CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4812
4.8 MEDIUM

A flaw was found in the Katello plugin for Foreman, where it is possible to store malicious JavaScript code in the "Description" field of a …

Jun 5, 2024
CVE-2024-3716
6.2 MEDIUM

A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue leaks the password in the process list and …

Jun 5, 2024
CVE-2024-36837
7.5 HIGH

SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductController.php file.

Jun 5, 2024
CVE-2024-35673
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Pure Chat by Ruby Pure Chat.This issue affects Pure Chat: from n/a through 2.22.

Jun 5, 2024
CVE-2024-5459
4.3 MEDIUM

The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on 'add_section', 'add_menu', …

Jun 5, 2024
CVE-2024-3469
6.1 MEDIUM

The GP Premium plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the message parameter in all versions up to, and including, 2.4.0 due …

Jun 5, 2024
CVE-2024-5526
7.7 HIGH

Grafana OnCall is an easy-to-use on-call management tool that will help reduce toil in on-call management through simpler workflows and interfaces that are tailored specifically …

Jun 5, 2024
CVE-2024-1662
7.5 HIGH

Missing Authentication for Critical Function, Missing Authorization vulnerability in PORTY Smart Tech Technology Joint Stock Company PowerBank Application allows Retrieve Embedded Sensitive Data.This issue affects …

Jun 5, 2024
CVE-2024-4001
6.4 MEDIUM

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_login_form' shortcode in all versions up to, and including, 3.2.93 …

Jun 5, 2024
CVE-2024-5536
6.4 MEDIUM

The GamiPress – Link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's gamipress_link shortcode in all versions up to, and including, …

Jun 5, 2024
CVE-2024-5571
6.4 MEDIUM

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress …

Jun 5, 2024
CVE-2024-4821
6.4 MEDIUM

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_lightbox shortcode in all versions up …

Jun 5, 2024
CVE-2024-4743
8.8 HIGH

The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to SQL Injection via the orderBy attribute of the lifterlms_favorites shortcode in …

Jun 5, 2024
CVE-2024-1272
7.5 HIGH

Inclusion of Sensitive Information in Source Code vulnerability in TNB Mobile Solutions Cockpit Software allows Retrieve Embedded Sensitive Data.This issue affects Cockpit Software: before v0.251.1.

Jun 5, 2024
CVE-2024-5453
4.3 MEDIUM

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Jun 5, 2024
CVE-2024-5439
6.4 MEDIUM

The Blocksy theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the custom_url parameter in all versions up to, and including, 2.0.50 due to …

Jun 5, 2024
CVE-2024-5006
6.4 MEDIUM

The Boostify Header Footer Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘size’ parameter in all versions up to, …

Jun 5, 2024
CVE-2024-4939
6.4 MEDIUM

The Weaver Xtreme Theme Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's div shortcode in all versions up to, and …

Jun 5, 2024
CVE-2024-23669
6.5 MEDIUM

An improper authorization in Fortinet FortiWebManager version 7.2.0 and 7.0.0 through 7.0.4 and 6.3.0 and 6.2.3 through 6.2.4 and 6.0.2 allows attacker to execute unauthorized …

Jun 5, 2024
CVE-2024-5222
6.4 MEDIUM

The Responsive Addons – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Jun 5, 2024
CVE-2024-4088
4.3 MEDIUM

The Gutenberg Blocks and Page Layouts – Attire Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Jun 5, 2024
CVE-2024-2368
4.3 MEDIUM

The Mollie Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.13. This is due to missing …

Jun 5, 2024
CVE-2024-1164
6.4 MEDIUM

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's contact form widget error message and redirect URL …

Jun 5, 2024
CVE-2024-4886
4.3 MEDIUM

The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in the request

Jun 5, 2024
CVE-2024-4295
9.8 CRITICAL

The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and including, …

Jun 5, 2024
CVE-2024-3667
7.4 HIGH

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' field of multiple widgets in all versions …

Jun 5, 2024
CVE-2024-2087
7.2 HIGH

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form name values in all versions up to, and …

Jun 5, 2024
CVE-2024-1940
7.1 HIGH

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post content in all versions up to, and including, 2.4.41 …

Jun 5, 2024
CVE-2024-1161
6.4 MEDIUM

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Attributes for blocks in all versions up …

Jun 5, 2024
CVE-2024-5149
6.5 MEDIUM

The BuddyForms plugin for WordPress is vulnerable to Email Verification Bypass in all versions up to, and including, 2.8.9 via the use of an insufficiently …

Jun 5, 2024
CVE-2024-34055
6.5 MEDIUM

Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.

Jun 5, 2024
CVE-2024-5262
9.8 CRITICAL

Files or Directories Accessible to External Parties vulnerability in smb server in ProjectDiscovery Interactsh allows remote attackers to read/write any files in the directory and …

Jun 5, 2024
CVE-2024-5483
5.3 MEDIUM

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.8 due to …

Jun 5, 2024
CVE-2024-5317
6.4 MEDIUM

The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'np1' parameter in all versions up to, and including, 8.3.4 due to …

Jun 5, 2024
CVE-2024-5636
6.3 MEDIUM

A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Jun 5, 2024
CVE-2024-4084
7.5 HIGH

A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of mintplex-labs/anything-llm, allowing attackers to bypass the official fix intended to restrict access to …

Jun 5, 2024
CVE-2020-35154

Rejected reason: CVE ID was once reserved, but never used.

Jun 5, 2024
CVE-2020-35153

Rejected reason: CVE ID was once reserved, but never used.

Jun 5, 2024
CVE-2020-27355

Rejected reason: CVE ID was once reserved, but never used.

Jun 5, 2024
CVE-2020-27354

Rejected reason: CVE ID was once reserved, but never used.

Jun 5, 2024
CVE-2020-27353

Rejected reason: CVE ID was once reserved, but never used.

Jun 4, 2024
CVE-2024-5635
6.3 MEDIUM

A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Jun 4, 2024
CVE-2024-36675
9.1 CRITICAL

LyLme_spage v1.9.5 is vulnerable to Server-Side Request Forgery (SSRF) via the get_head function.

Jun 4, 2024
CVE-2024-36121
5.9 MEDIUM

netty-incubator-codec-ohttp is the OHTTP implementation for netty. BoringSSLAEADContext keeps track of how many OHTTP responses have been sent and uses this sequence number to calculate …

Jun 4, 2024
CVE-2024-30889
5.4 MEDIUM

Cross Site Scripting vulnerability in audimex audimexEE v.15.1.2 and fixed in 15.1.3.9 allows a remote attacker to execute arbitrary code via the service, method, widget_type, …

Jun 4, 2024
CVE-2022-28658
5.5 MEDIUM

Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing

Jun 4, 2024
CVE-2022-28657
7.8 HIGH

Apport does not disable python crash handler before entering chroot

Jun 4, 2024
CVE-2022-28656
5.5 MEDIUM

is_closing_session() allows users to consume RAM in the Apport process

Jun 4, 2024
CVE-2022-28655
7.1 HIGH

is_closing_session() allows users to create arbitrary tcp dbus connections

Jun 4, 2024
CVE-2022-28654
5.5 MEDIUM

is_closing_session() allows users to fill up apport.log

Jun 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.