CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-1168
6.4 MEDIUM

The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's social image URL in all versions up to, …

Jun 20, 2024
CVE-2023-3204
6.5 MEDIUM

The Materialis theme for WordPress is vulnerable to limited arbitrary options updates in versions up to, and including, 1.1.24. This is due to missing authorization …

Jun 20, 2024
CVE-2024-6176

Allocation of Resources Without Limits or Throttling vulnerability in LG Electronics LG SuperSign CMS allows Port Scanning.This issue affects LG SuperSign CMS: from 4.1.3 before …

Jun 20, 2024
CVE-2024-6103
8.8 HIGH

Use after free in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jun 20, 2024
CVE-2024-6102
8.8 HIGH

Out of bounds memory access in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Jun 20, 2024
CVE-2024-6101
8.8 HIGH

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to perform out of bounds memory access via a crafted HTML …

Jun 20, 2024
CVE-2024-6100
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security …

Jun 20, 2024
CVE-2024-5182
9.1 CRITICAL

A path traversal vulnerability exists in mudler/localai version 2.14.0, where an attacker can exploit the `model` parameter during the model deletion process to delete arbitrary …

Jun 20, 2024
CVE-2024-36684
9.8 CRITICAL

In the module "Custom links" (pk_customlinks) <= 2.3 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a sensitive SQL …

Jun 19, 2024
CVE-2024-36680
7.5 HIGH

In the module "Facebook" (pkfacebook) <=1.0.1 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The ajax script facebookConnect.php have a sensitive SQL call …

Jun 19, 2024
CVE-2024-36679
10.0 CRITICAL

In the module "Module Live Chat Pro (All in One Messaging)" (livechatpro) <=8.4.0, a guest can perform PHP Code injection. Due to a predictable token, …

Jun 19, 2024
CVE-2024-36678
9.8 CRITICAL

In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a sensitive SQL …

Jun 19, 2024
CVE-2024-36677
7.5 HIGH

In the module "Login as customer PRO" (loginascustomerpro) <1.2.7 from Weblir for PrestaShop, a guest can access direct link to connect to each customer account …

Jun 19, 2024
CVE-2024-34994
9.8 CRITICAL

In the module "Channable" (channable) up to version 3.2.1 from Channable for PrestaShop, a guest can perform SQL injection via `ChannableFeedModuleFrontController::postProcess()`.

Jun 19, 2024
CVE-2024-34990
10.0 CRITICAL

In the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop, a customer can upload .php …

Jun 19, 2024
CVE-2024-33836
9.8 CRITICAL

In the module "JA Marketplace" (jamarketplace) up to version 9.0.1 from JA Module for PrestaShop, a guest can upload files with extensions .php. In version …

Jun 19, 2024
CVE-2024-38358
2.9 LOW

Wasmer is a web assembly (wasm) Runtime supporting WASIX, WASI and Emscripten. If the preopened directory has a symlink pointing outside, WASI programs can traverse …

Jun 19, 2024
CVE-2024-38357
6.1 MEDIUM

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content parsing code. This allowed specially crafted noscript …

Jun 19, 2024
CVE-2024-38356
6.1 MEDIUM

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content extraction code. When using the `noneditable_regexp` option, …

Jun 19, 2024
CVE-2024-38355
7.3 HIGH

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus …

Jun 19, 2024
CVE-2024-34993
6.3 MEDIUM

In the module "Bulk Export products to Google Merchant-Google Shopping" (bagoogleshopping) up to version 1.0.26 from Buy Addons for PrestaShop, a guest can perform SQL …

Jun 19, 2024
CVE-2024-38352

Rejected reason: CVE was assigned in error.

