CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-38480
4.0 MEDIUM

"Piccoma" App for Android and iOS versions prior to 6.20.0 uses a hard-coded API key for an external service, which may allow a local attacker …

Jul 1, 2024
CVE-2024-20081
6.7 MEDIUM

In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with …

Jul 1, 2024
CVE-2024-20079
6.7 MEDIUM

In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with …

Jul 1, 2024
CVE-2024-6419
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Medicine Tracker System 1.0. This vulnerability affects unknown code of the file /classes/Master.php?f=save_medicine. The manipulation of …

Jul 1, 2024
CVE-2024-6417
6.3 MEDIUM

A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Jun 30, 2024
CVE-2024-6416
6.3 MEDIUM

A vulnerability was found in SeaCMS 12.9. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /js/player/dmplayer/dmku/?ac=edit. …

Jun 30, 2024
CVE-2024-28794
5.4 MEDIUM

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …

Jun 30, 2024
CVE-2023-50964
5.4 MEDIUM

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …

Jun 30, 2024
CVE-2024-31898
5.4 MEDIUM

IBM InfoSphere Information Server 11.7 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references. IBM …

Jun 30, 2024
CVE-2024-28797
6.4 MEDIUM

IBM InfoSphere Information Server 11.7 is vulnerable stored to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …

Jun 30, 2024
CVE-2023-50953
5.4 MEDIUM

IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could …

Jun 30, 2024
CVE-2023-50952
5.4 MEDIUM

IBM InfoSphere Information Server 11.7 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, …

Jun 30, 2024
CVE-2024-35119
5.3 MEDIUM

IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in a stack …

Jun 30, 2024
CVE-2024-31902
4.3 MEDIUM

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a …

Jun 30, 2024
CVE-2023-50954
4.3 MEDIUM

IBM InfoSphere Information Server 11.7 returns sensitive information in URL information that could be used in further attacks against the system. IBM X-Force ID: 275776.

Jun 30, 2024
CVE-2024-5062
6.1 MEDIUM

A reflected Cross-Site Scripting (XSS) vulnerability was identified in zenml-io/zenml version 0.57.1. The vulnerability exists due to improper neutralization of input during web page generation, …

Jun 30, 2024
CVE-2024-28795
5.4 MEDIUM

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …

Jun 30, 2024
CVE-2024-6414
5.3 MEDIUM

A vulnerability classified as problematic has been found in Parsec Automation TrakSYS 11.x.x. Affected is an unknown function of the file TS/export/contentpage of the component …

Jun 30, 2024
CVE-2023-4017
6.1 MEDIUM

The Goya theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘attra-color’, 'attra-size', and 'product-cata' parameters in versions up to, and including, 1.0.8.7 …

Jun 29, 2024
CVE-2024-5819
6.4 MEDIUM

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to DOM-based Stored Cross-Site Scripting via HTML data …

Jun 29, 2024
CVE-2024-6363
6.4 MEDIUM

The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's stock_ticker shortcode in all versions up to, and including, 3.24.4 …

Jun 29, 2024
CVE-2024-5790
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attribute within the plugin's Gradient Heading widget in …

Jun 29, 2024
CVE-2024-5666
6.4 MEDIUM

The Extensions for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the EE Button widget in all versions …

Jun 29, 2024
CVE-2024-5942
4.3 MEDIUM

The Page and Post Clone plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0 via the …

Jun 29, 2024
CVE-2024-5889
6.1 MEDIUM

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘country’ parameter in all versions …

Jun 29, 2024
CVE-2024-5192
6.4 MEDIUM

The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells plugin for WordPress is …

Jun 29, 2024
CVE-2024-6405
6.1 MEDIUM

The Floating Social Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to …

Jun 29, 2024
CVE-2024-39828
6.1 MEDIUM

R74n Sandboxels 1.9 through 1.9.5 allows XSS via a message in a modified saved-game file. This was fixed in a hotfix to 1.9.5 on 2024-06-29.

Jun 28, 2024
CVE-2024-38533
6.5 MEDIUM

ZKsync Era is a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. There is possible invalid stack access due to the addresses used …

Jun 28, 2024
CVE-2024-38518
4.6 MEDIUM

BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker with a valid join link to a meeting can …

Jun 28, 2024
CVE-2024-29040
4.3 MEDIUM

This repository hosts source code implementing the Trusted Computing Group's (TCG) TPM2 Software Stack (TSS). The JSON Quote Info returned by Fapi_Quote has to be …

Jun 28, 2024
CVE-2024-38322
5.3 MEDIUM

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 agent username and password error response discrepancy exposes product to brute force enumeration. IBM X-Force ID: …

Jun 28, 2024
CVE-2024-35156
6.5 MEDIUM

IBM MQ 9.3 LTS and 9.3 CD could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in …

Jun 28, 2024
CVE-2024-35116
5.9 MEDIUM

IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, and 9.3 CD is vulnerable to a denial of service attack caused by an error …

Jun 28, 2024
CVE-2024-25053
5.9 MEDIUM

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is vulnerable to improper certificate validation when using the IBM Planning Analytics Data …

Jun 28, 2024
CVE-2024-25041
5.4 MEDIUM

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is potentially vulnerable to cross site scripting (XSS). A remote attacker could execute …

Jun 28, 2024
CVE-2024-25031
6.5 MEDIUM

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 uses an inadequate account lockout setting that could allow an attacker on the network to brute …

Jun 28, 2024
CVE-2022-38383
4.0 MEDIUM

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Software Suite 1.10.12.0 through 1.10.21.0 allows web pages to be stored locally which …

Jun 28, 2024
CVE-2024-35155
6.5 MEDIUM

IBM MQ Console 9.3 LTS and 9.3 CD could disclose could allow a remote attacker to obtain sensitive information when a detailed technical error message …

Jun 28, 2024
CVE-2024-31919
5.9 MEDIUM

IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD, in certain configurations, is vulnerable to a denial of service attack caused …

Jun 28, 2024
CVE-2024-6403
6.5 MEDIUM

A vulnerability, which was classified as critical, has been found in Tenda A301 15.13.08.12. Affected by this issue is the function formWifiBasicSet of the file …

Jun 28, 2024
CVE-2024-6402
6.5 MEDIUM

A vulnerability classified as critical was found in Tenda A301 15.13.08.12. Affected by this vulnerability is the function fromSetWirelessRepeat of the file /goform/SetOnlineDevName. The manipulation …

Jun 28, 2024
CVE-2024-38522
6.3 MEDIUM

Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. The CSP policy applied on the `tips.hushline.app` website and bundled by default in …

Jun 28, 2024
CVE-2024-35139
6.2 MEDIUM

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from the container due to incorrect default permissions. …

Jun 28, 2024
CVE-2024-35137
6.2 MEDIUM

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. …

Jun 28, 2024
CVE-2024-29038
4.3 MEDIUM

tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by …

Jun 28, 2024
CVE-2024-3801
6.1 MEDIUM

Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in one of GET header parameters. Only a part …

Jun 28, 2024
CVE-2024-3800
6.1 MEDIUM

Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in requested file names. Only a part of observed …

Jun 28, 2024
CVE-2024-37741
5.4 MEDIUM

OpenPLC 3 through 9cd8f1b allows XSS via an SVG document as a profile picture.

Jun 28, 2024
CVE-2024-5737
6.1 MEDIUM

Script afGdStream.php in AdmirorFrames Joomla! extension doesn’t specify a content type and as a result default (text/html) is used. An attacker may embed HTML tags …

Jun 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.