CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4149
4.8 MEDIUM

The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button WordPress plugin before 3.2.3 does not sanitise and …

Jun 13, 2024
CVE-2024-4145
7.2 HIGH

The Search & Replace WordPress plugin before 3.2.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to …

Jun 13, 2024
CVE-2024-3552
9.8 CRITICAL

The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX …

Jun 13, 2024
CVE-2024-3032
6.1 MEDIUM

Themify Builder WordPress plugin before 7.5.8 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

Jun 13, 2024
CVE-2024-2762
5.4 MEDIUM

The FooGallery WordPress plugin before 2.4.15, foogallery-premium WordPress plugin before 2.4.15 does not validate and escape some of its Gallery settings before outputting them back …

Jun 13, 2024
CVE-2024-2098
7.5 HIGH

The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLibrary' function in all …

Jun 13, 2024
CVE-2024-38295
9.8 CRITICAL

ALCASAR before 3.6.1 allows still_connected.php remote code execution.

Jun 13, 2024
CVE-2024-38294
9.8 CRITICAL

ALCASAR before 3.6.1 allows email_registration_back.php remote code execution.

Jun 13, 2024
CVE-2024-38293
9.6 CRITICAL

ALCASAR before 3.6.1 allows CSRF and remote code execution in activity.php.

Jun 13, 2024
CVE-2023-52890
4.5 MEDIUM

NTFS-3G before 75dcdc2 has a use-after-free in ntfs_uppercase_mbs in libntfs-3g/unistr.c. NOTE: discussion suggests that exploitation would be challenging.

Jun 13, 2024
CVE-2024-3922
10.0 CRITICAL

The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and including, 3.10.3 due to …

Jun 13, 2024
CVE-2024-4201
4.4 MEDIUM

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all …

Jun 12, 2024
CVE-2024-1963
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.4 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting …

Jun 12, 2024
CVE-2024-1736
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior …

Jun 12, 2024
CVE-2024-1495
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.1 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting …

Jun 12, 2024
CVE-2024-3468

There is a vulnerability in AVEVA PI Web API that could allow malicious code to execute on the PI Web API environment under the privileges …

Jun 12, 2024
CVE-2024-3467
7.8 HIGH

There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under the …

Jun 12, 2024
CVE-2024-37665
8.8 HIGH

An access control issue in Wvp GB28181 Pro 2.0 allows authenticated attackers to escalate privileges to Administrator via a crafted POST request.

Jun 12, 2024
CVE-2024-36523
6.5 MEDIUM

An access control issue in Wvp GB28181 Pro 2.0 allows users to continue to access information in the application after deleting their own or administrator …

Jun 12, 2024
CVE-2023-49559
3.7 LOW

An issue in vektah gqlparser open-source-library v.2.5.10 allows a remote attacker to cause a denial of service via a crafted script to the parserDirectives function.

Jun 12, 2024
CVE-2024-5798
2.6 LOW

Vault and Vault Enterprise did not properly validate the JSON Web Token (JWT) role-bound audience claim when using the Vault JWT auth method. This may …

Jun 12, 2024
CVE-2024-31881
6.5 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server …

Jun 12, 2024
CVE-2023-29267
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5is vulnerable to a denial of service, under specific configurations, as …

Jun 12, 2024
CVE-2024-5559
6.1 MEDIUM

CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists that could cause denial of service, device reboot, or an attacker gaining full control …

Jun 12, 2024
CVE-2024-37629
6.1 MEDIUM

SummerNote v0.9.1 is vulnerable to Cross Site Scripting (XSS) via the Code View Function.

Jun 12, 2024
CVE-2024-2747
7.8 HIGH

CWE-428: Unquoted search path or element vulnerability exists in Easergy Studio, which could cause privilege escalation when a valid user replaces a trusted file name …

Jun 12, 2024
CVE-2024-28762
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted …

Jun 12, 2024
CVE-2024-24051
5.5 MEDIUM

Improper input validation of printing files in Monoprice Select Mini V2 V37.115.32 allows attackers to instruct the device's movable parts to destinations that exceed the …

Jun 12, 2024
CVE-2024-0865
7.8 HIGH

CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in as a non-administrative user.

Jun 12, 2024
CVE-2024-5909
5.5 MEDIUM

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to …

Jun 12, 2024
CVE-2024-5908
7.5 HIGH

A problem with the Palo Alto Networks GlobalProtect app can result in exposure of encrypted user credentials, used for connecting to GlobalProtect, in application logs. …

Jun 12, 2024
CVE-2024-5907
7.0 HIGH

A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated …

Jun 12, 2024
CVE-2024-5906
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in Palo Alto Networks Prisma Cloud Compute software enables a malicious administrator with add/edit permissions for identity providers to store …

Jun 12, 2024
CVE-2024-5905
4.4 MEDIUM

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low privileged Windows user to …

Jun 12, 2024
CVE-2024-5898
6.3 MEDIUM

A vulnerability was found in itsourcecode Payroll Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jun 12, 2024
CVE-2024-5560
5.3 MEDIUM

CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service of the device’s web interface when an attacker sends a specially crafted HTTP request.

Jun 12, 2024
CVE-2024-5558
6.4 MEDIUM

CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists that could cause escalation of privileges when an attacker abuses a limited admin account.

Jun 12, 2024
CVE-2024-5557
4.5 MEDIUM

CWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause exposure of SNMP credentials when an attacker has access to the controller …

Jun 12, 2024
CVE-2024-37878
6.1 MEDIUM

Cross Site Scripting vulnerability in TWCMS v.2.0.3 allows a remote attacker to execute arbitrary code via the /TWCMS-gh-pages/twcms/runtime/twcms_view/default,index.htm.php" PHP directly echoes parameters input from external …

Jun 12, 2024
CVE-2024-37040
5.4 MEDIUM

CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a user with access to the device’s web interface …

Jun 12, 2024
CVE-2024-37039
5.9 MEDIUM

CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request.

Jun 12, 2024
CVE-2024-37038
7.5 HIGH

CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware …

Jun 12, 2024
CVE-2024-37037
8.1 HIGH

CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability exists that could allow an authenticated user with access to the device’s …

Jun 12, 2024
CVE-2024-37036
9.8 CRITICAL

CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass when sending a malformed POST request and particular configuration parameters are set.

Jun 12, 2024
CVE-2024-2230

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 12, 2024
CVE-2024-22855
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in the User Maintenance section of ITSS iMLog v1.307 allows attackers to execute arbitrary web scripts or HTML via a …

Jun 12, 2024
CVE-2024-5897
4.3 MEDIUM

A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is an …

Jun 12, 2024
CVE-2024-5896
7.3 HIGH

A vulnerability, which was classified as critical, was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. Affected is the function save_users of …

Jun 12, 2024
CVE-2024-5759
5.4 MEDIUM

An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized objects and launch scans without having the …

Jun 12, 2024
CVE-2024-37300
8.1 HIGH

OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. JupyterHub < 5.0, when used with `GlobusOAuthenticator`, could be …

Jun 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.