CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-34769
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in cyclonetheme Elegant Blocks allows Stored XSS.This issue affects Elegant Blocks: from …

Jun 3, 2024
CVE-2024-34767
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HasThemes ShopLentor allows Stored XSS.This issue affects ShopLentor: from n/a through …

Jun 3, 2024
CVE-2024-34766
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic ChaosTheory allows Stored XSS.This issue affects ChaosTheory: from n/a through …

Jun 3, 2024
CVE-2024-34385
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YITHEMES YITH WooCommerce Wishlist yith-woocommerce-wishlist.This issue affects YITH WooCommerce Wishlist: from n/a through …

Jun 3, 2024
CVE-2024-34803
4.3 MEDIUM

Missing Authorization vulnerability in Fastly.This issue affects Fastly: from n/a through 1.2.25.

Jun 3, 2024
CVE-2024-34801
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mervin Praison Praison SEO WordPress seo-wordpress allows DOM-Based XSS.This issue affects Praison SEO …

Jun 3, 2024
CVE-2024-34798
5.3 MEDIUM

Insertion of Sensitive Information into Log File vulnerability in Lukman Nakib Debug Log – Manger Tool.This issue affects Debug Log – Manger Tool: from n/a …

Jun 3, 2024
CVE-2024-34797
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Benoit Mercusot Simple Popup Manager allows Stored XSS.This issue affects Simple …

Jun 3, 2024
CVE-2024-34796
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AccessAlly PopupAlly allows Stored XSS.This issue affects PopupAlly: from n/a through …

Jun 3, 2024
CVE-2024-34795
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tainacan Tainacan tainacan.This issue affects Tainacan: from n/a through <= 0.21.3.

Jun 3, 2024
CVE-2024-34793
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kharim Tomlinson WP Next Post Navi allows Stored XSS.This issue affects …

Jun 3, 2024
CVE-2024-34791
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in wpbean WPB Elementor Addons allows Stored XSS.This issue affects WPB Elementor …

Jun 3, 2024
CVE-2024-34790
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hans van Eijsden,niwreg ImageMagick Sharpen Resized Images allows Stored XSS.This issue …

Jun 3, 2024
CVE-2024-34789
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Hait Post Grid Elementor Addon allows Stored XSS.This issue affects …

Jun 3, 2024
CVE-2024-34754
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A WP Life Contact Form Widget.This issue affects Contact Form Widget: from n/a through 1.3.9.

Jun 3, 2024
CVE-2024-35635
4.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through 5.0.9.

Jun 3, 2024
CVE-2024-35633
4.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Creative Themes Blocksy Companion blocksy-companion.This issue affects Blocksy Companion: from n/a through <= 2.0.42.

Jun 3, 2024
CVE-2024-23665
5.9 MEDIUM

Multiple improper authorization vulnerabilities [CWE-285] in FortiWeb version 7.4.2 and below, version 7.2.7 and below, version 7.0.10 and below, version 6.4.3 and below, version 6.3.23 …

Jun 3, 2024
CVE-2024-23664
6.1 MEDIUM

A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker …

Jun 3, 2024
CVE-2024-21478
6.2 MEDIUM

transient DOS when setting up a fence callback to free a KGSL memory entry object during DMA.

Jun 3, 2024
CVE-2023-43545
6.7 MEDIUM

Memory corruption when more scan frequency list or channels are sent from the user space.

Jun 3, 2024
CVE-2023-43544
6.7 MEDIUM

Memory corruption when IPC callback handle is used after it has been released during register callback by another thread.

Jun 3, 2024
CVE-2023-43543
6.7 MEDIUM

Memory corruption in Audio during a playback or a recording due to race condition between allocation and deallocation of graph object.

Jun 3, 2024
CVE-2023-43537
6.5 MEDIUM

Information disclosure while handling T2LM Action Frame in WLAN Host.

