CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-5692
5.3 MEDIUM

WordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.4.3 via the redirect_guess_404_permalink function. This can allow unauthenticated attackers to …

Apr 5, 2024
CVE-2024-31083
7.8 HIGH

A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers. This issue occurs when AllocateGlyph() is called to store new glyphs sent by …

Apr 5, 2024
CVE-2023-6523
8.8 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in ExtremePacs Extreme XDS allows Authentication Abuse.This issue affects Extreme XDS: before 3914.

Apr 5, 2024
CVE-2023-6522
7.2 HIGH

Incorrect Use of Privileged APIs vulnerability in ExtremePacs Extreme XDS allows Collect Data as Provided by Users.This issue affects Extreme XDS: before 3914.

Apr 5, 2024
CVE-2024-2447
6.5 MEDIUM

Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain types of post …

Apr 5, 2024
CVE-2024-29221
4.7 MEDIUM

Improper Access Control in Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 lacked proper access control in the …

Apr 5, 2024
CVE-2024-28949
4.3 MEDIUM

Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit the number of user preferences which allows an …

Apr 5, 2024
CVE-2024-27437
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Disable auto-enable of exclusive INTx IRQ Currently for devices requiring masking at the irqchip …

Apr 5, 2024
CVE-2024-26814
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vfio/fsl-mc: Block calling interrupt handler without trigger The eventfd_ctx trigger pointer of the vfio_fsl_mc_irq object …

Apr 5, 2024
CVE-2024-26813
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vfio/platform: Create persistent IRQ handlers The vfio-platform SET_IRQS ioctl currently allows loopback triggering of an …

Apr 5, 2024
CVE-2024-26812
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Create persistent INTx handler A vulnerability exists where the eventfd for INTx signaling can …

Apr 5, 2024
CVE-2024-26810
4.4 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Lock external INTx masking ops Mask operations through config space changes to DisINTx may …

Apr 5, 2024
CVE-2024-21848
3.1 LOW

Improper Access Control in Mattermost Server versions 8.1.x before 8.1.11 allows an attacker that is in a channel with an active call to keep participating …

Apr 5, 2024
CVE-2024-3217
8.8 HIGH

The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value' and 'attribute_id' parameters in all versions up to, and including, …

Apr 5, 2024
CVE-2024-30891
8.8 HIGH

A command injection vulnerability exists in /goform/exeCommand in Tenda AC18 v15.03.05.05, which allows attackers to construct cmdinput parameters for arbitrary command execution.

Apr 5, 2024
CVE-2024-30849
9.8 CRITICAL

Arbitrary file upload vulnerability in Sourcecodester Complete E-Commerce Site v1.0, allows remote attackers to execute arbitrary code via filename parameter in admin/products_photo.php.

Apr 5, 2024
CVE-2024-2115
8.8 HIGH

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.0. This is …

Apr 5, 2024
CVE-2024-29863
7.8 HIGH

A race condition in the installer executable in Qlik Qlikview before versions May 2022 SR3 (12.70.20300) and May 2023 SR2 (12,80.20200) may allow an existing …

Apr 5, 2024
CVE-2024-26329
6.2 MEDIUM

Chilkat before v9.5.0.98, allows attackers to obtain sensitive information via predictable PRNG in ChilkatRand::randomBytes function.

Apr 5, 2024
CVE-2024-29672
8.8 HIGH

Directory Traversal vulnerability in zly2006 Reden before v.0.2.514 allows a remote attacker to execute arbitrary code via the DEBUG_RTC_REQUEST_SYNC_DATA in KeyCallbacks.kt.

Apr 5, 2024
CVE-2024-27448
9.1 CRITICAL

MailDev 2 through 2.1.0 allows Remote Code Execution via a crafted Content-ID header for an e-mail attachment, leading to lib/mailserver.js writing arbitrary code into the …

Apr 5, 2024
CVE-2024-22363
7.5 HIGH

SheetJS Community Edition before 0.20.2 is vulnerable.to Regular Expression Denial of Service (ReDoS).

