CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-38555
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Discard command completions in internal error Fix use after free when FW completion arrives …

Jun 19, 2024
CVE-2024-38552
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix potential index out of bounds in color transformation function Fixes index out of …

Jun 19, 2024
CVE-2024-38545
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix UAF for cq async event The refcount of CQ is not protected by …

Jun 19, 2024
CVE-2024-38542
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: RDMA/mana_ib: boundary check before installing cq callbacks Add a boundary check inside mana_ib_install_cq_cb to prevent …

Jun 19, 2024
CVE-2024-38538
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: bridge: xmit: make sure we have at least eth header len bytes syzbot triggered …

Jun 19, 2024
CVE-2024-38329
7.7 HIGH

IBM Storage Protect for Virtual Environments: Data Protection for VMware 8.1.0.0 through 8.1.22.0 could allow a remote authenticated attacker to bypass security restrictions, caused by …

Jun 19, 2024
CVE-2024-36979
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: bridge: mst: fix vlan use-after-free syzbot reported a suspicious rcu usage[1] in bridge's mst …

Jun 19, 2024
CVE-2023-36684
7.1 HIGH

Missing Authorization vulnerability in Brainstorm Force Convert Pro.This issue affects Convert Pro: from n/a through 1.7.5.

Jun 19, 2024
CVE-2023-39998
8.2 HIGH

Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 27.1.1.

Jun 19, 2024
CVE-2023-38386
7.6 HIGH

Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.

Jun 19, 2024
CVE-2023-37870
8.1 HIGH

Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.1.9.

Jun 19, 2024
CVE-2023-35049
7.5 HIGH

Missing Authorization vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.4.0.

Jun 19, 2024
CVE-2023-47770
7.6 HIGH

Missing Authorization vulnerability in Muffin Group Betheme.This issue affects Betheme: from n/a through 27.1.1.

Jun 19, 2024
CVE-2023-46148
8.8 HIGH

Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.

Jun 19, 2024
CVE-2023-46146
8.3 HIGH

Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.

Jun 19, 2024
CVE-2023-45658
7.6 HIGH

Missing Authorization vulnerability in POSIMYTH Nexter.This issue affects Nexter: from n/a through 2.0.3.

Jun 19, 2024
CVE-2023-40608
8.2 HIGH

Missing Authorization vulnerability in Paid Memberships Pro Paid Memberships Pro CCBill Gateway.This issue affects Paid Memberships Pro CCBill Gateway: from n/a through 0.3.

Jun 19, 2024
CVE-2023-40004
7.3 HIGH

Missing Authorization vulnerability in ServMask All-in-One WP Migration Box Extension, ServMask All-in-One WP Migration OneDrive Extension, ServMask All-in-One WP Migration Dropbox Extension, ServMask All-in-One WP …

Jun 19, 2024
CVE-2024-35780
8.5 HIGH

Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.42.

Jun 19, 2024
CVE-2023-48760
8.2 HIGH

Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.

Jun 19, 2024
CVE-2023-48759
7.5 HIGH

Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.

Jun 19, 2024
CVE-2023-47783
8.3 HIGH

Missing Authorization vulnerability in Thrive Themes Thrive Theme Builder.This issue affects Thrive Theme Builder: from n/a before 3.24.0.

Jun 19, 2024
CVE-2023-47771
8.3 HIGH

Missing Authorization vulnerability in ThemePunch OHG Essential Grid.This issue affects Essential Grid: from n/a through 3.0.18.

