CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6680
6.3 MEDIUM

A vulnerability classified as critical was found in witmy my-springsecurity-plus up to 2024-07-04. Affected by this vulnerability is an unknown functionality of the file /api/dept/build. …

Jul 11, 2024
CVE-2024-39905
5.3 MEDIUM

Red is a fully modular Discord bot. Due to a bug in Red's Core API, 3rd-party cogs using the `@commands.can_manage_channel()` command permission check without additional …

Jul 11, 2024
CVE-2024-39528
5.7 MEDIUM

A Use After Free vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated, network-based attacker …

Jul 11, 2024
CVE-2024-39519
6.5 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX7000 Series allows …

Jul 11, 2024
CVE-2024-39317
6.5 MEDIUM

Wagtail is an open source content management system built on Django. A bug in Wagtail's `parse_query_string` would result in it taking a long time to …

Jul 11, 2024
CVE-2024-6679
6.3 MEDIUM

A vulnerability classified as critical has been found in witmy my-springsecurity-plus up to 2024-07-04. Affected is an unknown function of the file /api/role. The manipulation …

Jul 11, 2024
CVE-2024-37151
5.3 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Mishandling of multiple fragmented packets using the same IP ID …

Jul 11, 2024
CVE-2024-6035
6.1 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410. This vulnerability allows an attacker to inject malicious JavaScript code into the chat history …

Jul 11, 2024
CVE-2024-6528
5.4 MEDIUM

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a vulnerability leading to a cross-site scripting condition where …

Jul 11, 2024
CVE-2024-38433
6.7 MEDIUM

Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton …

Jul 11, 2024
CVE-2024-6256
6.4 MEDIUM

The Feeds for YouTube (YouTube video, channel, and gallery plugin) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'youtube-feed' shortcode in …

Jul 11, 2024
CVE-2024-5257
4.9 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer …

Jul 11, 2024
CVE-2024-6138
4.8 MEDIUM

The Secure Copy Content Protection and Content Locking WordPress plugin before 4.0.9 does not sanitise and escape some of its settings, which could allow high …

Jul 11, 2024
CVE-2024-6026
5.4 MEDIUM

The Slider by 10Web WordPress plugin before 1.2.56 does not sanitise and escape some of its Slide options, which could allow authenticated users with access …

Jul 11, 2024
CVE-2024-6025
5.4 MEDIUM

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.5 does not sanitise and escape some of its Quiz settings, which could allow contributors and …

Jul 11, 2024
CVE-2024-5444
5.4 MEDIUM

The Bible Text WordPress plugin through 0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Jul 11, 2024
CVE-2024-4655
5.4 MEDIUM

The Ultimate Blocks WordPress plugin before 3.1.9 does not validate and escape some of its block options before outputting them back in a page/post where …

Jul 11, 2024
CVE-2024-6554
5.3 MEDIUM

The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and …

Jul 11, 2024
CVE-2024-0619
5.3 MEDIUM

The Payflex Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the payment_callback() function in …

Jul 11, 2024
CVE-2024-6676
6.3 MEDIUM

A vulnerability has been found in witmy my-springsecurity-plus up to 2024-07-03 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Jul 11, 2024
CVE-2024-6210
5.3 MEDIUM

The Duplicator plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 1.5.9. This makes it possible for unauthenticated attackers …

Jul 11, 2024
CVE-2024-23485
4.6 MEDIUM

Improperly Preserved Integrity of Hardware Configuration State During a Power Save/Restore Operation (CWE-1304) in the Controller 6000 and 7000 can lead to secured door locks …

Jul 11, 2024
CVE-2024-23317
6.3 MEDIUM

External Control of File Name or Path (CWE-73) in the Controller 6000 and Controller 7000 allows an attacker with local access to the Controller to …

Jul 11, 2024
CVE-2024-22387
6.8 MEDIUM

External Control of Critical State Data (CWE-642) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated user to modify device I/O …

Jul 11, 2024
CVE-2016-15039
6.3 MEDIUM

A vulnerability classified as critical was found in mhuertos phpLDAPadmin up to 665dbc2690ebeb5392d38f1fece0a654225a0b38. Affected by this vulnerability is the function makeHttpRequest of the file htdocs/js/ajax_functions.js. …

