CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-37317
4.6 MEDIUM

The Nextcloud Notes app is a distraction free notes taking app for Nextcloud. If an attacker managed to share a folder called `Notes/` with a …

Jun 14, 2024
CVE-2024-37316
4.6 MEDIUM

Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachment data leading to a bad redirect for participants …

Jun 14, 2024
CVE-2024-33373
6.3 MEDIUM

An issue in the LB-LINK BL-W1210M v2.0 router allows attackers to bypass password complexity requirements and set single digit passwords for authentication. This vulnerability can …

Jun 14, 2024
CVE-2024-37312
6.3 MEDIUM

user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access control on the ID4me endpoint allows an attacker to register an account eventually …

Jun 14, 2024
CVE-2024-36656
6.1 MEDIUM

In MintHCM 4.0.3, a registered user can execute arbitrary JavaScript code and achieve a reflected Cross-site Scripting (XSS) attack.

Jun 14, 2024
CVE-2024-23442
6.1 MEDIUM

An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously …

Jun 14, 2024
CVE-2024-5731
6.8 MEDIUM

A vulnerability in the IPS Manager, Central Manager, and Local Manager communication workflow allows an attacker to control the destination of a request by manipulating …

Jun 14, 2024
CVE-2024-2023
4.3 MEDIUM

The Folders and Folders Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0 in Folders and 3.0.2 …

Jun 14, 2024
CVE-2023-51376
4.3 MEDIUM

Missing Authorization vulnerability in Brainstorm Force ProjectHuddle Client Site.This issue affects ProjectHuddle Client Site: from n/a through 1.0.34.

Jun 14, 2024
CVE-2024-34012
4.4 MEDIUM

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.24135.272.

Jun 14, 2024
CVE-2024-4863
6.4 MEDIUM

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘titleFont’ parameter …

Jun 14, 2024
CVE-2024-37182
4.7 MEDIUM

Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over …

Jun 14, 2024
CVE-2024-25142
5.5 MEDIUM

Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow. Airflow did not return "Cache-Control" header for dynamic content, which in case of …

Jun 14, 2024
CVE-2024-5465
5.9 MEDIUM

Function vulnerabilities in the Calendar module Impact: Successful exploitation of this vulnerability will affect availability.

Jun 14, 2024
CVE-2024-5464
4.0 MEDIUM

Vulnerability of insufficient permission verification in the NearLink module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jun 14, 2024
CVE-2024-36501
5.6 MEDIUM

Memory management vulnerability in the boottime module Impact: Successful exploitation of this vulnerability can affect integrity.

Jun 14, 2024
CVE-2024-36499
6.8 MEDIUM

Vulnerability of unauthorized screenshot capturing in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jun 14, 2024
CVE-2024-5994
6.4 MEDIUM

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom JS option in versions up to, …

Jun 14, 2024
CVE-2024-5155
6.1 MEDIUM

The Inquiry cart WordPress plugin through 3.4.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Jun 14, 2024
CVE-2024-4751
4.3 MEDIUM

The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Jun 14, 2024
CVE-2024-4480
6.1 MEDIUM

The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its email settings, which could allow attackers to …

Jun 14, 2024
CVE-2024-4271
4.6 MEDIUM

The SVGator WordPress plugin through 1.2.6 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious …

Jun 14, 2024
CVE-2024-4270
5.4 MEDIUM

The SVGMagic WordPress plugin through 1.1 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious …

Jun 14, 2024
CVE-2024-4005
4.8 MEDIUM

The Social Pixel WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jun 14, 2024
CVE-2024-3993
4.6 MEDIUM

The AZAN Plugin WordPress plugin through 0.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Jun 14, 2024
CVE-2024-3992
4.8 MEDIUM

The Amen WordPress plugin through 3.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jun 14, 2024
CVE-2024-3978
5.4 MEDIUM

The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post …

Jun 14, 2024
CVE-2024-3977
4.8 MEDIUM

The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jun 14, 2024
CVE-2024-3972
4.3 MEDIUM

The Similarity WordPress plugin through 3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Jun 14, 2024
CVE-2024-3971
4.3 MEDIUM

The Similarity WordPress plugin through 3.0 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged …

Jun 14, 2024
CVE-2024-3966
6.1 MEDIUM

The Pray For Me WordPress plugin through 1.0.4 does not sanitise and escape some parameters, which could unauthenticated visitors to perform Cross-Site Scripting attacks that …

Jun 14, 2024
CVE-2024-3965
5.4 MEDIUM

The Pray For Me WordPress plugin through 1.0.4 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Jun 14, 2024
CVE-2024-3754
4.7 MEDIUM

The Alemha watermarker WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jun 14, 2024
CVE-2024-2218
4.6 MEDIUM

The LuckyWP Table of Contents WordPress plugin through 2.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jun 14, 2024
CVE-2024-2122
6.4 MEDIUM

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via album gallery custom URLs in all versions up …

Jun 14, 2024
CVE-2024-23504
5.3 MEDIUM

Missing Authorization vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through 5.0.5.

Jun 14, 2024
CVE-2024-1295
6.5 MEDIUM

The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking …

Jun 14, 2024
CVE-2023-51497
5.4 MEDIUM

Missing Authorization vulnerability in Woo WooCommerce Ship to Multiple Addresses.This issue affects WooCommerce Ship to Multiple Addresses: from n/a through 3.8.9.

Jun 14, 2024
CVE-2023-51496
5.3 MEDIUM

Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.2.7.

Jun 14, 2024
CVE-2023-51495
6.5 MEDIUM

Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.2.7.

Jun 14, 2024
CVE-2023-51377
5.3 MEDIUM

Missing Authorization vulnerability in WPEverest Everest Forms.This issue affects Everest Forms: from n/a through 2.0.3.

Jun 14, 2024
CVE-2024-31160
4.8 MEDIUM

The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can …

Jun 14, 2024
CVE-2024-31159
4.8 MEDIUM

The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can …

Jun 14, 2024
CVE-2024-27180
6.7 MEDIUM

An attacker with admin access can install rogue applications. As for the affected products/models/versions, see the reference URL.

Jun 14, 2024
CVE-2024-27179
4.7 MEDIUM

Admin cookies are written in clear-text in logs. An attacker can retrieve them and bypass the authentication mechanism. As for the affected products/models/versions, see the …

Jun 14, 2024
CVE-2024-27175
4.4 MEDIUM

Remote Command program allows an attacker to read any file using a Local File Inclusion vulnerability. An attacker can read any file on the printer. …

Jun 14, 2024
CVE-2024-27163
6.5 MEDIUM

Toshiba printers will display the password of the admin user in clear-text and additional passwords when sending 2 specific HTTP requests to the internal API. …

Jun 14, 2024
CVE-2024-27162
6.1 MEDIUM

Toshiba printers provide a web interface that will load the JavaScript file. The file contains insecure codes vulnerable to XSS and is loaded inside all …

Jun 14, 2024
CVE-2024-27161
6.2 MEDIUM

all the Toshiba printers have programs containing a hardcoded key used to encrypt files. An attacker can decrypt the encrypted files using the hardcoded key. …

Jun 14, 2024
CVE-2024-27160
6.2 MEDIUM

All the Toshiba printers contain a shell script using the same hardcoded key to encrypt logs. An attacker can decrypt the encrypted files using the …

Jun 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.