CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6392
5.4 MEDIUM

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modification due to missing capability checks on the …

Jul 11, 2024
CVE-2024-6468
7.5 HIGH

Vault and Vault Enterprise did not properly handle requests originating from unauthorized IP addresses when the TCP listener option, proxy_protocol_behavior, was set to deny_unauthorized. When …

Jul 11, 2024
CVE-2024-36435
9.8 CRITICAL

An issue was discovered on Supermicro BMC firmware in select X11, X12, H12, B12, X13, H13, and B13 motherboards (and CMM6 modules). An unauthenticated user …

Jul 11, 2024
CVE-2022-29946
6.3 MEDIUM

NATS.io NATS Server before 2.8.2 and Streaming Server before 0.24.6 could allow a remote attacker to bypass security restrictions, caused by the failure to enforce …

Jul 11, 2024
CVE-2024-6531

Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such, the …

Jul 11, 2024
CVE-2024-6681
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in witmy my-springsecurity-plus up to 2024-07-04. Affected by this issue is some unknown functionality of …

Jul 11, 2024
CVE-2024-6485
6.4 MEDIUM

A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the …

Jul 11, 2024
CVE-2024-6484

Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such, the …

Jul 11, 2024
CVE-2024-39553
6.5 MEDIUM

An Exposure of Resource to Wrong Sphere vulnerability in the sampling service of Juniper Networks Junos OS Evolved allows an unauthenticated network-based attacker to send …

Jul 11, 2024
CVE-2024-39552
7.5 HIGH

An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows a network …

Jul 11, 2024
CVE-2024-39551
7.5 HIGH

An Uncontrolled Resource Consumption vulnerability in the H.323 ALG (Application Layer Gateway) of Juniper Networks Junos OS on SRX Series and MX Series with SPC3 …

Jul 11, 2024
CVE-2024-39550
6.5 MEDIUM

A Missing Release of Memory after Effective Lifetime vulnerability in the rtlogd process of Juniper Networks Junos OS on MX Series with SPC3 allows an …

Jul 11, 2024
CVE-2024-39549
7.5 HIGH

A Missing Release of Memory after Effective Lifetime vulnerability in the routing process daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows …

Jul 11, 2024
CVE-2024-39548
7.5 HIGH

An Uncontrolled Resource Consumption vulnerability in the aftmand process of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to consume memory resources, resulting …

Jul 11, 2024
CVE-2024-39546
7.3 HIGH

A Missing Authorization vulnerability in the Socket Intercept (SI) command file interface of Juniper Networks Junos OS Evolved allows an authenticated, low-privilege local attacker to …

Jul 11, 2024
CVE-2024-39545
7.5 HIGH

An Improper Check for Unusual or Exceptional Conditions vulnerability in the the IKE daemon (iked) of Juniper Networks Junos OS on SRX Series, MX Series …

Jul 11, 2024
CVE-2024-39543
6.5 MEDIUM

A Buffer Copy without Checking Size of Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS …

Jul 11, 2024
CVE-2024-39542
7.5 HIGH

An Improper Validation of Syntactic Correctness of Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series with MPC10/11 …

Jul 11, 2024
CVE-2024-39541
6.5 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, …

Jul 11, 2024
CVE-2024-39540
7.5 HIGH

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on SRX Series, and MX …

Jul 11, 2024
CVE-2024-39539
5.3 MEDIUM

A Missing Release of Memory after Effective Lifetime vulnerability in Juniper Networks Junos OS on MX Series allows an unauthenticated adjacent attacker to cause a …

Jul 11, 2024
CVE-2024-39538
6.5 MEDIUM

A Buffer Copy without Checking Size of Input vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved on ACX7000 Series allows …

Jul 11, 2024
CVE-2024-39537
6.5 MEDIUM

An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved on ACX 7000 Series allows an unauthenticated, network-based attacker …

