CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5905
4.4 MEDIUM

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low privileged Windows user to …

Jun 12, 2024
CVE-2024-5898
6.3 MEDIUM

A vulnerability was found in itsourcecode Payroll Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jun 12, 2024
CVE-2024-5560
5.3 MEDIUM

CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service of the device’s web interface when an attacker sends a specially crafted HTTP request.

Jun 12, 2024
CVE-2024-5558
6.4 MEDIUM

CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists that could cause escalation of privileges when an attacker abuses a limited admin account.

Jun 12, 2024
CVE-2024-5557
4.5 MEDIUM

CWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause exposure of SNMP credentials when an attacker has access to the controller …

Jun 12, 2024
CVE-2024-37878
6.1 MEDIUM

Cross Site Scripting vulnerability in TWCMS v.2.0.3 allows a remote attacker to execute arbitrary code via the /TWCMS-gh-pages/twcms/runtime/twcms_view/default,index.htm.php" PHP directly echoes parameters input from external …

Jun 12, 2024
CVE-2024-37040
5.4 MEDIUM

CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a user with access to the device’s web interface …

Jun 12, 2024
CVE-2024-37039
5.9 MEDIUM

CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request.

Jun 12, 2024
CVE-2024-22855
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in the User Maintenance section of ITSS iMLog v1.307 allows attackers to execute arbitrary web scripts or HTML via a …

Jun 12, 2024
CVE-2024-5897
4.3 MEDIUM

A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is an …

Jun 12, 2024
CVE-2024-5759
5.4 MEDIUM

An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized objects and launch scans without having the …

Jun 12, 2024
CVE-2024-5895
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. This issue affects the function …

Jun 12, 2024
CVE-2024-5893
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Cab Management System 1.0. This affects an unknown part of the file /cms/classes/Users.php?f=delete_client. The manipulation …

Jun 12, 2024
CVE-2024-37304
6.1 MEDIUM

NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While …

Jun 12, 2024
CVE-2024-37297
5.4 MEDIUM

WooCommerce is an open-source e-commerce platform built on WordPress. A vulnerability introduced in WooCommerce 8.8 allows for cross-site scripting. A bad actor can manipulate a …

Jun 12, 2024
CVE-2024-36691
6.3 MEDIUM

Insecure permissions in the AdminController.AjaxSave() method of PPGo_Jobs v2.8.0 allows authenticated attackers to arbitrarily modify users' account information.

Jun 12, 2024
CVE-2024-31217
5.3 MEDIUM

Strapi is an open-source content management system. Prior to version 4.22.0, a denial-of-service vulnerability is present in the media upload process causing the server to …

Jun 12, 2024
CVE-2024-2300
6.2 MEDIUM

HP Advance Mobile Applications for iOS and Android are potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices.

Jun 12, 2024
CVE-2024-5891
4.2 MEDIUM

A vulnerability was found in Quay. If an attacker can obtain the client ID for an application, they can use an OAuth token to authenticate …

Jun 12, 2024
CVE-2024-23445
6.5 MEDIUM

It was identified that if a cross-cluster API key https://www.elastic.co/guide/en/elasticsearch/reference/8.14/security-api-create-cross-cluster-api-key.html#security-api-create-cross-cluster-api-key-request-body restricts search for a given index using the query or the field_security parameter, and the …

Jun 12, 2024
CVE-2024-5313
6.5 MEDIUM

CWE-668: Exposure of the Resource Wrong Sphere vulnerability exists that exposes a SSH interface over the product network interface. This does not allow to directly …

Jun 12, 2024
CVE-2024-5056
6.5 MEDIUM

CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may prevent user to update the device firmware and prevent proper behavior of the …

Jun 12, 2024
CVE-2024-5674
6.5 MEDIUM

The Newsletter - API v1 and v2 addon plugin for WordPress is vulnerable to unauthorized subscribers management due to PHP type juggling issue on the …

Jun 12, 2024
CVE-2024-3492
6.4 MEDIUM

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event', 'location', and 'event_category' …

Jun 12, 2024
CVE-2024-1766
4.4 MEDIUM

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.2.86 …

Jun 12, 2024
CVE-2024-2092
5.4 MEDIUM

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Twitter Widget in all versions up to, and including, …

Jun 12, 2024
CVE-2023-51524
4.3 MEDIUM

Missing Authorization vulnerability in weForms.This issue affects weForms: from n/a through 1.6.18.

