CVE Database

46795+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6023
8.8 HIGH

The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when adding emails, which could allow attackers to make a logged in …

Jul 12, 2024
CVE-2024-6022
8.8 HIGH

The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged …

Jul 12, 2024
CVE-2024-6677
7.8 HIGH

Privilege escalation in uberAgent

Jul 12, 2024
CVE-2024-6468
7.5 HIGH

Vault and Vault Enterprise did not properly handle requests originating from unauthorized IP addresses when the TCP listener option, proxy_protocol_behavior, was set to deny_unauthorized. When …

Jul 11, 2024
CVE-2024-39552
7.5 HIGH

An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows a network …

Jul 11, 2024
CVE-2024-39551
7.5 HIGH

An Uncontrolled Resource Consumption vulnerability in the H.323 ALG (Application Layer Gateway) of Juniper Networks Junos OS on SRX Series and MX Series with SPC3 …

Jul 11, 2024
CVE-2024-39549
7.5 HIGH

A Missing Release of Memory after Effective Lifetime vulnerability in the routing process daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows …

Jul 11, 2024
CVE-2024-39548
7.5 HIGH

An Uncontrolled Resource Consumption vulnerability in the aftmand process of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to consume memory resources, resulting …

Jul 11, 2024
CVE-2024-39546
7.3 HIGH

A Missing Authorization vulnerability in the Socket Intercept (SI) command file interface of Juniper Networks Junos OS Evolved allows an authenticated, low-privilege local attacker to …

Jul 11, 2024
CVE-2024-39545
7.5 HIGH

An Improper Check for Unusual or Exceptional Conditions vulnerability in the the IKE daemon (iked) of Juniper Networks Junos OS on SRX Series, MX Series …

Jul 11, 2024
CVE-2024-39542
7.5 HIGH

An Improper Validation of Syntactic Correctness of Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series with MPC10/11 …

Jul 11, 2024
CVE-2024-39540
7.5 HIGH

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on SRX Series, and MX …

Jul 11, 2024
CVE-2024-39531
7.5 HIGH

An Improper Handling of Values vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX 7000 Series allows a network-based, …

Jul 11, 2024
CVE-2024-39904
8.8 HIGH

VNote is a note-taking platform. Prior to 3.18.1, a code execution vulnerability existed in VNote, which allowed an attacker to execute arbitrary programs on the …

Jul 11, 2024
CVE-2024-39530
7.5 HIGH

An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis management daemon (chassisd) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker …

Jul 11, 2024
CVE-2024-39529
7.5 HIGH

A Use of Externally-Controlled Format String vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based …

Jul 11, 2024
CVE-2024-39524
7.8 HIGH

An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their …

Jul 11, 2024
CVE-2024-39523
7.8 HIGH

An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their …

Jul 11, 2024
CVE-2024-39522
7.8 HIGH

An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their …

Jul 11, 2024
CVE-2024-39521
7.8 HIGH

An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their …

Jul 11, 2024
CVE-2024-39520
7.8 HIGH

An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their …

Jul 11, 2024
CVE-2024-38536
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A memory allocation failure due to `http.memcap` being reached leads …

Jul 11, 2024
CVE-2024-38535
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Suricata can run out of memory when parsing crafted HTTP/2 …

Jul 11, 2024
CVE-2024-38534
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Crafted modbus traffic can lead to unlimited resource accumulation within …

Jul 11, 2024
CVE-2024-28872
8.9 HIGH

The TLS certificate validation code is flawed. An attacker can obtain a TLS certificate from the Stork server and use it to connect to the …

Jul 11, 2024
CVE-2024-5681
7.8 HIGH

CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, and potentially kernel execution when a malicious actor with local user access …

Jul 11, 2024
CVE-2024-5680
7.1 HIGH

CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service when a malicious actor with local user access crafts a script/program using …

Jul 11, 2024
CVE-2024-5679
7.1 HIGH

CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or kernel memory leak when a malicious actor with local user access crafts a script/program …

Jul 11, 2024
CVE-2024-2602
7.3 HIGH

CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could result in remote code execution when an authenticated user …

Jul 11, 2024
CVE-2024-6666
8.8 HIGH

The WP ERP plugin for WordPress is vulnerable to SQL Injection via the ‘vendor_id’ and 'status' parameter in all versions up to, and including, 1.13.0 …

Jul 11, 2024
CVE-2024-1845
8.8 HIGH

The VikRentCar Car Rental Management System WordPress plugin before 1.3.2 does not have CSRF checks in some places, which could allow attackers to make logged …

Jul 11, 2024
CVE-2024-22280
8.5 HIGH

VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL …

Jul 11, 2024
CVE-2024-6653
7.3 HIGH

A vulnerability was found in code-projects Simple Task List 1.0. It has been declared as critical. This vulnerability affects unknown code of the file loginForm.php …

Jul 11, 2024
CVE-2024-6447
7.2 HIGH

The FULL – Cliente plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the license plan parameter in all versions up to, and including, …

Jul 11, 2024
CVE-2024-39565
8.8 HIGH

An Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in J-Web shipped with Juniper Networks Junos OS allows an unauthenticated, network-based attacker to …

Jul 10, 2024
CVE-2024-39562
7.5 HIGH

A Missing Release of Resource after Effective Lifetime vulnerability the xinetd process, responsible for spawning SSH daemon (sshd) instances, of Juniper Networks Junos OS Evolved …

Jul 10, 2024
CVE-2024-39555
7.5 HIGH

An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker …

Jul 10, 2024
CVE-2024-39518
7.5 HIGH

A Heap-based Buffer Overflow vulnerability in the telemetry sensor process (sensord) of Juniper Networks Junos OS on MX240, MX480, MX960 platforms using MPC10E causes a …

Jul 10, 2024
CVE-2024-6286
7.8 HIGH

Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

Jul 10, 2024
CVE-2024-6236
7.5 HIGH

Denial of Service in NetScaler Console (formerly NetScaler ADM), NetScaler Agent, and NetScaler SDX

Jul 10, 2024
CVE-2024-6151
7.8 HIGH

Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Virtual Delivery Agent for Windows used by Citrix Virtual Apps and Desktops and …

Jul 10, 2024
CVE-2024-6148
8.8 HIGH

Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5

Jul 10, 2024
CVE-2024-39693
7.5 HIGH

Next.js is a React framework. A Denial of Service (DoS) condition was identified in Next.js. Exploitation of the bug can trigger a crash, affecting the …

Jul 10, 2024
CVE-2024-38354
8.1 HIGH

CodiMD allows realtime collaborative markdown notes on all platforms. The notebook feature of Hackmd.io permits the rendering of iframe `HTML` tags with an improperly sanitized …

Jul 10, 2024
CVE-2024-37149
7.2 HIGH

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated technician user …

Jul 10, 2024
CVE-2024-37148
8.1 HIGH

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can …

Jul 10, 2024
CVE-2024-6235
8.8 HIGH

Sensitive information disclosure in NetScaler Console

Jul 10, 2024
CVE-2024-5491
7.5 HIGH

Denial of Service in NetScaler ADC and NetScaler Gateway in NetScaler

Jul 10, 2024
CVE-2024-32469
7.1 HIGH

Decidim is a participatory democracy framework. The pagination feature used in searches and filters is subject to potential XSS attack through a malformed URL using …

Jul 10, 2024
CVE-2024-37115
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Automattic Newspack Blocks.This issue affects Newspack Blocks: from n/a through 3.0.8.

Jul 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.