CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-2819
5.1 MEDIUM

Incorrect Default Permissions, Improper Preservation of Permissions vulnerability in Hitachi Ops Center Common Services allows File Manipulation.This issue affects Hitachi Ops Center Common Services: before …

Jul 2, 2024
CVE-2024-39314
4.7 MEDIUM

toy-blog is a headless content management system implementation. Starting in version 0.4.3 and prior to version 0.5.0, the administrative password was leaked through the command …

Jul 1, 2024
CVE-2024-39313
6.5 MEDIUM

toy-blog is a headless content management system implementation. Starting in version 0.5.4 and prior to version 0.6.1, articles with private visibility can be read if …

Jul 1, 2024
CVE-2024-39310
5.4 MEDIUM

The Basil recipe theme for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the `post_title` parameter in versions up to, and including, 2.0.4 due …

Jul 1, 2024
CVE-2024-37764
5.4 MEDIUM

MachForm up to version 19 is affected by an authenticated stored cross-site scripting.

Jul 1, 2024
CVE-2024-37763
5.4 MEDIUM

MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can view compiled forms results.

Jul 1, 2024
CVE-2024-23737
5.4 MEDIUM

Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Jira allows attackers to allows attackers to manipulate a user's S/MIME certificate of …

Jul 1, 2024
CVE-2024-39305
6.5 MEDIUM

Envoy is a cloud-native, open source edge and service proxy. Prior to versions 1.30.4, 1.29.7, 1.28.5, and 1.27.7. Envoy references already freed memory when route …

Jul 1, 2024
CVE-2024-32228
6.6 MEDIUM

FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end.

Jul 1, 2024
CVE-2024-39303
4.4 MEDIUM

Weblate is a web based localization tool. Prior to version 5.6.2, Weblate didn't correctly validate filenames when restoring project backup. It may be possible to …

Jul 1, 2024
CVE-2024-37146
6.1 MEDIUM

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting …

Jul 1, 2024
CVE-2024-37145
6.1 MEDIUM

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting …

Jul 1, 2024
CVE-2024-36423
6.1 MEDIUM

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting …

Jul 1, 2024
CVE-2024-36387
5.4 MEDIUM

Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.

Jul 1, 2024
CVE-2024-39879
5.0 MEDIUM

In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings

Jul 1, 2024
CVE-2024-39878
4.1 MEDIUM

In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection

Jul 1, 2024
CVE-2024-36996
5.3 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109, an attacker could determine whether or not another user …

Jul 1, 2024
CVE-2024-36995
5.4 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold …

Jul 1, 2024
CVE-2024-36994
5.4 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold …

Jul 1, 2024
CVE-2024-36993
5.4 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold …

Jul 1, 2024
CVE-2024-36992
5.4 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold …

Jul 1, 2024
CVE-2024-36990
6.5 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.2.2403.100, an authenticated, low-privileged user that does not hold the …

Jul 1, 2024
CVE-2024-36987
4.3 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, an authenticated, low-privileged user who does not hold the …

Jul 1, 2024
CVE-2024-36986
6.3 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, an authenticated user could run risky commands …

Jul 1, 2024
CVE-2024-20399
6.0 MEDIUM KEV

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root …

Jul 1, 2024
CVE-2024-36422
6.1 MEDIUM

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting …

Jul 1, 2024
CVE-2024-6375
5.4 MEDIUM

A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading …

Jul 1, 2024
CVE-2024-34696
4.5 MEDIUM

GeoServer is an open source server that allows users to share and edit geospatial data. Starting in version 2.10.0 and prior to versions 2.24.4 and …

Jul 1, 2024
CVE-2024-21482
6.8 MEDIUM

Memory corruption during the secure boot process, when the `bootm` command is used, it bypasses the authentication of the kernel/rootfs image.

Jul 1, 2024
CVE-2024-21466
6.5 MEDIUM

Information disclosure while parsing sub-IE length during new IE generation.

Jul 1, 2024
CVE-2024-21458
6.5 MEDIUM

Information disclosure while handling SA query action frame.

Jul 1, 2024
CVE-2024-21457
6.5 MEDIUM

INformation disclosure while handling Multi-link IE in beacon frame.

Jul 1, 2024
CVE-2024-21456
6.5 MEDIUM

Information Disclosure while parsing beacon frame in STA.

Jul 1, 2024
CVE-2024-6050
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation vulnerability in SOKRATES-software SOWA OPAC allows a Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into …

Jul 1, 2024
CVE-2024-38953
6.1 MEDIUM

phpok 6.4.003 contains a Cross Site Scripting (XSS) vulnerability in the ok_f() method under the framework/api/upload_control.php file.

Jul 1, 2024
CVE-2024-39853
6.5 MEDIUM

adolph_dudu ratio-swiper 0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39018
6.3 MEDIUM

harvey-woo cat5th/key-serializer v0.2.5 was discovered to contain a prototype pollution via the function "query". This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39002
6.3 MEDIUM

rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function util.clone. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39001
6.3 MEDIUM

ag-grid-enterprise v31.3.2 was discovered to contain a prototype pollution via the component _ModuleSupport.jsonApply. This vulnerability allows attackers to execute arbitrary code or cause a Denial …

Jul 1, 2024
CVE-2024-39000
6.5 MEDIUM

adolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-38997
6.5 MEDIUM

adolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function extendDefaults. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-38990
6.3 MEDIUM

Tada5hi sp-common v0.5.4 was discovered to contain a prototype pollution via the function mergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-38987
6.3 MEDIUM

aofl cli-lib v3.14.0 was discovered to contain a prototype pollution via the component defaultsDeep. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39430
5.1 MEDIUM

In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jul 1, 2024
CVE-2024-39429
5.1 MEDIUM

In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jul 1, 2024
CVE-2024-39428
6.8 MEDIUM

In trusty service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jul 1, 2024
CVE-2024-39427
5.1 MEDIUM

In trusty service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jul 1, 2024
CVE-2024-6130
4.8 MEDIUM

The Form Maker by 10Web WordPress plugin before 1.15.26 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jul 1, 2024
CVE-2024-4934
5.5 MEDIUM

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 does not validate and escape some of its Quiz fields before outputting them back in …

Jul 1, 2024
CVE-2024-3122
4.9 MEDIUM

CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remote attackers with administrator privilege to read arbitrary file …

Jul 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.