CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-3297
6.5 MEDIUM

An issue in the Certificate Authenticated Session Establishment (CASE) protocol for establishing secure sessions between two devices, as implemented in the Matter protocol versions before …

Jul 24, 2024
CVE-2024-39676
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot. This issue affects Apache Pinot: from 0.1 before 1.0.0. Users are recommended to …

Jul 24, 2024
CVE-2023-48362
8.8 HIGH

XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system …

Jul 24, 2024
CVE-2023-32471
6.0 MEDIUM

Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds read vulnerability. A local authenticated malicious user with high privileges could potentially exploit this …

Jul 24, 2024
CVE-2024-6629
6.4 MEDIUM

The All-in-One Video Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video shortcode in all versions up to, and including, …

Jul 24, 2024
CVE-2024-6571
5.3 MEDIUM

The Optimize Images ALT Text (alt tag) & names for SEO using AI plugin for WordPress is vulnerable to Full Path Disclosure in all versions …

Jul 24, 2024
CVE-2024-6553
5.3 MEDIUM

The WP Meteor Website Speed Optimization Addon plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.3.This is …

Jul 24, 2024
CVE-2023-32466
5.7 MEDIUM

Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this …

Jul 24, 2024
CVE-2024-6836
4.3 MEDIUM

The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells plugin for WordPress is …

Jul 24, 2024
CVE-2024-6094
4.8 MEDIUM

The WP ULike WordPress plugin before 4.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jul 24, 2024
CVE-2024-40767
6.5 MEDIUM

In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image …

Jul 24, 2024
CVE-2024-5861
5.3 MEDIUM

The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the wpep_square_disconnect() …

Jul 24, 2024
CVE-2024-3246
6.1 MEDIUM

The LiteSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.0.1. This is due to missing …

Jul 24, 2024
CVE-2024-7027
7.3 HIGH

The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 4.9.3. This is due to insufficient …

Jul 24, 2024
CVE-2024-6756
8.8 HIGH

The Social Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpw_auto_poster_get_image_path' function in all …

Jul 24, 2024
CVE-2024-6755
6.5 MEDIUM

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the ‘wpw_auto_poster_quick_delete_multiple’ …

Jul 24, 2024
CVE-2024-6754
5.4 MEDIUM

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the ‘wpw_auto_poster_update_tweet_template’ function in all …

Jul 24, 2024
CVE-2024-6753
7.2 HIGH

The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mapTypes’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions …

Jul 24, 2024
CVE-2024-6752
6.4 MEDIUM

The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_name’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions …

Jul 24, 2024
CVE-2024-6751
6.3 MEDIUM

The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.3.14. This is due to missing …

Jul 24, 2024
CVE-2024-6750
7.3 HIGH

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple …

Jul 24, 2024
CVE-2024-41656
7.1 HIGH

Sentry is an error tracking and performance monitoring platform. Starting in version 10.0.0 and prior to version 24.7.1, an unsanitized payload sent by an Integration …

Jul 23, 2024
CVE-2024-38176
8.1 HIGH

An improper restriction of excessive authentication attempts in GroupMe allows a unauthenticated attacker to elevate privileges over a network.

Jul 23, 2024
CVE-2024-38164
9.6 CRITICAL

An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on …

Jul 23, 2024
CVE-2024-0981
7.1 HIGH

Okta Browser Plugin versions 6.5.0 through 6.31.0 (Chrome/Edge/Firefox/Safari) are vulnerable to cross-site scripting. This issue occurs when the plugin prompts the user to save these …

Jul 23, 2024
CVE-2024-41668
8.3 HIGH

The cBioPortal for Cancer Genomics provides visualization, analysis, and download of large-scale cancer genomics data sets. When running a publicly exposed proxy endpoint without authentication, …

