CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-21454
7.5 HIGH

Transient DOS while decoding the ToBeSignedMessage in Automotive Telematics.

Apr 1, 2024
CVE-2024-21453
7.5 HIGH

Transient DOS while decoding message of size that exceeds the available system memory.

Apr 1, 2024
CVE-2024-21452
7.3 HIGH

Transient DOS while decoding an ASN.1 OER message containing a SEQUENCE of unknown extensions.

Apr 1, 2024
CVE-2023-33115
7.8 HIGH

Memory corruption while processing buffer initialization, when trusted report for certain report types are generated.

Apr 1, 2024
CVE-2023-33101
7.5 HIGH

Transient DOS while processing DL NAS TRANSPORT message with payload length 0.

Apr 1, 2024
CVE-2023-33100
7.5 HIGH

Transient DOS while processing DL NAS Transport message when message ID is not defined in the 3GPP specification.

Apr 1, 2024
CVE-2023-33099
7.5 HIGH

Transient DOS while processing SMS container of non-standard size received in DL NAS transport in NR.

Apr 1, 2024
CVE-2023-33023
8.4 HIGH

Memory corruption while processing finish_sign command to pass a rsp buffer.

Apr 1, 2024
CVE-2023-28547
8.4 HIGH

Memory corruption in SPS Application while requesting for public key in sorter TA.

Apr 1, 2024
CVE-2024-30871
8.8 HIGH

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /WebPages/applyhardware.php.

Apr 1, 2024
CVE-2024-30870
8.8 HIGH

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/address_interpret.php.

Apr 1, 2024
CVE-2023-6154
7.8 HIGH

A configuration setting issue in seccenter.exe as used in Bitdefender Total Security, Bitdefender Internet Security, Bitdefender Antivirus Plus, Bitdefender Antivirus Free allows an attacker to …

Apr 1, 2024
CVE-2024-26654
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: ALSA: sh: aica: reorder cleanup operations to avoid UAF bugs The dreamcastcard->timer could schedule the …

Apr 1, 2024
CVE-2024-26653
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: usb: misc: ljca: Fix double free in error handling path When auxiliary_device_add() returns error and …

Apr 1, 2024
CVE-2024-20053
8.4 HIGH

In flashc, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege with System …

Apr 1, 2024
CVE-2024-20040
8.8 HIGH

In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege with …

Apr 1, 2024
CVE-2024-20039
8.8 HIGH

In modem protocol, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with …

Apr 1, 2024
CVE-2024-31103
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kanban for WordPress Kanban Boards for WordPress allows Reflected XSS.This issue affects Kanban …

Mar 31, 2024
CVE-2024-31097
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stephan Spencer SEO Title Tag allows Reflected XSS.This issue affects SEO Title Tag: …

Mar 31, 2024
CVE-2024-31092
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Philip M. Hofer (Frumph) Comic Easel allows Reflected XSS.This issue affects Comic Easel: …

Mar 31, 2024
CVE-2024-31091
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SparkWeb Interactive, Inc. Custom Field Bulk Editor allows Reflected XSS.This issue affects Custom …

Mar 31, 2024
CVE-2024-31090
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 荒野无灯 Hacklog Down As PDF allows Reflected XSS.This issue affects Hacklog Down As …

Mar 31, 2024
CVE-2024-31087
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joel Starnes pageMash > Page Management allows Reflected XSS.This issue affects pageMash > …

Mar 31, 2024
CVE-2024-31085
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rob Marsh, SJ Post-Plugin Library allows Reflected XSS.This issue affects Post-Plugin Library: from …

Mar 31, 2024
CVE-2024-31084
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pulsar Web Design Weekly Class Schedule allows Reflected XSS.This issue affects Weekly Class …

Mar 31, 2024
CVE-2024-30561
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scientech It Solution Appointment Calendar allows Reflected XSS.This issue affects Appointment Calendar: from …

Mar 31, 2024
CVE-2024-30558
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Simpson Add Shortcodes Actions And Filters allows Reflected XSS.This issue affects Add …

Mar 31, 2024
CVE-2024-30551
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Toast Plugins Sticky Anything.This issue affects Sticky Anything: from n/a through 2.1.5.

