CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-37085
6.8 MEDIUM KEV

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that …

Jun 25, 2024
CVE-2022-48772
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: lgdt3306a: Add a check against null-pointer-def The driver should check whether the client provides …

Jun 25, 2024
CVE-2024-5451
6.4 MEDIUM

The The7 — Website and eCommerce Builder for WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the plugin's …

Jun 25, 2024
CVE-2024-38951
6.5 MEDIUM

A buffer overflow in PX4-Autopilot v1.12.3 allows attackers to cause a Denial of Service (DoS) via a crafted MavLink message.

Jun 25, 2024
CVE-2024-32111
5.0 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic WordPress allows Relative Path Traversal.This issue affects WordPress: from 6.5 through …

Jun 25, 2024
CVE-2024-6301
5.3 MEDIUM

Lack of validation of origin in federation API in Conduit, allowing any remote server to impersonate any user from any server in most EDUs

Jun 25, 2024
CVE-2024-6299
4.8 MEDIUM

Lack of consideration of key expiry when validating signatures in Conduit, allowing an attacker which has compromised an expired key to forge requests as the …

Jun 25, 2024
CVE-2024-4846
6.3 MEDIUM

Authentication bypass in the 2FA feature in Devolutions Server 2024.1.14.0 and earlier allows an authenticated attacker to authenticate to another user without being asked for …

Jun 25, 2024
CVE-2024-31111
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic WordPress allows Stored XSS.This issue affects WordPress: from 6.5 through …

Jun 25, 2024
CVE-2024-28832
4.8 MEDIUM

Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users with permission to change Global Settings …

Jun 25, 2024
CVE-2024-28831
5.4 MEDIUM

Stored XSS in some confirmation pop-ups in Checkmk before versions 2.3.0p7 and 2.2.0p28 allows Checkmk users to execute arbitrary scripts by injecting HTML elements into …

Jun 25, 2024
CVE-2024-6307
6.4 MEDIUM

WordPress Core is vulnerable to Stored Cross-Site Scripting via the HTML API in various versions prior to 6.5.5 due to insufficient input sanitization and output …

Jun 25, 2024
CVE-2024-4641
6.3 MEDIUM

OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format string from an external source as an …

Jun 25, 2024
CVE-2024-34142
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to …

Jun 25, 2024
CVE-2024-34141
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to …

Jun 25, 2024
CVE-2024-3249
4.3 MEDIUM

The Zita Elementor Site Library plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the import_xml_data, xml_data_import, …

Jun 25, 2024
CVE-2024-4759
5.5 MEDIUM

The Mime Types Extended WordPress plugin through 0.11 does not sanitise uploaded SVG files, which could allow users with a role as low as Author …

Jun 25, 2024
CVE-2024-22385
4.4 MEDIUM

Incorrect Default Permissions vulnerability in Hitachi Storage Provider for VMware vCenter allows local users to read and write specific files.This issue affects Hitachi Storage Provider …

Jun 25, 2024
CVE-2023-45195
5.3 MEDIUM

Adminer and AdminerEvo are vulnerable to SSRF via database connection fields. This could allow an unauthenticated remote attacker to enumerate or access systems the attacker …

Jun 24, 2024
CVE-2024-38903
4.1 MEDIUM

H3C Magic R230 V100R002's udpserver opens port 9034, allowing attackers to execute arbitrary commands.

Jun 24, 2024
CVE-2024-38897
5.3 MEDIUM

WAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information.

Jun 24, 2024
CVE-2024-38896
5.3 MEDIUM

WAVLINK WN551K1 found a command injection vulnerability through the start_hour parameter of /cgi-bin/nightled.cgi.

Jun 24, 2024
CVE-2024-38895
5.3 MEDIUM

WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information.

Jun 24, 2024
CVE-2024-38894
5.3 MEDIUM

WAVLINK WN551K1 found a command injection vulnerability through the IP parameter of /cgi-bin/touchlist_sync.cgi.

Jun 24, 2024
CVE-2024-38892
6.5 MEDIUM

An issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh component.

