CVE Database

4634+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-3073
2.7 LOW

The Easy WP SMTP by SendLayer – WordPress SMTP and Email Log Plugin plugin for WordPress is vulnerable to information exposure in all versions up …

Jun 13, 2024
CVE-2024-36226
3.5 LOW

Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A low-privileged …

Jun 13, 2024
CVE-2024-26127
3.5 LOW

Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A low-privileged …

Jun 13, 2024
CVE-2024-26126
3.5 LOW

Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A low-privileged …

Jun 13, 2024
CVE-2023-49559
3.7 LOW

An issue in vektah gqlparser open-source-library v.2.5.10 allows a remote attacker to cause a denial of service via a crafted script to the parserDirectives function.

Jun 12, 2024
CVE-2024-5798
2.6 LOW

Vault and Vault Enterprise did not properly validate the JSON Web Token (JWT) role-bound audience claim when using the Vault JWT auth method. This may …

Jun 12, 2024
CVE-2024-1891
3.5 LOW

A stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker could inject HTML code into a web application scan …

Jun 12, 2024
CVE-2024-29181
2.3 LOW

Strapi is an open-source content management system. Prior to version 4.19.1, a super admin can create a collection where an item in the collection has …

Jun 12, 2024
CVE-2024-5851
3.5 LOW

A vulnerability classified as problematic has been found in playSMS up to 1.4.7. Affected is an unknown function of the file /index.php?app=main&inc=feature_schedule&op=list of the component …

Jun 11, 2024
CVE-2024-5812
3.3 LOW

A low severity vulnerability in BIPS has been identified where an attacker with high privileges or a compromised high privilege account can overwrite Read-Only smart …

Jun 11, 2024
CVE-2024-21754
1.8 LOW

A use of password hash with insufficient computational effort vulnerability [CWE-916] affecting FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 6.4 all …

Jun 11, 2024
CVE-2023-38533
3.3 LOW

A vulnerability has been identified in TIA Administrator (All versions < V3 SP2). The affected component creates temporary download files in a directory with insecure …

Jun 11, 2024
CVE-2024-5829
3.5 LOW

A vulnerability classified as problematic was found in smallweigit Avue up to 3.4.4. Affected by this vulnerability is an unknown functionality of the component avueUeditor. …

Jun 11, 2024
CVE-2024-34684
3.7 LOW

On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated attacker with administrator access on the local server to access the password of a …

Jun 11, 2024
CVE-2024-22261
2.7 LOW

SQL-Injection in Harbor allows priviledge users to leak the task IDs

Jun 11, 2024
CVE-2024-27845
3.3 LOW

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.5 and iPadOS 17.5. An app may be …

Jun 10, 2024
CVE-2024-27819
2.4 LOW

The issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with …

Jun 10, 2024
CVE-2024-27814
2.4 LOW

This issue was addressed through improved state management. This issue is fixed in watchOS 10.5. A person with physical access to a device may be …

Jun 10, 2024
CVE-2024-27799
3.3 LOW

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS …

Jun 10, 2024
CVE-2024-36407
3.7 LOW

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, a user password can be reset from an …

Jun 10, 2024
CVE-2024-35749
3.7 LOW

Authentication Bypass by Spoofing vulnerability in Acurax Under Construction / Maintenance Mode from Acurax allows Authentication Bypass.This issue affects Under Construction / Maintenance Mode from …

Jun 10, 2024
CVE-2024-30512
3.7 LOW

Missing Authorization vulnerability in weForms.This issue affects weForms: from n/a through 1.6.20.

Jun 9, 2024
CVE-2024-5766
2.4 LOW

A vulnerability was found in Likeshop up to 2.5.7 and classified as problematic. This issue affects some unknown processing of the file /admin of the …

Jun 8, 2024
CVE-2024-5307
3.3 LOW

Kofax Power PDF AcroForm Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Kofax Power …

Jun 6, 2024
CVE-2024-32873
3.5 LOW

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. The spendable balance is not updated properly when delegating vested tokens. The issue …

Jun 6, 2024
CVE-2024-2213
3.3 LOW

An issue was discovered in zenml-io/zenml versions up to and including 0.55.4. Due to improper authentication mechanisms, an attacker with access to an active user …

Jun 6, 2024
CVE-2024-2032
3.1 LOW

A race condition vulnerability exists in zenml-io/zenml versions up to and including 0.55.3, which allows for the creation of multiple users with the same username …

Jun 6, 2024
CVE-2024-5657
3.7 LOW

The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.

