CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-30802
9.8 CRITICAL

An issue in Vehicle Management System 7.31.0.3_20230412 allows an attacker to escalate privileges via the login.html component.

May 14, 2024
CVE-2024-30801
5.5 MEDIUM

SQL Injection vulnerability in Cloud based customer service management platform v.1.0.0 allows a local attacker to execute arbitrary code via a crafted payload to Login.asp …

May 14, 2024
CVE-2024-30268
6.1 MEDIUM

Cacti provides an operational monitoring and fault management framework. A reflected cross-site scripting vulnerability on the 1.3.x DEV branch allows attackers to obtain cookies of …

May 14, 2024
CVE-2024-30259
8.2 HIGH

FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.5, 2.10.4, and …

May 14, 2024
CVE-2024-30258
8.2 HIGH

FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.5, 2.10.4, and …

May 14, 2024
CVE-2024-30172
7.5 HIGH

An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and …

May 14, 2024
CVE-2024-30171
5.9 MEDIUM

An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of …

May 14, 2024
CVE-2024-30055
5.4 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

May 14, 2024
CVE-2024-2923
6.4 MEDIUM

The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

May 14, 2024
CVE-2024-2846
4.4 MEDIUM

The Visual Footer Credit Remover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'selector' parameter in all versions up to, and including, …

May 14, 2024
CVE-2024-2785
6.4 MEDIUM

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Age Gate widget in all versions up to, …

May 14, 2024
CVE-2024-2749
5.9 MEDIUM

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's access control mechanism fails to properly restrict access to its settings, permitting any users …

May 14, 2024
CVE-2024-2662
7.2 HIGH

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to command injection in all versions up to, and including, 1.5.102. …

May 14, 2024
CVE-2024-2651
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 …

May 14, 2024
CVE-2024-2454
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting …

May 14, 2024
CVE-2024-2441
8.1 HIGH

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber privileges or above, …

May 14, 2024
CVE-2024-2299
6.1 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability exists in the parisneo/lollms-webui application due to improper validation of uploaded files in the profile picture upload functionality. Attackers …

May 14, 2024
CVE-2024-2290
7.2 HIGH

The Advanced Ads plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.52.1 via deserialization of untrusted input …

May 14, 2024
CVE-2024-2257
9.1 CRITICAL

This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to improper implementation of password policies. An attacker with physical …

May 14, 2024
CVE-2024-29895
10.0 CRITICAL

Cacti provides an operational monitoring and fault management framework. A command injection vulnerability on the 1.3.x DEV branch allows any unauthenticated user to execute arbitrary …

May 14, 2024
CVE-2024-29894
5.4 MEDIUM

Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 contain a residual cross-site scripting vulnerability caused by an incomplete …

May 14, 2024
CVE-2024-29857
7.5 HIGH

An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and …

May 14, 2024
CVE-2024-29800
8.0 HIGH

Deserialization of Untrusted Data vulnerability in Timber Team & Contributors Timber.This issue affects Timber: from n/a through 1.23.0.

May 14, 2024
CVE-2024-29513
7.8 HIGH

An issue in briscKernelDriver.sys in BlueRiSC WindowsSCOPE Cyber Forensics before 3.3 allows a local attacker to execute arbitrary code within the driver and create a …

May 14, 2024
CVE-2024-29212
9.9 CRITICAL

Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its components, under certain …

May 14, 2024
CVE-2024-29166
5.7 MEDIUM

HDF5 through 1.14.3 contains a buffer overflow in H5O__linfo_decode, resulting in the corruption of the instruction pointer and causing denial of service or potential code …

May 14, 2024
CVE-2024-29165
7.4 HIGH

HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_fletcher32, resulting in the corruption of the instruction pointer and causing denial of service or potential code …

May 14, 2024
CVE-2024-29164
9.8 CRITICAL

HDF5 through 1.14.3 contains a stack buffer overflow in H5R__decode_heap, resulting in the corruption of the instruction pointer and causing denial of service or potential …

May 14, 2024
CVE-2024-29163
7.4 HIGH

HDF5 through 1.14.3 contains a heap buffer overflow in H5T__bit_find, resulting in the corruption of the instruction pointer and causing denial of service or potential …

May 14, 2024
CVE-2024-29162
7.4 HIGH

HDF5 through 1.13.3 and/or 1.14.2 contains a stack buffer overflow in H5HG_read, resulting in denial of service or potential code execution.

May 14, 2024
CVE-2024-29161
8.8 HIGH

HDF5 through 1.14.3 contains a heap buffer overflow in H5A__attr_release_table, resulting in the corruption of the instruction pointer and causing denial of service or potential …

May 14, 2024
CVE-2024-29160
7.4 HIGH

HDF5 through 1.14.3 contains a heap buffer overflow in H5HG__cache_heap_deserialize, resulting in the corruption of the instruction pointer and causing denial of service or potential …

May 14, 2024
CVE-2024-29159
9.8 CRITICAL

HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corruption of the instruction pointer and causing denial of service or potential code …

May 14, 2024
CVE-2024-29158
7.4 HIGH

HDF5 through 1.14.3 contains a stack buffer overflow in H5FL_arr_malloc, resulting in the corruption of the instruction pointer and causing denial of service or potential …

May 14, 2024
CVE-2024-29157
9.8 CRITICAL

HDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read, resulting in the corruption of the instruction pointer and causing denial of service or potential …

May 14, 2024
CVE-2024-28866
3.1 LOW

GoCD is a continuous delivery server. GoCD versions from 19.4.0 to 23.5.0 (inclusive) are potentially vulnerable to a reflected cross-site scripting vulnerability on the loading …

May 14, 2024
CVE-2024-28781
5.4 MEDIUM

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4, and 8.0 through 8.0.0.1 is vulnerable to cross-site scripting. …

May 14, 2024
CVE-2024-28761
5.4 MEDIUM

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which …

May 14, 2024
CVE-2024-28760
4.3 MEDIUM

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 dashboard is vulnerable to a denial of service due to improper restrictions of resource …

May 14, 2024
CVE-2024-28759
4.3 MEDIUM

A crafted network packet may cause a buffer overrun in Wind River VxWorks 7 through 23.09.

May 14, 2024
CVE-2024-28285
9.8 CRITICAL

A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reside in the same system with a …

May 14, 2024
CVE-2024-28279
7.3 HIGH

Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via book.php?bookisbn=.

May 14, 2024
CVE-2024-28277
6.1 MEDIUM

In Sourcecodester School Task Manager v1.0, a vulnerability was identified within the subject_name= parameter, enabling Stored Cross-Site Scripting (XSS) attacks. This vulnerability allows attackers to …

May 14, 2024
CVE-2024-28276
6.1 MEDIUM

Sourcecodester School Task Manager 1.0 is vulnerable to Cross Site Scripting (XSS) via add-task.php?task_name=.

May 14, 2024
CVE-2024-28075
9.0 CRITICAL

The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote …

May 14, 2024
CVE-2024-27852
6.5 MEDIUM

A privacy issue was addressed with improved client ID handling for alternative app marketplaces. This issue is fixed in iOS 17.5 and iPadOS 17.5. A …

May 14, 2024
CVE-2024-27847
5.5 MEDIUM

This issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, …

May 14, 2024
CVE-2024-27843
7.8 HIGH

A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7. An app may …

May 14, 2024
CVE-2024-27842
7.8 HIGH

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to execute arbitrary code with …

May 14, 2024
CVE-2024-27841
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An app may be …

May 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.