CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-3332
6.5 MEDIUM

A malicious BLE device can send a specific order of packet sequence to cause a DoS attack on the victim BLE device

Jul 3, 2024
CVE-2024-39248
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in SimpCMS v0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title …

Jul 3, 2024
CVE-2024-6052
6.5 MEDIUM

Stored XSS in Checkmk before versions 2.3.0p8, 2.2.0p29, 2.1.0p45, and 2.0.0 (EOL) allows users to execute arbitrary scripts by injecting HTML elements

Jul 3, 2024
CVE-2024-39220
6.5 MEDIUM

BAS-IP AV-01D, AV-01MD, AV-01MFD, AV-01ED, AV-01KD, AV-01BD, AV-01KBD, AV-02D, AV-02IDE, AV-02IDR, AV-02IPD, AV-02FDE, AV-02FDR, AV-03D, AV-03BD, AV-04AFD, AV-04ASD, AV-04FD, AV-04SD, AV-05FD, AV-05SD, AA-07BD, AA-07BDI, BA-04BD, …

Jul 3, 2024
CVE-2024-6471
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Online Tours & Travels Management 1.0. This affects an unknown part of the file sms_setting.php. …

Jul 3, 2024
CVE-2024-37726
6.8 MEDIUM

Insecure Permissions vulnerability in Micro-Star International Co., Ltd MSI Center v.2.0.36.0 allows a local attacker to escalate privileges via the Export System Info function in …

Jul 3, 2024
CVE-2024-6428
5.3 MEDIUM

Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when creating a new user which allows …

Jul 3, 2024
CVE-2024-6340
6.4 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and …

Jul 3, 2024
CVE-2024-6263
6.4 MEDIUM

The WP Lightbox 2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 3.0.6.6 …

Jul 3, 2024
CVE-2024-4482
6.4 MEDIUM

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jul 3, 2024
CVE-2024-2375
5.4 MEDIUM

The WPQA Builder WordPress plugin before 6.1.1 does not sanitise and escape some of its Slider settings, which could allow high privilege users such as …

Jul 3, 2024
CVE-2024-2235
4.3 MEDIUM

The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make users vote on any polls, …

Jul 3, 2024
CVE-2024-2234
5.4 MEDIUM

The Himer WordPress theme before 2.1.1 does not sanitise and escape some of its Post settings, which could allow high privilege users such as Contributor …

Jul 3, 2024
CVE-2024-2233
4.3 MEDIUM

The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted …

Jul 3, 2024
CVE-2024-2231
6.5 MEDIUM

The allows any authenticated user to join a private group due to a missing authorization check on a function

Jul 3, 2024
CVE-2024-2040
4.3 MEDIUM

The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make users join private groups via …

Jul 3, 2024
CVE-2024-4543
4.3 MEDIUM

The Snippet Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.1.4. This is due to missing …

Jul 3, 2024
CVE-2024-39920
4.3 MEDIUM

The TCP protocol in RFC 9293 has a timing side channel that makes it easier for remote attackers to infer the content of one TCP …

Jul 3, 2024
CVE-2024-32673
5.5 MEDIUM

Improper Validation of Array Index vulnerability in Samsung Open Source Walrus Webassembly runtime engine allows a segmentation fault issue. This issue affects Walrus: before 72c7230f32a0b791355bbdfc78669701024b0956.

Jul 3, 2024
CVE-2024-6453
6.3 MEDIUM

A vulnerability was found in itsourcecode Farm Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jul 2, 2024
CVE-2024-39326
4.4 MEDIUM

SkillTree is a micro-learning gamification platform. Prior to version 2.12.6, the endpoint `/admin/projects/{projectname}/skills/{skillname}/video` (and probably others) is open to a cross-site request forgery (CSRF) vulnerability. …

Jul 2, 2024
CVE-2024-39325
5.3 MEDIUM

aimeos/ai-controller-frontend is the Aimeos frontend controller. Prior to versions 2024.04.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15, aimeos/ai-controller-frontend doesn't reset the payment status of a user's basket …