Jun 6, 2024
CVE-2023-50804
3.7 LOW

An issue was discovered in Samsung Mobile Processor, and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos …

Jun 5, 2024
CVE-2023-50803
3.7 LOW

An issue was discovered in Samsung Mobile Processor, and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos …

Jun 5, 2024
CVE-2023-52147
3.7 LOW

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in All In One WP Security & Firewall Team All In One WP Security & Firewall …

Jun 4, 2024
CVE-2023-49822
3.7 LOW

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in David Vongries Ultimate Dashboard allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Ultimate …

Jun 4, 2024
CVE-2023-49748
3.7 LOW

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPServeur, NicolasKulka, wpformation WPS Hide Login allows Accessing Functionality Not Properly Constrained by ACLs.This issue …

Jun 4, 2024
CVE-2023-49741
3.7 LOW

Authentication Bypass by Spoofing vulnerability in wpdevart Coming soon and Maintenance mode allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Coming soon and …

Jun 4, 2024
CVE-2023-48335
3.7 LOW

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Webcraftic Hide login page allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Hide …

Jun 4, 2024
CVE-2023-47818
3.7 LOW

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in LWS LWS Hide Login allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects LWS …

Jun 4, 2024
CVE-2023-47769
3.7 LOW

Authentication Bypass by Spoofing vulnerability in WP Maintenance allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Maintenance: from n/a through 6.1.3.

Jun 4, 2024
CVE-2023-27437
3.7 LOW

Missing Authorization vulnerability in Event Espresso Event Espresso 4 Decaf allows Functionality Misuse.This issue affects Event Espresso 4 Decaf: from n/a through 4.10.44.Decaf.

Jun 3, 2024
CVE-2023-24373
3.7 LOW

External Control of Assumed-Immutable Web Parameter vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Manipulating Hidden Fields.This issue affects Booking calendar, Appointment Booking System: …

Jun 3, 2024
CVE-2024-31684
3.5 LOW

Incorrect access control in the fingerprint authentication mechanism of Bitdefender Mobile Security v4.11.3-gms allows attackers to bypass fingerprint authentication due to the use of a …

Jun 3, 2024
CVE-2024-35196
2.0 LOW

Sentry is a developer-first error tracking and performance monitoring platform. Sentry's Slack integration incorrectly records the incoming request body in logs. This request data can …

May 31, 2024
CVE-2024-36119
1.8 LOW

Statamic is a, Laravel + Git powered CMS designed for building websites. In affected versions users registering via the `user:register_form` tag will have their password …

May 30, 2024
CVE-2024-36118
3.5 LOW

MeterSphere is a test management and interface testing tool. In affected versions users without workspace permissions can view functional test cases of other workspaces beyond …

May 30, 2024
CVE-2024-4330
3.3 LOW

A path traversal vulnerability was identified in the parisneo/lollms-webui repository, specifically within version 9.6. The vulnerability arises due to improper handling of user-supplied input in …

May 30, 2024
CVE-2024-34715
2.3 LOW

Fides is an open-source privacy engineering platform. The Fides webserver requires a connection to a hosted PostgreSQL database for persistent storage of application data. If …

May 29, 2024
CVE-2024-35311
3.3 LOW

Yubico YubiKey 5 Series before 5.7.0, Security Key Series before 5.7.0, YubiKey Bio Series before 5.6.4, and YubiKey 5 FIPS before 5.7.2 have Incorrect Access …

May 29, 2024
CVE-2024-5437
3.5 LOW

A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as problematic. Affected is the function save_category of the file …

May 29, 2024
CVE-2024-35239
2.7 LOW

Umbraco Commerce is an open source dotnet web forms solution. In affected versions an authenticated user that has access to edit Forms may inject unsafe …

May 28, 2024
CVE-2024-35403
2.7 LOW

TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function setIpPortFilterRules

May 28, 2024
CVE-2024-32944
3.3 LOW

Path traversal vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product installs a crafted UTAU voicebank installer (.uar file, .zip …

May 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.