Jun 19, 2024
CVE-2024-36117
8.6 HIGH

Reposilite is an open source, lightweight and easy-to-use repository manager for Maven based artifacts in JVM ecosystem. Reposilite v3.5.10 is affected by an Arbitrary File …

Jun 19, 2024
CVE-2024-36116
7.5 HIGH

Reposilite is an open source, lightweight and easy-to-use repository manager for Maven based artifacts in JVM ecosystem. Reposilite provides support for JavaDocs files, which are …

Jun 19, 2024
CVE-2024-36115
7.1 HIGH

Reposilite is an open source, lightweight and easy-to-use repository manager for Maven based artifacts in JVM ecosystem. As a Maven repository manager, Reposilite provides the …

Jun 19, 2024
CVE-2024-32030
8.1 HIGH

Kafka UI is an Open-Source Web UI for Apache Kafka Management. Kafka UI API allows users to connect to different Kafka brokers by specifying their …

Jun 19, 2024
CVE-2024-34444
7.1 HIGH

Missing Authorization vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a before 6.7.0.

Jun 19, 2024
CVE-2024-34443
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemePunch OHG Slider Revolution allows Stored XSS.This issue affects Slider Revolution: …

Jun 19, 2024
CVE-2024-22263
8.8 HIGH

Spring Cloud Data Flow is a microservices-based Streaming and Batch data processing in Cloud Foundry and Kubernetes. The Skipper server has the ability to receive …

Jun 19, 2024
CVE-2023-39312
9.1 CRITICAL

Missing Authorization vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.

Jun 19, 2024
CVE-2023-38394
5.4 MEDIUM

Missing Authorization vulnerability in Artbees JupiterX Core.This issue affects JupiterX Core: from 3.0.0 through 3.3.0.

Jun 19, 2024
CVE-2023-38393
7.6 HIGH

Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.

Jun 19, 2024
CVE-2023-36516
7.6 HIGH

Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3.

Jun 19, 2024
CVE-2023-36515
7.3 HIGH

Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3.

Jun 19, 2024
CVE-2023-25697
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in GamiPress.This issue affects GamiPress: from n/a through 2.5.6.

Jun 19, 2024
CVE-2022-45832
6.5 MEDIUM

Missing Authorization vulnerability in Hennessey Digital Attorney.This issue affects Attorney: from n/a through 3.

Jun 19, 2024
CVE-2021-47616
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: RDMA: Fix use-after-free in rxe_queue_cleanup On error handling path in rxe_qp_from_init() qp->sq.queue is freed and …

Jun 19, 2024
CVE-2021-47615

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 19, 2024
CVE-2021-47614
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix a user-after-free in add_pble_prm When irdma_hmc_sd_one fails, 'chunk' is freed while its still …

Jun 19, 2024
CVE-2021-47613
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: i2c: virtio: fix completion handling The driver currently assumes that the notify callback is only …

Jun 19, 2024
CVE-2021-47612
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfc: fix segfault in nfc_genl_dump_devices_done When kmalloc in nfc_genl_dump_devices() fails then nfc_genl_dump_devices_done() segfaults as below …

Jun 19, 2024
CVE-2021-47611
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mac80211: validate extended element ID is present Before attempting to parse an extended element, verify …

Jun 19, 2024
CVE-2021-47610
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix null ptr access msm_ioctl_gem_submit() Fix the below null pointer dereference in msm_ioctl_gem_submit(): 26545.260705: …

Jun 19, 2024
CVE-2021-47609
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scpi: Fix string overflow in SCPI genpd driver Without the bound checks for scpi_pd->name, …

Jun 19, 2024
CVE-2021-47608
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix kernel address leakage in atomic fetch The change in commit 37086bfdc737 ("bpf: Propagate …

Jun 19, 2024
CVE-2021-47607
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix kernel address leakage in atomic cmpxchg's r0 aux reg The implementation of BPF_CMPXCHG …

Jun 19, 2024
CVE-2021-47606
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: netlink: af_netlink: Prevent empty skb by adding a check on len. Adding a check …

Jun 19, 2024
CVE-2021-47605
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: vduse: fix memory corruption in vduse_dev_ioctl() The "config.offset" comes from the user. There needs to …

Jun 19, 2024
CVE-2021-47604
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: vduse: check that offset is within bounds in get_config() This condition checks "len" but it …

Jun 19, 2024
CVE-2021-47603
4.4 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: audit: improve robustness of the audit queue handling If the audit daemon were ever to …

Jun 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.