CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4148
7.5 HIGH

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary application, version 1.2.10. An attacker can exploit this vulnerability by maliciously manipulating regular …

Jun 1, 2024
CVE-2024-5348
8.8 HIGH

The Elements For Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.1 via the 'beforeafter_layout' attribute …

Jun 1, 2024
CVE-2024-3821
7.3 HIGH

The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability …

Jun 1, 2024
CVE-2024-3820
10.0 CRITICAL

The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to SQL Injection via the 'id_key' parameter of …

Jun 1, 2024
CVE-2024-3200
9.9 CRITICAL

The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'slug' attribute of the 'wpforo' shortcode in all versions up to, and …

Jun 1, 2024
CVE-2024-35636
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Uploadcare Uploadcare File Uploader and Adaptive Delivery (beta) uploadcare.This issue affects Uploadcare File Uploader and Adaptive Delivery (beta): from …

Jun 1, 2024
CVE-2024-4958
7.1 HIGH

The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due …

Jun 1, 2024
CVE-2024-2295
6.4 MEDIUM

The Contact Form Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [xyz-cfm-form] shortcode in all versions up to, and including, …

Jun 1, 2024
CVE-2024-2506
6.4 MEDIUM

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS functionality …

Jun 1, 2024
CVE-2024-1324
5.3 MEDIUM

The QQWorld Auto Save Images plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the save_remote_images_get_auto_saved_results() function …

Jun 1, 2024
CVE-2024-5501
6.4 MEDIUM

The Supreme Modules Lite – Divi Theme, Extra Theme and Divi Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_one_id’ parameter …

Jun 1, 2024
CVE-2024-4342
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image hotspot, image accordion, off canvas, woogrid, …

Jun 1, 2024
CVE-2024-4087
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Back to Top widget in all versions …

Jun 1, 2024
CVE-2023-6382
6.4 MEDIUM

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_slide' shortcode in all versions up …

Jun 1, 2024
CVE-2024-3565
6.4 MEDIUM

The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'content_block' shortcode in all versions up to, …

Jun 1, 2024
CVE-2024-3564
8.8 HIGH

The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the …

Jun 1, 2024
CVE-2024-4711
6.4 MEDIUM

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ajax_load_more shortcode in versions up to, …

Jun 1, 2024
CVE-2024-2933
6.4 MEDIUM

The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Social Profiles widget in all versions up …

Jun 1, 2024
CVE-2024-5138
8.1 HIGH

The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. …

May 31, 2024
CVE-2024-34009
7.5 HIGH

Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not affect other pages where ReCAPTCHA …

May 31, 2024
CVE-2024-34008
8.8 HIGH

Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk.

May 31, 2024
CVE-2024-34007
8.8 HIGH

The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.

May 31, 2024
CVE-2024-34006
4.3 MEDIUM

The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered.

May 31, 2024
CVE-2024-34005
6.5 MEDIUM

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore database …

May 31, 2024
CVE-2024-34004
6.5 MEDIUM

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore wiki …

May 31, 2024
CVE-2024-34003
5.9 MEDIUM

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore workshop …

May 31, 2024
CVE-2024-34002
6.5 MEDIUM

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore feedback …

May 31, 2024
CVE-2024-36845
4.3 MEDIUM

An invalid pointer in the modbus_receive() function of libmodbus v3.1.6 allows attackers to cause a Denial of Service (DoS) via a crafted message sent to …

May 31, 2024
CVE-2024-36844
7.5 HIGH

libmodbus v3.1.6 was discovered to contain a use-after-free via the ctx->backend pointer. This vulnerability allows attackers to cause a Denial of Service (DoS) via a …

May 31, 2024
CVE-2024-36843
7.5 HIGH

libmodbus v3.1.6 was discovered to contain a heap overflow via the modbus_mapping_free() function.

May 31, 2024
CVE-2024-34001
8.4 HIGH

Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk.

May 31, 2024
CVE-2024-34000
4.3 MEDIUM

ID numbers displayed in the lesson overview report required additional sanitizing to prevent a stored XSS risk.

May 31, 2024
CVE-2024-33999
9.8 CRITICAL

The referrer URL used by MFA required additional sanitizing, rather than being used directly.

May 31, 2024
CVE-2024-33998
5.4 MEDIUM

Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features.

May 31, 2024
CVE-2024-33997
6.1 MEDIUM

Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation.

May 31, 2024
CVE-2024-33996
6.2 MEDIUM

Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not …

May 31, 2024
CVE-2024-5564
8.1 HIGH

A vulnerability was found in libndp. This flaw allows a local malicious user to cause a buffer overflow in NetworkManager, triggered by sending a malformed …

May 31, 2024
CVE-2024-23316

HTTP request desynchronization in Ping Identity PingAccess, all versions prior to 8.0.1 affected allows an attacker to send specially crafted http header requests to create …

May 31, 2024
CVE-2024-5176

Insufficiently Protected Credentials vulnerability in Baxter Welch Allyn Configuration Tool may allow Remote Services with Stolen Credentials.This issue affects Welch Allyn Configuration Tool: versions 1.9.4.1 …

May 31, 2024
CVE-2024-35196
2.0 LOW

Sentry is a developer-first error tracking and performance monitoring platform. Sentry's Slack integration incorrectly records the incoming request body in logs. This request data can …

May 31, 2024
CVE-2024-31030
9.1 CRITICAL

An issue in coap_msg.c in Keith Cullen's FreeCoAP v.0.7 allows remote attackers to cause a Denial of Service or potentially disclose information via a specially …

May 31, 2024
CVE-2024-29848
7.2 HIGH

An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbitrary commands as SYSTEM.

May 31, 2024
CVE-2024-29846
8.0 HIGH

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute …

May 31, 2024
CVE-2024-29830
8.0 HIGH

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute …

May 31, 2024
CVE-2024-29829
8.0 HIGH

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute …

May 31, 2024
CVE-2024-29828
8.0 HIGH

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute …

May 31, 2024
CVE-2024-29827
8.8 HIGH

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute …

May 31, 2024
CVE-2024-29826
8.8 HIGH

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute …

May 31, 2024
CVE-2024-29825
8.8 HIGH

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute …

May 31, 2024
CVE-2024-29824
8.8 HIGH KEV

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute …

May 31, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.