CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6016
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in itsourcecode Online Laundry Management System 1.0. Affected by this issue is some unknown functionality …

Jun 15, 2024
CVE-2024-6015
6.3 MEDIUM

A vulnerability classified as critical was found in itsourcecode Online House Rental System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jun 15, 2024
CVE-2024-6014
6.3 MEDIUM

A vulnerability classified as critical has been found in itsourcecode Document Management System 1.0. Affected is an unknown function of the file edithis.php. The manipulation …

Jun 15, 2024
CVE-2024-6013
6.3 MEDIUM

A vulnerability was found in itsourcecode Online Book Store 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Jun 15, 2024
CVE-2024-6009
6.3 MEDIUM

A vulnerability has been found in itsourcecode Event Calendar 1.0 and classified as critical. Affected by this vulnerability is the function regConfirm/regDelete of the file …

Jun 15, 2024
CVE-2024-6008
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Online Book Store up to 1.0. Affected is an unknown function of the file …

Jun 15, 2024
CVE-2024-31870
3.3 LOW

IBM Db2 for i 7.2, 7.3, 7.4, and 7.5 supplies user defined table function is vulnerable to user enumeration by a local authenticated attacker, without …

Jun 15, 2024
CVE-2024-27275
7.4 HIGH

IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority requirement. A local user without administrator privilege …

Jun 15, 2024
CVE-2024-6007
6.3 MEDIUM

A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /protocol/iscgwtunnel/deleteiscgwrouteconf.php. The …

Jun 15, 2024
CVE-2024-6006
3.5 LOW

A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of …

Jun 15, 2024
CVE-2024-6005
3.5 LOW

A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Jun 15, 2024
CVE-2024-5611
6.4 MEDIUM

The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘label_years’ attribute within the Countdown widget in all versions …

Jun 15, 2024
CVE-2024-5858
4.3 MEDIUM

The AI Infographic Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the qcld_openai_title_generate_desc AJAX action …

Jun 15, 2024
CVE-2024-4551
6.4 MEDIUM

The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and …

Jun 15, 2024
CVE-2024-4258
9.8 CRITICAL

The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and …

Jun 15, 2024
CVE-2024-4095
6.4 MEDIUM

The Collapse-O-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'expand' and 'expandsub' shortcode in all versions up to, and including, …

Jun 15, 2024
CVE-2024-3105
9.9 CRITICAL

The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, …

Jun 15, 2024
CVE-2024-2695
6.4 MEDIUM

The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortcode in all versions up to, and including, 4.6.13 …

Jun 15, 2024
CVE-2024-1399
6.4 MEDIUM

The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all …

Jun 15, 2024
CVE-2024-6000
7.1 HIGH

The FooEvents for WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper capability setting on the 'display_ticket_themes_page' function in …

Jun 15, 2024
CVE-2024-5871
9.8 CRITICAL

The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of …

Jun 15, 2024
CVE-2024-5868
6.5 MEDIUM

The WooCommerce - Social Login plugin for WordPress is vulnerable to Email Verification in all versions up to, and including, 2.6.2 via the use of …

Jun 15, 2024
CVE-2024-5263
6.4 MEDIUM

The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Motion Text and Table widgets in all versions up to, …

Jun 15, 2024
CVE-2024-4479
6.4 MEDIUM

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sg_general_toggle_tab_enable and sg_accordion_style attributes within the plugin's JKit - Tabs …

Jun 15, 2024
CVE-2024-3815
5.5 MEDIUM

The Newspaper theme for WordPress is vulnerable to Stored Cross-Site Scripting via attachment meta in the archive page in all versions up to, and including, …

Jun 15, 2024
CVE-2024-3814
5.5 MEDIUM

The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'single' module in all versions up to, and including, 4.8 …

Jun 15, 2024
CVE-2024-3813
8.8 HIGH

The tagDiv Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8 via the 'td_block_title' shortcode 'block_template_id' …

Jun 15, 2024
CVE-2024-2544
7.4 HIGH

The Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on all …

Jun 15, 2024
CVE-2023-6696
8.1 HIGH

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing …

Jun 15, 2024
CVE-2024-6003
7.3 HIGH

A vulnerability was found in Guangdong Baolun Electronics IP Network Broadcasting Service Platform 2.0. It has been classified as critical. Affected is an unknown function …

Jun 14, 2024
CVE-2024-30120
2.9 LOW

HCL DRYiCE Optibot Reset Station is impacted by an Unused Parameter in the web application.

Jun 14, 2024
CVE-2024-30119
3.7 LOW

HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header. This could allow an attacker to intercept or manipulate data during …

Jun 14, 2024
CVE-2024-21988
5.3 MEDIUM

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible to disclosure of sensitive information via complex MiTM attacks due to a vulnerability …

Jun 14, 2024
CVE-2024-37889
6.5 MEDIUM

MyFinances is a web application for managing finances. MyFinances has a way to access other customer invoices while signed in as a user. This method …

Jun 14, 2024
CVE-2024-37831
9.8 CRITICAL

Itsourcecode Payroll Management System 1.0 is vulnerable to SQL Injection in payroll_items.php via the ID parameter.

Jun 14, 2024
CVE-2024-36600
8.4 HIGH

Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a crafted ISO 9660 image file.

Jun 14, 2024
CVE-2024-37888
6.1 MEDIUM

The Open Link is a CKEditor plugin, extending context menu with a possibility to open link in a new tab. The vulnerability allowed to execute …

Jun 14, 2024
CVE-2024-36599
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

Jun 14, 2024
CVE-2024-36598
8.1 HIGH

An arbitrary file upload vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary code via uploading a crafted image file.

Jun 14, 2024
CVE-2024-36597
8.8 HIGH

Aegon Life v1.0 was discovered to contain a SQL injection vulnerability via the client_id parameter at clientStatus.php.

Jun 14, 2024
CVE-2024-24320
8.8 HIGH

Directory Traversal vulnerability in Mgt-commerce CloudPanel v.2.0.0 thru v.2.4.0 allows a remote attacker to obtain sensitive information and execute arbitrary code via the service parameter …

Jun 14, 2024
CVE-2024-5659
6.5 MEDIUM

Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fault(MNRF/Assert). This …

Jun 14, 2024
CVE-2024-37369
8.8 HIGH

A privilege escalation vulnerability exists in the affected product. The vulnerability allows low-privilege users to edit scripts, bypassing Access Control Lists, and potentially gaining further …

Jun 14, 2024
CVE-2024-37887
3.5 LOW

Nextcloud Server is a self hosted personal cloud system. Private shared calendar events' recurrence exceptions can be read by sharees. It is recommended that the …

Jun 14, 2024
CVE-2024-37886
5.4 MEDIUM

user_oidc app is an OpenID Connect user backend for Nextcloud. An attacker could potentially trick the app into accepting a request that is not signed …

Jun 14, 2024
CVE-2024-37885
3.8 LOW

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. A code injection in Nextcloud Desktop Client for macOS …

Jun 14, 2024
CVE-2024-37884
3.5 LOW

Nextcloud Server is a self hosted personal cloud system. A malicious user was able to send delete requests for old versions of files they only …

Jun 14, 2024
CVE-2024-37883
4.3 MEDIUM

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A user with access to …

Jun 14, 2024
CVE-2024-37882
8.1 HIGH

Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share permissions could reshare the item with more permissions. It …

Jun 14, 2024
CVE-2024-37645
8.8 HIGH

TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow vulnerability via the submit-url parameter at /formSysLog .

Jun 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.