CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-35667
5.3 MEDIUM

Missing Authorization vulnerability in WP EasyCart.This issue affects WP EasyCart: from n/a through 5.5.19.

Jun 11, 2024
CVE-2024-35665
5.3 MEDIUM

Missing Authorization vulnerability in namithjawahar Insert Post Ads.This issue affects Insert Post Ads: from n/a through 1.3.2.

Jun 11, 2024
CVE-2024-35663
5.4 MEDIUM

Missing Authorization vulnerability in HahnCreativeGroup WP Translate.This issue affects WP Translate: from n/a through 5.3.0.

Jun 11, 2024
CVE-2024-35628
4.3 MEDIUM

Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web.This issue affects Photo Gallery by 10Web: from n/a through 1.8.25.

Jun 11, 2024
CVE-2024-35235
4.4 MEDIUM

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server …

Jun 11, 2024
CVE-2024-35168
4.3 MEDIUM

Missing Authorization vulnerability in Discourse WP Discourse.This issue affects WP Discourse: from n/a through 2.5.1.

Jun 11, 2024
CVE-2024-34826
6.3 MEDIUM

Missing Authorization vulnerability in Saleswonder Team: Tobias CF7 WOW Styler cf7-styler.This issue affects CF7 WOW Styler: from n/a through <= 1.6.4.

Jun 11, 2024
CVE-2024-34820
6.5 MEDIUM

Missing Authorization vulnerability in If So Plugin If-So Dynamic Content Personalization.This issue affects If-So Dynamic Content Personalization: from n/a through 1.7.1.

Jun 11, 2024
CVE-2024-32148
4.3 MEDIUM

Missing Authorization vulnerability in Salesforce Pardot.This issue affects Pardot: from n/a through 2.1.0.

Jun 11, 2024
CVE-2024-31495
4.3 MEDIUM

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.0.0 through 7.0.6 and version 7.2.0 allows privileged …

Jun 11, 2024
CVE-2024-26010
7.5 HIGH

A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiWeb, FortiAuthenticator, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.1 through 7.0.3, …

Jun 11, 2024
CVE-2024-24703
8.6 HIGH

Missing Authorization vulnerability in MultiVendorX WC Marketplace.This issue affects WC Marketplace: from n/a through 4.0.25.

Jun 11, 2024
CVE-2024-23111
6.8 MEDIUM

An improper neutralization of input during web page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions …

Jun 11, 2024
CVE-2024-23110
7.8 HIGH

A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0 all …

Jun 11, 2024
CVE-2024-21754
1.8 LOW

A use of password hash with insufficient computational effort vulnerability [CWE-916] affecting FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 6.4 all …

Jun 11, 2024
CVE-2023-52199
6.5 MEDIUM

Missing Authorization vulnerability in Matthias Pfefferle & Automattic ActivityPub.This issue affects ActivityPub: from n/a through 1.0.5.

Jun 11, 2024
CVE-2023-51498
5.3 MEDIUM

Missing Authorization vulnerability in Woo WooCommerce Canada Post Shipping.This issue affects WooCommerce Canada Post Shipping: from n/a through 2.8.3.

Jun 11, 2024
CVE-2023-46720
6.7 MEDIUM

A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.12 and 6.4.6 through 6.4.15 and 6.2.9 …

Jun 11, 2024
CVE-2023-23775
6.5 MEDIUM

Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerabilities [CWE-89] in FortiSOAR 7.2.0 and before 7.0.3 may allow an authenticated attacker …

Jun 11, 2024
CVE-2024-5189
6.4 MEDIUM

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Jun 11, 2024
CVE-2024-35683
5.3 MEDIUM

Missing Authorization vulnerability in Teplitsa of social technologies Leyka.This issue affects Leyka: from n/a through 3.31.1.

Jun 11, 2024
CVE-2024-35671
4.3 MEDIUM

Missing Authorization vulnerability in Minoji MJ Update History.This issue affects MJ Update History: from n/a through 1.0.4.