Jul 23, 2024
CVE-2024-41665
5.5 MEDIUM

Ampache, a web based audio/video streaming application and file manager, has a stored cross-site scripting (XSS) vulnerability in versions prior to 6.6.0. This vulnerability exists …

Jul 23, 2024
CVE-2020-11640
8.8 HIGH

AdvaBuild uses a command queue to launch certain operations. An attacker who gains access to the command queue can use it to launch an attack …

Jul 23, 2024
CVE-2020-11639
7.8 HIGH

An attacker could exploit the vulnerability by injecting garbage data or specially crafted data. Depending on the data injected each process might be affected differently. …

Jul 23, 2024
CVE-2024-41664
5.4 MEDIUM

Canarytokens help track activity and actions on a network. Prior to `sha-8ea5315`, Canarytokens.org was vulnerable to a blind SSRF in the Webhook alert feature. When …

Jul 23, 2024
CVE-2024-41178
7.5 HIGH

Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and earlier on all platforms using AWS WebIdentityTokens. On …

Jul 23, 2024
CVE-2024-6714
8.8 HIGH

An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege.

Jul 23, 2024
CVE-2024-41663
3.5 LOW

Canarytokens help track activity and actions on a network. A Cross-Site Scripting vulnerability was identified in the "Cloned Website" Canarytoken, whereby the Canarytoken's creator can …

Jul 23, 2024
CVE-2024-39702
5.9 MEDIUM

In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the string hashing function (used during string interning) allows HashDoS (Hash Denial of Service) attacks. An attacker could …

Jul 23, 2024
CVE-2024-6783
4.8 MEDIUM

A vulnerability has been discovered in Vue, that allows an attacker to perform XSS via prototype pollution. The attacker could change the prototype chain of …

Jul 23, 2024
CVE-2024-4076
7.5 HIGH

Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result in an assertion failure. This issue …

Jul 23, 2024
CVE-2024-41655
7.5 HIGH

TF2 Item Format helps users format TF2 items to the community standards. Versions of `tf2-item-format` since at least `4.2.6` and prior to `5.9.14` are vulnerable …

Jul 23, 2024
CVE-2024-41319
9.8 CRITICAL

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter in the webcmd function.

Jul 23, 2024
CVE-2024-40060
7.5 HIGH

go-chart v2.1.1 was discovered to contain an infinite loop via the drawCanvas() function.

Jul 23, 2024
CVE-2024-1975
7.5 HIGH

If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from a DNSSEC-signed domain in cache, …

Jul 23, 2024
CVE-2024-1737
7.5 HIGH

Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname (of any RTYPE) can suffer from degraded performance as …

Jul 23, 2024
CVE-2024-0760
7.5 HIGH

A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server …

Jul 23, 2024
CVE-2024-5602
7.8 HIGH

A stack-based buffer overflow vulnerability due to a missing bounds check in the NI I/O Trace Tool may result in arbitrary code execution. Successful exploitation …

Jul 23, 2024
CVE-2024-4081
7.8 HIGH

A memory corruption issue due to an improper length check in NI LabVIEW may disclose information or result in arbitrary code execution. Successful exploitation requires …

Jul 23, 2024
CVE-2024-4080
7.8 HIGH

A memory corruption issue due to an improper length check in LabVIEW tdcore.dll may disclose information or result in arbitrary code execution. Successful exploitation requires …

Jul 23, 2024
CVE-2024-4079
7.8 HIGH

An out of bounds read due to a missing bounds check in LabVIEW may disclose information or result in arbitrary code execution. Successful exploitation requires …

Jul 23, 2024
CVE-2024-41839
3.5 LOW

Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could lead to a security feature bypass. A low-privileged …

Jul 23, 2024
CVE-2024-41836
5.5 MEDIUM

InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS) condition. An …

Jul 23, 2024
CVE-2024-34128
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to …

Jul 23, 2024
CVE-2024-7014
8.1 HIGH

EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android application affecting versions 10.14.4 and older.

Jul 23, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.