CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5169
4.8 MEDIUM

The Video Widget WordPress plugin through 1.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jun 26, 2024
CVE-2024-5071
6.5 MEDIUM

The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the …

Jun 26, 2024
CVE-2024-4959
4.8 MEDIUM

The Frontend Checklist WordPress plugin through 2.3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jun 26, 2024
CVE-2024-4957
4.3 MEDIUM

The Frontend Checklist WordPress plugin through 2.3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jun 26, 2024
CVE-2024-4106
5.3 MEDIUM

A vulnerability has been found in FAST/TOOLS and CI Server. The affected products have built-in accounts with no passwords set. Therefore, if the product is …

Jun 26, 2024
CVE-2024-4105
5.8 MEDIUM

A vulnerability has been found in FAST/TOOLS and CI Server. The affected product's WEB HMI server's function to process HTTP requests has a security flaw …

Jun 26, 2024
CVE-2024-3633
5.4 MEDIUM

The WebP & SVG Support WordPress plugin through 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role as low as …

Jun 26, 2024
CVE-2024-34580
5.3 MEDIUM

Apache XML Security for C++ through 2.0.4 implements the XML Signature Syntax and Processing (XMLDsig) specification without protection against an SSRF payload in a KeyInfo …

Jun 26, 2024
CVE-2024-21520
6.1 MEDIUM

Versions of the package djangorestframework before 3.15.2 are vulnerable to Cross-site Scripting (XSS) via the break_long_headers template filter due to improper input sanitization before splitting …

Jun 26, 2024
CVE-2024-37139
6.5 MEDIUM

Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an Improper Control of a Resource Through its Lifetime vulnerability in …

Jun 26, 2024
CVE-2024-37138
4.1 MEDIUM

Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 on DDMC contain a relative path traversal vulnerability. A remote high privileged …

Jun 26, 2024
CVE-2024-27867
4.3 MEDIUM

An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 6A326, AirPods Firmware Update 6F8, and Beats Firmware …

Jun 26, 2024
CVE-2024-29175
5.9 MEDIUM

Dell PowerProtect Data Domain, versions prior to 7.13.0.0, LTS 7.7.5.40, LTS 7.10.1.30 contain an weak cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit …

Jun 26, 2024
CVE-2024-29174
4.4 MEDIUM

Dell Data Domain, versions prior to 7.13.0.0, LTS 7.7.5.30, LTS 7.10.1.20 contain an SQL Injection vulnerability. A local low privileged attacker could potentially exploit this …

Jun 26, 2024
CVE-2024-29173
6.8 MEDIUM

Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a Server-Side Request Forgery (SSRF) vulnerability. A remote high privileged attacker …

Jun 26, 2024
CVE-2024-28973
5.9 MEDIUM

Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a Stored Cross-Site Scripting Vulnerability. A remote high privileged attacker could …

Jun 26, 2024
CVE-2024-5173
6.4 MEDIUM

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video player widget settings in all …

Jun 26, 2024
CVE-2024-29954
5.9 MEDIUM

A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e prints sensitive information in log files. This …

Jun 26, 2024
CVE-2024-29953
4.3 MEDIUM

A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric …

Jun 26, 2024
CVE-2024-30931
6.1 MEDIUM

Stored Cross Site Scripting vulnerability in Emby Media Server Emby Media Server 4.8.3.0 allows a remote attacker to escalate privileges via the notifications.html component.

Jun 25, 2024
CVE-2024-30112
5.4 MEDIUM

HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of …

Jun 25, 2024
CVE-2024-5019
5.3 MEDIUM

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Arbitrary File Read issue exists in Wug.UI.Areas.Wug.Controllers.SessionController.CachedCSS. This vulnerability allows reading of any file with iisapppool\NmConsole …

Jun 25, 2024
CVE-2024-5018
5.3 MEDIUM

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Path Traversal vulnerability exists Wug.UI.Areas.Wug.Controllers.SessionController.LoadNMScript. This allows allows reading of any file from the applications web-root …

Jun 25, 2024
CVE-2024-5017
6.5 MEDIUM

In WhatsUp Gold versions released before 2023.1.3, a path traversal vulnerability exists. A specially crafted unauthenticated HTTP request to AppProfileImport can lead can lead to …

Jun 25, 2024
CVE-2024-35526
5.9 MEDIUM

An issue in Daemon PTY Limited FarCry Core framework before 7.2.14 allows attackers to access sensitive information in the /facade directory.

