CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-27159
6.2 MEDIUM

All the Toshiba printers contain a shell script using the same hardcoded key to encrypt logs. An attacker can decrypt the encrypted files using the …

Jun 14, 2024
CVE-2024-27157
6.8 MEDIUM

The sessions are stored in clear-text logs. An attacker can retrieve authentication sessions. A remote attacker can retrieve the credentials and bypass the authentication mechanism. …

Jun 14, 2024
CVE-2024-27156
6.8 MEDIUM

The session cookies, used for authentication, are stored in clear-text logs. An attacker can retrieve authentication sessions. A remote attacker can retrieve the credentials and …

Jun 14, 2024
CVE-2024-0892
4.3 MEDIUM

The Schema App Structured Data plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due …

Jun 14, 2024
CVE-2023-6492
4.3 MEDIUM

The Simple Sitemap – Create a Responsive HTML Sitemap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Jun 14, 2024
CVE-2024-27154
6.2 MEDIUM

Passwords are stored in clear-text logs. An attacker can retrieve passwords. As for the affected products/models/versions, see the reference URL.

Jun 14, 2024
CVE-2024-27146
6.7 MEDIUM

The Toshiba printers do not implement privileges separation. As for the affected products/models/versions, see the reference URL.

Jun 14, 2024
CVE-2024-27142
5.9 MEDIUM

Toshiba printers use XML communication for the API endpoint provided by the printer. For the endpoint, XML parsing library is used and it is vulnerable …

Jun 14, 2024
CVE-2024-27141
5.9 MEDIUM

Toshiba printers use XML communication for the API endpoint provided by the printer. For the endpoint, XML parsing library is used and it is vulnerable …

Jun 14, 2024
CVE-2024-5985
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Best Online News Portal 1.0. This affects an unknown part of the file /admin/index.php. The …

Jun 14, 2024
CVE-2024-5981
6.3 MEDIUM

A vulnerability was found in itsourcecode Online House Rental System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Jun 14, 2024
CVE-2023-51523
4.3 MEDIUM

Missing Authorization vulnerability in WriterSystem WooCommerce Easy Duplicate Product.This issue affects WooCommerce Easy Duplicate Product: from n/a through 0.3.0.7.

Jun 14, 2024
CVE-2023-51516
5.4 MEDIUM

Missing Authorization vulnerability in Business Directory Team Business Directory Plugin.This issue affects Business Directory Plugin: from n/a through 6.3.9.

Jun 14, 2024
CVE-2023-51507
5.3 MEDIUM

Missing Authorization vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.16.

Jun 14, 2024
CVE-2023-37394
5.3 MEDIUM

Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator.This issue affects WP Dummy Content Generator: from n/a through 2.3.0.

Jun 14, 2024
CVE-2023-36695
5.4 MEDIUM

Missing Authorization vulnerability in Maxime Schoeni Sublanguage.This issue affects Sublanguage: from n/a through 2.9.

Jun 14, 2024
CVE-2023-36694
6.3 MEDIUM

Missing Authorization vulnerability in Bryan Lee Kingkong Board.This issue affects Kingkong Board: from n/a through 2.1.0.2.

Jun 14, 2024
CVE-2023-36504
6.5 MEDIUM

Missing Authorization vulnerability in BBS e-Theme BBS e-Popup.This issue affects BBS e-Popup: from n/a through 2.4.5.

Jun 14, 2024
CVE-2023-35045
4.3 MEDIUM

Missing Authorization vulnerability in Fat Rat Fat Rat Collect.This issue affects Fat Rat Collect: from n/a through 2.6.7.

Jun 14, 2024
CVE-2023-35040
5.3 MEDIUM

Missing Authorization vulnerability in SendPress SendPress Newsletters.This issue affects SendPress Newsletters: from n/a through 1.23.11.6.

Jun 14, 2024
CVE-2023-29174
6.5 MEDIUM

Missing Authorization vulnerability in NervyThemes SKU Label Changer For WooCommerce.This issue affects SKU Label Changer For WooCommerce: from n/a through 3.0.