Jun 19, 2024
CVE-2024-36978
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: sched: sch_multiq: fix possible OOB write in multiq_tune() q->bands will be assigned to qopt->bands …

Jun 19, 2024
CVE-2024-6132
8.8 HIGH

The Pexels: Free Stock Photos plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'pexels_fsp_images_options_validate' function in …

Jun 19, 2024
CVE-2024-5574
7.5 HIGH

The WP Magazine Modules Lite plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.2 via the 'blockLayout' …

Jun 19, 2024
CVE-2024-5343
8.8 HIGH

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Jun 19, 2024
CVE-2024-5724
8.8 HIGH

The Photo Video Gallery Master plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5.3 via deserialization of …

Jun 19, 2024
CVE-2024-2381
8.8 HIGH

The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_save_image function …

Jun 19, 2024
CVE-2024-6125
8.1 HIGH

The Login with phone number plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 1.7.34. This is due to …

Jun 19, 2024
CVE-2024-6146
8.8 HIGH

Actiontec WCB6200Q uh_get_postdata_withupload Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Actiontec WCB6200Q …

Jun 19, 2024
CVE-2024-6145
8.8 HIGH

Actiontec WCB6200Q Cookie Format String Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Actiontec WCB6200Q routers. …

Jun 19, 2024
CVE-2024-6144
8.8 HIGH

Actiontec WCB6200Q Multipart Boundary Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Actiontec …

Jun 19, 2024
CVE-2024-6143
8.8 HIGH

Actiontec WCB6200Q uh_tcp_recv_header Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Actiontec WCB6200Q routers. …

Jun 19, 2024
CVE-2024-6142
8.8 HIGH

Actiontec WCB6200Q uh_tcp_recv_content Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Actiontec WCB6200Q routers. …

Jun 19, 2024
CVE-2024-38276
8.8 HIGH

Incorrect CSRF token checks resulted in multiple CSRF risks.

Jun 18, 2024
CVE-2024-38275
7.5 HIGH

The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to …

Jun 18, 2024
CVE-2024-37821
8.8 HIGH

An arbitrary file upload vulnerability in the Upload Template function of Dolibarr ERP CRM up to v19.0.1 allows attackers to execute arbitrary code via uploading …

Jun 18, 2024
CVE-2024-36974
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/sched: taprio: always validate TCA_TAPRIO_ATTR_PRIOMAP If one TCA_TAPRIO_ATTR_PRIOMAP attribute has been provided, taprio_parse_mqprio_opt() must validate …

Jun 18, 2024
CVE-2024-22002
7.8 HIGH

CORSAIR iCUE 5.9.105 with iCUE Murals on Windows allows unprivileged users to insert DLL files in the cuepkg-1.2.6 subdirectory of the installation directory.

Jun 18, 2024
CVE-2022-23829
8.2 HIGH

A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native System Management Mode …

Jun 18, 2024
CVE-2024-38348
8.8 HIGH

CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Staff Info module via the searvalu parameter.

Jun 18, 2024
CVE-2024-38347
8.8 HIGH

CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Room Information module via the id parameter.

Jun 18, 2024
CVE-2024-37802
8.8 HIGH

CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Patient Info module via the searvalu parameter.

Jun 18, 2024
CVE-2024-5275
7.8 HIGH

A hard-coded password in the FileCatalyst TransferAgent can be found which can be used to unlock the keystore from which contents may be read out, …

Jun 18, 2024
CVE-2024-6116
7.3 HIGH

A vulnerability, which was classified as critical, has been found in itsourcecode Simple Online Hotel Reservation System 1.0. Affected by this issue is some unknown …

Jun 18, 2024
CVE-2023-47726
7.1 HIGH

IBM QRadar Suite Software 1.10.12.0 through 1.10.21.0 and IBM Cloud Pak for Security 1.10.12.0 through 1.10.21.0 could allow an authenticated user to execute certain arbitrary …

Jun 18, 2024
CVE-2024-6115
7.3 HIGH

A vulnerability classified as critical was found in itsourcecode Simple Online Hotel Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the …

Jun 18, 2024
CVE-2024-6114
7.3 HIGH

A vulnerability classified as critical has been found in itsourcecode Monbela Tourist Inn Online Reservation System up to 1.0. Affected is an unknown function of …

Jun 18, 2024
CVE-2024-6112
7.3 HIGH

A vulnerability classified as critical was found in itsourcecode Pool of Bethesda Online Reservation System 1.0. This vulnerability affects unknown code of the file index.php. …

Jun 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.