Mar 31, 2024
CVE-2024-30550
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Responsive Image Gallery, Gallery Album allows Reflected XSS.This issue affects Responsive Image …

Mar 31, 2024
CVE-2024-31123
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebDorado SpiderFAQ allows Reflected XSS.This issue affects SpiderFAQ: from n/a through 1.3.2.

Mar 31, 2024
CVE-2024-31116
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web 10Web Map Builder for Google Maps.This issue affects 10Web Map …

Mar 31, 2024
CVE-2024-31112
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stephanie Leary Convert Post Types allows Reflected XSS.This issue affects Convert Post Types: …

Mar 31, 2024
CVE-2024-31110
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Katz Web Services, Inc. Contact Form 7 Newsletter allows Reflected XSS.This issue affects …

Mar 31, 2024
CVE-2024-31107
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DiSo Development Team OpenID allows Reflected XSS.This issue affects OpenID: from n/a through …

Mar 31, 2024
CVE-2024-31106
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yooslider Yoo Slider allows Reflected XSS.This issue affects Yoo Slider: from n/a through …

Mar 31, 2024
CVE-2024-30535
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WhiteStudio Easy Form Builder.This issue affects Easy Form Builder: from n/a …

Mar 31, 2024
CVE-2024-30533
7.5 HIGH

Unrestricted Upload of File with Dangerous Type vulnerability in Techeshta Layouts for Elementor.This issue affects Layouts for Elementor: from n/a before 1.8.

Mar 31, 2024
CVE-2024-30489
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in loopus WP Cost Estimation & Payment Forms Builder.This issue affects WP …

Mar 31, 2024
CVE-2024-31094
8.5 HIGH

Deserialization of Untrusted Data vulnerability in Filter Custom Fields & Taxonomies Light.This issue affects Filter Custom Fields & Taxonomies Light: from n/a through 1.05.

Mar 31, 2024
CVE-2023-41724
8.8 HIGH

A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat actor to execute arbitrary commands on the underlying operating system of the …

Mar 31, 2024
CVE-2024-1522
8.8 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability in the parisneo/lollms-webui project allows remote attackers to execute arbitrary code on a victim's system. The vulnerability stems from …

Mar 30, 2024
CVE-2024-3018
8.8 HIGH

The Essential Addons for Elementor plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.13 via deserialization of …

Mar 30, 2024
CVE-2024-3088
7.3 HIGH

A vulnerability, which was classified as critical, was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. This affects an unknown part of the file /admin/forgot-password.php …

Mar 30, 2024
CVE-2024-3087
7.3 HIGH

A vulnerability, which was classified as critical, has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this issue is some unknown functionality …

Mar 30, 2024
CVE-2024-3085
7.3 HIGH

A vulnerability classified as critical has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected is an unknown function of the file /admin/login.php of …

Mar 30, 2024
CVE-2024-2047
8.8 HIGH

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.6 via the render_raw function. …

Mar 30, 2024
CVE-2024-30441
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Post Grid allows Reflected XSS.This issue affects Post Grid: from n/a through …

Mar 29, 2024
CVE-2024-30439
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BestWebSoft Limit Attempts by BestWebSoft allows Reflected XSS.This issue affects Limit Attempts by …

Mar 29, 2024
CVE-2024-30435
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH Nexter Blocks the-plus-addons-for-block-editor.This issue affects Nexter Blocks: from n/a through <= 3.2.5.

Mar 29, 2024
CVE-2024-30431
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hometory Mang Board WP allows Reflected XSS.This issue affects Mang Board WP: from …

Mar 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.