CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-28970
4.7 MEDIUM

Dell Client BIOS contains an Out-of-bounds Write vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to platform denial …

Jun 12, 2024
CVE-2024-0160
6.8 MEDIUM

Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by bypassing BIOS authorization …

Jun 12, 2024
CVE-2024-5892
6.4 MEDIUM

The Divi Torque Lite – Divi Theme and Extra Theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘support_unfiltered_files_upload’ function in all …

Jun 12, 2024
CVE-2024-4924
6.1 MEDIUM

The Social Sharing Plugin WordPress plugin before 3.3.63 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jun 12, 2024
CVE-2024-36454
5.3 MEDIUM

Use of uninitialized resource issue exists in IPCOM EX2 Series (V01L0x Series) V01L07NF0201 and earlier, and IPCOM VE2 Series V01L07NF0201 and earlier. If this vulnerability …

Jun 12, 2024
CVE-2024-0427
6.3 MEDIUM

The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.4.1 does not properly escape user-controlled input when it is reflected in some of …

Jun 12, 2024
CVE-2024-3559
6.4 MEDIUM

The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_content]' parameter versions up to, and including, 2.6.7 due …

Jun 12, 2024
CVE-2024-5553
4.4 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via several parameters in all versions up to, and including, …

Jun 12, 2024
CVE-2024-4564
6.4 MEDIUM

The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Jun 12, 2024
CVE-2024-4892
6.4 MEDIUM

The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ parameter in versions up to, and including, 12.4.1 due to insufficient …

Jun 12, 2024
CVE-2024-36103
6.8 MEDIUM

OS command injection vulnerability in WRC-X5400GS-B v1.0.10 and earlier, and WRC-X5400GSA-B v1.0.10 and earlier allows a network-adjacent attacker with an administrative privilege to execute arbitrary …

Jun 12, 2024
CVE-2024-5843
6.5 MEDIUM

Inappropriate implementation in Downloads in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to obfuscate security UI via a malicious file. (Chromium security severity: …

Jun 11, 2024
CVE-2024-5840
6.5 MEDIUM

Policy bypass in CORS in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium …

Jun 11, 2024
CVE-2024-5839
6.5 MEDIUM

Inappropriate Implementation in Memory Allocator in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jun 11, 2024
CVE-2024-5646
6.4 MEDIUM

The Futurio Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘header_size’ attribute within the Advanced Text Block widget in all versions …

Jun 11, 2024
CVE-2024-4669
6.4 MEDIUM

The Events Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Basic Slider, Upcoming Events, and Schedule widgets in all …

Jun 11, 2024
CVE-2024-34406
5.3 MEDIUM

Improper exception handling in McAfee Security: Antivirus VPN for Android before 8.3.0 could allow an attacker to cause a denial of service through the use …

Jun 11, 2024
CVE-2024-28024
4.1 MEDIUM

A vulnerability exists in the FOXMAN-UN/UNEM in which sensitive information is stored in cleartext within a resource that might be accessible to another control sphere.

Jun 11, 2024
CVE-2024-28022
6.5 MEDIUM

A vulnerability exists in the UNEM server / APIGateway that if exploited allows a malicious user to perform an arbitrary number of authentication attempts using …

Jun 11, 2024
CVE-2024-36821
6.8 MEDIUM

Insecure permissions in Linksys Velop WiFi 5 (WHW01v1) 1.1.13.202617 allows attackers to escalate privileges from Guest to root.

Jun 11, 2024
CVE-2024-35263
5.7 MEDIUM

Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

Jun 11, 2024
CVE-2024-35255
5.5 MEDIUM

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

Jun 11, 2024
CVE-2024-35253
4.4 MEDIUM

Microsoft Azure File Sync Elevation of Privilege Vulnerability

Jun 11, 2024
CVE-2024-34815
5.4 MEDIUM

Missing Authorization vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and customers: from n/a through <= …

Jun 11, 2024
CVE-2024-34804
5.4 MEDIUM

Missing Authorization vulnerability in Tagembed.This issue affects Tagembed: from n/a through 5.8.

Jun 11, 2024
CVE-2024-34799
6.5 MEDIUM

Missing Authorization vulnerability in Repute Infosystems BookingPress.This issue affects BookingPress: from n/a through 1.0.82.

Jun 11, 2024
CVE-2024-34768
5.3 MEDIUM

Missing Authorization vulnerability in Fastly.This issue affects Fastly: from n/a through 1.2.25.

