CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-36674
6.1 MEDIUM

LyLme_spage v1.9.5 is vulnerable to Cross Site Scripting (XSS) via admin/link.php.

Jun 3, 2024
CVE-2024-32983
8.2 HIGH

Misskey is an open source, decentralized microblogging platform. Misskey doesn't perform proper normalization on the JSON structures of incoming signed ActivityPub activity objects before processing …

Jun 3, 2024
CVE-2024-36128
7.5 HIGH

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.2, providing a non-numeric length value to the random string …

Jun 3, 2024
CVE-2024-36127
7.5 HIGH

apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in log output. This vulnerability is fixed …

Jun 3, 2024
CVE-2024-36124
5.3 MEDIUM

iq80 Snappy is a compression/decompression library. When uncompressing certain data, Snappy tries to read outside the bounds of the given byte arrays. Because Snappy uses …

Jun 3, 2024
CVE-2024-36123
6.5 MEDIUM

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The page `MediaWiki:Tagline` has its contents used unescaped, so custom HTML (including …

Jun 3, 2024
CVE-2024-5197
9.1 CRITICAL

There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may …

Jun 3, 2024
CVE-2024-36729
6.3 MEDIUM

TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by …

Jun 3, 2024
CVE-2024-36728
8.1 HIGH

TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by …

Jun 3, 2024
CVE-2024-36569
8.1 HIGH

Sourcecodester Gas Agency Management System v1.0 is vulnerable to arbitrary code execution via editClientImage.php.

Jun 3, 2024
CVE-2024-36568
9.8 CRITICAL

Sourcecodester Gas Agency Management System v1.0 is vulnerable to SQL Injection via /gasmark/editbrand.php?id=.

Jun 3, 2024
CVE-2024-0336

Missing Authentication for Critical Function vulnerability in EMTA Grup PDKS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PDKS: from V3.04 before 20240603. …

Jun 3, 2024
CVE-2024-35632
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks. Integration for Contact Form 7 and Constant Contact.This issue affects Integration for Contact Form 7 and Constant …

Jun 3, 2024
CVE-2024-34770
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Popup Maker Popup Maker WP popup-maker-wp allows Stored XSS.This issue affects Popup Maker …

Jun 3, 2024
CVE-2024-34769
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in cyclonetheme Elegant Blocks allows Stored XSS.This issue affects Elegant Blocks: from …

Jun 3, 2024
CVE-2024-34767
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HasThemes ShopLentor allows Stored XSS.This issue affects ShopLentor: from n/a through …

Jun 3, 2024
CVE-2024-34766
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic ChaosTheory allows Stored XSS.This issue affects ChaosTheory: from n/a through …

Jun 3, 2024
CVE-2024-34764

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Collision with another CVE ID.

Jun 3, 2024
CVE-2024-34385
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YITHEMES YITH WooCommerce Wishlist yith-woocommerce-wishlist.This issue affects YITH WooCommerce Wishlist: from n/a through …

Jun 3, 2024
CVE-2024-35631
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Foliovision FV Flowplayer Video Player allows Reflected XSS.This issue affects FV …

Jun 3, 2024
CVE-2024-35630
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LJ Apps WP TripAdvisor Review Slider allows Blind SQL Injection.This issue …

Jun 3, 2024
CVE-2024-34803
4.3 MEDIUM

Missing Authorization vulnerability in Fastly.This issue affects Fastly: from n/a through 1.2.25.

Jun 3, 2024
CVE-2024-34801
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mervin Praison Praison SEO WordPress seo-wordpress allows DOM-Based XSS.This issue affects Praison SEO …

Jun 3, 2024
CVE-2024-34798
5.3 MEDIUM

Insertion of Sensitive Information into Log File vulnerability in Lukman Nakib Debug Log – Manger Tool.This issue affects Debug Log – Manger Tool: from n/a …

Jun 3, 2024
CVE-2024-34797
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Benoit Mercusot Simple Popup Manager allows Stored XSS.This issue affects Simple …

Jun 3, 2024
CVE-2024-34796
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AccessAlly PopupAlly allows Stored XSS.This issue affects PopupAlly: from n/a through …

Jun 3, 2024
CVE-2024-34795
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tainacan Tainacan tainacan.This issue affects Tainacan: from n/a through <= 0.21.3.

