CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6407
9.8 CRITICAL

CWE-200: Information Exposure vulnerability exists that could cause disclosure of credentials when a specially crafted message is sent to the device.

Jul 11, 2024
CVE-2024-6528
5.4 MEDIUM

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a vulnerability leading to a cross-site scripting condition where …

Jul 11, 2024
CVE-2024-5681
7.8 HIGH

CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, and potentially kernel execution when a malicious actor with local user access …

Jul 11, 2024
CVE-2024-5680
7.1 HIGH

CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service when a malicious actor with local user access crafts a script/program using …

Jul 11, 2024
CVE-2024-5679
7.1 HIGH

CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or kernel memory leak when a malicious actor with local user access crafts a script/program …

Jul 11, 2024
CVE-2024-2602
7.3 HIGH

CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could result in remote code execution when an authenticated user …

Jul 11, 2024
CVE-2024-38433
6.7 MEDIUM

Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton …

Jul 11, 2024
CVE-2024-6666
8.8 HIGH

The WP ERP plugin for WordPress is vulnerable to SQL Injection via the ‘vendor_id’ and 'status' parameter in all versions up to, and including, 1.13.0 …

Jul 11, 2024
CVE-2024-6624
9.8 CRITICAL

The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3. This is due to improper …

Jul 11, 2024
CVE-2024-6385
9.6 CRITICAL

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from …

Jul 11, 2024
CVE-2024-6256
6.4 MEDIUM

The Feeds for YouTube (YouTube video, channel, and gallery plugin) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'youtube-feed' shortcode in …

Jul 11, 2024
CVE-2024-5470
3.8 LOW

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Guest …

Jul 11, 2024
CVE-2024-5257
4.9 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer …

Jul 11, 2024
CVE-2024-2880
2.7 LOW

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from …

Jul 11, 2024
CVE-2024-6138
4.8 MEDIUM

The Secure Copy Content Protection and Content Locking WordPress plugin before 4.0.9 does not sanitise and escape some of its settings, which could allow high …

Jul 11, 2024
CVE-2024-6026
5.4 MEDIUM

The Slider by 10Web WordPress plugin before 1.2.56 does not sanitise and escape some of its Slide options, which could allow authenticated users with access …

Jul 11, 2024
CVE-2024-6025
5.4 MEDIUM

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.5 does not sanitise and escape some of its Quiz settings, which could allow contributors and …

Jul 11, 2024
CVE-2024-5444
5.4 MEDIUM

The Bible Text WordPress plugin through 0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Jul 11, 2024
CVE-2024-4655
5.4 MEDIUM

The Ultimate Blocks WordPress plugin before 3.1.9 does not validate and escape some of its block options before outputting them back in a page/post where …

Jul 11, 2024
CVE-2024-1845
8.8 HIGH

The VikRentCar Car Rental Management System WordPress plugin before 1.3.2 does not have CSRF checks in some places, which could allow attackers to make logged …

Jul 11, 2024
CVE-2024-22280
8.5 HIGH

VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL …

Jul 11, 2024
CVE-2024-6554
5.3 MEDIUM

The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and …

Jul 11, 2024
CVE-2024-6397
9.8 CRITICAL

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 0.1.0.44. …

Jul 11, 2024
CVE-2024-0619
5.3 MEDIUM

The Payflex Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the payment_callback() function in …

Jul 11, 2024
CVE-2024-6676
6.3 MEDIUM

A vulnerability has been found in witmy my-springsecurity-plus up to 2024-07-03 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Jul 11, 2024
CVE-2024-6210
5.3 MEDIUM

The Duplicator plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 1.5.9. This makes it possible for unauthenticated attackers …

Jul 11, 2024
CVE-2024-23485
4.6 MEDIUM

Improperly Preserved Integrity of Hardware Configuration State During a Power Save/Restore Operation (CWE-1304) in the Controller 6000 and 7000 can lead to secured door locks …

