CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4621
4.8 MEDIUM

The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 does not sanitise and escape some of its settings, which could allow high …

Jun 7, 2024
CVE-2024-4354
6.4 MEDIUM

The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.3 …

Jun 7, 2024
CVE-2024-4042
6.4 MEDIUM

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Jun 7, 2024
CVE-2024-3288
5.4 MEDIUM

The Logo Slider WordPress plugin before 4.0.0 does not validate and escape some of its Slider Settings before outputting them back in attributes, which could …

Jun 7, 2024
CVE-2023-6491
4.3 MEDIUM

The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the wpmtst_save_view_sticky function in all …

Jun 7, 2024
CVE-2024-5640
6.4 MEDIUM

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jun 7, 2024
CVE-2024-5612
6.4 MEDIUM

The Essential Addons for Elementor Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eael_lightbox_open_btn_icon’ parameter within the Lightbox & Modal widget …

Jun 7, 2024
CVE-2024-5425
6.4 MEDIUM

The WP jQuery Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ attribute in all versions up to, and including, 1.5.4 …

Jun 7, 2024
CVE-2024-37384
6.1 MEDIUM

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.

Jun 7, 2024
CVE-2024-37383
6.1 MEDIUM KEV

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

Jun 7, 2024
CVE-2024-36082
6.5 MEDIUM

SQL injection vulnerability in Music Store - WordPress eCommerce versions prior to 1.1.14 allows a remote authenticated attacker with an administrative privilege to execute arbitrary …

Jun 7, 2024
CVE-2024-1988
6.4 MEDIUM

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Jun 7, 2024
CVE-2024-5607
5.4 MEDIUM

The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Jun 7, 2024
CVE-2024-3987
5.4 MEDIUM

The WP Mobile Menu – The Mobile-Friendly Responsive Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt text in all versions …

Jun 7, 2024
CVE-2024-1768
6.4 MEDIUM

The Clever Fox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's info box block in all versions up to, and including, …

Jun 7, 2024
CVE-2024-1689
4.3 MEDIUM

The WooCommerce Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the woocommerce_tool_toggle_module() function in all …

Jun 7, 2024
CVE-2023-6876
5.4 MEDIUM

The Clever Fox – One Click Website Importer by Nayra Themes plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Jun 7, 2024
CVE-2022-4968
6.5 MEDIUM

netplan leaks the private key of wireguard to local users. Versions after 1.0 are not affected.

Jun 7, 2024
CVE-2024-4013
5.6 MEDIUM

A bug exists in the API, mesh_node_power_off(), which fails to copy the contents of the Replay Protection List (RPL) from RAM to NVM before powering …

Jun 6, 2024
CVE-2024-36775
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

Jun 6, 2024
CVE-2024-22525
5.5 MEDIUM

dnspod-sr 0dfbd37 contains a SEGV.

Jun 6, 2024
CVE-2024-22524
5.5 MEDIUM

dnspod-sr 0dfbd37 is vulnerable to buffer overflow.

Jun 6, 2024
CVE-2024-36795
4.0 MEDIUM

Insecure permissions in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to access URLs and directories embedded within the firmware via unspecified vectors.

Jun 6, 2024
CVE-2024-5550
5.3 MEDIUM

In h2oai/h2o-3 version 3.40.0.4, an exposure of sensitive information vulnerability exists due to an arbitrary system path lookup feature. This vulnerability allows any remote user …

Jun 6, 2024
CVE-2024-5478
6.1 MEDIUM

A Cross-site Scripting (XSS) vulnerability exists in the SAML metadata endpoint `/auth/saml/${org?.id}/metadata` of lunary-ai/lunary version 1.2.7. The vulnerability arises due to the application's failure to …

Jun 6, 2024
CVE-2024-5278
6.1 MEDIUM

gaizhenbiao/chuanhuchatgpt is vulnerable to an unrestricted file upload vulnerability due to insufficient validation of uploaded file types in its `/upload` endpoint. Specifically, the `handle_file_upload` function …

Jun 6, 2024
CVE-2024-5248
6.5 MEDIUM

In lunary-ai/lunary version 1.2.5, an improper access control vulnerability exists due to a missing permission check in the `GET /v1/users/me/org` endpoint. The platform's role definitions …

Jun 6, 2024
CVE-2024-5206
4.7 MEDIUM

A sensitive data leakage vulnerability was identified in scikit-learn's TfidfVectorizer, specifically in versions up to and including 1.4.1.post1, which was fixed in version 1.5.0. The …

Jun 6, 2024
CVE-2024-5131
6.5 MEDIUM

An Improper Access Control vulnerability exists in the lunary-ai/lunary repository, affecting versions up to and including 1.2.2. The vulnerability allows unauthorized users to view any …

