CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-27372
6.7 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_config_get_nl_params(), there is …

Jun 5, 2024
CVE-2024-27371
6.7 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_followup_get_nl_params(), there is …

Jun 5, 2024
CVE-2024-27370
6.7 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_config_get_nl_params(), there is …

Jun 5, 2024
CVE-2023-49927
5.3 MEDIUM

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos …

Jun 5, 2024
CVE-2024-5184
6.5 MEDIUM

The EmailGPT service contains a prompt injection vulnerability. The service uses an API service that allows a malicious user to inject a direct prompt and …

Jun 5, 2024
CVE-2024-35674
4.3 MEDIUM

Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): …

Jun 5, 2024
CVE-2024-20405
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a stored XSS attack by exploiting an …

Jun 5, 2024
CVE-2024-24789
5.5 MEDIUM

The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to …

Jun 5, 2024
CVE-2024-5629
4.7 MEDIUM

An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception …

Jun 5, 2024
CVE-2024-4812
4.8 MEDIUM

A flaw was found in the Katello plugin for Foreman, where it is possible to store malicious JavaScript code in the "Description" field of a …

Jun 5, 2024
CVE-2024-3716
6.2 MEDIUM

A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue leaks the password in the process list and …

Jun 5, 2024
CVE-2024-35673
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Pure Chat by Ruby Pure Chat.This issue affects Pure Chat: from n/a through 2.22.

Jun 5, 2024
CVE-2024-5459
4.3 MEDIUM

The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on 'add_section', 'add_menu', …

Jun 5, 2024
CVE-2024-3469
6.1 MEDIUM

The GP Premium plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the message parameter in all versions up to, and including, 2.4.0 due …

Jun 5, 2024
CVE-2024-4001
6.4 MEDIUM

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_login_form' shortcode in all versions up to, and including, 3.2.93 …

Jun 5, 2024
CVE-2024-5536
6.4 MEDIUM

The GamiPress – Link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's gamipress_link shortcode in all versions up to, and including, …

Jun 5, 2024
CVE-2024-5571
6.4 MEDIUM

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress …

Jun 5, 2024
CVE-2024-4821
6.4 MEDIUM

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_lightbox shortcode in all versions up …

Jun 5, 2024
CVE-2024-5453
4.3 MEDIUM

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Jun 5, 2024
CVE-2024-5439
6.4 MEDIUM

The Blocksy theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the custom_url parameter in all versions up to, and including, 2.0.50 due to …

Jun 5, 2024
CVE-2024-5006
6.4 MEDIUM

The Boostify Header Footer Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘size’ parameter in all versions up to, …

Jun 5, 2024
CVE-2024-4939
6.4 MEDIUM

The Weaver Xtreme Theme Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's div shortcode in all versions up to, and …

Jun 5, 2024
CVE-2024-23669
6.5 MEDIUM

An improper authorization in Fortinet FortiWebManager version 7.2.0 and 7.0.0 through 7.0.4 and 6.3.0 and 6.2.3 through 6.2.4 and 6.0.2 allows attacker to execute unauthorized …

Jun 5, 2024
CVE-2024-5222
6.4 MEDIUM

The Responsive Addons – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Jun 5, 2024
CVE-2024-4088
4.3 MEDIUM

The Gutenberg Blocks and Page Layouts – Attire Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Jun 5, 2024
CVE-2024-2368
4.3 MEDIUM

The Mollie Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.13. This is due to missing …

Jun 5, 2024
CVE-2024-1164
6.4 MEDIUM

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's contact form widget error message and redirect URL …

Jun 5, 2024
CVE-2024-4886
4.3 MEDIUM

The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in the request

Jun 5, 2024
CVE-2024-1161
6.4 MEDIUM

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Attributes for blocks in all versions up …

Jun 5, 2024
CVE-2024-5149
6.5 MEDIUM

The BuddyForms plugin for WordPress is vulnerable to Email Verification Bypass in all versions up to, and including, 2.8.9 via the use of an insufficiently …

Jun 5, 2024
CVE-2024-34055
6.5 MEDIUM

Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.

Jun 5, 2024
CVE-2024-5483
5.3 MEDIUM

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.8 due to …

Jun 5, 2024
CVE-2024-5317
6.4 MEDIUM

The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'np1' parameter in all versions up to, and including, 8.3.4 due to …

Jun 5, 2024
CVE-2024-5636
6.3 MEDIUM

A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Jun 5, 2024
CVE-2024-5635
6.3 MEDIUM

A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Jun 4, 2024
CVE-2024-36121
5.9 MEDIUM

netty-incubator-codec-ohttp is the OHTTP implementation for netty. BoringSSLAEADContext keeps track of how many OHTTP responses have been sent and uses this sequence number to calculate …

Jun 4, 2024
CVE-2024-30889
5.4 MEDIUM

Cross Site Scripting vulnerability in audimex audimexEE v.15.1.2 and fixed in 15.1.3.9 allows a remote attacker to execute arbitrary code via the service, method, widget_type, …

Jun 4, 2024
CVE-2022-28658
5.5 MEDIUM

Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing

Jun 4, 2024
CVE-2022-28656
5.5 MEDIUM

is_closing_session() allows users to consume RAM in the Apport process

Jun 4, 2024
CVE-2022-28654
5.5 MEDIUM

is_closing_session() allows users to fill up apport.log

Jun 4, 2024
CVE-2022-28652
5.5 MEDIUM

~/.config/apport/settings parsing is vulnerable to "billion laughs" attack

Jun 4, 2024
CVE-2024-4220
4.3 MEDIUM

Prior to 23.1, an information disclosure vulnerability exists within BeyondInsight which can allow an attacker to enumerate usernames.

Jun 4, 2024
CVE-2024-4219
4.8 MEDIUM

Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, resulting in a server-side request forgery vulnerability.

Jun 4, 2024
CVE-2024-34364
5.7 MEDIUM

Envoy is a cloud-native, open source edge and service proxy. Envoy exposed an out-of-memory (OOM) vector from the mirror response, since async HTTP client will …

Jun 4, 2024
CVE-2024-34362
5.9 MEDIUM

Envoy is a cloud-native, open source edge and service proxy. There is a use-after-free in `HttpConnectionManager` (HCM) with `EnvoyQuicServerStream` that can crash Envoy. An attacker …

Jun 4, 2024
CVE-2024-32975
5.9 MEDIUM

Envoy is a cloud-native, open source edge and service proxy. There is a crash at `QuicheDataReader::PeekVarInt62Length()`. It is caused by integer underflow in the `QuicStreamSequencerBuffer::PeekRegion()` …

Jun 4, 2024
CVE-2024-32974
5.9 MEDIUM

Envoy is a cloud-native, open source edge and service proxy. A crash was observed in `EnvoyQuicServerStream::OnInitialHeadersComplete()` with following call stack. It is a use-after-free caused …

Jun 4, 2024
CVE-2024-23326
5.9 MEDIUM

Envoy is a cloud-native, open source edge and service proxy. A theoretical request smuggling vulnerability exists through Envoy if a server can be tricked into …

Jun 4, 2024
CVE-2024-32464
6.1 MEDIUM

Action Text brings rich text content and editing to Rails. Instances of ActionText::Attachable::ContentAttachment included within a rich_text_area tag could potentially contain unsanitized HTML. This vulnerability …

Jun 4, 2024
CVE-2024-30528
5.4 MEDIUM

Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar.This issue affects Spiffy Calendar: from n/a through 4.9.10.

Jun 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.