CVE Database

59714+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23189
5.4 MEDIUM

Embedded content references at tasks could be used to temporarily execute script code in the context of the users browser session. To exploit this an …

Apr 8, 2024
CVE-2023-52554
6.5 MEDIUM

Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 8, 2024
CVE-2023-52551
5.3 MEDIUM

Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 8, 2024
CVE-2023-52544
4.3 MEDIUM

Vulnerability of file path verification being bypassed in the email module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 8, 2024
CVE-2023-52543
6.2 MEDIUM

Permission verification vulnerability in the system module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2023-52542
6.5 MEDIUM

Permission verification vulnerability in the system module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2024-1958
4.8 MEDIUM

The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Apr 8, 2024
CVE-2024-1956
6.1 MEDIUM

The wpb-show-core WordPress plugin before 2.7 does not sanitise and escape the parameters before outputting it back in the response of an unauthenticated request, leading …

Apr 8, 2024
CVE-2024-1752
6.1 MEDIUM

The Font Farsi WordPress plugin through 1.6.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Apr 8, 2024
CVE-2024-1589
6.1 MEDIUM

The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Apr 8, 2024
CVE-2024-1588
6.8 MEDIUM

The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Apr 8, 2024
CVE-2024-1292
4.7 MEDIUM

The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape some parameters before outputting them back in the page, leading to a …

Apr 8, 2024
CVE-2024-23658
4.4 MEDIUM

In camera driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System …

Apr 8, 2024
CVE-2023-52536
4.4 MEDIUM

In faceid service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service …

Apr 8, 2024
CVE-2023-52535
4.4 MEDIUM

In vsp driver, there is a possible missing verification incorrect input. This could lead to local denial of service with no additional execution privileges needed

Apr 8, 2024
CVE-2023-52534
5.9 MEDIUM

In ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote denial of service with no additional execution …

Apr 8, 2024
CVE-2023-52533
5.3 MEDIUM

In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed

Apr 8, 2024
CVE-2023-52352
5.5 MEDIUM

In Network Adapter Service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed

Apr 8, 2024
CVE-2023-52350
4.4 MEDIUM

In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Apr 8, 2024
CVE-2023-52349
4.4 MEDIUM

In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Apr 8, 2024
CVE-2023-52348
4.4 MEDIUM

In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Apr 8, 2024
CVE-2023-52347
5.5 MEDIUM

In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Apr 8, 2024
CVE-2023-52346
4.4 MEDIUM

In modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with System execution privileges …

Apr 8, 2024
CVE-2023-52345
6.0 MEDIUM

In modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with System execution privileges …

Apr 8, 2024
CVE-2023-52344
5.3 MEDIUM

In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed

Apr 8, 2024
CVE-2023-52343
5.5 MEDIUM

In SecurityCommand message after as security has been actived., there is a possible improper input validation. This could lead to remote information disclosure no additional …

Apr 8, 2024
CVE-2024-3436
6.3 MEDIUM

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /Admin/edit-photo.php …

Apr 8, 2024
CVE-2024-3434
5.4 MEDIUM

A vulnerability classified as critical was found in CP Plus Wi-Fi Camera up to 20240401. Affected by this vulnerability is an unknown functionality of the …

Apr 8, 2024
CVE-2021-47208
4.3 MEDIUM

The Mojolicious module before 9.11 for Perl has a bug in format detection that can potentially be exploited for denial of service.

Apr 8, 2024
CVE-2024-3432
5.5 MEDIUM

A vulnerability was found in PuneethReddyHC Event Management 1.0. It has been rated as critical. This issue affects some unknown processing of the file /backend/register.php. …

Apr 7, 2024
CVE-2024-3431
4.7 MEDIUM

A vulnerability was found in EyouCMS 1.6.5. It has been declared as critical. This vulnerability affects unknown code of the file /login.php?m=admin&c=Field&a=channel_edit of the component …

Apr 7, 2024
CVE-2024-31951
6.5 MEDIUM

In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ext_link for OSPF …

Apr 7, 2024
CVE-2024-31950
6.5 MEDIUM

In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read …

Apr 7, 2024
CVE-2024-31949
6.5 MEDIUM

In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/GR capability as a dynamic capability because malformed data results in a …

Apr 7, 2024
CVE-2024-31948
6.5 MEDIUM

In FRRouting (FRR) through 9.1, an attacker using a malformed Prefix SID attribute in a BGP UPDATE packet can cause the bgpd daemon to crash.

Apr 7, 2024
CVE-2024-31349
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MailMunch MailMunch – Grow your Email List allows Stored XSS.This issue affects MailMunch …

Apr 7, 2024
CVE-2024-31348
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Testimonials allows Stored XSS.This issue affects Testimonials: from n/a through 3.0.5.

Apr 7, 2024
CVE-2024-31346
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blocksmarket Gradient Text Widget for Elementor allows Stored XSS.This issue affects Gradient Text …

Apr 7, 2024
CVE-2024-31344
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phpbits Creative Studio Easy Login Styler – White Label Admin Login Page for …

Apr 7, 2024
CVE-2024-31308
4.4 MEDIUM

Deserialization of Untrusted Data vulnerability in VJInfotech WP Import Export Lite.This issue affects WP Import Export Lite: from n/a through 3.9.26.

Apr 7, 2024
CVE-2024-31306
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Stored XSS.This issue affects Essential Blocks for …

Apr 7, 2024
CVE-2024-31296
4.3 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Repute Infosystems BookingPress.This issue affects BookingPress: from n/a through 1.0.81.

Apr 7, 2024
CVE-2024-31291
4.3 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.6.

Apr 7, 2024
CVE-2024-31258
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Micro.Company Form to Chat App allows Stored XSS.This issue affects Form to Chat …

Apr 7, 2024
CVE-2024-31257
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Formsite Formsite | Embed online forms to collect orders, registrations, leads, and surveys …

Apr 7, 2024
CVE-2024-31236
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons allows Stored XSS.This issue affects Royal Elementor Addons: …

Apr 7, 2024
CVE-2024-22155
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 8.5.2.

Apr 7, 2024
CVE-2024-3425
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Online Courseware 1.0. Affected by this vulnerability is an unknown functionality of the file admin/activateall.php. The …

Apr 7, 2024
CVE-2024-3424
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Online Courseware 1.0. Affected is an unknown function of the file admin/listscore.php. The manipulation of …

Apr 7, 2024
CVE-2024-3423
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Courseware 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin/activateteach.php. …

Apr 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.