CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4620
9.8 CRITICAL

The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 allows unauthenticated users to modify uploaded files in such a way that PHP …

Jun 7, 2024
CVE-2024-4354
6.4 MEDIUM

The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.3 …

Jun 7, 2024
CVE-2024-4042
6.4 MEDIUM

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Jun 7, 2024
CVE-2024-3592
9.9 CRITICAL

The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'question_id' …

Jun 7, 2024
CVE-2024-3288
5.4 MEDIUM

The Logo Slider WordPress plugin before 4.0.0 does not validate and escape some of its Slider Settings before outputting them back in attributes, which could …

Jun 7, 2024
CVE-2023-6491
4.3 MEDIUM

The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the wpmtst_save_view_sticky function in all …

Jun 7, 2024
CVE-2024-5640
6.4 MEDIUM

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jun 7, 2024
CVE-2024-5612
6.4 MEDIUM

The Essential Addons for Elementor Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eael_lightbox_open_btn_icon’ parameter within the Lightbox & Modal widget …

Jun 7, 2024
CVE-2024-4902
7.2 HIGH

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the ‘course_id’ parameter in all versions …

Jun 7, 2024
CVE-2024-5425
6.4 MEDIUM

The WP jQuery Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ attribute in all versions up to, and including, 1.5.4 …

Jun 7, 2024
CVE-2024-4887
7.5 HIGH

The Qi Addons For Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7.2 via the 'behavior' …

Jun 7, 2024
CVE-2024-37385
9.8 CRITICAL

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete …

Jun 7, 2024
CVE-2024-37384
6.1 MEDIUM

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.

Jun 7, 2024
CVE-2024-37383
6.1 MEDIUM KEV

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

Jun 7, 2024
CVE-2024-36082
6.5 MEDIUM

SQL injection vulnerability in Music Store - WordPress eCommerce versions prior to 1.1.14 allows a remote authenticated attacker with an administrative privilege to execute arbitrary …

Jun 7, 2024
CVE-2024-1988
6.4 MEDIUM

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Jun 7, 2024
CVE-2024-5607
5.4 MEDIUM

The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Jun 7, 2024
CVE-2024-3987
5.4 MEDIUM

The WP Mobile Menu – The Mobile-Friendly Responsive Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt text in all versions …

Jun 7, 2024
CVE-2024-1768
6.4 MEDIUM

The Clever Fox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's info box block in all versions up to, and including, …

Jun 7, 2024
CVE-2023-32475
7.6 HIGH

Dell BIOS contains a missing support for integrity check vulnerability. An attacker with physical access to the system could potentially bypass security mechanisms to run …

Jun 7, 2024
CVE-2024-1689
4.3 MEDIUM

The WooCommerce Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the woocommerce_tool_toggle_module() function in all …

Jun 7, 2024
CVE-2023-6876
5.4 MEDIUM

The Clever Fox – One Click Website Importer by Nayra Themes plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Jun 7, 2024
CVE-2022-4968
6.5 MEDIUM

netplan leaks the private key of wireguard to local users. Versions after 1.0 are not affected.

Jun 7, 2024
CVE-2023-37539
8.4 HIGH

The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. An attacker with the ability to edit documents in the catalog application/database …

Jun 6, 2024
CVE-2024-4013
5.6 MEDIUM

A bug exists in the API, mesh_node_power_off(), which fails to copy the contents of the Replay Protection List (RPL) from RAM to NVM before powering …

Jun 6, 2024
CVE-2024-36823
7.5 HIGH

The encrypt() function of Ninja Core v7.0.0 was discovered to use a weak cryptographic algorithm, leading to a possible leakage of sensitive information.

Jun 6, 2024
CVE-2024-36775
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

Jun 6, 2024
CVE-2024-36774
7.2 HIGH

An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.

Jun 6, 2024
CVE-2024-24199
7.5 HIGH

smartdns commit 54b4dc was discovered to contain a misaligned address at smartdns/src/dns.c.

