CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-35185
5.3 MEDIUM

Minder is a software supply chain security platform. Prior to version 0.0.49, the Minder REST ingester is vulnerable to a denial of service attack via …

May 16, 2024
CVE-2024-35176
5.3 MEDIUM

REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has …

May 16, 2024
CVE-2024-34808
4.3 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samuel Marshall JCH Optimize.This issue affects JCH Optimize: from n/a through 4.2.0.

May 16, 2024
CVE-2024-34805
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Webvitaly iFrame allows Stored XSS.This issue affects iFrame: from n/a through …

May 16, 2024
CVE-2024-34760
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPBlockart Magazine Blocks allows Stored XSS.This issue affects Magazine Blocks: from …

May 16, 2024
CVE-2024-34751
4.4 MEDIUM

Deserialization of Untrusted Data vulnerability in WebToffee Order Export & Order Import for WooCommerce.This issue affects Order Export & Order Import for WooCommerce: from n/a …

May 16, 2024
CVE-2024-34273
5.9 MEDIUM

njwt up to v0.4.0 was discovered to contain a prototype pollution in the Parser.prototype.parse method.

May 16, 2024
CVE-2024-34958
6.5 MEDIUM

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/banner_deal.php?mudi=add

May 16, 2024
CVE-2024-34957
5.4 MEDIUM

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/sysImages_deal.php?mudi=infoSet.

May 16, 2024
CVE-2024-34582
6.1 MEDIUM

Sunhillo SureLine through 8.10.0 on RICI 5000 devices allows cgi/usrPasswd.cgi userid_change XSS within the Forgot Password feature.

May 16, 2024
CVE-2023-46842
6.5 MEDIUM

Unlike 32-bit PV guests, HVM guests may switch freely between 64-bit and other modes. This in particular means that they may set registers used to …

May 16, 2024
CVE-2024-4760
6.3 MEDIUM

A voltage glitch during the startup of EEFC NVM controllers on Microchip SAM E70/S70/V70/V71, SAM G55, SAM 4C/4S/4N/4E, and SAM 3S/3N/3U microcontrollers allows access to …

May 16, 2024
CVE-2024-4993
6.3 MEDIUM

Vulnerability in SiAdmin 1.1 that allows XSS via the /show.php query parameter. This vulnerability could allow a remote attacker to send a specially crafted URL …

May 16, 2024
CVE-2024-4580
6.4 MEDIUM

The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters …

May 16, 2024
CVE-2024-30287
5.5 MEDIUM

Adobe Framemaker versions 2020.5, 2022.3 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

May 16, 2024
CVE-2024-30286
5.5 MEDIUM

Adobe Framemaker versions 2020.5, 2022.3 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

May 16, 2024
CVE-2024-30283
5.5 MEDIUM

Adobe Framemaker versions 2020.5, 2022.3 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

May 16, 2024
CVE-2024-4634
6.4 MEDIUM

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hfe_svg_mime_types’ function in versions up to, and including, …

May 16, 2024
CVE-2024-4617
6.4 MEDIUM

The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in versions up …

May 16, 2024
CVE-2024-4400
6.4 MEDIUM

The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plguin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown …

May 16, 2024
CVE-2024-4385
6.4 MEDIUM

The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 1.8.16 due to insufficient …

May 16, 2024
CVE-2024-4288
6.4 MEDIUM

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in versions …

May 16, 2024
CVE-2024-35302
5.4 MEDIUM

In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible

May 16, 2024
CVE-2024-35301
5.5 MEDIUM

In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token

May 16, 2024
CVE-2024-35299
5.9 MEDIUM

In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation

May 16, 2024
CVE-2024-4973
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Simple Chat System 1.0. This vulnerability affects unknown code of the file /register.php. The manipulation of …

May 16, 2024
CVE-2024-4972
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Simple Chat System 1.0. This affects an unknown part of the file /login.php. The manipulation …

May 16, 2024
CVE-2024-4967
6.3 MEDIUM

A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

May 16, 2024
CVE-2024-4391
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Event Calendar widget in all versions up to, …

May 16, 2024
CVE-2024-4263
5.4 MEDIUM

A broken access control vulnerability exists in mlflow/mlflow versions before 2.10.1, where low privilege users with only EDIT permissions on an experiment can delete any …

May 16, 2024
CVE-2024-3887
5.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Form Builder widget in all versions up to, …

May 16, 2024
CVE-2024-3851
5.4 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability exists in the 'imartinez/privategpt' repository due to improper validation of file uploads. Attackers can exploit this vulnerability by uploading …

May 16, 2024
CVE-2024-30309
5.5 MEDIUM

Substance3D - Painter versions 9.1.2 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

May 16, 2024
CVE-2024-30308
5.5 MEDIUM

Substance3D - Painter versions 9.1.2 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

May 16, 2024
CVE-2024-30298
5.5 MEDIUM

Animate versions 24.0.2, 23.0.5 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

May 16, 2024
CVE-2024-30281
5.5 MEDIUM

Substance3D - Designer versions 13.1.1 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

May 16, 2024
CVE-2024-20793
5.5 MEDIUM

Illustrator versions 28.4, 27.9.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

May 16, 2024
CVE-2024-4965
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000-40 V31R02B1413C and classified as critical. This issue affects some unknown processing of the …

May 16, 2024
CVE-2024-4964
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DAR-7000-40 V31R02B1413C and classified as critical. This vulnerability affects unknown code of the …

May 16, 2024
CVE-2024-4546
6.4 MEDIUM

The Custom Post Type Attachment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pdf_attachment' shortcode in all versions up to, and …

May 16, 2024
CVE-2024-4478
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Group widget in all versions up to, …

May 16, 2024
CVE-2024-4963
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DAR-7000-40 V31R02B1413C. This affects an unknown part of the …

May 16, 2024
CVE-2024-4962
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-7000-40 V31R02B1413C. Affected by this issue is some …

May 16, 2024
CVE-2024-4961
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in D-Link DAR-7000-40 V31R02B1413C. Affected by this vulnerability is an unknown functionality of …

May 16, 2024
CVE-2024-4960
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in D-Link DAR-7000-40 V31R02B1413C. Affected is an unknown function of the file …

May 16, 2024
CVE-2024-4946
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Art Gallery Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown …

May 16, 2024
CVE-2024-4843
4.3 MEDIUM

ePO doesn't allow a regular privileged user to delete tasks or assignments. Insecure direct object references that allow a least privileged user to manipulate the …

May 16, 2024
CVE-2024-4635
6.4 MEDIUM

The Menu Icons by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘add_mime_type’ function in versions up to, and including, 0.13.13 …

May 16, 2024
CVE-2024-4279
6.5 MEDIUM

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference to Arbitrary Course Deletion in versions …

May 16, 2024
CVE-2024-3644
4.8 MEDIUM

The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.