CVE Database

59444+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6867
6.5 MEDIUM

An information disclosure vulnerability exists in the lunary-ai/lunary, specifically in the `runs/{run_id}/related` endpoint. This endpoint does not verify that the user has the necessary access …

Sep 13, 2024
CVE-2024-6582
4.3 MEDIUM

A broken access control vulnerability exists in the latest version of lunary-ai/lunary. The `saml.ts` file allows a user from one organization to update the Identity …

Sep 13, 2024
CVE-2024-6087
6.5 MEDIUM

An improper access control vulnerability exists in lunary-ai/lunary at the latest commit (a761d83) on the main branch. The vulnerability allows an attacker to use the …

Sep 13, 2024
CVE-2024-31416
5.6 MEDIUM

The Eaton Foreseer software provides multiple customizable input fields for the users to configure parameters in the tool like alarms, reports, etc. Some of these …

Sep 13, 2024
CVE-2024-31415
6.3 MEDIUM

The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The …

Sep 13, 2024
CVE-2024-31414
6.7 MEDIUM

The Eaton Foreseer software provides users the capability to customize the dashboard in WebView pages. However, the input fields for this feature in the Eaton …

Sep 13, 2024
CVE-2024-44798
4.8 MEDIUM

phpgurukul Bus Pass Management System 1.0 is vulnerable to Cross-site scripting (XSS) in /admin/pass-bwdates-reports-details.php via fromdate and todate parameters.

Sep 13, 2024
CVE-2024-44685
5.0 MEDIUM

Titan SFTP and Titan MFT Server 2.0.25.2426 and earlier have a vulnerability a vulnerability where sensitive information, including passwords, is exposed in clear text within …

Sep 13, 2024
CVE-2024-8747
6.4 MEDIUM

The Email Obfuscate Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email-obfuscate' shortcode in all versions up to, and including, …

Sep 13, 2024
CVE-2024-8737
6.1 MEDIUM

The PDF Thumbnail Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Sep 13, 2024
CVE-2024-8734
6.1 MEDIUM

The Lucas String Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Sep 13, 2024
CVE-2024-8732
6.1 MEDIUM

The Roles & Capabilities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Sep 13, 2024
CVE-2024-8731
6.1 MEDIUM

The Cron Jobs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in …

Sep 13, 2024
CVE-2024-8730
6.1 MEDIUM

The Exit Notifier plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in …

Sep 13, 2024
CVE-2024-8714
6.1 MEDIUM

The WordPress Affiliates Plugin — SliceWP Affiliates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping …

Sep 13, 2024
CVE-2024-8242
4.3 MEDIUM

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to arbitrary file uploads due to missing …

Sep 13, 2024
CVE-2024-6544
5.3 MEDIUM

The Custom Post Limits plugin for WordPress is vulnerable to full path disclosure in all versions up to, and including, 4.4.1. This is due to …

Sep 13, 2024
CVE-2024-5884
6.4 MEDIUM

The Beauty theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tpl_featured_cat_id’ parameter in all versions up to, and including, 1.1.4 due to …

Sep 13, 2024
CVE-2024-5870
6.4 MEDIUM

The Tweaker5 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, …

Sep 13, 2024
CVE-2024-5869
6.4 MEDIUM

The Neighborly theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, …

Sep 13, 2024
CVE-2024-5867
6.4 MEDIUM

The Delicate theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter within the theme's Button shortcode in all versions up to, …

Sep 13, 2024
CVE-2024-5789
6.4 MEDIUM

The Triton Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the theme's Button shortcode in all versions up …

Sep 13, 2024
CVE-2024-45111
5.5 MEDIUM

Illustrator versions 28.6, 27.9.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Sep 13, 2024
CVE-2024-43759
5.5 MEDIUM

Illustrator versions 28.6, 27.9.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS). An attacker could …

Sep 13, 2024
CVE-2024-41867
5.5 MEDIUM

After Effects versions 23.6.6, 24.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Sep 13, 2024
CVE-2024-39385
5.5 MEDIUM

Premiere Pro versions 24.5, 23.6.8 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker …

Sep 13, 2024
CVE-2024-39382
5.5 MEDIUM

After Effects versions 23.6.6, 24.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Sep 13, 2024
CVE-2024-8742
6.4 MEDIUM

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Sep 13, 2024
CVE-2024-8665
6.1 MEDIUM

The YITH Custom Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Sep 13, 2024
CVE-2024-8664
6.1 MEDIUM

The WP Test Email plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Sep 13, 2024
CVE-2024-8663
6.1 MEDIUM

The WP Simple Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping …

Sep 13, 2024
CVE-2024-7888
6.3 MEDIUM

The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on …

Sep 13, 2024
CVE-2024-5567
6.4 MEDIUM

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 27.5.5 due to …

Sep 13, 2024
CVE-2024-46712
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Disable coherent dumb buffers without 3d Coherent surfaces make only sense if the host …

Sep 13, 2024
CVE-2024-46711
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: fix ID 0 endp usage after multiple re-creations 'local_addr_used' and 'add_addr_accepted' are decremented …

Sep 13, 2024
CVE-2024-46710
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Prevent unmapping active read buffers The kms paths keep a persistent map active to …

Sep 13, 2024
CVE-2024-46709
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix prime with external buffers Make sure that for external buffers mapping goes through …

Sep 13, 2024
CVE-2024-46708
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pinctrl: qcom: x1e80100: Fix special pin offsets Remove the erroneus 0x100000 offset to prevent the …

Sep 13, 2024
CVE-2024-46707
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Make ICC_*SGI*_EL1 undef in the absence of a vGICv3 On a system with …

Sep 13, 2024
CVE-2024-46706
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tty: serial: fsl_lpuart: mark last busy before uart_add_one_port With "earlycon initcall_debug=1 loglevel=8" in bootargs, kernel …

Sep 13, 2024
CVE-2024-46705
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe: reset mmio mappings with devm Set our various mmio mappings to NULL. This should …

Sep 13, 2024
CVE-2024-46704
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: workqueue: Fix spruious data race in __flush_work() When flushing a work item for cancellation, __flush_work() …

Sep 13, 2024
CVE-2024-46703
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Revert "serial: 8250_omap: Set the console genpd always on if no console suspend" This reverts …

Sep 13, 2024
CVE-2024-46702
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Mark XDomain as unplugged when router is removed I noticed that when we do …

Sep 13, 2024
CVE-2024-46701
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: libfs: fix infinite directory reads for offset dir After we switch tmpfs dir operations from …

Sep 13, 2024
CVE-2024-41873
5.5 MEDIUM

Media Encoder versions 24.5, 23.6.8 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Sep 13, 2024
CVE-2024-41872
5.5 MEDIUM

Media Encoder versions 24.5, 23.6.8 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Sep 13, 2024
CVE-2024-41871
5.5 MEDIUM

Media Encoder versions 24.5, 23.6.8 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Sep 13, 2024
CVE-2024-41870
5.5 MEDIUM

Media Encoder versions 24.5, 23.6.8 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Sep 13, 2024
CVE-2024-7864
6.5 MEDIUM

The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation in the output_sub_admin_page_0() function, allowing attackers to make logged in …

Sep 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.