Jun 6, 2024
CVE-2024-24198
7.5 HIGH

smartdns commit 54b4dc was discovered to contain a misaligned address at smartdns/src/util.c.

Jun 6, 2024
CVE-2024-24195
7.5 HIGH

robdns commit d76d2e6 was discovered to contain a misaligned address at /src/zonefile-insertion.c.

Jun 6, 2024
CVE-2024-24194
7.5 HIGH

robdns commit d76d2e6 was discovered to contain a NULL pointer dereference via the item->tokens component at /src/conf-parse.c.

Jun 6, 2024
CVE-2024-24192
9.1 CRITICAL

robdns commit d76d2e6 was discovered to contain a heap overflow via the component block->filename at /src/zonefile-insertion.c.

Jun 6, 2024
CVE-2024-22525
5.5 MEDIUM

dnspod-sr 0dfbd37 contains a SEGV.

Jun 6, 2024
CVE-2024-22524
5.5 MEDIUM

dnspod-sr 0dfbd37 is vulnerable to buffer overflow.

Jun 6, 2024
CVE-2023-51847
7.5 HIGH

An issue in obgm and Libcoap v.a3ed466 allows a remote attacker to cause a denial of service via thecoap_context_t function in the src/coap_threadsafe.c:297:3 component.

Jun 6, 2024
CVE-2023-49441
7.5 HIGH

dnsmasq 2.9 is vulnerable to Integer Overflow via forward_query.

Jun 6, 2024
CVE-2024-36795
4.0 MEDIUM

Insecure permissions in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to access URLs and directories embedded within the firmware via unspecified vectors.

Jun 6, 2024
CVE-2024-32752
9.1 CRITICAL

The iSTAR door controllers running firmware prior to version 6.6.B, does not support authenticated communications with ICU, which may allow an attacker to gain unauthorized …

Jun 6, 2024
CVE-2024-22074
9.8 CRITICAL

Dynamsoft Service 1.8.1025 through 1.8.2013, 1.7.0330 through 1.7.2531, 1.6.0428 through 1.6.1112, 1.5.0625 through 1.5.3116, 1.4.0618 through 1.4.1230, and 1.0.516 through 1.3.0115 has Incorrect Access Control. …

Jun 6, 2024
CVE-2024-5552
7.5 HIGH

kubeflow/kubeflow is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to inefficient regular expression complexity in its email validation mechanism. An attacker …

Jun 6, 2024
CVE-2024-5550
5.3 MEDIUM

In h2oai/h2o-3 version 3.40.0.4, an exposure of sensitive information vulnerability exists due to an arbitrary system path lookup feature. This vulnerability allows any remote user …

Jun 6, 2024
CVE-2024-5480

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 6, 2024
CVE-2024-5478
6.1 MEDIUM

A Cross-site Scripting (XSS) vulnerability exists in the SAML metadata endpoint `/auth/saml/${org?.id}/metadata` of lunary-ai/lunary version 1.2.7. The vulnerability arises due to the application's failure to …

Jun 6, 2024
CVE-2024-5328
9.3 CRITICAL

A Server-Side Request Forgery (SSRF) vulnerability exists in the lunary-ai/lunary application, specifically within the endpoint '/auth/saml/tto/download-idp-xml'. The vulnerability arises due to the application's failure to …

Jun 6, 2024
CVE-2024-5307
3.3 LOW

Kofax Power PDF AcroForm Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Kofax Power …

Jun 6, 2024
CVE-2024-5306
7.8 HIGH

Kofax Power PDF PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jun 6, 2024
CVE-2024-5305
7.8 HIGH

Kofax Power PDF PDF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations …

Jun 6, 2024
CVE-2024-5304
7.8 HIGH

Kofax Power PDF TGA File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jun 6, 2024
CVE-2024-5278
6.1 MEDIUM

gaizhenbiao/chuanhuchatgpt is vulnerable to an unrestricted file upload vulnerability due to insufficient validation of uploaded file types in its `/upload` endpoint. Specifically, the `handle_file_upload` function …

Jun 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.