Jun 25, 2024
CVE-2024-34400
6.1 MEDIUM

An issue was discovered in VirtoSoftware Virto Kanban Board Web Part before 5.3.5.1 for SharePoint 2019. There is /_layouts/15/Virto.KanbanTaskManager/api/KanbanData.ashx LinkTitle2 XSS.

Jun 25, 2024
CVE-2024-21739
5.3 MEDIUM

Geehy APM32F103CCT6, APM32F103RCT6, APM32F103RCT7, and APM32F103VCT6 devices have Incorrect Access Control.

Jun 25, 2024
CVE-2024-37894
6.3 MEDIUM

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Out-of-bounds Write error when assigning ESI variables, Squid …

Jun 25, 2024
CVE-2024-37167
4.3 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users are able to see backlog items that they should not …

Jun 25, 2024
CVE-2024-37820
5.4 MEDIUM

A nil pointer dereference in PingCAP TiDB v8.2.0-alpha-216-gfe5858b allows attackers to crash the application via expression.inferCollation.

Jun 25, 2024
CVE-2024-36819
5.4 MEDIUM

MAP-OS 4.45.0 and earlier is vulnerable to Cross-Site Scripting (XSS). This vulnerability allows malicious users to insert a malicious payload into the "Client Name" input. …

Jun 25, 2024
CVE-2024-0171
5.3 MEDIUM

Dell PowerEdge Server BIOS contains an TOCTOU race condition vulnerability. A local low privileged attacker could potentially exploit this vulnerability to gain access to otherwise …

Jun 25, 2024
CVE-2024-39470
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: eventfs: Fix a possible null pointer dereference in eventfs_find_events() In function eventfs_find_events,there is a potential …

Jun 25, 2024
CVE-2024-39468
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix deadlock in smb2_find_smb_tcon() Unlock cifs_tcp_ses_lock before calling cifs_put_smb_ses() to avoid such deadlock.

Jun 25, 2024
CVE-2024-39466
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: thermal/drivers/qcom/lmh: Check for SCM availability at probe Up until now, the necessary scm availability check …

Jun 25, 2024
CVE-2024-39465
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: mgb4: Fix double debugfs remove Fixes an error where debugfs_remove_recursive() is called first on …

Jun 25, 2024
CVE-2024-39464
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: v4l: async: Fix notifier list entry init struct v4l2_async_notifier has several list_head members, but …

Jun 25, 2024
CVE-2024-39461
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: clk: bcm: rpi: Assign ->num before accessing ->hws Commit f316cdff8d67 ("clk: Annotate struct clk_hw_onecell_data with …

Jun 25, 2024
CVE-2024-39371
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring: check for non-NULL file pointer in io_file_can_poll() In earlier kernels, it was possible to …

Jun 25, 2024
CVE-2024-39301
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/9p: fix uninit-value in p9_client_rpc() Syzbot with the help of KMSAN reported the following error: …

Jun 25, 2024
CVE-2024-39298
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/memory-failure: fix handling of dissolved but not taken off from buddy pages When I did …

Jun 25, 2024
CVE-2024-39296
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bonding: fix oops during rmmod "rmmod bonding" causes an oops ever since commit cc317ea3d927 ("bonding: …

Jun 25, 2024
CVE-2024-39293
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Revert "xsk: Support redirect to any socket bound to the same umem" This reverts commit …

Jun 25, 2024
CVE-2024-39276
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: fix mb_cache_entry's e_refcnt leak in ext4_xattr_block_cache_find() Syzbot reports a warning as follows: ============================================ WARNING: …

Jun 25, 2024
CVE-2024-38661
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: s390/ap: Fix crash in AP internal function modify_bitmap() A system crash like this Failing address: …

Jun 25, 2024
CVE-2024-38385
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: genirq/irqdesc: Prevent use-after-free in irq_find_at_or_after() irq_find_at_or_after() dereferences the interrupt descriptor which is returned by mt_find() …

Jun 25, 2024
CVE-2024-38306
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: protect folio::private when attaching extent buffer folios [BUG] Since v6.8 there are rare kernel …

Jun 25, 2024
CVE-2024-37354
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix crash on racing fsync and size-extending write into prealloc We have been seeing …

Jun 25, 2024
CVE-2024-37087
5.3 MEDIUM

The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition.

Jun 25, 2024
CVE-2024-37086
6.8 MEDIUM

VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot may trigger an …

Jun 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.