Jul 11, 2024
CVE-2024-23317
6.3 MEDIUM

External Control of File Name or Path (CWE-73) in the Controller 6000 and Controller 7000 allows an attacker with local access to the Controller to …

Jul 11, 2024
CVE-2024-23194
3.3 LOW

Improper output Neutralization for Logs (CWE-117) in the Command Centre API Diagnostics Endpoint could allow an attacker limited ability to modify Command Centre log files. …

Jul 11, 2024
CVE-2024-22387
6.8 MEDIUM

External Control of Critical State Data (CWE-642) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated user to modify device I/O …

Jul 11, 2024
CVE-2016-15039
6.3 MEDIUM

A vulnerability classified as critical was found in mhuertos phpLDAPadmin up to 665dbc2690ebeb5392d38f1fece0a654225a0b38. Affected by this vulnerability is the function makeHttpRequest of the file htdocs/js/ajax_functions.js. …

Jul 11, 2024
CVE-2024-40618
9.6 CRITICAL

Whale browser before 3.26.244.21 allows an attacker to execute malicious JavaScript due to improper sanitization when processing a built-in extension.

Jul 11, 2024
CVE-2024-6653
7.3 HIGH

A vulnerability was found in code-projects Simple Task List 1.0. It has been declared as critical. This vulnerability affects unknown code of the file loginForm.php …

Jul 11, 2024
CVE-2024-6447
7.2 HIGH

The FULL – Cliente plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the license plan parameter in all versions up to, and including, …

Jul 11, 2024
CVE-2024-6652
6.3 MEDIUM

A vulnerability was found in itsourcecode Gym Management System 1.0. It has been classified as critical. This affects an unknown part of the file manage_member.php. …

Jul 10, 2024
CVE-2024-6650
2.4 LOW

A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this issue is the function …

Jul 10, 2024
CVE-2024-6037
9.1 CRITICAL

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir). …

Jul 10, 2024
CVE-2024-6036
9.1 CRITICAL

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to restart the server at will by sending a specific request to the `/queue/join?` endpoint with …

Jul 10, 2024
CVE-2024-39565
8.8 HIGH

An Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in J-Web shipped with Juniper Networks Junos OS allows an unauthenticated, network-based attacker to …

Jul 10, 2024
CVE-2024-39562
7.5 HIGH

A Missing Release of Resource after Effective Lifetime vulnerability the xinetd process, responsible for spawning SSH daemon (sshd) instances, of Juniper Networks Junos OS Evolved …

Jul 10, 2024
CVE-2024-39561
5.8 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX4600 and SRX5000 Series allows …

Jul 10, 2024
CVE-2024-39560
6.5 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a logically …

Jul 10, 2024
CVE-2024-39559
5.9 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS Evolved may allow a network-based unauthenticated attacker to …

Jul 10, 2024
CVE-2024-39558
6.5 MEDIUM

An Unchecked Return Value vulnerability in the Routing Protocol Daemon (rpd) on Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows a logically …

Jul 10, 2024
CVE-2024-39557
6.5 MEDIUM

An Uncontrolled Resource Consumption vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS Evolved allows an unauthenticated, adjacent attacker to …

Jul 10, 2024
CVE-2024-39556
6.4 MEDIUM

A Stack-Based Buffer Overflow vulnerability in Juniper Networks Junos OS and Juniper Networks Junos OS Evolved may allow a local, low-privileged attacker with access to …

Jul 10, 2024
CVE-2024-39555
7.5 HIGH

An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker …

Jul 10, 2024
CVE-2024-39554
5.9 MEDIUM

A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Juniper Networks …

Jul 10, 2024
CVE-2024-39518
7.5 HIGH

A Heap-based Buffer Overflow vulnerability in the telemetry sensor process (sensord) of Juniper Networks Junos OS on MX240, MX480, MX960 platforms using MPC10E causes a …

Jul 10, 2024
CVE-2024-39517
6.5 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Layer 2 Address Learning Daemon (l2ald) on Juniper Networks Junos OS and Junos OS …

Jul 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.