CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-36378
5.9 MEDIUM

In JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokens

May 29, 2024
CVE-2024-36377
6.5 MEDIUM

In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions

May 29, 2024
CVE-2024-36376
6.5 MEDIUM

In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissions

May 29, 2024
CVE-2024-36375
5.3 MEDIUM

In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed

May 29, 2024
CVE-2024-36374
4.6 MEDIUM

In JetBrains TeamCity before 2024.03.2 stored XSS via build step settings was possible

May 29, 2024
CVE-2024-36373
4.6 MEDIUM

In JetBrains TeamCity before 2024.03.2 several stored XSS in untrusted builds settings were possible

May 29, 2024
CVE-2024-36372
4.6 MEDIUM

In JetBrains TeamCity before 2023.05.6 reflected XSS on the subscriptions page was possible

May 29, 2024
CVE-2024-36371
4.6 MEDIUM

In JetBrains TeamCity before 2023.05.6, 2023.11.5 stored XSS in Commit status publisher was possible

May 29, 2024
CVE-2024-36370
4.6 MEDIUM

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via OAuth connection settings was possible

May 29, 2024
CVE-2024-36369
4.6 MEDIUM

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was possible

May 29, 2024
CVE-2024-36368
4.6 MEDIUM

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 reflected XSS via OAuth provider configuration was possible

May 29, 2024
CVE-2024-36367
4.6 MEDIUM

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party reports was possible

May 29, 2024
CVE-2024-36366
5.4 MEDIUM

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grouping and filtering operations

May 29, 2024
CVE-2024-36365
6.8 MEDIUM

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent

May 29, 2024
CVE-2024-36364
6.5 MEDIUM

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisher build features was possible

May 29, 2024
CVE-2024-36363
4.6 MEDIUM

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 several Stored XSS in code inspection reports were possible

May 29, 2024
CVE-2024-36362
6.5 MEDIUM

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible

May 29, 2024
CVE-2024-25975
6.5 MEDIUM

The application implements an up- and downvote function which alters a value within a JSON file. The POST parameters are not filtered properly and therefore …

May 29, 2024
CVE-2024-5185
7.3 HIGH

The EmbedAI application is susceptible to security issues that enable Data Poisoning attacks. This weakness could result in the application becoming compromised, leading to unauthorized …

May 29, 2024
CVE-2024-5039
6.4 MEDIUM

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up …

May 29, 2024
CVE-2024-25977
7.3 HIGH

The application does not change the session token when using the login or logout functionality. An attacker can set a session token in the victim's …

May 29, 2024
CVE-2024-25976
6.1 MEDIUM

When LDAP authentication is activated in the configuration it is possible to obtain reflected XSS execution by creating a custom URL that the victim only …

May 29, 2024
CVE-2023-42005
7.4 HIGH

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 3.5, 4.0, 4.5, 4.6, 4.7, and 4.8 could allow a …

May 29, 2024
CVE-2024-27313
6.3 MEDIUM

Zoho ManageEngine PAM360 is vulnerable to Stored XSS vulnerability. This vulnerability is applicable only in the version 6610.

May 29, 2024
CVE-2023-52881
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tcp: do not accept ACK of bytes we never sent This patch is based on …

May 29, 2024
CVE-2024-28826
8.8 HIGH

Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and in Checkmk 2.0.0 (EOL) allows attackers with sufficient …

May 29, 2024
CVE-2024-3412
9.1 CRITICAL

The WP STAGING WordPress Backup Plugin – Migration Backup Restore plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation …

May 29, 2024
CVE-2024-5086
6.4 MEDIUM

The Essential Addons for Elementor PRO – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

May 29, 2024
CVE-2024-36015
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ppdev: Add an error check in register_device In register_device, the return value of ida_simple_get is …

May 29, 2024
CVE-2024-36014
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/arm/malidp: fix a possible null pointer dereference In malidp_mw_connector_reset, new memory is allocated with kzalloc, …

May 29, 2024
CVE-2024-4419
4.4 MEDIUM

The Fetch JFT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.3 due to …

May 29, 2024
CVE-2024-3937
4.8 MEDIUM

The Playlist for Youtube WordPress plugin through 1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 29, 2024
CVE-2024-3921
4.8 MEDIUM

The Gianism WordPress plugin through 5.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 29, 2024
CVE-2024-3050
9.1 CRITICAL

The Site Reviews WordPress plugin before 7.0.0 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be …

May 29, 2024
CVE-2024-4611
8.1 HIGH

The AppPresser plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'decrypt_value' and on the 'doCookieAuth' functions in all versions up …

May 29, 2024
CVE-2024-21512
8.2 HIGH

Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitization passed to fields and tables when using …

May 29, 2024
CVE-2023-6743
8.8 HIGH

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, …

May 29, 2024
CVE-2024-0434
5.3 MEDIUM

The WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

May 29, 2024
CVE-2024-5204
8.8 HIGH

The Swiss Toolkit For WP plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.7. This is due to the …

May 29, 2024
CVE-2024-5150
9.8 CRITICAL

The Login with phone number plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.26. This is due to the …

May 29, 2024
CVE-2024-5437
3.5 LOW

A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as problematic. Affected is the function save_category of the file …

May 29, 2024
CVE-2024-36112
6.3 MEDIUM

Nautobot is a Network Source of Truth and Network Automation Platform. A user with permissions to view Dynamic Group records (`extras.view_dynamicgroup` permission) can use the …

May 28, 2024
CVE-2024-23580
6.5 MEDIUM

HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of One-Time Passwords (OTPs). This could allow an attacker with access to the database to …

May 28, 2024
CVE-2024-23579
6.5 MEDIUM

HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of security questions. This could allow an attacker with access to the database to recover …

May 28, 2024
CVE-2023-30314
6.5 MEDIUM

An issue discovered in 360 V6G, 360 T5G, 360 T6M, and 360 P1 routers allows attackers to hijack TCP sessions which could lead to a …

May 28, 2024
CVE-2023-30312
7.3 HIGH

An issue discovered in OpenWrt 18.06, 19.07, 21.02, 22.03, and beyond allows off-path attackers to hijack TCP sessions, which could lead to a denial of …

May 28, 2024
CVE-2024-35548
5.4 MEDIUM

A SQL injection vulnerability in Mybatis plus versions below 3.5.6 allows remote attackers to obtain database information via a Boolean blind injection. NOTE: the vendor's …

May 28, 2024
CVE-2024-35511
4.7 MEDIUM

phpgurukul Men Salon Management System v2.0 is vulnerable to SQL Injection via the "username" parameter of /msms/admin/index.php.

May 28, 2024
CVE-2024-35240
5.4 MEDIUM

Umbraco Commerce is an open source dotnet ecommerce solution. In affected versions there exists a stored Cross-site scripting (XSS) issue which would enable attackers to …

May 28, 2024
CVE-2024-35239
2.7 LOW

Umbraco Commerce is an open source dotnet web forms solution. In affected versions an authenticated user that has access to edit Forms may inject unsafe …

May 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.