CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-30337
7.8 HIGH

Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. …

Apr 2, 2024
CVE-2024-30336
7.8 HIGH

Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. …

Apr 2, 2024
CVE-2024-29834
6.4 MEDIUM

This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as unloading topics and triggering compaction. These …

Apr 2, 2024
CVE-2024-30532
4.9 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Builderall Team Builderall Builder for WordPress.This issue affects Builderall Builder for WordPress: from n/a through 2.0.1.

Apr 2, 2024
CVE-2024-30531
4.9 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Nelio Software Nelio Content.This issue affects Nelio Content: from n/a through 3.2.0.

Apr 2, 2024
CVE-2024-24888
6.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks.This issue affects Gutenberg Blocks by Kadence Blocks: from n/a through <= 3.2.25.

Apr 2, 2024
CVE-2024-31109
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Toastie Studio Woocommerce Social Media Share Buttons allows Stored XSS.This issue affects Woocommerce Social Media Share Buttons: from n/a …

Apr 2, 2024
CVE-2024-31105
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Adam Bowen Tax Rate Upload allows Reflected XSS.This issue affects Tax Rate Upload: from n/a through 2.4.5.

Apr 2, 2024
CVE-2024-30809
7.5 HIGH

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in Ap4Sample.h in AP4_Sample::GetOffset() const, leading to a Denial of Service (DoS), as demonstrated …

Apr 2, 2024
CVE-2024-30808
2.7 LOW

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_SubStream::~AP4_SubStream at Ap4ByteStream.cpp, leading to a Denial of Service (DoS), as demonstrated by …

Apr 2, 2024
CVE-2024-30807
7.5 HIGH

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_UnknownAtom::~AP4_UnknownAtom at Ap4Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by …

Apr 2, 2024
CVE-2024-30806
6.5 MEDIUM

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated …

Apr 2, 2024
CVE-2024-30335
7.1 HIGH

Foxit PDF Reader AcroForm Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF …

Apr 2, 2024
CVE-2024-3151
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Bdtask Multi-Store Inventory Management System up to 20240325. Affected is an unknown function of the …

Apr 2, 2024
CVE-2024-2435
4.3 MEDIUM

For an attacker with pre-existing access to send a signal to a workflow, the attacker can make the signal name a script that executes when …

Apr 2, 2024
CVE-2024-28287
7.3 HIGH

A DOM-based open redirection in the returnUrl parameter of INSTINCT UI Web Client 6.5.0 allows attackers to redirect users to malicious sites via a crafted …

Apr 2, 2024
CVE-2024-22248
7.1 HIGH

VMware SD-WAN Orchestrator contains an open redirect vulnerability. A malicious actor may be able to redirect a victim to an attacker controlled domain due to …

Apr 2, 2024
CVE-2024-22247
4.8 MEDIUM

VMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability. A malicious actor with physical access to the SD-WAN Edge appliance during activation can …

Apr 2, 2024
CVE-2024-22246
7.4 HIGH

VMware SD-WAN Edge contains an unauthenticated command injection vulnerability potentially leading to remote code execution. A malicious actor with local access to the Edge Router …

Apr 2, 2024
CVE-2024-30248
7.7 HIGH

Piccolo Admin is an admin interface/content management system for Python, built on top of Piccolo. Piccolo's admin panel allows media files to be uploaded. As …

Apr 2, 2024
CVE-2024-22780
6.1 MEDIUM

Cross Site Scripting vulnerability in CA17 TeamsACS v.1.0.1 allows a remote attacker to execute arbitrary code via a crafted script to the errmsg parameter.

Apr 2, 2024
CVE-2024-30965
8.8 HIGH

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/member_scores.php.

Apr 2, 2024
CVE-2024-30621
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the serverName parameter in the function fromAdvSetMacMtuWan.

Apr 2, 2024
CVE-2024-30620
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the serviceName parameter in the function fromAdvSetMacMtuWan.

Apr 2, 2024
CVE-2024-30946
5.5 MEDIUM

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/co_do.php.

Apr 2, 2024
CVE-2024-2389
10.0 CRITICAL

In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified. An unauthenticated user can gain entry to the …

Apr 2, 2024
CVE-2024-29514
8.8 HIGH

File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file.

Apr 2, 2024
CVE-2023-50313
5.3 MEDIUM

IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for outbound TLS connections caused by a failure to honor user configuration. …

Apr 2, 2024
CVE-2024-29949
7.2 HIGH

There is a command injection vulnerability in some Hikvision NVRs. This could allow an authenticated user with administrative rights to execute arbitrary commands.

Apr 2, 2024
CVE-2024-29948
3.8 LOW

There is an out-of-bounds read vulnerability in some Hikvision NVRs. An authenticated attacker could exploit this vulnerability by sending specially crafted messages to a vulnerable …

Apr 2, 2024
CVE-2024-29947
2.7 LOW

There is a NULL dereference pointer vulnerability in some Hikvision NVRs. Due to an insufficient validation of a parameter in a message, an attacker may …

Apr 2, 2024
CVE-2023-6951
6.6 MEDIUM

A Use of Weak Credentials vulnerability affecting the Wi-Fi network generated by a set of DJI drones could allow a remote attacker to derive the …

Apr 2, 2024
CVE-2023-6950
3.0 LOW

An Improper Input Validation vulnerability affecting the FTP service running on the DJI Mavic Mini 3 Pro could allow an attacker to craft a malicious …

Apr 2, 2024
CVE-2023-6949
5.2 MEDIUM

A Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80 could …

Apr 2, 2024
CVE-2023-6948
3.0 LOW

A Buffer Copy without Checking Size of Input issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could …

Apr 2, 2024
CVE-2023-51456
6.8 MEDIUM

A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to …

Apr 2, 2024
CVE-2023-51455
6.8 MEDIUM

A Improper Validation of Array Index issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an …

Apr 2, 2024
CVE-2023-51454
6.8 MEDIUM

A Out-of-bounds Write issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to overwrite …

Apr 2, 2024
CVE-2023-51453
3.0 LOW

A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to …

Apr 2, 2024
CVE-2023-51452
3.0 LOW

A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to …

Apr 2, 2024
CVE-2024-2745
3.3 LOW

Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when …

Apr 2, 2024
CVE-2024-1946
6.4 MEDIUM

The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block content in all versions up to, and including, 3.1.2 due …

Apr 2, 2024
CVE-2024-1807
6.5 MEDIUM

The Product Sort and Display for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Apr 2, 2024
CVE-2024-1732
5.3 MEDIUM

The Sharkdropship for AliExpress Dropshipping and Affiliate plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the …

Apr 2, 2024
CVE-2024-2931
4.3 MEDIUM

The WPFront User Role Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.1.11184 via the wpfront_user_role_editor_assign_roles_user_autocomplete …

Apr 2, 2024
CVE-2024-31005
8.1 HIGH

An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4MdhdAtom.cpp,AP4_MdhdAtom::AP4_MdhdAtom,mp4fragment

Apr 2, 2024
CVE-2024-31004
9.8 CRITICAL

An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_StsdAtom::AP4_StsdAtom,mp4fragment.

Apr 2, 2024
CVE-2024-31003
8.8 HIGH

Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4_MemoryByteStream::WritePartial at Ap4ByteStream.cpp.

Apr 2, 2024
CVE-2024-31002
9.8 CRITICAL

Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4 BitReader::ReadCache() at Ap4Utils.cpp component.

Apr 2, 2024
CVE-2024-20799
5.4 MEDIUM

Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Apr 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.