Jun 6, 2024
CVE-2024-5126
6.5 MEDIUM

An improper access control vulnerability exists in the lunary-ai/lunary repository, specifically within the versions.patch functionality for updating prompts. Affected versions include 1.2.2 up to but …

Jun 6, 2024
CVE-2024-4890
4.9 MEDIUM

A blind SQL injection vulnerability exists in the berriai/litellm application, specifically within the '/team/update' process. The vulnerability arises due to the improper handling of the …

Jun 6, 2024
CVE-2024-3404
6.5 MEDIUM

In gaizhenbiao/chuanhuchatgpt, specifically the version tagged as 20240121, there exists a vulnerability due to improper access control mechanisms. This flaw allows an authenticated attacker to …

Jun 6, 2024
CVE-2024-3402
5.4 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability existed in version (20240121) of gaizhenbiao/chuanhuchatgpt due to inadequate sanitization and validation of model output data. Despite user-input validation …

Jun 6, 2024
CVE-2024-3153
6.5 MEDIUM

mintplex-labs/anything-llm is affected by an uncontrolled resource consumption vulnerability in its upload file endpoint, leading to a denial of service (DOS) condition. Specifically, the server …

Jun 6, 2024
CVE-2024-3102
5.3 MEDIUM

A JSON Injection vulnerability exists in the `mintplex-labs/anything-llm` application, specifically within the username parameter during the login process at the `/api/request-token` endpoint. The vulnerability arises …

Jun 6, 2024
CVE-2024-3099
5.4 MEDIUM

A vulnerability in mlflow/mlflow version 2.11.1 allows attackers to create multiple models with the same name by exploiting URL encoding. This flaw can lead to …

Jun 6, 2024
CVE-2024-37364
6.8 MEDIUM

Ariane Allegro Scenario Player through 2024-03-05, when Ariane Duo kiosk mode is used, allows physically proximate attackers to obtain sensitive information (such as hotel invoice …

Jun 6, 2024
CVE-2024-37154
5.3 MEDIUM

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Users are able to delegate tokens that have not yet been vested. This …

Jun 6, 2024
CVE-2024-36735
5.3 MEDIUM

OneFlow-Inc. Oneflow v0.9.1 does not display an error or warning when the oneflow.eye parameter is floating.

Jun 6, 2024
CVE-2024-2965
4.7 MEDIUM

A Denial-of-Service (DoS) vulnerability exists in the `SitemapLoader` class of the `langchain-ai/langchain` repository, affecting all versions. The `parse_sitemap` method, responsible for parsing sitemaps and extracting …

Jun 6, 2024
CVE-2024-2383
6.1 MEDIUM

A clickjacking vulnerability exists in zenml-io/zenml versions up to and including 0.55.5 due to the application's failure to set appropriate X-Frame-Options or Content-Security-Policy HTTP headers. …

Jun 6, 2024
CVE-2024-2171
4.8 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability was identified in the zenml-io/zenml repository, specifically within the 'logo_url' field. By injecting malicious payloads into this field, an …

Jun 6, 2024
CVE-2024-2035
6.5 MEDIUM

An improper authorization vulnerability exists in the zenml-io/zenml repository, specifically within the API PUT /api/v1/users/id endpoint. This vulnerability allows any authenticated user to modify the …

Jun 6, 2024
CVE-2024-23793
6.3 MEDIUM

The file upload feature in OTRS and ((OTRS)) Community Edition has a path traversal vulnerability. This issue permits authenticated agents or customer users to upload …

Jun 6, 2024
CVE-2024-22326
5.0 MEDIUM

IBM System Storage DS8900F 89.22.19.0, 89.30.68.0, 89.32.40.0, 89.33.48.0, 89.40.83.0, and 89.40.93.0 could allow a remote user to create an LDAP connection with a valid username …

Jun 6, 2024
CVE-2024-5268
6.5 MEDIUM

Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos …

Jun 6, 2024
CVE-2024-5256
4.3 MEDIUM

Sonos Era 100 SMB2 Message Handling Integer Underflow Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos …

Jun 6, 2024
CVE-2024-5127
5.4 MEDIUM

In lunary-ai/lunary versions 1.2.2 through 1.2.25, an improper access control vulnerability allows users on the Free plan to invite other members and assign them any …

Jun 6, 2024
CVE-2024-3504
6.5 MEDIUM

An improper access control vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, where an admin can update any organization user to the organization …

Jun 6, 2024
CVE-2024-37156
6.1 MEDIUM

The SuluFormBundle adds support for creating dynamic forms in Sulu Admin. The TokenController get parameter formName is not sanitized in the returned input field which …

Jun 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.