CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-20079
6.7 MEDIUM

In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with …

Jul 1, 2024
CVE-2024-20078
9.8 CRITICAL

In venc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution …

Jul 1, 2024
CVE-2024-20077
7.5 HIGH

In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service with no additional execution …

Jul 1, 2024
CVE-2024-20076
7.5 HIGH

In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service with no additional execution …

Jul 1, 2024
CVE-2024-6419
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Medicine Tracker System 1.0. This vulnerability affects unknown code of the file /classes/Master.php?f=save_medicine. The manipulation of …

Jul 1, 2024
CVE-2024-6418
7.3 HIGH

A vulnerability classified as critical has been found in SourceCodester Medicine Tracker System 1.0. This affects an unknown part of the file /classes/Users.php?f=register_user. The manipulation …

Jun 30, 2024
CVE-2024-6417
6.3 MEDIUM

A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Jun 30, 2024
CVE-2024-6416
6.3 MEDIUM

A vulnerability was found in SeaCMS 12.9. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /js/player/dmplayer/dmku/?ac=edit. …

Jun 30, 2024
CVE-2024-34703
7.5 HIGH

Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. Prior …

Jun 30, 2024
CVE-2024-28794
5.4 MEDIUM

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …

Jun 30, 2024
CVE-2023-50964
5.4 MEDIUM

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …

Jun 30, 2024
CVE-2024-31898
5.4 MEDIUM

IBM InfoSphere Information Server 11.7 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references. IBM …

Jun 30, 2024
CVE-2024-28797
6.4 MEDIUM

IBM InfoSphere Information Server 11.7 is vulnerable stored to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …

Jun 30, 2024
CVE-2023-50953
5.4 MEDIUM

IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could …

Jun 30, 2024
CVE-2023-50952
5.4 MEDIUM

IBM InfoSphere Information Server 11.7 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, …

Jun 30, 2024
CVE-2024-35119
5.3 MEDIUM

IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in a stack …

Jun 30, 2024
CVE-2024-31902
4.3 MEDIUM

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a …

Jun 30, 2024
CVE-2024-28798
7.2 HIGH

IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …

Jun 30, 2024
CVE-2023-50954
4.3 MEDIUM

IBM InfoSphere Information Server 11.7 returns sensitive information in URL information that could be used in further attacks against the system. IBM X-Force ID: 275776.

Jun 30, 2024
CVE-2024-5062
6.1 MEDIUM

A reflected Cross-Site Scripting (XSS) vulnerability was identified in zenml-io/zenml version 0.57.1. The vulnerability exists due to improper neutralization of input during web page generation, …

Jun 30, 2024
CVE-2024-28795
5.4 MEDIUM

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …

Jun 30, 2024
CVE-2023-35022
3.3 LOW

IBM InfoSphere Information Server 11.7 could allow a local user to update projects that they do not have the authorization to access. IBM X-Force ID: …

Jun 30, 2024
CVE-2024-6415
2.4 LOW

A vulnerability classified as problematic was found in Ingenico Estate Manager 2023. Affected by this vulnerability is an unknown functionality of the file /emgui/rest/preferences/PREF_HOME_PAGE/sponsor/3/ of …

Jun 30, 2024
CVE-2024-6414
5.3 MEDIUM

A vulnerability classified as problematic has been found in Parsec Automation TrakSYS 11.x.x. Affected is an unknown function of the file TS/export/contentpage of the component …

Jun 30, 2024
CVE-2024-5926
9.1 CRITICAL

A path traversal vulnerability in the get-project-files functionality of stitionai/devika allows attackers to read arbitrary files from the filesystem and cause a Denial of Service …

Jun 30, 2024
CVE-2024-39848
9.1 CRITICAL

Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways. This is related to internet2.middleware.grouper.ws.security.WsGrouperLdapAuthentication and the use of the …

Jun 29, 2024
CVE-2024-39846
3.5 LOW

NewPass before 1.2.0 stores passwords (rather than password hashes) directly, which makes it easier to obtain unauthorized access to sensitive information. NOTE: in each case, …

Jun 29, 2024
CVE-2024-39840
8.8 HIGH

Factorio before 1.1.101 allows a crafted server to execute arbitrary code on clients via a custom map that leverages the ability of certain Lua base …

Jun 29, 2024
CVE-2024-2386
8.8 HIGH

The WordPress Plugin for Google Maps – WP MAPS plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'put_wpgm' shortcode …

Jun 29, 2024
CVE-2024-25943
7.6 HIGH

iDRAC9, versions prior to 7.00.00.172 for 14th Generation and 7.10.50.00 for 15th and 16th Generations, contains a session hijacking vulnerability in IPMI. A remote attacker …

Jun 29, 2024
CVE-2023-4017
6.1 MEDIUM

The Goya theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘attra-color’, 'attra-size', and 'product-cata' parameters in versions up to, and including, 1.0.8.7 …

Jun 29, 2024
CVE-2024-5819
6.4 MEDIUM

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to DOM-based Stored Cross-Site Scripting via HTML data …

Jun 29, 2024
CVE-2024-6363
6.4 MEDIUM

The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's stock_ticker shortcode in all versions up to, and including, 3.24.4 …

Jun 29, 2024
CVE-2024-5790
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attribute within the plugin's Gradient Heading widget in …

Jun 29, 2024
CVE-2024-5666
6.4 MEDIUM

The Extensions for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the EE Button widget in all versions …

Jun 29, 2024
CVE-2024-6265
9.8 CRITICAL

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection …

Jun 29, 2024
CVE-2024-5942
4.3 MEDIUM

The Page and Post Clone plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0 via the …

Jun 29, 2024
CVE-2024-5889
6.1 MEDIUM

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘country’ parameter in all versions …

Jun 29, 2024
CVE-2024-5598
7.5 HIGH

The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.4 via the 'fma_local_file_system' function. …

Jun 29, 2024
CVE-2024-5192
6.4 MEDIUM

The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells plugin for WordPress is …

Jun 29, 2024
CVE-2024-6405
6.1 MEDIUM

The Floating Social Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to …

Jun 29, 2024
CVE-2019-25211
9.1 CRITICAL

parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is …

Jun 29, 2024
CVE-2024-37371
9.1 CRITICAL

In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with …

Jun 28, 2024
CVE-2024-39828
6.1 MEDIUM

R74n Sandboxels 1.9 through 1.9.5 allows XSS via a message in a modified saved-game file. This was fixed in a hotfix to 1.9.5 on 2024-06-29.

Jun 28, 2024
CVE-2024-38533
6.5 MEDIUM

ZKsync Era is a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. There is possible invalid stack access due to the addresses used …

Jun 28, 2024
CVE-2024-38532
7.1 HIGH

The NXP Data Co-Processor (DCP) is a built-in hardware module for specific NXP SoCs¹ that implements a dedicated AES cryptographic engine for encryption/decryption operations. The …

Jun 28, 2024
CVE-2024-38525
7.5 HIGH

dd-trace-cpp is the Datadog distributed tracing for C++. When the library fails to extract trace context due to malformed unicode, it logs the list of …

Jun 28, 2024
CVE-2024-37370
7.5 HIGH

In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing …

Jun 28, 2024
CVE-2024-39307
3.5 LOW

Kavita is a cross platform reading server. Opening an ebook with malicious scripts inside leads to code execution inside the browsing context. Kavita doesn't sanitize …

Jun 28, 2024
CVE-2024-39302
3.7 LOW

BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker may be able to exploit the overly elevated file …

Jun 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.