CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5970
6.4 MEDIUM

The MaxGalleria plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's maxgallery_thumb shortcode in all versions up to, and including, 6.4.4 due …

Jun 18, 2024
CVE-2024-6128
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in spa-cartcms 1.9.0.6. This issue affects some unknown processing of the file /checkout of the …

Jun 18, 2024
CVE-2024-38277
5.4 MEDIUM

A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between …

Jun 18, 2024
CVE-2024-38274
6.1 MEDIUM

Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt.

Jun 18, 2024
CVE-2024-38273
5.4 MEDIUM

Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.

Jun 18, 2024
CVE-2024-36977
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: Wait unconditionally after issuing EndXfer command Currently all controller IP/revisions except DWC3_usb3 >= …

Jun 18, 2024
CVE-2024-36976
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Revert "media: v4l2-ctrls: show all owned controls in log_status" This reverts commit 9801b5b28c6929139d6fceeee8d739cc67bb2739. This patch …

Jun 18, 2024
CVE-2024-36975
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Do not use WARN when encode fails When asn1_encode_sequence() fails, WARN is not …

Jun 18, 2024
CVE-2024-37791
6.0 MEDIUM

DuxCMS3 v3.1.3 was discovered to contain a SQL injection vulnerability via the keyword parameter at /article/Content/index?class_id.

Jun 18, 2024
CVE-2024-38351
5.4 MEDIUM

Pocketbase is an open source web backend written in go. In affected versions a malicious user may be able to compromise other user accounts. In …

Jun 18, 2024
CVE-2024-37904
5.7 MEDIUM

Minder is an open source Software Supply Chain Security Platform. Minder's Git provider is vulnerable to a denial of service from a maliciously configured GitHub …

Jun 18, 2024
CVE-2024-37803
5.4 MEDIUM

Multiple stored cross-site scripting (XSS) vulnerabilities in CodeProjects Health Care hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a …

Jun 18, 2024
CVE-2024-37800
6.1 MEDIUM

CodeProjects Restaurant Reservation System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Date parameter at index.php.

Jun 18, 2024
CVE-2024-37799
5.4 MEDIUM

CodeProjects Restaurant Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the reserv_id parameter at view_reservations.php.

Jun 18, 2024
CVE-2024-21685
6.5 MEDIUM

This High severity Information Disclosure vulnerability was introduced in versions 9.4.0, 9.12.0, and 9.15.0 of Jira Core Data Center. This Information Disclosure vulnerability, with a …

Jun 18, 2024
CVE-2024-6109
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jun 18, 2024
CVE-2024-38506
6.3 MEDIUM

In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows

Jun 18, 2024
CVE-2024-38505
5.3 MEDIUM

In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site

Jun 18, 2024
CVE-2024-38504
4.3 MEDIUM

In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles

Jun 18, 2024
CVE-2024-6108
4.3 MEDIUM

A vulnerability was found in Genexis Tilgin Home Gateway 322_AS0500-03_05_13_05. It has been classified as problematic. Affected is an unknown function of the file /vood/cgi-bin/vood_view.cgi?act=index&lang=EN# …

Jun 18, 2024
CVE-2024-5953
5.7 MEDIUM

A denial of service vulnerability was found in the 389-ds-base LDAP server. This issue may allow an authenticated user to cause a server denial of …

Jun 18, 2024
CVE-2024-5533
6.4 MEDIUM

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.25.1 due to insufficient input sanitization and …

Jun 18, 2024
CVE-2024-5172
4.8 MEDIUM

The Expert Invoice WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jun 18, 2024
CVE-2024-4094
5.4 MEDIUM

The Simple Share Buttons Adder WordPress plugin before 8.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jun 18, 2024
CVE-2024-3276
4.8 MEDIUM

The Lightbox & Modal Popup WordPress Plugin WordPress plugin before 2.7.28, foobox-image-lightbox-premium WordPress plugin before 2.7.28 does not sanitise and escape some of its settings, …

Jun 18, 2024
CVE-2024-34024
6.3 MEDIUM

Observable response discrepancy issue exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, an unauthenticated remote attacker may determine …