Apr 5, 2024
CVE-2023-52235
8.8 HIGH

SpaceX Starlink Wi-Fi router GEN 2 before 2023.53.0 and Starlink Dish before 07dd2798-ff15-4722-a9ee-de28928aed34 allow CSRF (e.g., for a reboot) via a DNS Rebinding attack.

Apr 5, 2024
CVE-2024-2509
6.5 MEDIUM

The Gutenberg Blocks by Kadence Blocks WordPress plugin before 3.2.26 does not validate and escape some of its block options before outputting them back in …

Apr 5, 2024
CVE-2023-5973
4.3 MEDIUM

Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user if the portName contains reserved …

Apr 5, 2024
CVE-2024-3321
3.5 LOW

A vulnerability classified as problematic has been found in SourceCodester eLearning System 1.0. This affects an unknown part of the component Maintenance Module. The manipulation …

Apr 5, 2024
CVE-2024-3320
3.5 LOW

A vulnerability was found in SourceCodester eLearning System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation …

Apr 5, 2024
CVE-2024-31498
8.8 HIGH

Yubico ykman-gui (aka YubiKey Manager GUI) before 1.2.6 on Windows, when Edge is not used, allows privilege escalation because browser windows can open as Administrator.

Apr 4, 2024
CVE-2024-31212
6.7 MEDIUM

InstantCMS is a free and open source content management system. A SQL injection vulnerability affects instantcms v2.16.2 in which an attacker with administrative privileges can …

Apr 4, 2024
CVE-2024-31211
5.5 MEDIUM

WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows for code execution via its `__destruct()` magic method. …

Apr 4, 2024
CVE-2024-31210
7.6 HIGH

WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted …

Apr 4, 2024
CVE-2024-31206
8.2 HIGH

dectalk-tts is a Node package to interact with the aeiou Dectalk web API. In `[email protected]`, network requests to the third-party API are sent over HTTP, …

Apr 4, 2024
CVE-2024-27981
9.8 CRITICAL

A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.0.28 and earlier) allows a malicious actor with …

Apr 4, 2024
CVE-2024-21894
9.8 CRITICAL

A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially …

Apr 4, 2024
CVE-2024-3316
6.3 MEDIUM

A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Apr 4, 2024
CVE-2024-29981
4.3 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Apr 4, 2024
CVE-2024-29049
4.1 MEDIUM

Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability

Apr 4, 2024
CVE-2024-3315
6.3 MEDIUM

A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Apr 4, 2024
CVE-2024-3314
6.3 MEDIUM

A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Users.php. …

Apr 4, 2024
CVE-2024-3311
6.3 MEDIUM

A vulnerability was found in Dreamer CMS up to 4.1.3.0. It has been declared as critical. Affected by this vulnerability is the function ZipUtils.unZipFiles of …

Apr 4, 2024
CVE-2024-31204
6.1 MEDIUM

mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identified in mailcow affecting versions prior to 2024-04. This …

Apr 4, 2024
CVE-2024-30270
6.2 MEDIUM

mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identified in mailcow affecting versions prior to 2024-04. This …

Apr 4, 2024
CVE-2024-30264
8.1 HIGH

Typebot is an open-source chatbot builder. A reflected cross-site scripting (XSS) in the sign-in page of typebot.io prior to version 2.24.0 may allow an attacker …

Apr 4, 2024
CVE-2023-45288
7.5 HIGH

An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state …

Apr 4, 2024
CVE-2024-30255
5.3 MEDIUM

Envoy is a cloud-native, open source edge and service proxy. The HTTP/2 protocol stack in Envoy versions prior to 1.29.3, 1.28.2, 1.27.4, and 1.26.8 are …

Apr 4, 2024
CVE-2024-29387
8.8 HIGH

projeqtor up to 11.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /view/print.php.

Apr 4, 2024
CVE-2024-29386
5.4 MEDIUM

projeqtor up to 11.2.0 was discovered to contain a SQL injection vulnerability via the component /view/criticalResourceExport.php.

Apr 4, 2024
CVE-2024-27316
7.5 HIGH

HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not …

Apr 4, 2024
CVE-2024-24795
6.3 MEDIUM

HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an …

Apr 4, 2024
CVE-2024-22053
8.2 HIGH

A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially …

Apr 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.