CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-35696
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Fahad Mahmood WP Docs allows Reflected XSS.This issue affects WP Docs: …

Jun 8, 2024
CVE-2024-35694
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja.This issue affects WPMobile.App: from n/a through <= 11.41.

Jun 8, 2024
CVE-2024-35693
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list.This issue affects 12 Step Meeting …

Jun 8, 2024
CVE-2024-35687
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library link-library allows Reflected XSS.This issue affects Link …

Jun 8, 2024
CVE-2024-35679
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP GiveWP give.This issue affects GiveWP: from n/a through <= 3.12.0.

Jun 8, 2024
CVE-2024-37408
7.3 HIGH

fprintd through 1.94.3 lacks a security attention mechanism, and thus unexpected actions might be authorized by "auth sufficient pam_fprintd.so" for Sudo. NOTE: the supplier disputes …

Jun 8, 2024
CVE-2024-35718
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tribulant Newsletters allows Reflected XSS.This issue affects Newsletters: from n/a through …

Jun 8, 2024
CVE-2024-35750
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdevart Responsive Image Gallery, Gallery Album.This issue affects Responsive Image Gallery, …

Jun 8, 2024
CVE-2024-35737
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Loopus WP Visitors Tracker allows Reflected XSS.This issue affects WP Visitors …

Jun 8, 2024
CVE-2024-35736
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer.This issue affects Visualizer: from n/a through 3.11.1.

Jun 8, 2024
CVE-2024-35734
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodePeople WP Time Slots Booking Form allows Stored XSS.This issue affects …

Jun 8, 2024
CVE-2024-35733
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in RLDD Auto Coupons for WooCommerce allows Reflected XSS.This issue affects Auto …

Jun 8, 2024
CVE-2024-35730
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in realmag777 Active Products Tables for WooCommerce allows Reflected XSS.This issue affects …

Jun 8, 2024
CVE-2024-5091
7.4 HIGH

The SKT Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Age Gate and Creative Slider widgets in all …

Jun 8, 2024
CVE-2024-3668
8.8 HIGH

The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.10.17. This is due to …

Jun 8, 2024
CVE-2024-0444
8.8 HIGH

GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. …

Jun 7, 2024
CVE-2024-1694
7.8 HIGH

Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to bypass discretionary access control via a malicious file. (Chromium …

Jun 7, 2024
CVE-2023-7261
7.8 HIGH

Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security …

Jun 7, 2024
CVE-2023-49224
8.0 HIGH

Precor touchscreen console P62, P80, and P82 contains a default SSH public key in the authorized_keys file. A remote attacker could use this key to …

Jun 7, 2024
CVE-2023-49223
8.8 HIGH

Precor touchscreen console P62, P80, and P82 could allow a remote attacker to obtain sensitive information because the root password is stored in /etc/passwd. An …

Jun 7, 2024
CVE-2023-49222
8.8 HIGH

Precor touchscreen console P82 contains a private SSH key that corresponds to a default public key. A remote attacker could exploit this to gain root …

Jun 7, 2024
CVE-2023-49221
7.8 HIGH

Precor touchscreen console P62, P80, and P82 could allow a remote attacker (within the local network) to bypass security restrictions, and access the service menu, …

Jun 7, 2024
CVE-2024-36827
7.5 HIGH

An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of ebookmeta before v1.2.8 allows attackers to access sensitive information or cause a Denial of …

Jun 7, 2024
CVE-2024-5745
7.3 HIGH

A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Jun 7, 2024
CVE-2024-32502
8.4 HIGH

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, …

Jun 7, 2024
CVE-2024-31959
8.4 HIGH

An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the validation of native handles, which …

Jun 7, 2024
CVE-2024-30162
7.2 HIGH

Invision Community through 4.7.16 allows remote code execution via the applications/core/modules/admin/editor/toolbar.php IPS\core\modules\admin\editor\_toolbar::addPlugin() method. This method handles uploaded ZIP files that are extracted into the applications/core/interface/ckeditor/ckeditor/plugins/ …

Jun 7, 2024
CVE-2024-32503
8.4 HIGH

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, …

Jun 7, 2024
CVE-2024-36792
8.2 HIGH

An issue in the implementation of the WPS in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to gain access to the router's pin.

Jun 7, 2024
CVE-2024-36790
8.8 HIGH

Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 was discovered to store credentials in plaintext.

Jun 7, 2024
CVE-2024-36789
8.1 HIGH

An issue in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to create passwords that do not conform to defined security standards.

Jun 7, 2024
CVE-2024-36787
8.8 HIGH

An issue in Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 allows attackers to bypass authentication and access the administrative interface via unspecified vectors.

Jun 7, 2024
CVE-2024-5599
7.5 HIGH

The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.7 …

Jun 7, 2024
CVE-2024-5542
7.2 HIGH

The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Navigation …

Jun 7, 2024
CVE-2024-5733
7.3 HIGH

A vulnerability was found in itsourcecode Online Discussion Forum 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Jun 7, 2024
CVE-2024-4610
7.8 HIGH KEV

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper …

Jun 7, 2024
CVE-2024-5637
7.5 HIGH

The Market Exporter plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'remove_files' function in all …

Jun 7, 2024
CVE-2024-5732
7.3 HIGH

A vulnerability was found in Clash up to 0.20.1 on Windows. It has been declared as critical. This vulnerability affects unknown code of the component …

Jun 7, 2024
CVE-2024-4902
7.2 HIGH

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the ‘course_id’ parameter in all versions …

Jun 7, 2024
CVE-2024-4887
7.5 HIGH

The Qi Addons For Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7.2 via the 'behavior' …

Jun 7, 2024
CVE-2023-32475
7.6 HIGH

Dell BIOS contains a missing support for integrity check vulnerability. An attacker with physical access to the system could potentially bypass security mechanisms to run …

Jun 7, 2024
CVE-2023-37539
8.4 HIGH

The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. An attacker with the ability to edit documents in the catalog application/database …

Jun 6, 2024
CVE-2024-36823
7.5 HIGH

The encrypt() function of Ninja Core v7.0.0 was discovered to use a weak cryptographic algorithm, leading to a possible leakage of sensitive information.

Jun 6, 2024
CVE-2024-36774
7.2 HIGH

An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.

Jun 6, 2024
CVE-2024-24199
7.5 HIGH

smartdns commit 54b4dc was discovered to contain a misaligned address at smartdns/src/dns.c.

Jun 6, 2024
CVE-2024-24198
7.5 HIGH

smartdns commit 54b4dc was discovered to contain a misaligned address at smartdns/src/util.c.

Jun 6, 2024
CVE-2024-24195
7.5 HIGH

robdns commit d76d2e6 was discovered to contain a misaligned address at /src/zonefile-insertion.c.

Jun 6, 2024
CVE-2024-24194
7.5 HIGH

robdns commit d76d2e6 was discovered to contain a NULL pointer dereference via the item->tokens component at /src/conf-parse.c.

Jun 6, 2024
CVE-2023-51847
7.5 HIGH

An issue in obgm and Libcoap v.a3ed466 allows a remote attacker to cause a denial of service via thecoap_context_t function in the src/coap_threadsafe.c:297:3 component.

Jun 6, 2024
CVE-2023-49441
7.5 HIGH

dnsmasq 2.9 is vulnerable to Integer Overflow via forward_query.

Jun 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.