Jul 11, 2024
CVE-2024-6652
6.3 MEDIUM

A vulnerability was found in itsourcecode Gym Management System 1.0. It has been classified as critical. This affects an unknown part of the file manage_member.php. …

Jul 10, 2024
CVE-2024-39561
5.8 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX4600 and SRX5000 Series allows …

Jul 10, 2024
CVE-2024-39560
6.5 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a logically …

Jul 10, 2024
CVE-2024-39559
5.9 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS Evolved may allow a network-based unauthenticated attacker to …

Jul 10, 2024
CVE-2024-39558
6.5 MEDIUM

An Unchecked Return Value vulnerability in the Routing Protocol Daemon (rpd) on Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows a logically …

Jul 10, 2024
CVE-2024-39557
6.5 MEDIUM

An Uncontrolled Resource Consumption vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS Evolved allows an unauthenticated, adjacent attacker to …

Jul 10, 2024
CVE-2024-39556
6.4 MEDIUM

A Stack-Based Buffer Overflow vulnerability in Juniper Networks Junos OS and Juniper Networks Junos OS Evolved may allow a local, low-privileged attacker with access to …

Jul 10, 2024
CVE-2024-39554
5.9 MEDIUM

A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Juniper Networks …

Jul 10, 2024
CVE-2024-39517
6.5 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Layer 2 Address Learning Daemon (l2ald) on Juniper Networks Junos OS and Junos OS …

Jul 10, 2024
CVE-2024-39514
6.5 MEDIUM

An Improper Check or Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos and Junos OS Evolved allows an …

Jul 10, 2024
CVE-2024-39513
5.5 MEDIUM

An Improper Input Validation vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved allows a local, low-privileged attacker to cause a …

Jul 10, 2024
CVE-2024-39512
6.6 MEDIUM

An Improper Physical Access Control vulnerability in the console port control of Juniper Networks Junos OS Evolved allows an attacker with physical access to the …

Jul 10, 2024
CVE-2024-39511
5.5 MEDIUM

An Improper Input Validation vulnerability in the 802.1X Authentication (dot1x) Daemon of Juniper Networks Junos OS allows a local, low-privileged attacker with access to the …

Jul 10, 2024
CVE-2024-6150
4.3 MEDIUM

A non-admin user can cause short-term disruption in Target VM availability in Citrix Provisioning

Jul 10, 2024
CVE-2024-6149
6.1 MEDIUM

Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5

Jul 10, 2024
CVE-2024-38353
5.3 MEDIUM

CodiMD allows realtime collaborative markdown notes on all platforms. CodiMD before 2.5.4 is missing authentication and access control vulnerability allowing an unauthenticated attacker to gain …

Jul 10, 2024
CVE-2024-25076
6.8 MEDIUM

An issue was discovered on Renesas SmartBond DA14691, DA14695, DA14697, and DA14699 devices. The bootrom function responsible for validating the Flash Product Header directly uses …

Jul 10, 2024
CVE-2024-6649
4.3 MEDIUM

A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is the …

Jul 10, 2024
CVE-2024-5913
6.1 MEDIUM

An improper input validation vulnerability in Palo Alto Networks PAN-OS software enables an attacker with the ability to tamper with the physical file system to …

Jul 10, 2024
CVE-2024-5911
4.9 MEDIUM

An arbitrary file upload vulnerability in Palo Alto Networks Panorama software enables an authenticated read-write administrator with access to the web interface to disrupt system …

Jul 10, 2024
CVE-2024-5492
6.1 MEDIUM

Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway

Jul 10, 2024
CVE-2024-37147
4.3 MEDIUM

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can …

Jul 10, 2024
CVE-2024-27095
5.4 MEDIUM

Decidim is a participatory democracy framework. The admin panel is subject to potential XSS attach in case the attacker manages to modify some records being …

Jul 10, 2024
CVE-2024-27090
5.3 MEDIUM

Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. If an …

Jul 10, 2024
CVE-2024-6647
4.7 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Croogo up to 4.0.7. This affects an unknown part of the …

Jul 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.