CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-38470
6.1 MEDIUM

zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /own.php.

Jun 17, 2024
CVE-2024-38469
6.3 MEDIUM

zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /pay.php.

Jun 17, 2024
CVE-2024-37625
6.1 MEDIUM

zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /index.php.

Jun 17, 2024
CVE-2024-37624
6.1 MEDIUM

Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /chajian/inputChajian.php. component.

Jun 17, 2024
CVE-2024-37623
6.1 MEDIUM

Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /kaoqin/tpl_kaoqin_locationchange.html component.

Jun 17, 2024
CVE-2024-37622
6.1 MEDIUM

Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the num parameter at /flow/flow.php.

Jun 17, 2024
CVE-2024-37620
6.1 MEDIUM

PHPVOD v4.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /view/admin/view.php.

Jun 17, 2024
CVE-2024-37619
6.1 MEDIUM

StrongShop v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the spec_group_id parameter at /spec/index.blade.php.

Jun 17, 2024
CVE-2024-6055
4.7 MEDIUM

Improper removal of sensitive information in data source export feature in Devolutions Remote Desktop Manager 2024.1.32.0 and earlier on Windows allows an attacker that obtains …

Jun 17, 2024
CVE-2024-5741
6.5 MEDIUM

Stored XSS in inventory tree rendering in Checkmk before 2.3.0p7, 2.2.0p28, 2.1.0p45 and 2.0.0 (EOL)

Jun 17, 2024
CVE-2024-36289
5.3 MEDIUM

Reusing a nonce, key pair in encryption issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. If …

Jun 17, 2024
CVE-2024-36279
5.3 MEDIUM

Reliance on obfuscation or encryption of security-relevant inputs without integrity checking issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for …

Jun 17, 2024
CVE-2024-36277
5.3 MEDIUM

Improper verification of cryptographic signature issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. The affected app …

Jun 17, 2024
CVE-2024-4305
6.8 MEDIUM

The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.1.0 does not validate and escape some of its block options before outputting …

Jun 17, 2024
CVE-2024-3236
5.4 MEDIUM

The Popup Builder WordPress plugin before 1.1.33 does not sanitise and escape some of its Notification fields, which could allow users such as contributor and …

Jun 17, 2024
CVE-2024-6044
6.5 MEDIUM

Certain models of D-Link wireless routers have a path traversal vulnerability. Unauthenticated attackers on the same local area network can read arbitrary system files by …

Jun 17, 2024
CVE-2024-6041
6.3 MEDIUM

A vulnerability was found in itsourcecode Gym Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jun 16, 2024
CVE-2024-6039
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Feng Office 3.11.1.2. Affected is an unknown function of the component Workspaces. The manipulation of …

Jun 16, 2024
CVE-2023-27636
5.4 MEDIUM

Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.

Jun 16, 2024
CVE-2024-38465
5.3 MEDIUM

Shenzhen Guoxin Synthesis image system before 8.3.0 allows username enumeration because of the response discrepancy of incorrect versus error.

Jun 16, 2024
CVE-2024-38460
4.9 MEDIUM

In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL …

Jun 16, 2024
CVE-2024-38454
6.1 MEDIUM

ExpressionEngine before 7.4.11 allows XSS.

Jun 16, 2024
CVE-2024-38443
6.2 MEDIUM

C/sorting/binary_insertion_sort.c in The Algorithms - C through e5dad3f has a segmentation fault for deep recursion, which may affect common use cases such as sorting an …

Jun 16, 2024
CVE-2024-36397
6.1 MEDIUM

Vantiva - MediaAccess DGA2232 v19.4 - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Jun 16, 2024
CVE-2024-38394
4.3 MEDIUM

Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kernel's underlying device matching logic allow a physically proximate …

Jun 16, 2024
CVE-2024-6016
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in itsourcecode Online Laundry Management System 1.0. Affected by this issue is some unknown functionality …

Jun 15, 2024
CVE-2024-6015
6.3 MEDIUM

A vulnerability classified as critical was found in itsourcecode Online House Rental System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jun 15, 2024
CVE-2024-6014
6.3 MEDIUM

A vulnerability classified as critical has been found in itsourcecode Document Management System 1.0. Affected is an unknown function of the file edithis.php. The manipulation …

Jun 15, 2024
CVE-2024-6013
6.3 MEDIUM

A vulnerability was found in itsourcecode Online Book Store 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Jun 15, 2024
CVE-2024-6009
6.3 MEDIUM

A vulnerability has been found in itsourcecode Event Calendar 1.0 and classified as critical. Affected by this vulnerability is the function regConfirm/regDelete of the file …

Jun 15, 2024
CVE-2024-6008
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Online Book Store up to 1.0. Affected is an unknown function of the file …

Jun 15, 2024
CVE-2024-6007
6.3 MEDIUM

A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /protocol/iscgwtunnel/deleteiscgwrouteconf.php. The …

Jun 15, 2024
CVE-2024-5611
6.4 MEDIUM

The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘label_years’ attribute within the Countdown widget in all versions …

Jun 15, 2024
CVE-2024-5858
4.3 MEDIUM

The AI Infographic Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the qcld_openai_title_generate_desc AJAX action …

Jun 15, 2024
CVE-2024-4551
6.4 MEDIUM

The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and …

Jun 15, 2024
CVE-2024-4095
6.4 MEDIUM

The Collapse-O-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'expand' and 'expandsub' shortcode in all versions up to, and including, …

Jun 15, 2024
CVE-2024-2695
6.4 MEDIUM

The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortcode in all versions up to, and including, 4.6.13 …

Jun 15, 2024
CVE-2024-1399
6.4 MEDIUM

The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all …

Jun 15, 2024
CVE-2024-5868
6.5 MEDIUM

The WooCommerce - Social Login plugin for WordPress is vulnerable to Email Verification in all versions up to, and including, 2.6.2 via the use of …

Jun 15, 2024
CVE-2024-5263
6.4 MEDIUM

The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Motion Text and Table widgets in all versions up to, …

Jun 15, 2024
CVE-2024-4479
6.4 MEDIUM

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sg_general_toggle_tab_enable and sg_accordion_style attributes within the plugin's JKit - Tabs …

Jun 15, 2024
CVE-2024-3815
5.5 MEDIUM

The Newspaper theme for WordPress is vulnerable to Stored Cross-Site Scripting via attachment meta in the archive page in all versions up to, and including, …

Jun 15, 2024
CVE-2024-3814
5.5 MEDIUM

The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'single' module in all versions up to, and including, 4.8 …

Jun 15, 2024
CVE-2024-21988
5.3 MEDIUM

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible to disclosure of sensitive information via complex MiTM attacks due to a vulnerability …

Jun 14, 2024
CVE-2024-37889
6.5 MEDIUM

MyFinances is a web application for managing finances. MyFinances has a way to access other customer invoices while signed in as a user. This method …

Jun 14, 2024
CVE-2024-37888
6.1 MEDIUM

The Open Link is a CKEditor plugin, extending context menu with a possibility to open link in a new tab. The vulnerability allowed to execute …

Jun 14, 2024
CVE-2024-36599
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

Jun 14, 2024
CVE-2024-5659
6.5 MEDIUM

Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fault(MNRF/Assert). This …

Jun 14, 2024
CVE-2024-37886
5.4 MEDIUM

user_oidc app is an OpenID Connect user backend for Nextcloud. An attacker could potentially trick the app into accepting a request that is not signed …

Jun 14, 2024
CVE-2024-37883
4.3 MEDIUM

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A user with access to …

Jun 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.