CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-38083
4.3 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Jun 13, 2024
CVE-2024-30058
5.4 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Jun 13, 2024
CVE-2024-30057
5.4 MEDIUM

Microsoft Edge for iOS Spoofing Vulnerability

Jun 13, 2024
CVE-2024-36589
4.3 MEDIUM

An issue in Annonshop.app DecentralizeJustice/anonymousLocker commit 2b2b4 to ba9fd and DecentralizeJustice/anonBackend commit 57837 to cd815 was discovered to store credentials in plaintext.

Jun 13, 2024
CVE-2024-36588
6.5 MEDIUM

An issue in Annonshop.app DecentralizeJustice/ anonymousLocker commit 2b2b4 allows attackers to send messages erroneously attributed to arbitrary users via a crafted HTTP request.

Jun 13, 2024
CVE-2024-38280
4.6 MEDIUM

An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data …

Jun 13, 2024
CVE-2024-38279
4.6 MEDIUM

The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system …

Jun 13, 2024
CVE-2024-37280
4.9 MEDIUM

A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type. Under certain circumstances, ingesting …

Jun 13, 2024
CVE-2024-37279
4.3 MEDIUM

A flaw was discovered in Kibana, allowing view-only users of alerting to use the run_soon API making the alerting rule run continuously, potentially affecting the …

Jun 13, 2024
CVE-2024-37877
5.5 MEDIUM

UERANSIM before 3.2.6 allows out-of-bounds read when a RLS packet is sent to gNodeB with malformed PDU length. This occurs in function readOctetString in src/utils/octet_view.cpp …

Jun 13, 2024
CVE-2024-29169
5.4 MEDIUM

Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal audit REST API. A remote authenticated attacker …

Jun 13, 2024
CVE-2023-35860
5.3 MEDIUM

A Directory Traversal vulnerability in Modern Campus - Omni CMS 2023.1 allows a remote, unauthenticated attacker to enumerate file system information via the dir parameter …

Jun 13, 2024
CVE-2023-35859
6.1 MEDIUM

A Reflected Cross-Site Scripting (XSS) vulnerability in the blog function of Modern Campus - Omni CMS 2023.1 allows a remote attacker to inject arbitrary scripts …

Jun 13, 2024
CVE-2023-35858
5.3 MEDIUM

XPath Injection vulnerabilities in the blog and RSS functions of Modern Campus - Omni CMS 2023.1 allow a remote, unauthenticated attacker to obtain application information.

Jun 13, 2024
CVE-2024-29168
5.4 MEDIUM

Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal assets REST API. A remote authenticated attacker …

Jun 13, 2024
CVE-2024-28969
4.3 MEDIUM

Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal update REST API (if enabled by …

Jun 13, 2024
CVE-2024-28968
5.4 MEDIUM

Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for internal email and collection settings REST APIs (if …

Jun 13, 2024
CVE-2024-28967
5.4 MEDIUM

Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal maintenance REST API (if enabled by …

Jun 13, 2024
CVE-2024-28966
5.4 MEDIUM

Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal update REST API (if enabled by …

Jun 13, 2024
CVE-2024-28965
5.4 MEDIUM

Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal enable REST API (if enabled by …

Jun 13, 2024
CVE-2024-37309
5.3 MEDIUM

CrateDB is a distributed SQL database. A high-risk vulnerability has been identified in versions prior to 5.7.2 where the TLS endpoint (port 4200) permits client-initiated …

Jun 13, 2024
CVE-2024-37308
5.4 MEDIUM

The Cooked Pro recipe plugin for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the `_recipe_settings[post_title]` parameter in versions up to, and including, 1.7.15.4 …

Jun 13, 2024
CVE-2024-36647
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Church CRM v5.8.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Jun 13, 2024
CVE-2024-25052
4.4 MEDIUM

IBM Jazz Reporting Service 7.0.3 stores user credentials in plain clear text which can be read by an admin user. IBM X-Force ID: 283363.

Jun 13, 2024
CVE-2024-36395
6.1 MEDIUM

Verint - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Jun 13, 2024
CVE-2024-34130
5.5 MEDIUM

Acrobat Mobile Sign Android versions 24.4.2.33155 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker …

Jun 13, 2024
CVE-2024-34113
5.5 MEDIUM

ColdFusion versions 2023u7, 2021u13 and earlier are affected by a Weak Cryptography for Passwords vulnerability that could result in a security feature bypass. This vulnerability …

Jun 13, 2024
CVE-2024-32856
5.1 MEDIUM

Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit …

Jun 13, 2024
CVE-2024-30278
5.5 MEDIUM

Media Encoder versions 23.6.5, 24.3 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Jun 13, 2024
CVE-2024-4176
4.1 MEDIUM

An Cross site scripting vulnerability in the EDR XConsole before this release allowed an attacker to potentially leverage an XSS/HTML-Injection using command line variables. A …

Jun 13, 2024
CVE-2024-34111
6.5 MEDIUM

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system …

Jun 13, 2024
CVE-2024-34107
5.3 MEDIUM

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. …

Jun 13, 2024
CVE-2024-34106
5.3 MEDIUM

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An …

Jun 13, 2024
CVE-2024-34105
4.8 MEDIUM

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin …

Jun 13, 2024
CVE-2024-30285
5.5 MEDIUM

Audition versions 24.2, 23.6.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service condition. An attacker could …

Jun 13, 2024
CVE-2024-30276
5.5 MEDIUM

Audition versions 24.2, 23.6.4 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Jun 13, 2024
CVE-2024-1565
6.4 MEDIUM

The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable …

Jun 13, 2024
CVE-2024-0979
6.1 MEDIUM

The Dashboard Widgets Suite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 3.4.3 …

Jun 13, 2024
CVE-2024-4615
6.4 MEDIUM

The Elespare – Blog, Magazine and Newspaper Addons for Elementor with Templates, Widgets, Kits, and Header/Footer Builder. One Click Import: No Coding Required! plugin for …

Jun 13, 2024
CVE-2024-36239
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier Answer: are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to execute …

Jun 13, 2024
CVE-2024-36238
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to execute arbitrary …

Jun 13, 2024
CVE-2024-36236
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier Answer: are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to execute …

Jun 13, 2024
CVE-2024-36235
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to execute arbitrary …

Jun 13, 2024
CVE-2024-36234
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to execute arbitrary …

Jun 13, 2024
CVE-2024-36233
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier Answer: are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to execute …

Jun 13, 2024
CVE-2024-36232
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Jun 13, 2024
CVE-2024-36231
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier Answer: are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to execute …

Jun 13, 2024
CVE-2024-36230
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to execute arbitrary …

Jun 13, 2024
CVE-2024-36229
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier Answer: are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to execute …

Jun 13, 2024
CVE-2024-36228
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier Answer: are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to execute …

Jun 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.