CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-3183
8.1 HIGH

A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for …

Jun 12, 2024
CVE-2023-52177
5.4 MEDIUM

Missing Authorization vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.3.

Jun 12, 2024
CVE-2023-52117
4.3 MEDIUM

Missing Authorization vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid: from n/a through 5.6.6.

Jun 12, 2024
CVE-2023-51680
4.3 MEDIUM

Missing Authorization vulnerability in TechnoVama Quotes for WooCommerce.This issue affects Quotes for WooCommerce: from n/a through 2.0.1.

Jun 12, 2024
CVE-2023-51679
5.4 MEDIUM

Missing Authorization vulnerability in BulkGate BulkGate SMS Plugin for WooCommerce.This issue affects BulkGate SMS Plugin for WooCommerce: from n/a through 3.0.2.

Jun 12, 2024
CVE-2023-51671
5.4 MEDIUM

Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.

Jun 12, 2024
CVE-2023-51670
4.3 MEDIUM

Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.

Jun 12, 2024
CVE-2023-51537
5.3 MEDIUM

Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.5.

Jun 12, 2024
CVE-2023-51526
4.3 MEDIUM

Missing Authorization vulnerability in Brett Shumaker Simple Staff List.This issue affects Simple Staff List: from n/a through 2.2.4.

Jun 12, 2024
CVE-2024-5873

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 12, 2024
CVE-2024-5783

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 12, 2024
CVE-2024-5782

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 12, 2024
CVE-2024-5781

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 12, 2024
CVE-2024-5780

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 12, 2024
CVE-2024-5779

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 12, 2024
CVE-2024-5778

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 12, 2024
CVE-2024-5777

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 12, 2024
CVE-2024-5776

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 12, 2024
CVE-2024-3925
6.4 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jun 12, 2024
CVE-2024-2698
8.8 HIGH

A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition for granting the "forwardable" flag …

Jun 12, 2024
CVE-2024-5739
6.1 MEDIUM

The in-app browser of LINE client for iOS versions below 14.9.0 contains a Universal XSS (UXSS) vulnerability. This vulnerability allows for cross-site scripting (XSS) where …

Jun 12, 2024
CVE-2024-28970
4.7 MEDIUM

Dell Client BIOS contains an Out-of-bounds Write vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to platform denial …

Jun 12, 2024
CVE-2024-0160
6.8 MEDIUM

Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by bypassing BIOS authorization …

Jun 12, 2024
CVE-2024-5892
6.4 MEDIUM

The Divi Torque Lite – Divi Theme and Extra Theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘support_unfiltered_files_upload’ function in all …

Jun 12, 2024
CVE-2024-4924
6.1 MEDIUM

The Social Sharing Plugin WordPress plugin before 3.3.63 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jun 12, 2024
CVE-2024-36454
5.3 MEDIUM

Use of uninitialized resource issue exists in IPCOM EX2 Series (V01L0x Series) V01L07NF0201 and earlier, and IPCOM VE2 Series V01L07NF0201 and earlier. If this vulnerability …

Jun 12, 2024
CVE-2024-0427
6.3 MEDIUM

The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.4.1 does not properly escape user-controlled input when it is reflected in some of …

Jun 12, 2024
CVE-2024-3559
6.4 MEDIUM

The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_content]' parameter versions up to, and including, 2.6.7 due …

Jun 12, 2024
CVE-2024-5553
4.4 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via several parameters in all versions up to, and including, …

Jun 12, 2024
CVE-2024-4564
6.4 MEDIUM

The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Jun 12, 2024
CVE-2024-36856
7.5 HIGH

RMQTT Broker 0.4.0 is vulnerable to Denial of Service (DoS) due to improper session resource management. An attacker can exhaust system memory and crash the …

Jun 12, 2024
CVE-2024-5543
8.1 HIGH

The Slideshow Gallery LITE plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all versions up to, and including, 1.8.1 …

Jun 12, 2024
CVE-2024-4892
6.4 MEDIUM

The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ parameter in versions up to, and including, 12.4.1 due to insufficient …

Jun 12, 2024
CVE-2024-4315
9.1 CRITICAL

parisneo/lollms version 9.5 is vulnerable to Local File Inclusion (LFI) attacks due to insufficient path sanitization. The `sanitize_path_from_endpoint` function fails to properly sanitize Windows-style paths …

Jun 12, 2024
CVE-2024-36103
6.8 MEDIUM

OS command injection vulnerability in WRC-X5400GS-B v1.0.10 and earlier, and WRC-X5400GSA-B v1.0.10 and earlier allows a network-adjacent attacker with an administrative privilege to execute arbitrary …

Jun 12, 2024
CVE-2024-35225
9.6 CRITICAL

Jupyter Server Proxy allows users to run arbitrary external processes alongside their notebook server and provide authenticated web access to them. Versions of 3.x prior …

Jun 11, 2024
CVE-2024-5847
8.8 HIGH

Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. …

Jun 11, 2024
CVE-2024-5846
8.8 HIGH

Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. …

Jun 11, 2024
CVE-2024-5845
8.8 HIGH

Use after free in Audio in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. …

Jun 11, 2024
CVE-2024-5844
8.8 HIGH

Heap buffer overflow in Tab Strip in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memory read via …

Jun 11, 2024
CVE-2024-5843
6.5 MEDIUM

Inappropriate implementation in Downloads in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to obfuscate security UI via a malicious file. (Chromium security severity: …

Jun 11, 2024
CVE-2024-5842
8.8 HIGH

Use after free in Browser UI in Google Chrome prior to 126.0.6478.54 allowed a remote attacker who convinced a user to engage in specific UI …

Jun 11, 2024
CVE-2024-5841
8.8 HIGH

Use after free in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jun 11, 2024
CVE-2024-5840
6.5 MEDIUM

Policy bypass in CORS in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium …

Jun 11, 2024
CVE-2024-5839
6.5 MEDIUM

Inappropriate Implementation in Memory Allocator in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jun 11, 2024
CVE-2024-5838
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform out of bounds memory access via a crafted HTML …

Jun 11, 2024
CVE-2024-5837
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted …

Jun 11, 2024
CVE-2024-5836
8.8 HIGH

Inappropriate Implementation in DevTools in Google Chrome prior to 126.0.6478.54 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary …

Jun 11, 2024
CVE-2024-5835
8.8 HIGH

Heap buffer overflow in Tab Groups in Google Chrome prior to 126.0.6478.54 allowed a remote attacker who convinced a user to engage in specific UI …

Jun 11, 2024
CVE-2024-5834
8.8 HIGH

Inappropriate implementation in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security …

Jun 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.