Jul 11, 2024
CVE-2024-39536
5.3 MEDIUM

A Missing Release of Memory after Effective Lifetime vulnerability in the Periodic Packet Management Daemon (ppmd) of Juniper Networks Junos OS and Junos OS Evolved …

Jul 11, 2024
CVE-2024-39535
6.5 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX 7000 Series …

Jul 11, 2024
CVE-2024-39533
5.8 MEDIUM

An Unimplemented or Unsupported Feature in the UI vulnerability in Juniper Networks Junos OS on QFX5000 Series and EX4600 Series allows an unauthenticated, network-based attacker …

Jul 11, 2024
CVE-2024-39532
6.3 MEDIUM

An Insertion of Sensitive Information into Log File vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high …

Jul 11, 2024
CVE-2024-39531
7.5 HIGH

An Improper Handling of Values vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX 7000 Series allows a network-based, …

Jul 11, 2024
CVE-2024-6680
6.3 MEDIUM

A vulnerability classified as critical was found in witmy my-springsecurity-plus up to 2024-07-04. Affected by this vulnerability is an unknown functionality of the file /api/dept/build. …

Jul 11, 2024
CVE-2024-39905
5.3 MEDIUM

Red is a fully modular Discord bot. Due to a bug in Red's Core API, 3rd-party cogs using the `@commands.can_manage_channel()` command permission check without additional …

Jul 11, 2024
CVE-2024-39904
8.8 HIGH

VNote is a note-taking platform. Prior to 3.18.1, a code execution vulnerability existed in VNote, which allowed an attacker to execute arbitrary programs on the …

Jul 11, 2024
CVE-2024-39530
7.5 HIGH

An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis management daemon (chassisd) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker …

Jul 11, 2024
CVE-2024-39529
7.5 HIGH

A Use of Externally-Controlled Format String vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based …

Jul 11, 2024
CVE-2024-39528
5.7 MEDIUM

A Use After Free vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated, network-based attacker …

Jul 11, 2024
CVE-2024-39524
7.8 HIGH

An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their …

Jul 11, 2024
CVE-2024-39523
7.8 HIGH

An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their …

Jul 11, 2024
CVE-2024-39522
7.8 HIGH

An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their …

Jul 11, 2024
CVE-2024-39521
7.8 HIGH

An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their …

Jul 11, 2024
CVE-2024-39520
7.8 HIGH

An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their …

Jul 11, 2024
CVE-2024-39519
6.5 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX7000 Series allows …

Jul 11, 2024
CVE-2024-39317
6.5 MEDIUM

Wagtail is an open source content management system built on Django. A bug in Wagtail's `parse_query_string` would result in it taking a long time to …

Jul 11, 2024
CVE-2024-32753

Under certain circumstances the camera may be susceptible to known vulnerabilities associated with the JQuery versions prior to 3.5.0 third-party component

Jul 11, 2024
CVE-2024-6679
6.3 MEDIUM

A vulnerability classified as critical has been found in witmy my-springsecurity-plus up to 2024-07-04. Affected is an unknown function of the file /api/role. The manipulation …

Jul 11, 2024
CVE-2024-38536
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A memory allocation failure due to `http.memcap` being reached leads …

Jul 11, 2024
CVE-2024-38535
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Suricata can run out of memory when parsing crafted HTTP/2 …

Jul 11, 2024
CVE-2024-38534
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Crafted modbus traffic can lead to unlimited resource accumulation within …

Jul 11, 2024
CVE-2024-37151
5.3 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Mishandling of multiple fragmented packets using the same IP ID …

Jul 11, 2024
CVE-2024-28872
8.9 HIGH

The TLS certificate validation code is flawed. An attacker can obtain a TLS certificate from the Stork server and use it to connect to the …

Jul 11, 2024
CVE-2024-6035
6.1 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410. This vulnerability allows an attacker to inject malicious JavaScript code into the chat history …

Jul 11, 2024
CVE-2024-6643

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.