Jun 11, 2024
CVE-2024-34442
5.3 MEDIUM

Missing Authorization vulnerability in weDevs weDocs.This issue affects weDocs: from n/a through 2.1.4.

Jun 11, 2024
CVE-2024-2013
10.0 CRITICAL

An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited allows attackers without any access to interact with the …

Jun 11, 2024
CVE-2024-2012
9.1 CRITICAL

vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow unintended commands or code to be executed …

Jun 11, 2024
CVE-2024-2011
8.6 HIGH

A heap-based buffer overflow vulnerability exists in the FOXMAN-UN/UNEM that if exploited will generally lead to a denial of service but can be used to …

Jun 11, 2024
CVE-2024-28023
5.7 MEDIUM

A vulnerability exists in the message queueing mechanism that if exploited can lead to the exposure of resources or functionality to unintended actors, possibly providing …

Jun 11, 2024
CVE-2024-28021
7.4 HIGH

A vulnerability exists in the FOXMAN-UN/UNEM server that affects the message queueing mechanism’s certificate validation. If exploited an attacker could spoof a trusted entity causing …

Jun 11, 2024
CVE-2023-52183
5.4 MEDIUM

Missing Authorization vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migration: from n/a through 1.4.3.

Jun 11, 2024
CVE-2024-5702
7.5 HIGH

Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects Firefox < 125, Firefox ESR < 115.12, and …

Jun 11, 2024
CVE-2024-5701
9.8 CRITICAL

Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of …

Jun 11, 2024
CVE-2024-5700
7.0 HIGH

Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruption and we presume …

Jun 11, 2024
CVE-2024-5699
9.8 CRITICAL

In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be checked …

Jun 11, 2024
CVE-2024-5698
6.1 MEDIUM

By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This could have led …

Jun 11, 2024
CVE-2024-5697
4.3 MEDIUM

A website was able to detect when a user took a screenshot of a page using the built-in Screenshot functionality in Firefox. This vulnerability affects …

Jun 11, 2024
CVE-2024-5696
8.6 HIGH

By manipulating the text in an `&lt;input&gt;` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox …

Jun 11, 2024
CVE-2024-5695
9.8 CRITICAL

If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered, and in rarer …

Jun 11, 2024
CVE-2024-5694
7.5 HIGH

An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section of the heap. This vulnerability affects …

Jun 11, 2024
CVE-2024-5693
6.1 MEDIUM

Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. This …

Jun 11, 2024
CVE-2024-5692
6.5 MEDIUM

On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such …

Jun 11, 2024
CVE-2024-5691
4.7 MEDIUM

By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions …

Jun 11, 2024
CVE-2024-5690
4.3 MEDIUM

By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects …

Jun 11, 2024
CVE-2024-5689
4.3 MEDIUM

In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button that appeared, and …

Jun 11, 2024
CVE-2024-5688
8.1 HIGH

If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Firefox < 127, Firefox …

Jun 11, 2024
CVE-2024-5687
5.3 MEDIUM

If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. …

Jun 11, 2024
CVE-2024-2462

Allow attackers to intercept or falsify data exchanges between the client and the server

Jun 11, 2024
CVE-2024-2461

If exploited an attacker could traverse the file system to access files or directories that would otherwise be inaccessible

Jun 11, 2024
CVE-2024-36266
9.3 CRITICAL

A vulnerability has been identified in PowerSys (All versions < V3.11). The affected application insufficiently protects responses to authentication requests. This could allow a local …

Jun 11, 2024
CVE-2024-35303
7.8 HIGH

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0012), Tecnomatix Plant Simulation V2404 (All versions < V2404.0001). The affected applications …

Jun 11, 2024
CVE-2024-35292
8.2 HIGH

A vulnerability has been identified in SIMATIC S7-200 SMART CPU CR40 (6ES7288-1CR40-0AA0) (All versions), SIMATIC S7-200 SMART CPU CR60 (6ES7288-1CR60-0AA0) (All versions), SIMATIC S7-200 SMART …

Jun 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.