CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-49224
8.0 HIGH

Precor touchscreen console P62, P80, and P82 contains a default SSH public key in the authorized_keys file. A remote attacker could use this key to …

Jun 7, 2024
CVE-2023-49223
8.8 HIGH

Precor touchscreen console P62, P80, and P82 could allow a remote attacker to obtain sensitive information because the root password is stored in /etc/passwd. An …

Jun 7, 2024
CVE-2023-49222
8.8 HIGH

Precor touchscreen console P82 contains a private SSH key that corresponds to a default public key. A remote attacker could exploit this to gain root …

Jun 7, 2024
CVE-2023-49221
7.8 HIGH

Precor touchscreen console P62, P80, and P82 could allow a remote attacker (within the local network) to bypass security restrictions, and access the service menu, …

Jun 7, 2024
CVE-2024-3133

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 7, 2024
CVE-2024-37388
9.1 CRITICAL

An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of lxml before v4.9.1 allows attackers to access sensitive information or cause a Denial of …

Jun 7, 2024
CVE-2024-36827
7.5 HIGH

An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of ebookmeta before v1.2.8 allows attackers to access sensitive information or cause a Denial of …

Jun 7, 2024
CVE-2024-36811

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-37295. Reason: This candidate is a reservation duplicate of CVE-2024-37295. Notes: All CVE users should reference …

Jun 7, 2024
CVE-2024-23595

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 7, 2024
CVE-2023-6997

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 7, 2024
CVE-2024-5745
7.3 HIGH

A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Jun 7, 2024
CVE-2024-4152

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 7, 2024
CVE-2024-3380

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 7, 2024
CVE-2024-37163
6.4 MEDIUM

SkyScrape is a GUI Dashboard for AWS Infrastructure and Managing Resources and Usage Costs. SkyScrape's API requests are currently unsecured HTTP requests, leading to potential …

Jun 7, 2024
CVE-2024-32502
8.4 HIGH

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, …

Jun 7, 2024
CVE-2024-31959
8.4 HIGH

An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the validation of native handles, which …

Jun 7, 2024
CVE-2024-31958
6.8 MEDIUM

An issue was discovered in Samsung Mobile Processor EExynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the validation of native handles, which …

Jun 7, 2024
CVE-2024-30163
9.8 CRITICAL

Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\_store::_categoryView() method, where user input passed through the filter request parameter is not properly sanitized …

Jun 7, 2024
CVE-2024-30162
7.2 HIGH

Invision Community through 4.7.16 allows remote code execution via the applications/core/modules/admin/editor/toolbar.php IPS\core\modules\admin\editor\_toolbar::addPlugin() method. This method handles uploaded ZIP files that are extracted into the applications/core/interface/ckeditor/ckeditor/plugins/ …

Jun 7, 2024
CVE-2024-32503
8.4 HIGH

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, …

Jun 7, 2024
CVE-2024-37162
4.0 MEDIUM

zsa is a library for building typesafe server actions in Next.js. All users are impacted. The zsa application transfers the parse error stack from the …

Jun 7, 2024
CVE-2024-36792
8.2 HIGH

An issue in the implementation of the WPS in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to gain access to the router's pin.

Jun 7, 2024
CVE-2024-36790
8.8 HIGH

Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 was discovered to store credentials in plaintext.

Jun 7, 2024
CVE-2024-36789
8.1 HIGH

An issue in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to create passwords that do not conform to defined security standards.

Jun 7, 2024
CVE-2024-36788
4.8 MEDIUM

Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 does not properly set the HTTPOnly flag for cookies. This allows attackers to possibly intercept and access sensitive communications between the …

Jun 7, 2024
CVE-2024-36787
8.8 HIGH

An issue in Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 allows attackers to bypass authentication and access the administrative interface via unspecified vectors.

Jun 7, 2024
CVE-2024-36773
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

Jun 7, 2024
CVE-2024-37160
4.8 MEDIUM

Formwork is a flat file-based Content Management System (CMS). An attackers (requires administrator privilege) to execute arbitrary web scripts by modifying site options via /panel/options/site. …

Jun 7, 2024
CVE-2024-31878
5.3 MEDIUM

IBM i 7.2, 7.3, 7.4, and 7.5 Service Tools Server (SST) is vulnerable to SST user enumeration by a remote attacker. This vulnerability can be …

Jun 7, 2024
CVE-2024-5599
7.5 HIGH

The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.7 …

Jun 7, 2024
CVE-2024-5542
7.2 HIGH

The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Navigation …

Jun 7, 2024
CVE-2024-5438
4.3 MEDIUM

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and …

Jun 7, 2024
CVE-2024-5382
6.5 MEDIUM

The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to …

Jun 7, 2024
CVE-2024-36673
9.8 CRITICAL

Sourcecodester Pharmacy/Medical Store Point of Sale System 1.0 is vulnerable SQL Injection via login.php. This vulnerability stems from inadequate validation of user inputs for the …

Jun 7, 2024
CVE-2024-5734
6.3 MEDIUM

A vulnerability classified as critical has been found in itsourcecode Online Discussion Forum 1.0. Affected is an unknown function of the file /members/poster.php. The manipulation …

Jun 7, 2024
CVE-2024-5733
7.3 HIGH

A vulnerability was found in itsourcecode Online Discussion Forum 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Jun 7, 2024
CVE-2024-4610
7.8 HIGH KEV

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper …

Jun 7, 2024
CVE-2024-5637
7.5 HIGH

The Market Exporter plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'remove_files' function in all …

Jun 7, 2024
CVE-2024-5732
7.3 HIGH

A vulnerability was found in Clash up to 0.20.1 on Windows. It has been declared as critical. This vulnerability affects unknown code of the component …

Jun 7, 2024
CVE-2024-5645
6.4 MEDIUM

The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_css_id’ parameter within the Button widget in all versions up to, …

Jun 7, 2024
CVE-2024-5481
6.8 MEDIUM

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.8.23 …

Jun 7, 2024
CVE-2024-5426
6.4 MEDIUM

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘svg’ parameter in all versions …

Jun 7, 2024
CVE-2023-5424
4.7 MEDIUM

The WS Form LITE plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.9.217. This allows unauthenticated attackers to embed …

Jun 7, 2024
CVE-2024-4703
6.4 MEDIUM

The One Page Express Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's one_page_express_contact_form shortcode in all versions up to, and …

Jun 7, 2024
CVE-2024-4489
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_upload_mimes’ function in versions up to, and including, …

Jun 7, 2024
CVE-2024-4488
6.4 MEDIUM

The Royal Elementor Addons and Templates for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘inline_list’ parameter in versions up to, and including, 1.3.976 …

Jun 7, 2024
CVE-2024-4451
6.4 MEDIUM

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_video_player shortcode in all versions up to, and including, …

Jun 7, 2024
CVE-2024-5003
5.4 MEDIUM

The WP Stacker WordPress plugin through 1.8.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Jun 7, 2024
CVE-2024-4756
5.4 MEDIUM

The WP Backpack WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jun 7, 2024
CVE-2024-4621
4.8 MEDIUM

The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 does not sanitise and escape some of its settings, which could allow high …

Jun 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.