CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-20257
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an authenticated, remote attacker to conduct an …

May 15, 2024
CVE-2024-20256
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Web Appliance could allow an …

May 15, 2024
CVE-2024-4837
5.3 MEDIUM

In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality …

May 15, 2024
CVE-2024-4357
6.5 MEDIUM

An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege attacker to read systems file via XML …

May 15, 2024
CVE-2024-3970
5.3 MEDIUM

Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure by directory traversal.

May 15, 2024
CVE-2024-3488
5.6 MEDIUM

File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a file without authentication.

May 15, 2024
CVE-2024-3485
5.3 MEDIUM

Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure.

May 15, 2024
CVE-2024-3484
5.7 MEDIUM

Path Traversal found in OpenText™ iManager 3.2.6.0200. This can lead to privilege escalation or file disclosure.

May 15, 2024
CVE-2024-28087
6.5 MEDIUM

In Bonitasoft runtime Community edition, the lack of dynamic permissions causes IDOR vulnerability. Dynamic permissions existed only in Subscription edition and have now been restored …

May 15, 2024
CVE-2024-27593
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Filter function of Eramba Version 3.22.3 Community Edition allows authenticated attackers to execute arbitrary web scripts or …

May 15, 2024
CVE-2023-7258
4.8 MEDIUM

A denial of service exists in Gvisor Sandbox where a bug in reference counting code in mount point tracking could lead to a panic, making …

May 15, 2024
CVE-2024-4903
6.3 MEDIUM

A vulnerability was found in Tongda OA 2017. It has been declared as critical. This vulnerability affects unknown code of the file /general/meeting/manage/delete.php. The manipulation …

May 15, 2024
CVE-2024-3318
4.2 MEDIUM

A file path traversal vulnerability was identified in the DelimitedFileConnector Cloud Connector that allowed an authenticated administrator to set arbitrary connector attributes, including the “file“ …

May 15, 2024
CVE-2024-3317
6.5 MEDIUM

An improper access control was identified in the Identity Security Cloud (ISC) message server API that allowed an authenticated user to exfiltrate job processing metadata …

May 15, 2024
CVE-2024-35179
6.8 MEDIUM

Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, when using `RUN_AS_USER`, the specified user (and therefore, web interface admins) can read …

May 15, 2024
CVE-2024-31216
5.1 MEDIUM

The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3-compatible buckets. The source-controller implements …

May 15, 2024
CVE-2024-34954
6.1 MEDIUM

Code-projects Budget Management 1.0 is vulnerable to Cross Site Scripting (XSS) via the budget parameter.

May 15, 2024
CVE-2024-2248
6.4 MEDIUM

A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted) may allow threat actors to take over the end …

May 15, 2024
CVE-2023-6323
4.3 MEDIUM

ThroughTek Kalay SDK does not verify the authenticity of received messages, allowing an attacker to impersonate an authoritative server.

May 15, 2024
CVE-2024-4702
6.4 MEDIUM

The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 1.2.1 …

May 15, 2024
CVE-2024-34101
5.5 MEDIUM

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

May 15, 2024
CVE-2024-30312
5.5 MEDIUM

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

May 15, 2024
CVE-2024-30311
5.5 MEDIUM

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

May 15, 2024
CVE-2024-4636
6.4 MEDIUM

The Image Optimization by Optimole – Lazy Load, CDN, Convert WebP & AVIF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘allow_meme_types’ …

May 15, 2024
CVE-2024-3824
5.5 MEDIUM

The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check in place when resetting its settings, which could allow attackers to make a …

May 15, 2024
CVE-2024-3822
4.8 MEDIUM

The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

May 15, 2024
CVE-2024-3749
6.5 MEDIUM

The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download files …

May 15, 2024
CVE-2024-3748
6.5 MEDIUM

The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user to manipulate the `user_id` to …

May 15, 2024
CVE-2024-3634
4.8 MEDIUM

The month name translation benaceur WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, which could allow high privilege users such …

May 15, 2024
CVE-2024-3631
4.3 MEDIUM

The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check when unlinking twitter accounts, which could allow attackers to make logged in admins …

May 15, 2024
CVE-2024-3630
5.4 MEDIUM

The HL Twitter WordPress plugin through 2014.1.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2024
CVE-2024-3548
6.1 MEDIUM

The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.1.2 does not sanitise and escape a parameter before outputting it back in the page, …

May 15, 2024
CVE-2024-3407
5.3 MEDIUM

The WP Prayer WordPress plugin through 2.0.9 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

May 15, 2024
CVE-2024-4894
5.3 MEDIUM

ITPison OMICARD EDM fails to properly filter specific URL parameter, allowing unauthenticated remote attackers to modify the parameters and conduct Server-Side Request Forgery (SSRF) attacks. …

May 15, 2024
CVE-2024-4208
6.4 MEDIUM

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the typer effect …

May 15, 2024
CVE-2024-3189
5.4 MEDIUM

The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Testimonial', 'Progress Bar', …

May 15, 2024
CVE-2024-4734
4.4 MEDIUM

The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and …

May 15, 2024
CVE-2024-4656
4.4 MEDIUM

The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user agent header in all versions up …

May 15, 2024
CVE-2024-4618
6.4 MEDIUM

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Team Member widget in all versions up to, and …

May 15, 2024
CVE-2024-4373
6.4 MEDIUM

The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to …

May 15, 2024
CVE-2024-4199
4.3 MEDIUM

The Bulk Posts Editing For WordPress plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on the plugin's …

May 15, 2024
CVE-2024-35109
6.5 MEDIUM

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /homePro_deal.php?mudi=add&nohrefStr=close.

May 15, 2024
CVE-2024-3744
6.5 MEDIUM

A security issue was discovered in azure-file-csi-driver where an actor with access to the driver logs could observe service account tokens. These tokens could then …

May 15, 2024
CVE-2024-4370
6.4 MEDIUM

The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget Image Box in all versions …

May 15, 2024
CVE-2024-4363
6.4 MEDIUM

The Visual Portfolio, Photo Gallery & Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ parameter in all versions up …

May 15, 2024
CVE-2024-0437
4.3 MEDIUM

The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vulnerable to Sensitive Information Exposure in all …

May 15, 2024
CVE-2024-4666
6.4 MEDIUM

The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in …

May 14, 2024
CVE-2024-31483
4.9 MEDIUM

An authenticated sensitive information disclosure vulnerability exists in the CLI service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability …

May 14, 2024
CVE-2024-31482
5.3 MEDIUM

An unauthenticated Denial-of-Service (DoS) vulnerability exists in the ANSI escape code service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the …

May 14, 2024
CVE-2024-31481
5.3 MEDIUM

Unauthenticated Denial of Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability …

May 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.