Jun 3, 2024
CVE-2024-34794
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tainacan Tainacan tainacan.This issue affects Tainacan: from n/a through <= 0.21.3.

Jun 3, 2024
CVE-2024-34793
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kharim Tomlinson WP Next Post Navi allows Stored XSS.This issue affects …

Jun 3, 2024
CVE-2024-34791
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in wpbean WPB Elementor Addons allows Stored XSS.This issue affects WPB Elementor …

Jun 3, 2024
CVE-2024-34790
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hans van Eijsden,niwreg ImageMagick Sharpen Resized Images allows Stored XSS.This issue …

Jun 3, 2024
CVE-2024-34789
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Hait Post Grid Elementor Addon allows Stored XSS.This issue affects …

Jun 3, 2024
CVE-2024-34754
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A WP Life Contact Form Widget.This issue affects Contact Form Widget: from n/a through 1.3.9.

Jun 3, 2024
CVE-2024-3829
9.1 CRITICAL

qdrant/qdrant version 1.9.0-dev is vulnerable to arbitrary file read and write during the snapshot recovery process. Attackers can exploit this vulnerability by manipulating snapshot files …

Jun 3, 2024
CVE-2024-35635
4.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through 5.0.9.

Jun 3, 2024
CVE-2024-35633
4.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Creative Themes Blocksy Companion blocksy-companion.This issue affects Blocksy Companion: from n/a through <= 2.0.42.

Jun 3, 2024
CVE-2024-23670
7.8 HIGH

An improper authorization in Fortinet FortiWebManager version 7.2.0 and 7.0.0 through 7.0.4 and 6.3.0 and 6.2.3 through 6.2.4 and 6.0.2 allows attacker to execute unauthorized …

Jun 3, 2024
CVE-2024-23668
8.8 HIGH

An improper authorization in Fortinet FortiWebManager version 7.2.0 and 7.0.0 through 7.0.4 and 6.3.0 and 6.2.3 through 6.2.4 and 6.0.2 allows attacker to execute unauthorized …

Jun 3, 2024
CVE-2024-23667
7.8 HIGH

An improper authorization in Fortinet FortiWebManager version 7.2.0 and 7.0.0 through 7.0.4 and 6.3.0 and 6.2.3 through 6.2.4 and 6.0.2 allows attacker to execute unauthorized …

Jun 3, 2024
CVE-2024-23665
5.9 MEDIUM

Multiple improper authorization vulnerabilities [CWE-285] in FortiWeb version 7.4.2 and below, version 7.2.7 and below, version 7.0.10 and below, version 6.4.3 and below, version 6.3.23 …

Jun 3, 2024
CVE-2024-23664
6.1 MEDIUM

A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker …

Jun 3, 2024
CVE-2024-23363
7.5 HIGH

Transient DOS while processing an improperly formatted Fine Time Measurement (FTM) management frame.

Jun 3, 2024
CVE-2024-23360
8.4 HIGH

Memory corruption while creating a LPAC client as LPAC engine was allowed to access GPU registers.

Jun 3, 2024
CVE-2024-21478
6.2 MEDIUM

transient DOS when setting up a fence callback to free a KGSL memory entry object during DMA.

Jun 3, 2024
CVE-2023-43556
9.3 CRITICAL

Memory corruption in Hypervisor when platform information mentioned is not aligned.

Jun 3, 2024
CVE-2023-43555
8.2 HIGH

Information disclosure in Video while parsing mp2 clip with invalid section length.

Jun 3, 2024
CVE-2023-43551
9.1 CRITICAL

Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.

Jun 3, 2024
CVE-2023-43545
6.7 MEDIUM

Memory corruption when more scan frequency list or channels are sent from the user space.

Jun 3, 2024
CVE-2023-43544
6.7 MEDIUM

Memory corruption when IPC callback handle is used after it has been released during register callback by another thread.

Jun 3, 2024
CVE-2023-43543
6.7 MEDIUM

Memory corruption in Audio during a playback or a recording due to race condition between allocation and deallocation of graph object.

Jun 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.