CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-36761
9.8 CRITICAL

naga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs.

Jun 12, 2024
CVE-2024-1891
3.5 LOW

A stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker could inject HTML code into a web application scan …

Jun 12, 2024
CVE-2024-5895
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. This issue affects the function …

Jun 12, 2024
CVE-2024-5894
7.3 HIGH

A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects unknown code of the file manage_product.php. The manipulation of …

Jun 12, 2024
CVE-2024-5893
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Cab Management System 1.0. This affects an unknown part of the file /cms/classes/Users.php?f=delete_client. The manipulation …

Jun 12, 2024
CVE-2024-37304
6.1 MEDIUM

NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While …

Jun 12, 2024
CVE-2024-37297
5.4 MEDIUM

WooCommerce is an open-source e-commerce platform built on WordPress. A vulnerability introduced in WooCommerce 8.8 allows for cross-site scripting. A bad actor can manipulate a …

Jun 12, 2024
CVE-2024-36840
9.1 CRITICAL

SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code and obtain sensitive information via the id parameter …

Jun 12, 2024
CVE-2024-36691
6.3 MEDIUM

Insecure permissions in the AdminController.AjaxSave() method of PPGo_Jobs v2.8.0 allows authenticated attackers to arbitrarily modify users' account information.

Jun 12, 2024
CVE-2024-36265
9.8 CRITICAL

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: from 0.8.0. As this project …

Jun 12, 2024
CVE-2024-34065
7.1 HIGH

Strapi is an open-source content management system. By combining two vulnerabilities (an `Open Redirect` and `session token sent as URL query parameter`) in @strapi/plugin-users-permissions before …

Jun 12, 2024
CVE-2024-31217
5.3 MEDIUM

Strapi is an open-source content management system. Prior to version 4.22.0, a denial-of-service vulnerability is present in the media upload process causing the server to …

Jun 12, 2024
CVE-2024-2300
6.2 MEDIUM

HP Advance Mobile Applications for iOS and Android are potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices.

Jun 12, 2024
CVE-2024-29181
2.3 LOW

Strapi is an open-source content management system. Prior to version 4.19.1, a super admin can create a collection where an item in the collection has …

Jun 12, 2024
CVE-2024-28964
7.8 HIGH

Dell Common Event Enabler, version 8.9.10.0 and prior, contain an insecure deserialization vulnerability in CAVATools. A local unauthenticated attacker could potentially exploit this vulnerability, leading …

Jun 12, 2024
CVE-2024-5891
4.2 MEDIUM

A vulnerability was found in Quay. If an attacker can obtain the client ID for an application, they can use an OAuth token to authenticate …

Jun 12, 2024
CVE-2024-36699

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not …

Jun 12, 2024
CVE-2024-36264
9.8 CRITICAL

** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submarine.auth.default.secret`, a default value will be …

Jun 12, 2024
CVE-2024-36263
8.1 HIGH

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Submarine Server Core. This issue …

Jun 12, 2024
CVE-2024-23445
6.5 MEDIUM

It was identified that if a cross-cluster API key https://www.elastic.co/guide/en/elasticsearch/reference/8.14/security-api-create-cross-cluster-api-key.html#security-api-create-cross-cluster-api-key-request-body restricts search for a given index using the query or the field_security parameter, and the …

Jun 12, 2024
CVE-2024-1659
9.8 CRITICAL

Arbitrary File Upload vulnerability in MegaBIP software allows attacker to upload any file to the server (including a PHP code file) without an authentication. This …

Jun 12, 2024
CVE-2024-1577
9.8 CRITICAL

Remote Code Execution vulnerability in MegaBIP software allows to execute arbitrary code on the server without requiring authentication by saving crafted by the attacker PHP …

Jun 12, 2024
CVE-2024-1576
9.8 CRITICAL

SQL Injection vulnerability in MegaBIP software allows attacker to obtain site administrator privileges, including access to the administration panel and the ability to change the …

Jun 12, 2024
CVE-2024-5313
6.5 MEDIUM

CWE-668: Exposure of the Resource Wrong Sphere vulnerability exists that exposes a SSH interface over the product network interface. This does not allow to directly …

Jun 12, 2024
CVE-2024-25949
8.8 HIGH

Dell OS10 Networking Switches, versions10.5.6.x, 10.5.5.x, 10.5.4.x and 10.5.3.x ,contain an improper authorization vulnerability. A remote authenticated attacker could potentially exploit this vulnerability leading to …

