUM

A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products that could allow a …

Apr 5, 2024
CVE-2024-2312
6.7 MEDIUM

GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks after exit. This lead …

Apr 5, 2024
CVE-2024-29783
6.7 MEDIUM

In tmu_get_tr_thresholds, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no …

Apr 5, 2024
CVE-2024-29782
5.5 MEDIUM

In tmu_get_tr_num_thresholds of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Apr 5, 2024
CVE-2024-29755
4.4 MEDIUM

In tmu_get_pi of tmu.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with …

Apr 5, 2024
CVE-2024-29754
6.2 MEDIUM

In TMU_IPC_GET_TABLE, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no …

Apr 5, 2024
CVE-2024-29751
5.5 MEDIUM

In asn1_ec_pkey_parse_p384 of asn1_common.c, there is a possible OOB Read due to a missing null check. This could lead to local information disclosure with no …

Apr 5, 2024
CVE-2024-29750
5.5 MEDIUM

In km_exp_did_inner of kmv.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Apr 5, 2024
CVE-2024-29747
5.9 MEDIUM

In _dvfs_get_lv of dvfs.c, there is a possible out of bounds read due to a missing null check. This could lead to local information disclosure …

Apr 5, 2024
CVE-2024-29745
5.5 MEDIUM KEV

there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction …

Apr 5, 2024
CVE-2024-29744
5.5 MEDIUM

In tmu_get_gov_time_windows, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no …

Apr 5, 2024
CVE-2024-29742
5.5 MEDIUM

In apply_minlock_constraint of dvfs.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Apr 5, 2024
CVE-2024-29739
5.5 MEDIUM

In tmu_get_temp_lut of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Apr 5, 2024
CVE-2024-29738
5.5 MEDIUM

In gov_init, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no …

Apr 5, 2024
CVE-2024-27232
5.5 MEDIUM

In asn1_ec_pkey_parse of asn1_common.c, there is a possible OOB read due to a missing null check. This could lead to local information disclosure with no …

Apr 5, 2024
CVE-2024-27231
5.9 MEDIUM

In tmu_get_tr_stats of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Apr 5, 2024
CVE-2024-28065
5.9 MEDIUM

In Unify CP IP Phone firmware 1.10.4.3, files are not encrypted and contain sensitive information such as the root password hash.

Apr 5, 2024
CVE-2024-3346
6.3 MEDIUM

A vulnerability was found in Byzoro Smart S80 up to 20240328. It has been declared as critical. This vulnerability affects unknown code of the file …

Apr 5, 2024
CVE-2024-31852
5.9 MEDIUM

LLVM before 18.1.3 generates code in which the LR register can be overwritten without data being saved to the stack, and thus there can sometimes …

Apr 5, 2024
CVE-2023-49965
6.8 MEDIUM

SpaceX Starlink Wi-Fi router Gen 2 before 2023.48.0 allows XSS via the ssid and password parameters on the Setup Page.

Apr 5, 2024
CVE-2024-2499
6.4 MEDIUM

The Squelch Tabs and Accordions Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'accordions' shortcode in all versions up to, …

Apr 5, 2024
CVE-2024-2380
4.6 MEDIUM

Stored XSS in graph rendering in Checkmk <2.3.0b4.

Apr 5, 2024
CVE-2023-5692
5.3 MEDIUM

WordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.4.3 via the redirect_guess_404_permalink function. This can allow unauthenticated attackers to …

Apr 5, 2024
CVE-2024-2447
6.5 MEDIUM

Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain types of post …

Apr 5, 2024
CVE-2024-29221
4.7 MEDIUM

Improper Access Control in Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 lacked proper access control in the …

Apr 5, 2024
CVE-2024-28949
4.3 MEDIUM

Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit the number of user preferences which allows an …

Apr 5, 2024
CVE-2024-27437
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Disable auto-enable of exclusive INTx IRQ Currently for devices requiring masking at the irqchip …

Apr 5, 2024
CVE-2024-26814
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vfio/fsl-mc: Block calling interrupt handler without trigger The eventfd_ctx trigger pointer of the vfio_fsl_mc_irq object …

Apr 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.