CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-29823
8.8 HIGH

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute …

May 31, 2024
CVE-2024-29822
8.8 HIGH

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute …

May 31, 2024
CVE-2024-22060
4.9 MEDIUM

An unrestricted file upload vulnerability in web component of Ivanti Neurons for ITSM allows a remote, authenticated, high privileged user to write arbitrary files into …

May 31, 2024
CVE-2024-22059
8.8 HIGH

A SQL injection vulnerability in web component of Ivanti Neurons for ITSM allows a remote authenticated user to read/modify/delete information in the underlying database. This …

May 31, 2024
CVE-2024-22058
7.8 HIGH

A buffer overflow allows a low privilege user on the local machine that has the EPM Agent installed to execute arbitrary code with elevated permissions …

May 31, 2024
CVE-2024-1275

Use of Default Cryptographic Key vulnerability in Baxter Welch Allyn Connex Spot Monitor may allow Configuration/Environment Manipulation.This issue affects Welch Allyn Connex Spot Monitor in …

May 31, 2024
CVE-2023-46810
7.3 HIGH

A local privilege escalation vulnerability in Ivanti Secure Access Client for Linux before 22.7R1, allows a low privileged user to execute code as root.

May 31, 2024
CVE-2023-38551
8.2 HIGH

A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inject malicious code on a victim’s browser, thereby leading …

May 31, 2024
CVE-2023-38042
7.8 HIGH

A local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEM.

May 31, 2024
CVE-2021-44534
6.5 MEDIUM

Insufficient user input filtering leads to arbitrary file read by non-authenticated attacker, which results in sensitive information disclosure.

May 31, 2024
CVE-2024-36120
8.1 HIGH

javascript-deobfuscator removes common JavaScript obfuscation techniques. In affected versions crafted payloads targeting expression simplification can lead to code execution. This issue has been patched in …

May 31, 2024
CVE-2024-35142
8.4 HIGH

IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges. IBM X-Force …

May 31, 2024
CVE-2024-35140
7.7 HIGH

IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to improper certificate validation. IBM X-Force ID: …

May 31, 2024
CVE-2024-28736
7.1 HIGH

An issue in Debezium Community debezium-ui v.2.5 allows a local attacker to execute arbitrary code via the refresh page function.

May 31, 2024
CVE-2022-25038
6.1 MEDIUM

wanEditor v4.7.11 was discovered to contain a cross-site scripting (XSS) vulnerability via the video upload function.

May 31, 2024
CVE-2022-25037
5.4 MEDIUM

An issue in wanEditor v4.7.11 and fixed in v.4.7.12 and v.5 was discovered to contain a cross-site scripting (XSS) vulnerability via the image upload function.

May 31, 2024
CVE-2024-5565
8.1 HIGH

The Vanna library uses a prompt function to present the user with visualized results, it is possible to alter the prompt using prompt injection and …

May 31, 2024
CVE-2024-36108
9.8 CRITICAL

casgate is an Open Source Identity and Access Management system. In affected versions `casgate` allows remote unauthenticated attacker to obtain sensitive information via GET request …

May 31, 2024
CVE-2023-7073
6.4 MEDIUM

The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.7 via …

May 31, 2024
CVE-2024-31908
6.4 MEDIUM

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web …

May 31, 2024
CVE-2024-31907
5.4 MEDIUM

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

May 31, 2024
CVE-2024-31889
5.4 MEDIUM

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

May 31, 2024
CVE-2024-5538

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 31, 2024
CVE-2024-5484

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 31, 2024
CVE-2024-22338
4.0 MEDIUM

IBM Security Verify Access OIDC Provider 22.09 through 23.03 could disclose sensitive information to a local user due to hazardous input validation. IBM X-Force ID: …

May 31, 2024
CVE-2024-5347
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'arrow' attribute within the plugin's Post Navigation widget in …

May 31, 2024
CVE-2024-5041
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ha-ia-content-button’ parameter in all versions up to, and including, …

May 31, 2024
CVE-2024-4160
6.4 MEDIUM

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' shortcode in all versions up to, and including, 3.2.90 …

May 31, 2024
CVE-2024-23692
9.8 CRITICAL KEV

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to …

May 31, 2024
CVE-2024-5436
9.8 CRITICAL

Type confusion in Snapchat LensCore could lead to denial of service or arbitrary code execution prior to version 12.88. We recommend upgrading to version 12.88 …

May 31, 2024
CVE-2024-5525
8.3 HIGH

Improper privilege management vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows a local user to access the application as an administrator without any provided …

May 31, 2024
CVE-2024-5524
5.3 MEDIUM

Information exposure vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows unregistered users to access all internal links of the application without providing any credentials.

May 31, 2024
CVE-2024-5523
8.8 HIGH

SQL injection vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability could allow an authenticated local user to send a specially crafted SQL query to the …

May 31, 2024
CVE-2024-5427
6.4 MEDIUM

The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's …

May 31, 2024
CVE-2024-4469
7.5 HIGH

The WP STAGING WordPress Backup Plugin WordPress plugin before 3.5.0 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may …

May 31, 2024
CVE-2024-4379
5.4 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Global Tooltip widget in all versions up to, …

May 31, 2024
CVE-2024-4376
6.4 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fancy Text widget in all versions up to, …

May 31, 2024
CVE-2024-4205
4.3 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_template_content() function …

May 31, 2024
CVE-2024-36246
9.8 CRITICAL

Missing authorization vulnerability exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a result, …

May 31, 2024
CVE-2024-23847
5.9 MEDIUM

Incorrect default permissions issue exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a …

May 31, 2024
CVE-2024-2793
7.2 HIGH

The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Stored Cross-Site Scripting via comments in all versions up …

May 31, 2024
CVE-2024-37032
8.8 HIGH

Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the …

May 31, 2024
CVE-2024-5418
6.4 MEDIUM

The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slitems' attribute within the plugin's De Product Tab & Slide …

May 31, 2024
CVE-2024-5345
8.8 HIGH

The Responsive Owl Carousel for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2.0 via the …

May 31, 2024
CVE-2024-32850
9.8 CRITICAL

Improper neutralization of special elements used in a command ('Command Injection') exists in SkyBridge MB-A100/MB-A110 firmware Ver. 4.2.2 and earlier and SkyBridge BASIC MB-A130 firmware …

May 31, 2024
CVE-2024-37018
9.1 CRITICAL

The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the path that is taken by discovery packets.

May 31, 2024
CVE-2024-37017
8.1 HIGH

asdcplib (aka AS-DCP Lib) 2.13.1 has a heap-based buffer over-read in ASDCP::TimedText::MXFReader::h__Reader::MD_to_TimedText_TDesc in AS_DCP_TimedText.cpp in libasdcp.so.

May 31, 2024
CVE-2024-5499
8.8 HIGH

Out of bounds write in Streams API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary code inside a sandbox via …

May 30, 2024
CVE-2024-5498
8.8 HIGH

Use after free in Presentation API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

May 30, 2024
CVE-2024-5497
8.8 HIGH

Out of bounds memory access in Browser UI in Google Chrome prior to 125.0.6422.141 allowed a remote attacker who convinced a user to engage in …

May 30, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.