CVE Database

59444+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-45312
5.3 MEDIUM

Overleaf is a web-based collaborative LaTeX editor. Overleaf Community Edition and Server Pro prior to version 5.0.7 (or 4.2.7 for the 4.x series) contain a …

Sep 2, 2024
CVE-2024-45308
6.5 MEDIUM

HedgeDoc is an open source, real-time, collaborative, markdown notes application. When using HedgeDoc 1 with MySQL or MariaDB, it is possible to create notes with …

Sep 2, 2024
CVE-2024-45306
4.5 MEDIUM

Vim is an open source, command line text editor. Patch v9.1.0038 optimized how the cursor position is calculated and removed a loop, that verified that …

Sep 2, 2024
CVE-2024-44947
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fuse: Initialize beyond-EOF page contents before setting uptodate fuse_notify_store(), unlike fuse_do_readpage(), does not enable page …

Sep 2, 2024
CVE-2024-43801
4.6 MEDIUM

Jellyfin is an open source self hosted media server. The Jellyfin user profile image upload accepts SVG files, allowing for a stored XSS attack against …

Sep 2, 2024
CVE-2024-43797
6.3 MEDIUM

audiobookshelf is a self-hosted audiobook and podcast server. A non-admin user is not allowed to create libraries (or access only the ones they have permission …

Sep 2, 2024
CVE-2024-43792
6.3 MEDIUM

Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.17.0 of the Halo project. This vulnerability …

Sep 2, 2024
CVE-2020-36830
4.3 MEDIUM

A vulnerability was found in nescalante urlregex up to 0.5.0 and classified as problematic. This issue affects some unknown processing of the file index.js of …

Sep 2, 2024
CVE-2024-38858
6.1 MEDIUM

Improper neutralization of input in Checkmk before version 2.3.0p14 allows attackers to inject and run malicious scripts in the Robotmk logs view.

Sep 2, 2024
CVE-2024-33043
5.5 MEDIUM

Transient DOS while handling PS event when Program Service name length offset value is set to 255.

Sep 2, 2024
CVE-2024-33016
6.8 MEDIUM

memory corruption when an invalid firehose patch command is invoked.

Sep 2, 2024
CVE-2024-7692
6.1 MEDIUM

The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Sep 2, 2024
CVE-2024-7691
6.1 MEDIUM

The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks against …

Sep 2, 2024
CVE-2024-7690
4.3 MEDIUM

The DN Popup WordPress plugin through 1.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Sep 2, 2024
CVE-2024-7354
6.1 MEDIUM

The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting …

Sep 2, 2024
CVE-2024-8365
6.2 MEDIUM

Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token …

Sep 2, 2024
CVE-2024-45528
5.4 MEDIUM

CodeAstro MembershipM-PHP (aka Membership Management System in PHP) 1.0 allows add_members.php fullname stored XSS.

Sep 2, 2024
CVE-2024-45527
6.1 MEDIUM

REDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSRF via index.php?logout=1, and can …

Sep 2, 2024
CVE-2024-39775
6.5 MEDIUM

in OpenHarmony v4.1.0 and prior versions allow a remote attacker cause information leak through out-of-bounds Read.

Sep 2, 2024
CVE-2024-39612
5.5 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

Sep 2, 2024
CVE-2024-38382
5.5 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

Sep 2, 2024
CVE-2024-20088
4.4 MEDIUM

In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Sep 2, 2024
CVE-2024-20087
6.7 MEDIUM

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Sep 2, 2024
CVE-2024-20086
6.7 MEDIUM

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Sep 2, 2024
CVE-2024-20085
4.4 MEDIUM

In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Sep 2, 2024
CVE-2024-20084
4.4 MEDIUM

In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Sep 2, 2024
CVE-2024-45270
4.3 MEDIUM

WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Hero image selection feature. While logged in to the WordPress …

Sep 2, 2024
CVE-2024-45269
4.3 MEDIUM

WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Carousel image selection feature. While logged in to the WordPress …

Sep 2, 2024
CVE-2024-45509
6.5 MEDIUM

In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.

Sep 1, 2024
CVE-2024-5053
4.2 MEDIUM

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized Malichimp …

Sep 1, 2024
CVE-2024-8366
4.3 MEDIUM

A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php?id=userProfileEdit …

Aug 31, 2024
CVE-2024-44946
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: kcm: Serialise kcm_sendmsg() for the same socket. syzkaller reported UAF in kcm_release(). [0] The scenario …

Aug 31, 2024
CVE-2022-4539
5.3 MEDIUM

The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1.2. This is due to insufficient …

Aug 31, 2024
CVE-2024-8108
6.4 MEDIUM

The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alignment' parameter in all versions up to, and including, 2.01 …

Aug 31, 2024
CVE-2024-0111
4.4 MEDIUM

NVIDIA CUDA Toolkit contains a vulnerability in command 'cuobjdump' where a user may cause a crash or produce incorrect output by passing a malformed ELF …

Aug 31, 2024
CVE-2024-0110
4.4 MEDIUM

NVIDIA CUDA Toolkit contains a vulnerability in command `cuobjdump` where a user may cause an out-of-bound write by passing in a malformed ELF file. A …

Aug 31, 2024
CVE-2022-4536
5.3 MEDIUM

The IP Vault – WP Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1. This is due …

Aug 31, 2024
CVE-2022-4100
5.3 MEDIUM

The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 due to the plugin improperly …

Aug 31, 2024
CVE-2024-8276
6.4 MEDIUM

The WPZOOM Portfolio Lite – Filterable Portfolio Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ attribute within the 'wp:wpzoom-blocks' Gutenberg …

Aug 31, 2024
CVE-2024-39579
6.7 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contains an incorrect privilege assignment vulnerability. A local high privileged attacker could potentially exploit this vulnerability to gain …

Aug 31, 2024
CVE-2024-39578
6.3 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.1 contains a UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, …

Aug 31, 2024
CVE-2024-5212
6.1 MEDIUM

The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ parameter in all versions up to, and including, 5.0 due …

Aug 31, 2024
CVE-2024-3886
6.1 MEDIUM

The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ parameter in all versions up to, and including, 5.0 due …

Aug 31, 2024
CVE-2024-8006
4.4 MEDIUM

Remote packet capture support is disabled by default in libpcap. When a user builds libpcap with remote packet capture support enabled, one of the functions …

Aug 31, 2024
CVE-2024-45304
5.3 MEDIUM

Cairo-Contracts are OpenZeppelin Contracts written in Cairo for Starknet, a decentralized ZK Rollup. This vulnerability can lead to unauthorized ownership transfer, contrary to the original …

Aug 31, 2024
CVE-2023-7256
4.4 MEDIUM

In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls getaddrinfo() and possibly freeaddrinfo(), but does not clearly …

Aug 31, 2024
CVE-2024-6585
5.4 MEDIUM

Multiple stored cross-site scripting (“XSS”) vulnerabilities in the markdown dashboard and dashboard comment functionality of Lightdash version 0.1024.6 allows remote authenticated threat actors to inject …

Aug 30, 2024
CVE-2024-8348
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management System 1.0. Affected by this issue is the function delete_category …

Aug 30, 2024
CVE-2024-8347
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Computer Laboratory Management System 1.0. Affected by this vulnerability is the function delete_record of the file …

Aug 30, 2024
CVE-2024-8285
5.9 MEDIUM

A flaw was found in Kroxylicious. When establishing the connection with the upstream Kafka server using a TLS secured connection, Kroxylicious fails to properly verify …

Aug 30, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.