CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-39020
6.3 MEDIUM

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/vpsApiData_deal.php?mudi=rev&nohrefStr=close

Jul 5, 2024
CVE-2024-39019
5.4 MEDIUM

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/idcProData_deal.php?mudi=del

Jul 5, 2024
CVE-2024-39174
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the Publish Article function of yzmcms v7.1 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Jul 5, 2024
CVE-2024-39178
5.4 MEDIUM

MyPower vc8100 V100R001C00B030 was discovered to contain an arbitrary file read vulnerability via the component /tcpdump/tcpdump.php?menu_uuid.

Jul 5, 2024
CVE-2024-39150
5.9 MEDIUM

vditor v.3.9.8 and before is vulnerable to Arbitrary file read via a crafted data packet.

Jul 5, 2024
CVE-2024-27717
6.5 MEDIUM

Cross Site Request Forgery vulnerability in Eskooly Free Online School Management Software v.3.0 and before allows a remote attacker to escalate privileges via the Token …

Jul 5, 2024
CVE-2024-27716
5.4 MEDIUM

Cross Site Scripting vulnerability in Eskooly Web Product v.3.0 and before allows a remote attacker to execute arbitrary code via the message sending and user …

Jul 5, 2024
CVE-2024-29318
5.4 MEDIUM

Volmarg Personal Management System 1.4.64 is vulnerable to stored cross site scripting (XSS) via upload of a SVG file with embedded javascript code.

Jul 5, 2024
CVE-2024-6505
6.8 MEDIUM

A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the indirections_table data within RSS …

Jul 5, 2024
CVE-2024-23588
5.3 MEDIUM

HCL Nomad server on Domino fails to properly handle users configured with limited Domino access resulting in a possible denial of service vulnerability.

Jul 5, 2024
CVE-2024-6524
5.5 MEDIUM

A vulnerability was found in ShopXO up to 6.1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

Jul 5, 2024
CVE-2024-39485
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: v4l: async: Properly re-initialise notifier entry in unregister The notifier_entry of a notifier is …

Jul 5, 2024
CVE-2024-39484
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mmc: davinci: Don't strip remove function when driver is builtin Using __exit for the remove …

Jul 5, 2024
CVE-2024-39483
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: WARN on vNMI + NMI window iff NMIs are outright masked When requesting …

Jul 5, 2024
CVE-2024-39482
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bcache: fix variable length array abuse in btree_iter btree_iter is used in two ways: either …

Jul 5, 2024
CVE-2024-39481
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: mc: Fix graph walk in media_pipeline_start The graph walk tries to follow all links, …

Jul 5, 2024
CVE-2024-39478
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Do not free stack buffer RSA text data uses variable length buffer …

Jul 5, 2024
CVE-2024-39477
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: do not call vma_add_reservation upon ENOMEM sysbot reported a splat [1] on __unmap_hugepage_range(). This …

Jul 5, 2024
CVE-2024-39476
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: md/raid5: fix deadlock that raid5d() wait for itself to clear MD_SB_CHANGE_PENDING Xiao reported that lvm2 …

Jul 5, 2024
CVE-2024-39475
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fbdev: savage: Handle err return when savagefb_check_var failed The commit 04e5eac8f3ab("fbdev: savage: Error out if …

Jul 5, 2024
CVE-2024-39474
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: fix vmalloc which may return null if called with __GFP_NOFAIL commit a421ef303008 ("mm: allow …

Jul 5, 2024
CVE-2024-39473
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-topology: Fix input format query of process modules without base extension If a …

Jul 5, 2024
CVE-2024-39472
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xfs: fix log recovery buffer allocation for the legacy h_size fixup Commit a70f9fe52daa ("xfs: detect …

Jul 5, 2024
CVE-2024-34481
6.1 MEDIUM

drupal-wiki.com Drupal Wiki before 8.31.1 allows XSS via comments, captions, and image titles of a Wiki page.

