CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-38857
4.3 MEDIUM

Improper neutralization of input in Checkmk before versions 2.3.0p8, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows attackers to craft malicious links that can facilitate phishing attacks.

Jul 2, 2024
CVE-2024-37479
8.5 HIGH

Local File Inclusion vulnerability in LA-Studio LA-Studio Element Kit for Elementor via "LaStudioKit Progress Bar" widget in New Post, specifically in the "progress_type" attribute.This issue …

Jul 2, 2024
CVE-2024-37134
6.7 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability to gain …

Jul 2, 2024
CVE-2024-37133
6.7 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to …

Jul 2, 2024
CVE-2024-37132
6.7 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an incorrect privilege assignment vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, …

Jul 2, 2024
CVE-2024-37126
6.7 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to …

Jul 2, 2024
CVE-2023-41928
5.3 MEDIUM

The device is observed to accept deprecated TLS protocols, increasing the risk of cryptographic weaknesses.

Jul 2, 2024
CVE-2023-41927
5.3 MEDIUM

The server supports at least one cipher suite which is on the NCSC-NL list of cipher suites to be phased out, increasing the risk of …

Jul 2, 2024
CVE-2023-41926
8.8 HIGH

The webserver utilizes basic authentication for its user login to the configuration interface. As encryption is disabled on port 80, it enables potential eavesdropping on …

Jul 2, 2024
CVE-2023-41923
7.2 HIGH

The user management section of the web application permits the creation of user accounts with excessively weak passwords, including single-character passwords.

Jul 2, 2024
CVE-2023-41922
7.2 HIGH

A 'Cross-site Scripting' (XSS) vulnerability, characterized by improper input neutralization during web page generation, has been discovered. This vulnerability allows for Stored XSS attacks to …

Jul 2, 2024
CVE-2023-41921
9.8 CRITICAL

A vulnerability allows attackers to download source code or an executable from a remote location and execute the code without sufficiently verifying the origin and …

Jul 2, 2024
CVE-2023-41920
9.8 CRITICAL

The vulnerability allows attackers access to the root account without having to authenticate. Specifically, if the device is configured with the IP address of 10.10.10.10, …

Jul 2, 2024
CVE-2023-41919
9.8 CRITICAL

Hardcoded credentials are discovered within the application's source code, creating a potential security risk for unauthorized access.

Jul 2, 2024
CVE-2023-41918
10.0 CRITICAL

A vulnerability allows unauthorized access to functionality inadequately constrained by ACLs. Attackers may exploit this to unauthenticated execute commands potentially leading to unauthorized data manipulation, …

Jul 2, 2024
CVE-2023-41917
10.0 CRITICAL

Inadequate input validation exposes the system to potential remote code execution (RCE) risks. Attackers can exploit this vulnerability by appending shell commands to the Speed-Measurement …

Jul 2, 2024
CVE-2024-6172
9.8 CRITICAL

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via …

Jul 2, 2024
CVE-2024-5219
6.4 MEDIUM

The Easy Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feature in all versions up to, and …

Jul 2, 2024
CVE-2024-32854
6.7 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privilege attacker could potentially exploit this vulnerability, leading to …

Jul 2, 2024
CVE-2024-32853
4.4 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.2 contain an execution with unnecessary privileges vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading …

Jul 2, 2024
CVE-2024-32852
5.9 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.0 contain use of a broken or risky cryptographic algorithm vulnerability. An unprivileged network malicious attacker could potentially exploit …

Jul 2, 2024
CVE-2024-0158
5.1 MEDIUM

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI …

Jul 2, 2024
CVE-2024-5767
8.8 HIGH

The sitetweet WordPress plugin through 0.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Jul 2, 2024
CVE-2024-5606
8.8 HIGH

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 is vulnerable does not validate and escape the question_id parameter in the qsm_bulk_delete_question_from_database AJAX action, …

Jul 2, 2024
CVE-2024-4627
5.4 MEDIUM

The Rank Math SEO WordPress plugin before 1.0.219 does not sanitise and escape some of its settings, which could allow users with access to the …

