CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-3486
7.8 HIGH

XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to information disclosure and remote code execution.

May 15, 2024
CVE-2024-3485
5.3 MEDIUM

Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure.

May 15, 2024
CVE-2024-3484
5.7 MEDIUM

Path Traversal found in OpenText™ iManager 3.2.6.0200. This can lead to privilege escalation or file disclosure.

May 15, 2024
CVE-2024-3483
7.8 HIGH

Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger command injection and insecure deserialization issues.

May 15, 2024
CVE-2024-34082
8.5 HIGH

Grav is a file-based Web platform. Prior to version 1.7.46, a low privilege user account with page edit privilege can read any server files using …

May 15, 2024
CVE-2024-28087
6.5 MEDIUM

In Bonitasoft runtime Community edition, the lack of dynamic permissions causes IDOR vulnerability. Dynamic permissions existed only in Subscription edition and have now been restored …

May 15, 2024
CVE-2024-28042
8.4 HIGH

SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Center.

May 15, 2024
CVE-2024-27593
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Filter function of Eramba Version 3.22.3 Community Edition allows authenticated attackers to execute arbitrary web scripts or …

May 15, 2024
CVE-2023-7258
4.8 MEDIUM

A denial of service exists in Gvisor Sandbox where a bug in reference counting code in mount point tracking could lead to a panic, making …

May 15, 2024
CVE-2023-5938
8.0 HIGH

Multiple functions use archives without properly validating the filenames therein, rendering the application vulnerable to path traversal via 'zip slip' attacks. An administrator able to …

May 15, 2024
CVE-2024-4903
6.3 MEDIUM

A vulnerability was found in Tongda OA 2017. It has been declared as critical. This vulnerability affects unknown code of the file /general/meeting/manage/delete.php. The manipulation …

May 15, 2024
CVE-2024-3319
9.1 CRITICAL

An issue was identified in the Identity Security Cloud (ISC) Transform preview and IdentityProfile preview API endpoints that allowed an authenticated administrator to execute user-defined …

May 15, 2024
CVE-2024-3318
4.2 MEDIUM

A file path traversal vulnerability was identified in the DelimitedFileConnector Cloud Connector that allowed an authenticated administrator to set arbitrary connector attributes, including the “file“ …

May 15, 2024
CVE-2024-3317
6.5 MEDIUM

An improper access control was identified in the Identity Security Cloud (ISC) message server API that allowed an authenticated user to exfiltrate job processing metadata …

May 15, 2024
CVE-2024-35179
6.8 MEDIUM

Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, when using `RUN_AS_USER`, the specified user (and therefore, web interface admins) can read …

May 15, 2024
CVE-2024-31216
5.1 MEDIUM

The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3-compatible buckets. The source-controller implements …

May 15, 2024
CVE-2023-5937
3.8 LOW

On Windows systems, the Arc configuration files resulted to be world-readable. This can lead to information disclosure by local attackers, via exfiltration of sensitive data …

May 15, 2024
CVE-2023-5936
7.8 HIGH

On Unix systems (Linux, MacOS), Arc uses a temporary file with unsafe privileges. By tampering with such file, a malicious local user in the system …

May 15, 2024
CVE-2023-5935
7.4 HIGH

When configuring Arc (e.g. during the first setup), a local web interface is provided to ease the configuration process. Such web interface lacks authentication and …

May 15, 2024
CVE-2024-34955
9.8 CRITICAL

Code-projects Budget Management 1.0 is vulnerable to SQL Injection via the delete parameter.

May 15, 2024
CVE-2024-34954
6.1 MEDIUM

Code-projects Budget Management 1.0 is vulnerable to Cross Site Scripting (XSS) via the budget parameter.

May 15, 2024
CVE-2024-27353
7.4 HIGH

A memory corruption vulnerability in SdHost and SdMmcDevice in Insyde InsydeH2O kernel 5.2 before 05.29.09, kernel 5.3 before 05.38.09, kernel 5.4 before 05.46.09, kernel 5.5 …

May 15, 2024
CVE-2024-25079
7.4 HIGH

A memory corruption vulnerability in HddPassword in Insyde InsydeH2O kernel 5.2 before 05.29.09, kernel 5.3 before 05.38.09, kernel 5.4 before 05.46.09, kernel 5.5 before 05.54.09, …

May 15, 2024
CVE-2024-25078
7.4 HIGH

A memory corruption vulnerability in StorageSecurityCommandDxe in Insyde InsydeH2O before kernel 5.2: IB19130163 in 05.29.07, kernel 5.3: IB19130163 in 05.38.07, kernel 5.4: IB19130163 in 05.46.07, …

May 15, 2024
CVE-2024-4670
8.8 HIGH

The All-in-One Video Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.5 via the aiovg_search_form shortcode. …

May 15, 2024
CVE-2024-2248
6.4 MEDIUM

A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted) may allow threat actors to take over the end …

May 15, 2024
CVE-2023-6324
8.1 HIGH

ThroughTek Kalay SDK uses a predictable PSK value in the DTLS session when encountering an unexpected PSK identity

May 15, 2024
CVE-2023-6323
4.3 MEDIUM

ThroughTek Kalay SDK does not verify the authenticity of received messages, allowing an attacker to impersonate an authoritative server.

May 15, 2024
CVE-2023-6322
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the message parsing functionality of the Roku Indoor Camera SE version 3.0.2.4679 and Wyze Cam v3 version 4.36.11.5859. …

May 15, 2024
CVE-2023-6321
7.2 HIGH

A command injection vulnerability exists in the IOCTL that manages OTA updates. A specially crafted command can lead to command execution as the root user. …

May 15, 2024
CVE-2024-4702
6.4 MEDIUM

The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 1.2.1 …

May 15, 2024
CVE-2024-34101
5.5 MEDIUM

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

May 15, 2024
CVE-2024-34100
7.8 HIGH

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

May 15, 2024
CVE-2024-34099
7.8 HIGH

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context …

May 15, 2024
CVE-2024-34098
7.8 HIGH

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context …

May 15, 2024
CVE-2024-34097
7.8 HIGH

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

May 15, 2024
CVE-2024-34096
7.8 HIGH

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

May 15, 2024
CVE-2024-34095
7.8 HIGH

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

May 15, 2024
CVE-2024-34094
7.8 HIGH

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

May 15, 2024
CVE-2024-30312
5.5 MEDIUM

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

May 15, 2024
CVE-2024-30311
5.5 MEDIUM

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

May 15, 2024
CVE-2024-30310
7.8 HIGH

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

May 15, 2024
CVE-2024-30284
7.8 HIGH

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

May 15, 2024
CVE-2024-4010
8.8 HIGH

The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to …

May 15, 2024
CVE-2024-4636
6.4 MEDIUM

The Image Optimization by Optimole – Lazy Load, CDN, Convert WebP & AVIF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘allow_meme_types’ …

May 15, 2024
CVE-2024-3824
5.5 MEDIUM

The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check in place when resetting its settings, which could allow attackers to make a …

May 15, 2024
CVE-2024-3823
2.4 LOW

The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which …

May 15, 2024
CVE-2024-3822
4.8 MEDIUM

The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

May 15, 2024
CVE-2024-3749
6.5 MEDIUM

The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download files …

May 15, 2024
CVE-2024-3748
6.5 MEDIUM

The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user to manipulate the `user_id` to …

May 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.