Jun 12, 2024
CVE-2023-51413
5.3 MEDIUM

Missing Authorization vulnerability in Piotnet Forms.This issue affects Piotnet Forms: from n/a through 1.0.29.

Jun 12, 2024
CVE-2023-47845
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Lim Kai Yang Grab & Save.This issue affects Grab & Save: from n/a through 1.0.4.

Jun 12, 2024
CVE-2023-47828
4.3 MEDIUM

Missing Authorization vulnerability in Mandrill wpMandrill.This issue affects wpMandrill: from n/a through 1.33.

Jun 12, 2024
CVE-2023-44234
4.3 MEDIUM

Missing Authorization vulnerability in Bastianon Massimo WP GPX Map.This issue affects WP GPX Map: from n/a through 1.7.08.

Jun 12, 2024
CVE-2023-41240
5.3 MEDIUM

Missing Authorization vulnerability in Vark Pricing Deals for WooCommerce.This issue affects Pricing Deals for WooCommerce: from n/a through 2.0.3.2.

Jun 12, 2024
CVE-2023-40672
5.4 MEDIUM

Missing Authorization vulnerability in Hardik Chavada Sticky Social Media Icons.This issue affects Sticky Social Media Icons: from n/a through 2.1.

Jun 12, 2024
CVE-2023-40603
5.3 MEDIUM

Missing Authorization vulnerability in Gangesh Matta Simple Org Chart.This issue affects Simple Org Chart: from n/a through 2.3.4.

Jun 12, 2024
CVE-2023-40209
6.5 MEDIUM

Missing Authorization vulnerability in Himalaya Saxena Highcompress Image Compressor.This issue affects Highcompress Image Compressor: from n/a through 6.0.0.

Jun 12, 2024
CVE-2023-38395
5.4 MEDIUM

Missing Authorization vulnerability in Afzal Multani WP Clone Menu.This issue affects WP Clone Menu: from n/a through 1.0.1.

Jun 12, 2024
CVE-2023-25030
4.3 MEDIUM

Missing Authorization vulnerability in Buy Me a Coffee.This issue affects Buy Me a Coffee: from n/a through 3.7.

Jun 12, 2024
CVE-2024-5742
6.7 MEDIUM

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a …

Jun 12, 2024
CVE-2024-5468
6.5 MEDIUM

The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to unauthorized site option deletion due to a missing validation and capability checks …

Jun 12, 2024
CVE-2024-5266
6.4 MEDIUM

The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpdm_user_dashboard, wpdm_package, wpdm_packages, wpdm_search_result, and wpdm_tag shortcodes in all versions up …

Jun 12, 2024
CVE-2023-52177
5.4 MEDIUM

Missing Authorization vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.3.

Jun 12, 2024
CVE-2023-52117
4.3 MEDIUM

Missing Authorization vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid: from n/a through 5.6.6.

Jun 12, 2024
CVE-2023-51680
4.3 MEDIUM

Missing Authorization vulnerability in TechnoVama Quotes for WooCommerce.This issue affects Quotes for WooCommerce: from n/a through 2.0.1.

Jun 12, 2024
CVE-2023-51679
5.4 MEDIUM

Missing Authorization vulnerability in BulkGate BulkGate SMS Plugin for WooCommerce.This issue affects BulkGate SMS Plugin for WooCommerce: from n/a through 3.0.2.

Jun 12, 2024
CVE-2023-51671
5.4 MEDIUM

Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.

Jun 12, 2024
CVE-2023-51670
4.3 MEDIUM

Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.

Jun 12, 2024
CVE-2023-51537
5.3 MEDIUM

Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.5.

Jun 12, 2024
CVE-2023-51526
4.3 MEDIUM

Missing Authorization vulnerability in Brett Shumaker Simple Staff List.This issue affects Simple Staff List: from n/a through 2.2.4.

Jun 12, 2024
CVE-2024-3925
6.4 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jun 12, 2024
CVE-2024-5739
6.1 MEDIUM

The in-app browser of LINE client for iOS versions below 14.9.0 contains a Universal XSS (UXSS) vulnerability. This vulnerability allows for cross-site scripting (XSS) where …

Jun 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.