Jul 2, 2024
CVE-2024-3999
4.8 MEDIUM

The EazyDocs WordPress plugin before 2.5.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jul 2, 2024
CVE-2024-1427
6.4 MEDIUM

The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Jul 2, 2024
CVE-2024-5349
8.8 HIGH

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.8.1 via the …

Jul 2, 2024
CVE-2024-5419
6.4 MEDIUM

The Void Contact Form 7 Widget For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cf7_redirect_page' attribute within the …

Jul 2, 2024
CVE-2024-5938
6.4 MEDIUM

The Boot Store theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter within the theme's Button shortcode in all versions up …

Jul 2, 2024
CVE-2024-4679
7.8 HIGH

Incorrect Default Permissions vulnerability in Hitachi JP1/Extensible SNMP Agent for Windows, Hitachi JP1/Extensible SNMP Agent on Windows, Hitachi Job Management Partner1/Extensible SNMP Agent on Windows …

Jul 2, 2024
CVE-2024-2819
5.1 MEDIUM

Incorrect Default Permissions, Improper Preservation of Permissions vulnerability in Hitachi Ops Center Common Services allows File Manipulation.This issue affects Hitachi Ops Center Common Services: before …

Jul 2, 2024
CVE-2024-39314
4.7 MEDIUM

toy-blog is a headless content management system implementation. Starting in version 0.4.3 and prior to version 0.5.0, the administrative password was leaked through the command …

Jul 1, 2024
CVE-2024-39313
6.5 MEDIUM

toy-blog is a headless content management system implementation. Starting in version 0.5.4 and prior to version 0.6.1, articles with private visibility can be read if …

Jul 1, 2024
CVE-2024-39310
5.4 MEDIUM

The Basil recipe theme for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the `post_title` parameter in versions up to, and including, 2.0.4 due …

Jul 1, 2024
CVE-2024-39309
9.8 CRITICAL

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability in versions prior to 6.5.7 …

Jul 1, 2024
CVE-2024-37765
8.8 HIGH

Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.

Jul 1, 2024
CVE-2024-37764
5.4 MEDIUM

MachForm up to version 19 is affected by an authenticated stored cross-site scripting.

Jul 1, 2024
CVE-2024-37763
5.4 MEDIUM

MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can view compiled forms results.

Jul 1, 2024
CVE-2024-37762
9.9 CRITICAL

MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.

Jul 1, 2024
CVE-2024-23737
5.4 MEDIUM

Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Jira allows attackers to allows attackers to manipulate a user's S/MIME certificate of …

Jul 1, 2024
CVE-2024-23736
8.8 HIGH

Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Confluence allows attackers to manipulate a user's S/MIME certificate of PGP key via …

Jul 1, 2024
CVE-2024-5322
9.1 CRITICAL

The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can lead to authentication bypass. This vulnerability is …

Jul 1, 2024
CVE-2024-39305
6.5 MEDIUM

Envoy is a cloud-native, open source edge and service proxy. Prior to versions 1.30.4, 1.29.7, 1.28.5, and 1.27.7. Envoy references already freed memory when route …

Jul 1, 2024
CVE-2024-38368
9.3 CRITICAL

trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. A vulnerability affected older pods which migrated from the pre-2014 pull request workflow to trunk. …

Jul 1, 2024
CVE-2024-38367
8.2 HIGH

trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. Prior to commit d4fa66f49cedab449af9a56a21ab40697b9f7b97, the trunk sessions verification step could be manipulated for owner session …

Jul 1, 2024
CVE-2024-38366
10.0 CRITICAL

trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. The part of trunk which verifies whether a user has a real email address on …

Jul 1, 2024
CVE-2024-32230
7.8 HIGH

FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug at libavcodec/mpegvideo_enc.c:1216:21 in load_input_picture in FFmpeg7.0

Jul 1, 2024
CVE-2024-32229
8.4 HIGH

FFmpeg 7.0 contains a heap-buffer-overflow at libavfilter/vf_tiltandshift.c:189:5 in copy_column.

Jul 1, 2024
CVE-2024-32228
6.6 MEDIUM

FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end.

Jul 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.