Jun 12, 2024
CVE-2024-5211
7.2 HIGH

A path traversal vulnerability in mintplex-labs/anything-llm allowed a manager to bypass the `normalizePath()` function, intended to defend against path traversal attacks. This vulnerability enables the …

Jun 12, 2024
CVE-2024-5056
6.5 MEDIUM

CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may prevent user to update the device firmware and prevent proper behavior of the …

Jun 12, 2024
CVE-2024-5674
6.5 MEDIUM

The Newsletter - API v1 and v2 addon plugin for WordPress is vulnerable to unauthorized subscribers management due to PHP type juggling issue on the …

Jun 12, 2024
CVE-2024-4898
9.8 CRITICAL

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due to a missing authorization checks on …

Jun 12, 2024
CVE-2024-3492
6.4 MEDIUM

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event', 'location', and 'event_category' …

Jun 12, 2024
CVE-2024-1766
4.4 MEDIUM

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.2.86 …

Jun 12, 2024
CVE-2024-4845
8.8 HIGH

The Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘options[list_id]’ parameter in all versions up to, and including, 5.7.22 due to …

Jun 12, 2024
CVE-2024-2092
5.4 MEDIUM

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Twitter Widget in all versions up to, and including, …

Jun 12, 2024
CVE-2023-51524
4.3 MEDIUM

Missing Authorization vulnerability in weForms.This issue affects weForms: from n/a through 1.6.18.

Jun 12, 2024
CVE-2023-51413
5.3 MEDIUM

Missing Authorization vulnerability in Piotnet Forms.This issue affects Piotnet Forms: from n/a through 1.0.29.

Jun 12, 2024
CVE-2023-48280
7.5 HIGH

Missing Authorization vulnerability in Consensu.IO Consensu.Io.This issue affects Consensu.Io: from n/a through 1.0.1.

Jun 12, 2024
CVE-2023-47845
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Lim Kai Yang Grab & Save.This issue affects Grab & Save: from n/a through 1.0.4.

Jun 12, 2024
CVE-2023-47828
4.3 MEDIUM

Missing Authorization vulnerability in Mandrill wpMandrill.This issue affects wpMandrill: from n/a through 1.33.

Jun 12, 2024
CVE-2023-44234
4.3 MEDIUM

Missing Authorization vulnerability in Bastianon Massimo WP GPX Map.This issue affects WP GPX Map: from n/a through 1.7.08.

Jun 12, 2024
CVE-2023-41240
5.3 MEDIUM

Missing Authorization vulnerability in Vark Pricing Deals for WooCommerce.This issue affects Pricing Deals for WooCommerce: from n/a through 2.0.3.2.

Jun 12, 2024
CVE-2023-40672
5.4 MEDIUM

Missing Authorization vulnerability in Hardik Chavada Sticky Social Media Icons.This issue affects Sticky Social Media Icons: from n/a through 2.1.

Jun 12, 2024
CVE-2023-40603
5.3 MEDIUM

Missing Authorization vulnerability in Gangesh Matta Simple Org Chart.This issue affects Simple Org Chart: from n/a through 2.3.4.

Jun 12, 2024
CVE-2023-40209
6.5 MEDIUM

Missing Authorization vulnerability in Himalaya Saxena Highcompress Image Compressor.This issue affects Highcompress Image Compressor: from n/a through 6.0.0.

Jun 12, 2024
CVE-2023-38395
5.4 MEDIUM

Missing Authorization vulnerability in Afzal Multani WP Clone Menu.This issue affects WP Clone Menu: from n/a through 1.0.1.

Jun 12, 2024
CVE-2023-25030
4.3 MEDIUM

Missing Authorization vulnerability in Buy Me a Coffee.This issue affects Buy Me a Coffee: from n/a through 3.7.

Jun 12, 2024
CVE-2024-5742
6.7 MEDIUM

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a …

Jun 12, 2024
CVE-2024-5468
6.5 MEDIUM

The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to unauthorized site option deletion due to a missing validation and capability checks …

Jun 12, 2024
CVE-2024-5266
6.4 MEDIUM

The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpdm_user_dashboard, wpdm_package, wpdm_packages, wpdm_search_result, and wpdm_tag shortcodes in all versions up …

Jun 12, 2024
CVE-2024-5203

Rejected reason: After careful review of CVE-2024-5203, it has been determined that the issue is not exploitable in real-world scenarios. Moreover, the exploit assumes that …

Jun 12, 2024
CVE-2024-5154
8.1 HIGH

A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This …

Jun 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.