CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-40819
6.1 MEDIUM

ID4Portais in version < V.2022.837.002a returns message parameter unsanitized in the response, resulting in a HTML Injection vulnerability.

Aug 6, 2024
CVE-2024-7531
6.5 MEDIUM

Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In …

Aug 6, 2024
CVE-2024-7529
6.5 MEDIUM

The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability …

Aug 6, 2024
CVE-2024-7526
6.5 MEDIUM

ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnerability affects …

Aug 6, 2024
CVE-2024-7524
6.1 MEDIUM

Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by Content Security Policy in "strict-dynamic" …

Aug 6, 2024
CVE-2024-7518
6.5 MEDIUM

Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affects Firefox …

Aug 6, 2024
CVE-2024-6359
6.4 MEDIUM

Privilege escalation vulnerability identified in OpenText ArcSight Intelligence.

Aug 6, 2024
CVE-2024-6358
6.3 MEDIUM

Incorrect Authorization vulnerability identified in OpenText ArcSight Intelligence.

Aug 6, 2024
CVE-2024-6357
6.3 MEDIUM

Insecure Direct Object Reference vulnerability identified in OpenText ArcSight Intelligence.

Aug 6, 2024
CVE-2024-7317
6.4 MEDIUM

The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG …

Aug 6, 2024
CVE-2024-7246
5.3 MEDIUM

It's possible for a gRPC client communicating with a HTTP/2 proxy to poison the HPACK table between the proxy and the backend such that other …

Aug 6, 2024
CVE-2024-7084
4.8 MEDIUM

The Ajax Search Lite WordPress plugin before 4.12.1 does not sanitise and escape some parameters, which could allow users with a role as low as …

Aug 6, 2024
CVE-2024-7082
6.1 MEDIUM

The Easy Table of Contents WordPress plugin before 2.0.68 does not sanitise and escape some parameters, which could allow users with a role as low …

Aug 6, 2024
CVE-2024-7055
6.3 MEDIUM

A vulnerability was found in FFmpeg up to 7.0.1. It has been classified as critical. This affects the function pnm_decode_frame in the library /libavcodec/pnmdec.c. The …

Aug 6, 2024
CVE-2024-6766
5.4 MEDIUM

The shortcodes-ultimate-pro WordPress plugin before 7.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the …

Aug 6, 2024
CVE-2024-6651
6.1 MEDIUM

The WordPress File Upload WordPress plugin before 4.24.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Aug 6, 2024
CVE-2024-6201
5.3 MEDIUM

HaloITSM versions up to 2.146.1 are affected by a Template Injection vulnerability within the engine used to generate emails. This can lead to the leakage …

Aug 6, 2024
CVE-2024-5708
6.4 MEDIUM

The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in all versions up to, and including, 7.7 …

Aug 6, 2024
CVE-2024-7506
6.3 MEDIUM

A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Aug 6, 2024
CVE-2024-39817
6.5 MEDIUM

Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to the …

Aug 6, 2024
CVE-2024-7500
6.3 MEDIUM

A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been rated as critical. Affected by this issue is the function save_settings of …

Aug 6, 2024
CVE-2024-7009
4.2 MEDIUM

Unsanitized user-input in Calibre <= 7.15.0 allow users with permissions to perform full-text searches to achieve SQL injection on the SQLite database.

Aug 6, 2024
CVE-2024-7008
5.4 MEDIUM

Unsanitized user-input in Calibre <= 7.15.0 allow attackers to perform reflected cross-site scripting.

Aug 6, 2024
CVE-2024-28962
6.5 MEDIUM

Dell Command | Update, Dell Update, and Alienware Update UWP, versions prior to 5.4, contain an Exposed Dangerous Method or Function vulnerability. An unauthenticated attacker …

Aug 6, 2024
CVE-2024-7499
6.3 MEDIUM

A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Aug 6, 2024
CVE-2024-5963
6.7 MEDIUM

Unquoted Executable Path vulnerability in Hitachi Device Manager on Windows (Device Manager Server component).This issue affects Hitachi Device Manager: before 8.8.7-00.

Aug 6, 2024
CVE-2024-7497
6.3 MEDIUM

A vulnerability was found in itsourcecode Airline Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/index.php. The …

Aug 6, 2024
CVE-2024-7496
6.3 MEDIUM

A vulnerability has been found in itsourcecode Airline Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file /index.php. The …

Aug 6, 2024
CVE-2024-7495
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Laravel Accounting System 1.0. This affects an unknown part of the file app/Http/Controllers/HomeController.php. The …

Aug 6, 2024
CVE-2024-7537
5.5 MEDIUM

oFono QMI SMS Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. Authentication is …

Aug 6, 2024
CVE-2024-7494
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Clinics Patient Management System 1.0. Affected by this issue is some unknown functionality …

Aug 5, 2024
CVE-2024-34343
6.3 MEDIUM

Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. The `navigateTo` function attempts to blockthe `javascript:` protocol, but …

Aug 5, 2024
CVE-2024-41958
6.6 MEDIUM

mailcow: dockerized is an open source groupware/email suite based on docker. A vulnerability has been discovered in the two-factor authentication (2FA) mechanism. This flaw allows …

Aug 5, 2024
CVE-2024-41820
6.0 MEDIUM

Kubean is a cluster lifecycle management toolchain based on kubespray and other cluster LCM engine. The ClusterRole has `*` verbs of `*` resources. If a …

Aug 5, 2024
CVE-2024-41816
5.4 MEDIUM

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the ‘[cooked-timer]’ shortcode in versions …

Aug 5, 2024
CVE-2024-6361
5.4 MEDIUM

Improper Neutralization vulnerability (XSS) has been discovered in OpenText™ ALM Octane. The vulnerability affects all version prior to version 23.4. The vulnerability could cause remote …

Aug 5, 2024
CVE-2024-41381
6.1 MEDIUM

microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php.

Aug 5, 2024
CVE-2024-41380
6.1 MEDIUM

microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_tagging_tagged.php.

Aug 5, 2024
CVE-2024-41200
5.5 MEDIUM

A segmentation fault in KMPlayer v4.2.2.65 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file.

Aug 5, 2024
CVE-2024-21978
6.0 MEDIUM

Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption.

Aug 5, 2024
CVE-2023-31355
6.0 MEDIUM

Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially allowing reading of memory from …

Aug 5, 2024
CVE-2024-23357
6.2 MEDIUM

Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.

Aug 5, 2024
CVE-2024-23350
6.5 MEDIUM

Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integrity check has failed, and the other is …

Aug 5, 2024
CVE-2024-21467
6.5 MEDIUM

Information disclosure while handling beacon probe frame during scan entry generation in client side.

Aug 5, 2024
CVE-2024-21459
6.5 MEDIUM

Information disclosure while handling beacon or probe response frame in STA.

Aug 5, 2024
CVE-2024-6710
5.4 MEDIUM

The Ditty WordPress plugin before 3.1.45 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to …

Aug 5, 2024
CVE-2024-6498
4.8 MEDIUM

The Chatbot for WordPress by Collect.chat ⚡️ WordPress plugin before 2.4.4 does not sanitise and escape some of its settings, which could allow high privilege …

Aug 5, 2024
CVE-2024-6270
4.8 MEDIUM

The Community Events WordPress plugin before 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Aug 5, 2024
CVE-2024-5081
6.1 MEDIUM

The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Aug 5, 2024
CVE-2024-3636
5.4 MEDIUM

The Pinpoint Booking System WordPress plugin before 2.9.9.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Aug 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.