Jun 3, 2024
CVE-2024-35639
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webliberty Simple Spoiler simple-spoiler.This issue affects Simple Spoiler: from n/a through <= 1.2.

Jun 3, 2024
CVE-2024-35638
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in JumpDEMAND Inc. ActiveDEMAND.This issue affects ActiveDEMAND: from n/a through 0.2.43.

Jun 3, 2024
CVE-2024-35637
4.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.3.6.

Jun 3, 2024
CVE-2024-36964
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs/9p: only translate RWX permissions for plain 9P2000 Garbage in plain 9P2000's perm bits is …

Jun 3, 2024
CVE-2024-36962
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: ks8851: Queue RX packets in IRQ handler instead of disabling BHs Currently the driver …

Jun 3, 2024
CVE-2024-36961
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: thermal/debugfs: Fix two locking issues with thermal zone debug With the current thermal zone locking …

Jun 3, 2024
CVE-2024-35640
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tomas Cordero Safety Exit allows Stored XSS.This issue affects Safety Exit: …

Jun 3, 2024
CVE-2024-31493
6.5 MEDIUM

An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 and below, version 7.0.3 and below may …

Jun 3, 2024
CVE-2024-23107
5.5 MEDIUM

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, 6.3 all …

Jun 3, 2024
CVE-2023-48789
4.3 MEDIUM

A client-side enforcement of server-side security in Fortinet FortiPortal version 6.0.0 through 6.0.14 allows attacker to improper access control via crafted HTTP requests.

Jun 3, 2024
CVE-2024-35643
5.9 MEDIUM

Cross Site Scripting (XSS) vulnerability in Xabier Miranda WP Back Button allows Stored XSS.This issue affects WP Back Button: from n/a through 1.1.3.

Jun 3, 2024
CVE-2024-35642
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bryan Hadaway Site Favicon allows Stored XSS.This issue affects Site Favicon: …

Jun 3, 2024
CVE-2024-35641
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in GregRoss Just Writing Statistics allows Stored XSS.This issue affects Just Writing …

Jun 3, 2024
CVE-2024-37031
6.1 MEDIUM

The Active Admin (aka activeadmin) framework before 3.2.2 for Ruby on Rails allows stored XSS in certain situations where users can create entities (to be …

Jun 3, 2024
CVE-2023-51436
5.9 MEDIUM

Cross-site scripting vulnerability exists in UNIVERSAL PASSPORT RX versions 1.0.0 to 1.0.8, which may allow a remote authenticated attacker with an administrative privilege to execute …

Jun 3, 2024
CVE-2023-42427
6.5 MEDIUM

Cross-site scripting vulnerability exists in UNIVERSAL PASSPORT RX versions 1.0.0 to 1.0.7, which may allow a remote authenticated attacker to execute an arbitrary script on …

Jun 3, 2024
CVE-2024-20075
6.7 MEDIUM

In eemgpu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Jun 3, 2024
CVE-2024-20074
6.6 MEDIUM

In dmc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Jun 3, 2024
CVE-2024-20073
6.6 MEDIUM

In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with …

Jun 3, 2024
CVE-2024-20072
6.6 MEDIUM

In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with …

Jun 3, 2024
CVE-2024-20071
4.4 MEDIUM

In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System …

Jun 3, 2024
CVE-2024-20070
5.1 MEDIUM

In modem, there is a possible information disclosure due to using risky cryptographic algorithm during connection establishment negotiation. This could lead to remote information disclosure, …

Jun 3, 2024
CVE-2024-20069
6.5 MEDIUM

In modem, there is a possible selection of less-secure algorithm during the VoWiFi IKE due to a missing DH downgrade check. This could lead to …

Jun 3, 2024
CVE-2024-20068
5.9 MEDIUM

In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution …

Jun 3, 2024
CVE-2024-20065
4.0 MEDIUM

In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution …

Jun 3, 2024
CVE-2024-5590
6.3 MEDIUM

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been declared as critical. This vulnerability affects unknown code of the file …

Jun 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.