Jul 5, 2024
CVE-2024-32498
6.5 MEDIUM

An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external …

Jul 5, 2024
CVE-2024-37474
6.5 MEDIUM

Cross Site Scripting (XSS) vulnerability in Automattic Newspack Ads allows Stored XSS.This issue affects Newspack Ads: from n/a through 1.47.1.

Jul 4, 2024
CVE-2024-37476
6.5 MEDIUM

Cross Site Scripting (XSS) vulnerability in Automattic Newspack Campaigns allows Stored XSS.This issue affects Newspack Campaigns: from n/a through 2.31.1.

Jul 4, 2024
CVE-2024-39929
5.4 MEDIUM

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable …

Jul 4, 2024
CVE-2024-22277
6.4 MEDIUM

VMware Cloud Director Availability contains an HTML injection vulnerability. A malicious actor with network access to VMware Cloud Director Availability can craft malicious HTML tags …

Jul 4, 2024
CVE-2024-39211
5.3 MEDIUM

Kaiten 57.128.8 allows remote attackers to enumerate user accounts via a crafted POST request, because a login response contains a user_email field only if the …

Jul 4, 2024
CVE-2024-39884
6.2 MEDIUM

A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, …

Jul 4, 2024
CVE-2024-1574
6.7 MEDIUM

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in the licensing feature of Mitsubishi Electric GENESIS64 versions 10.97.2 and prior, Mitsubishi …

Jul 4, 2024
CVE-2024-1573
5.9 MEDIUM

Missing Authentication for Critical Function vulnerability in the mobile monitoring feature of Mitsubishi Electric GENESIS64 versions 10.97.2 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.2 …

Jul 4, 2024
CVE-2024-5641
6.4 MEDIUM

The One Click Order Re-Order plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ced_ocor_save_general_setting' function …

Jul 4, 2024
CVE-2024-3639
6.4 MEDIUM

The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Posts Grid widget in all versions up to, …

Jul 4, 2024
CVE-2024-3638
6.4 MEDIUM

The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Marquee Text Widget, Testimonials Widget, and Testimonial Slider …

Jul 4, 2024
CVE-2024-2926
6.4 MEDIUM

The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, …

Jul 4, 2024
CVE-2024-38471
6.8 MEDIUM

Multiple TP-LINK products allow a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by restoring a crafted backup file. The affected device, …

Jul 4, 2024
CVE-2024-38344
5.4 MEDIUM

A cross-site request forgery vulnerability exists in WP Tweet Walls versions prior to 1.0.4. If this vulnerability is exploited, an attacker allows a user who …

Jul 4, 2024
CVE-2024-6383
5.3 MEDIUM

The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow where the function might attempt to allocate too small of buffer …

Jul 3, 2024
CVE-2024-39683
5.7 MEDIUM

ZITADEL is an open-source identity infrastructure tool. ZITADEL provides users the ability to list all user sessions of the current user agent (browser). Starting in …

Jul 3, 2024
CVE-2024-37157
6.4 MEDIUM

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passed` branches, a malicious …

Jul 3, 2024
CVE-2024-36113
4.9 MEDIUM

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch, version 3.3.0.beta3 on the `beta` branch, and version 3.3.0.beta4-dev on the …

Jul 3, 2024
CVE-2024-35234
4.2 MEDIUM

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch, an attacker can execute …

Jul 3, 2024
CVE-2024-33870
6.3 MEDIUM

An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory …

Jul 3, 2024
CVE-2024-33869
5.3 MEDIUM

An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction …

Jul 3, 2024
CVE-2024-29510
6.3 MEDIUM

Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.

Jul 3, 2024
CVE-2024-29507
5.4 MEDIUM

Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.

Jul 3, 2024
CVE-2024-5821
6.2 MEDIUM

The vulnerability allows an attacker to access sensitive files on the server by confusing the agent with incorrect file names. When a user requests the …

Jul 3, 2024
CVE-2024-31223
5.3 MEDIUM

Fides is an open-source privacy engineering platform, and `SERVER_SIDE_FIDES_API_URL` is a server-side configuration environment variable used by the Fides Privacy Center to communicate with the …

Jul 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.