Jun 11, 2024
CVE-2024-34763
5.3 MEDIUM

Missing Authorization vulnerability in Saleswonder Team: Tobias Builder for WooCommerce reviews shortcodes – ReviewShort woo-product-reviews-shortcode.This issue affects Builder for WooCommerce reviews shortcodes – ReviewShort: from …

Jun 11, 2024
CVE-2024-34758
5.3 MEDIUM

Missing Authorization vulnerability in Wpmet WP Fundraising Donation and Crowdfunding Platform.This issue affects WP Fundraising Donation and Crowdfunding Platform: from n/a through 1.6.4.

Jun 11, 2024
CVE-2024-32146
4.3 MEDIUM

Missing Authorization vulnerability in Aspose.Cloud Marketplace Aspose.Words Exporter.This issue affects Aspose.Words Exporter: from n/a through 6.3.1.

Jun 11, 2024
CVE-2024-32143
4.3 MEDIUM

Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.1.0.

Jun 11, 2024
CVE-2024-30096
5.5 MEDIUM

Windows Cryptographic Services Information Disclosure Vulnerability

Jun 11, 2024
CVE-2024-30076
6.8 MEDIUM

Windows Container Manager Service Elevation of Privilege Vulnerability

Jun 11, 2024
CVE-2024-30069
4.7 MEDIUM

Windows Remote Access Connection Manager Information Disclosure Vulnerability

Jun 11, 2024
CVE-2024-30067
5.5 MEDIUM

Winlogon Elevation of Privilege Vulnerability

Jun 11, 2024
CVE-2024-30066
5.5 MEDIUM

Winlogon Elevation of Privilege Vulnerability

Jun 11, 2024
CVE-2024-30065
5.5 MEDIUM

Windows Themes Denial of Service Vulnerability

Jun 11, 2024
CVE-2024-30063
6.7 MEDIUM

Windows Distributed File System (DFS) Remote Code Execution Vulnerability

Jun 11, 2024
CVE-2024-30052
4.7 MEDIUM

Visual Studio Remote Code Execution Vulnerability

Jun 11, 2024
CVE-2024-29060
6.7 MEDIUM

Visual Studio Elevation of Privilege Vulnerability

Jun 11, 2024
CVE-2024-26330
6.5 MEDIUM

An issue was discovered in Kape CyberGhostVPN 8.4.3.12823 on Windows. After a successful logout, user credentials remain in memory while the process is still open, …

Jun 11, 2024
CVE-2024-23518
4.3 MEDIUM

Missing Authorization vulnerability in Navneil Naicker ACF Photo Gallery Field.This issue affects ACF Photo Gallery Field: from n/a through 2.6.

Jun 11, 2024
CVE-2023-52227
4.3 MEDIUM

Missing Authorization vulnerability in MailerLite MailerLite – WooCommerce integration.This issue affects MailerLite – WooCommerce integration: from n/a through 2.0.8.

Jun 11, 2024
CVE-2023-52224
4.3 MEDIUM

Missing Authorization vulnerability in Revolut Revolut Gateway for WooCommerce.This issue affects Revolut Gateway for WooCommerce: from n/a through 4.9.7.

Jun 11, 2024
CVE-2023-48273
5.3 MEDIUM

Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Preloader for Website.This issue affects Preloader for Website: from n/a through 1.2.2.

Jun 11, 2024
CVE-2024-5813
5.9 MEDIUM

A medium severity vulnerability in BIPS has been identified where an authenticated attacker with high privileges can access the SSH private keys via an information …

Jun 11, 2024
CVE-2024-34822
5.3 MEDIUM

Missing Authorization vulnerability in weDevs weMail.This issue affects weMail: from n/a through 1.14.2.

Jun 11, 2024
CVE-2024-34821
5.3 MEDIUM

Missing Authorization vulnerability in Anssi Laitila Contact List contact-list.This issue affects Contact List: from n/a through <= 2.9.87.

Jun 11, 2024
CVE-2024-34819
5.3 MEDIUM

Missing Authorization vulnerability in Moreconvert Team MC Woocommerce Wishlist smart-wishlist-for-more-convert.This issue affects MC Woocommerce Wishlist: from n/a through <= 1.7.2.

Jun 11, 2024
CVE-2024-34753
5.3 MEDIUM

Missing Authorization vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73.

Jun 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.