Jun 14, 2024
CVE-2024-33253
5.4 MEDIUM

Cross-site scripting (XSS) vulnerability in GUnet OpenEclass E-learning Platform version 3.15 and before allows a authenticated privileged attacker to execute arbitrary code via the title …

Jun 13, 2024
CVE-2024-0103
5.4 MEDIUM

NVIDIA Triton Inference Server for Linux contains a vulnerability where a user may cause an incorrect Initialization of resource by network issue. A successful exploit …

Jun 13, 2024
CVE-2024-0094
5.5 MEDIUM

NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where an untrusted guest VM can cause improper control of the interaction …

Jun 13, 2024
CVE-2024-0093
6.5 MEDIUM

NVIDIA GPU software for Linux contains a vulnerability where it can expose sensitive information to an actor that is not explicitly authorized to have access …

Jun 13, 2024
CVE-2024-0092
5.5 MEDIUM

NVIDIA GPU Driver for Windows and Linux contains a vulnerability where an improper check or improper handling of exception conditions might lead to denial of …

Jun 13, 2024
CVE-2024-0086
5.5 MEDIUM

NVIDIA vGPU software for Linux contains a vulnerability where the software can dereference a NULL pointer. A successful exploit of this vulnerability might lead to …

Jun 13, 2024
CVE-2024-0085
6.3 MEDIUM

NVIDIA vGPU software for Windows and Linux contains a vulnerability where unprivileged users could execute privileged operations on the host. A successful exploit of this …

Jun 13, 2024
CVE-2024-32930
5.5 MEDIUM

In plugin_ipc_handler of slc_plugin.c, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure of 4 bytes of …

Jun 13, 2024
CVE-2024-32926
5.5 MEDIUM

there is a possible information disclosure due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. …

Jun 13, 2024
CVE-2024-32923
4.0 MEDIUM

there is a possible cellular denial of service due to a logic error in the code. This could lead to remote denial of service with …

Jun 13, 2024
CVE-2024-32918
6.1 MEDIUM

Permission Bypass allowing attackers to disable HDCP 2.2 encryption by not completing the HDCP Key Exchange initialization steps

Jun 13, 2024
CVE-2024-32916
5.9 MEDIUM

In fvp_freq_histogram_init of fvp.c, there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution …

Jun 13, 2024
CVE-2024-32915
4.3 MEDIUM

In CellInfoListParserV2::FillCellInfo() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Jun 13, 2024
CVE-2024-32914
5.5 MEDIUM

In tpu_get_int_state of tpu.c, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution …

Jun 13, 2024
CVE-2024-32912
5.5 MEDIUM

there is a possible persistent Denial of Service due to test/debugging code left in a production build. This could lead to local denial of service …

Jun 13, 2024
CVE-2024-32910
5.5 MEDIUM

In handle_msg_shm_map_req of trusty/user/base/lib/spi/srv/tipc/tipc.c, there is a possible stack data disclosure due to uninitialized data. This could lead to local information disclosure with no additional …

Jun 13, 2024
CVE-2024-32904
4.7 MEDIUM

In ProtocolVsimOperationAdapter() of protocolvsimadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Jun 13, 2024
CVE-2024-32898
4.7 MEDIUM

In ProtocolCellIdentityParserV4::Parse() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Jun 13, 2024
CVE-2024-32897
5.9 MEDIUM

In ProtocolCdmaCallWaitingIndAdapter::GetCwInfo() of protocolsmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure …

Jun 13, 2024
CVE-2024-32893
5.5 MEDIUM

In _s5e9865_mif_set_rate of exynos_dvfs.c, there is a possible out of bounds read due to improper casting. This could lead to local information disclosure with no …

Jun 13, 2024
CVE-2024-29785
5.5 MEDIUM

In aur_get_state of aurora.c, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution …

Jun 13, 2024
CVE-2024-29780
5.5 MEDIUM

In hwbcc_ns_deprivilege of trusty/user/base/lib/hwbcc/client/hwbcc.c, there is a possible uninitialized stack data disclosure due to uninitialized data. This could lead to local information disclosure with no …

Jun 13, 2024
CVE-2024-29778
4.7 MEDIUM

In ProtocolPsDedicatedBearInfoAdapter::processQosSession of protocolpsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Jun 13, 2024
CVE-2024-5952
6.5 MEDIUM

Deep Sea Electronics DSE855 Restart Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Deep Sea Electronics DSE855 …

Jun 13, 2024
CVE-2024-5951
6.5 MEDIUM

Deep Sea Electronics DSE855 Factory Reset Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Deep Sea Electronics …

Jun 13, 2024
CVE-2024-5949
6.5 MEDIUM

Deep Sea Electronics DSE855 Multipart Boundary Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Deep …

Jun 13, 2024
CVE-2024-5947
6.5 MEDIUM

Deep Sea Electronics DSE855 Configuration Backup Missing Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Deep …

Jun 13, 2024
CVE-2024-38313
4.3 MEDIUM

In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual website address …

Jun 13, 2024
CVE-2024-38312
6.5 MEDIUM

When browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed app bundle after app termination …

Jun 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.