Jul 2, 2024
CVE-2024-39322
5.5 MEDIUM

aimeos/ai-admin-jsonadm is the Aimeos e-commerce JSON API for administrative tasks. In versions prior to 2020.10.13, 2021.10.6, 2022.10.3, 2023.10.4, and 2024.4.2, improper access control allows editors …

Jul 2, 2024
CVE-2024-6452
6.3 MEDIUM

A vulnerability classified as critical was found in linlinjava litemall up to 1.8.0. Affected by this vulnerability is an unknown functionality of the file AdminGoodscontroller.java. …

Jul 2, 2024
CVE-2024-39315
5.7 MEDIUM

Pomerium is an identity and context-aware access proxy. Prior to version 0.26.1, the Pomerium user info page (at `/.pomerium`) unintentionally included serialized OAuth2 access and …

Jul 2, 2024
CVE-2022-25479
5.5 MEDIUM

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 allows for …

Jul 2, 2024
CVE-2022-25477
5.5 MEDIUM

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 leaks driver …

Jul 2, 2024
CVE-2024-6382
6.4 MEDIUM

Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. …

Jul 2, 2024
CVE-2024-6381
4.0 MEDIUM

The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at …

Jul 2, 2024
CVE-2024-39891
5.3 MEDIUM KEV

In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, …

Jul 2, 2024
CVE-2024-5866
5.0 MEDIUM

Vulnerability in Delinea Centrify PAS v. 21.3 and possibly others. The application is prone to the path traversal vulnerability allowing listing of arbitrary directory outside …

Jul 2, 2024
CVE-2024-39316
6.5 MEDIUM

Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.5, Regular Expression Denial of Service (ReDoS) vulnerability exists …

Jul 2, 2024
CVE-2024-25087
5.5 MEDIUM

Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.7.0 allows local attackers to cause a Windows blue screen error.

Jul 2, 2024
CVE-2024-22105
5.5 MEDIUM

Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error.

Jul 2, 2024
CVE-2024-32932
6.8 MEDIUM

Under certain circumstances the web interface users credentials may be recovered by an authenticated user.

Jul 2, 2024
CVE-2024-22104
5.5 MEDIUM

Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS).

Jul 2, 2024
CVE-2024-22103
5.5 MEDIUM

Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS).

Jul 2, 2024
CVE-2024-22102
5.5 MEDIUM

Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error.

Jul 2, 2024
CVE-2023-51778
5.5 MEDIUM

Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS).

Jul 2, 2024
CVE-2023-51777
5.5 MEDIUM

Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error.

Jul 2, 2024
CVE-2024-39143
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in ResidenceCMS 2.10.1 that allows a low-privilege user to create malicious property content with HTML inside which acts …

Jul 2, 2024
CVE-2024-32757
6.8 MEDIUM

Under certain circumstances unnecessary user details are provided within system logs

Jul 2, 2024
CVE-2024-32756
6.8 MEDIUM

Under certain circumstances the Linux users credentials may be recovered by an authenticated user.

Jul 2, 2024
CVE-2024-39119
5.4 MEDIUM

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/info_deal.php?mudi=rev&nohrefStr=close.

Jul 2, 2024
CVE-2024-6441
6.3 MEDIUM

A vulnerability was found in ORIPA up to 1.72. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

Jul 2, 2024
CVE-2024-6440
6.3 MEDIUM

A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0. It has been classified as critical. Affected is an unknown function of the …

Jul 2, 2024
CVE-2024-6439
6.3 MEDIUM

A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0 and classified as critical. This issue affects some unknown processing of the file …

Jul 2, 2024
CVE-2024-6438
6.3 MEDIUM

A vulnerability has been found in Hitout Carsale 1.0 and classified as critical. This vulnerability affects unknown code of the file OrderController.java. The manipulation of …

Jul 2, 2024
CVE-2024-6264
6.4 MEDIUM

The Post Meta Data Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$meta_key’ parameter in all versions up to, and including, …

Jul 2, 2024
CVE-2024-6099
5.3 MEDIUM

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthenticated bypass to user registration in versions up to, and including, 4.2.6.8.1. This …

Jul 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.