Jun 18, 2024
CVE-2024-33622
6.5 MEDIUM

Missing authentication for critical function vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, sensitive information may be …

Jun 18, 2024
CVE-2024-0066
5.3 MEDIUM

Johan Fagerström, member of the AXIS OS Bug Bounty Program, has found that a O3C feature may expose sensitive traffic between the client (Axis device) …

Jun 18, 2024
CVE-2024-5860
4.3 MEDIUM

The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the tc_dl_delete_tickets …

Jun 18, 2024
CVE-2024-5541
5.3 MEDIUM

The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ibtana_visual_editor_register_ajax_json_endpont' …

Jun 18, 2024
CVE-2024-4375
6.4 MEDIUM

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_layer' shortcode in all versions up …

Jun 18, 2024
CVE-2024-1634
6.5 MEDIUM

The Scheduling Plugin – Online Booking for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on …

Jun 18, 2024
CVE-2024-0845
6.4 MEDIUM

The PDF Viewer for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the render function in all versions up to, and including, …

Jun 18, 2024
CVE-2024-6083
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPVibe 11.0.46. Affected is an unknown function of the file /app/uploading/upload-mp3.php of the component Media …

Jun 18, 2024
CVE-2024-6067
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Music Class Enrollment System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jun 17, 2024
CVE-2024-6066
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. Affected is an unknown function of the file payment_report.php. …

Jun 17, 2024
CVE-2024-6064
5.3 MEDIUM

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been declared as problematic. This vulnerability affects the function xmt_node_end of the file src/scene_manager/loader_xmt.c of the …

Jun 17, 2024
CVE-2024-37828
4.8 MEDIUM

A stored cross-site scripting (XSS) in Vermeg Agile Reporter v23.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Jun 17, 2024
CVE-2024-37798
5.9 MEDIUM

Cross-site scripting (XSS) vulnerability in search-appointment.php in the Admin Panel in Phpgurukul Beauty Parlour Management System 1.0 allows remote attackers to inject arbitrary web script …

Jun 17, 2024
CVE-2024-37895
5.7 MEDIUM

Lobe Chat is an open-source LLMs/AI chat framework. In affected versions if an attacker can successfully authenticate through SSO/Access Code, they can obtain the real …

Jun 17, 2024
CVE-2024-37893
5.9 MEDIUM

Firefly III is a free and open source personal finance manager. In affected versions an MFA bypass in the Firefly III OAuth flow may allow …

Jun 17, 2024
CVE-2024-37891
4.4 MEDIUM

urllib3 is a user-friendly HTTP client library for Python. When using urllib3's proxy support with `ProxyManager`, the `Proxy-Authorization` header is only sent to the configured …

Jun 17, 2024
CVE-2024-37664
5.2 MEDIUM

Redmi router RB03 v1.0.57 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack …

Jun 17, 2024
CVE-2024-37663
4.1 MEDIUM

Redmi router RB03 v1.0.57 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic …

Jun 17, 2024
CVE-2024-37662
6.3 MEDIUM

TP-LINK TL-7DR5130 v1.0.23 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the …

Jun 17, 2024
CVE-2024-37661
6.3 MEDIUM

TP-LINK TL-7DR5130 v1.0.23 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic between …

Jun 17, 2024
CVE-2024-36527
6.5 MEDIUM

puppeteer-renderer v.3.2.0 and before is vulnerable to Directory Traversal. Attackers can exploit the URL parameter using the file protocol to read sensitive information from the …

Jun 17, 2024
CVE-2018-25103
5.3 MEDIUM

There exists use-after-free vulnerabilities in lighttpd <= 1.4.50 request parsing which might read from invalid pointers to memory used in the same request, not from …

Jun 17, 2024
CVE-2024-36578
5.9 MEDIUM

akbr update 1.0.0 is vulnerable to Prototype Pollution via update/index.js.

Jun 17, 2024
CVE-2024-36574
6.3 MEDIUM

A Prototype Pollution issue in flatten-json 1.0.1 allows an attacker to execute arbitrary code via module.exports.unflattenJSON (flatten-json/index.js:42)

Jun 17, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.