Jun 24, 2024
CVE-2024-37681
6.5 MEDIUM

An issue the background management system of Shanxi Internet Chuangxiang Technology Co., Ltd v1.0.1 allows a remote attacker to cause a denial of service via …

Jun 24, 2024
CVE-2024-37678
5.3 MEDIUM

Cross Site Scripting vulnerability in Hangzhou Meisoft Information Technology Co., Ltd. Finesoft v.8.0 and before allows a remote attacker to execute arbitrary code via a …

Jun 24, 2024
CVE-2024-34312
6.1 MEDIUM

Virtual Programming Lab for Moodle up to v4.2.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component vplide.js.

Jun 24, 2024
CVE-2024-37732
6.1 MEDIUM

Cross Site Scripting vulnerability in Anchor CMS v.0.12.7 allows a remote attacker to execute arbitrary code via a crafted .pdf file.

Jun 24, 2024
CVE-2024-37680
6.1 MEDIUM

Hangzhou Meisoft Information Technology Co., Ltd. FineSoft <=8.0 is affected by Cross Site Scripting (XSS) which allows remote attackers to execute arbitrary code. Enter any …

Jun 24, 2024
CVE-2024-37679
6.1 MEDIUM

Cross Site Scripting vulnerability in Hangzhou Meisoft Information Technology Co., Ltd. Finesoft v.8.0 and before allows a remote attacker to execute arbitrary code via a …

Jun 24, 2024
CVE-2021-45785
6.5 MEDIUM

TruDesk Help Desk/Ticketing Solution v1.1.11 is vulnerable to a Cross-Site Request Forgery (CSRF) attack which would allow an attacker to restart the server, causing a …

Jun 24, 2024
CVE-2023-49793
6.5 MEDIUM

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Zip files uploaded to the server endpoint …

Jun 24, 2024
CVE-2024-6104
6.0 MEDIUM

go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth …

Jun 24, 2024
CVE-2024-33881
5.3 MEDIUM

An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows an NTLMv2 hash leak via a …

Jun 24, 2024
CVE-2024-33880
5.3 MEDIUM

An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. It discloses full pathnames via Virto.SharePoint.FileDownloader/Api/Download.ashx?action=archive.

Jun 24, 2024
CVE-2024-39292
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: um: Add winch to winch_handlers before registering winch IRQ Registering a winch IRQ is racy, …

Jun 24, 2024
CVE-2024-38663
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix list corruption from resetting io stat Since commit 3b8cc6298724 ("blk-cgroup: Optimize blkcg_rstat_flush()"), each …

Jun 24, 2024
CVE-2024-37825
5.4 MEDIUM

An issue in EnvisionWare Computer Access & Reservation Control SelfCheck v1.0 (fixed in OneStop 3.2.0.27184 Hotfix May 2024) allows unauthenticated attackers on the same network …

Jun 24, 2024
CVE-2024-37026
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Only use reserved BCS instances for usm migrate exec queue The GuC context scheduling …

Jun 24, 2024
CVE-2024-37021
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fpga: manager: add owner module and take its refcount The current implementation of the fpga …

Jun 24, 2024
CVE-2024-36479
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fpga: bridge: add owner module and take its refcount The current implementation of the fpga …

Jun 24, 2024
CVE-2024-35247
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fpga: region: add owner module and take its refcount The current implementation of the fpga …

Jun 24, 2024
CVE-2024-34030
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI: of_property: Return error for int_map allocation failure Return -ENOMEM from of_pci_prop_intr_map() if kcalloc() fails …

Jun 24, 2024
CVE-2024-33847
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: don't allow unaligned truncation on released compress inode f2fs image may be corrupted …

Jun 24, 2024
CVE-2024-32936
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: ti: j721e-csi2rx: Fix races while restarting DMA After the frame is submitted to DMA, …

Jun 24, 2024
CVE-2024-3264
5.3 MEDIUM

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Mia Technology Inc. Mia-Med Health Aplication allows Signature Spoofing by Improper Validation.This issue affects Mia-Med …

Jun 24, 2024
CVE-2024-37233
4.3 MEDIUM

Improper Authentication vulnerability in Play.Ht allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Play.Ht: from n/a through 3.6.4.

Jun 24, 2024
CVE-2024-36038
6.3 MEDIUM

Zoho ManageEngine ITOM products versions from 128234 to 128248 are affected by the stored cross-site scripting vulnerability in the proxy server option.

Jun 24, 2024
CVE-2024-4754
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Next4Biz CRM & BPM Software Business Process Manangement (BPM) allows Stored XSS.This issue …

Jun 24, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.