CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-44247
6.6 MEDIUM

A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 6.4 all versions may allow a privileged attacker to execute code or commands via crafted HTTP …

May 14, 2024
CVE-2023-36640
6.7 MEDIUM

A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, …

May 14, 2024
CVE-2023-24204
5.4 MEDIUM

SQL injection vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitrary code via the name parameter in get-quote.php.

May 14, 2024
CVE-2023-24203
5.4 MEDIUM

Cross Site Scripting vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitary code via the company or query parameter(s).

May 14, 2024
CVE-2024-4871
6.8 MEDIUM

A vulnerability was found in Satellite. When running a remote execution job on a host, the host's SSH key is not being checked. When the …

May 14, 2024
CVE-2024-4860
5.4 MEDIUM

The 'WordPress RSS Aggregator' WordPress Plugin, versions < 4.23.9 are affected by a Cross-Site Scripting (XSS) vulnerability due to the lack of sanitization of the …

May 14, 2024
CVE-2024-4859
5.7 MEDIUM

Solidus <= 4.3.4 is affected by a Stored Cross-Site Scripting vulnerability in the order tracking URL.

May 14, 2024
CVE-2024-4624
6.4 MEDIUM

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugins for WordPress is vulnerable to Stored Cross-Site Scripting via the …

May 14, 2024
CVE-2024-4473
6.4 MEDIUM

The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "aThemes: Portfolio" widget in all versions up to, and including, 1.31 …

May 14, 2024
CVE-2024-4445
6.5 MEDIUM

The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

May 14, 2024
CVE-2024-4440
6.4 MEDIUM

The 140+ Widgets | Best Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all …

May 14, 2024
CVE-2024-4392
6.4 MEDIUM

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpvideo shortcode in all …

May 14, 2024
CVE-2024-4333
6.4 MEDIUM

The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to …

May 14, 2024
CVE-2024-4144
6.5 MEDIUM

The Simple Basic Contact Form plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 20240502. This …

May 14, 2024
CVE-2024-4139
4.3 MEDIUM

Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an …

May 14, 2024
CVE-2024-4138
4.3 MEDIUM

Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an …

May 14, 2024
CVE-2024-3579
6.1 MEDIUM

Open-source project Online Shopping System Advanced is vulnerable to Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will …

May 14, 2024
CVE-2024-3374
5.3 MEDIUM

An unauthenticated user can trigger a fatal assertion in the server while generating ftdc diagnostic metrics due to attempting to build a BSON object that …

May 14, 2024
CVE-2024-3241
5.4 MEDIUM

The Ultimate Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where …

May 14, 2024
CVE-2024-35012
6.3 MEDIUM

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoType_deal.php?mudi=add&nohrefStr=close.

May 14, 2024
CVE-2024-35011
5.4 MEDIUM

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoType_deal.php?mudi=rev&nohrefStr=close.

May 14, 2024
CVE-2024-34914
5.3 MEDIUM

php-censor v2.1.4 and fixed in v.2.1.5 was discovered to utilize a weak hashing algorithm for its remember_key value. This allows attackers to bruteforce to bruteforce …

May 14, 2024
CVE-2024-34717
5.3 MEDIUM

PrestaShop is an open source e-commerce web application. In PrestaShop 8.1.5, any invoice can be downloaded from front-office in anonymous mode, by supplying a random …

May 14, 2024
CVE-2024-34712
6.5 MEDIUM

Oceanic is a NodeJS library for interfacing with Discord. Prior to version 1.10.4, input to functions such as `Client.rest.channels.removeBan` is not url-encoded, resulting in specially …

May 14, 2024
CVE-2024-34687
6.5 MEDIUM

SAP NetWeaver Application Server for ABAP and ABAP Platform do not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker can …

May 14, 2024
CVE-2024-34358
5.3 MEDIUM

TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, …

May 14, 2024
CVE-2024-34357
5.4 MEDIUM

TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, …

May 14, 2024
CVE-2024-34356
5.4 MEDIUM

TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, …

May 14, 2024
CVE-2024-34243
5.4 MEDIUM

Konga v0.14.9 is vulnerable to Cross Site Scripting (XSS) via the username parameter.

May 14, 2024
CVE-2024-34191
6.5 MEDIUM

htmly v2.9.6 was discovered to contain an arbitrary file deletion vulnerability via the delete_post() function at admin.php. This vulnerability allows attackers to delete arbitrary files …

May 14, 2024
CVE-2024-33867
4.8 MEDIUM

An issue was discovered in linqi before 1.4.0.1 on Windows. There is a hardcoded password salt.

May 14, 2024
CVE-2024-33866
5.5 MEDIUM

An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/DocumentTemplate/{GUID] XSS.

May 14, 2024
CVE-2024-33864
5.9 MEDIUM

An issue was discovered in linqi before 1.4.0.1 on Windows. There is SSRF via Document template generation; i.e., via remote images in process creation, file …

May 14, 2024
CVE-2024-33647
6.5 MEDIUM

A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The Apache Lucene based query engine in the affected application lacks proper access …

May 14, 2024
CVE-2024-33498
5.3 MEDIUM

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC …

May 14, 2024
CVE-2024-33497
6.3 MEDIUM

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC …

May 14, 2024
CVE-2024-33496
6.3 MEDIUM

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC …

May 14, 2024
CVE-2024-33495
6.5 MEDIUM

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC …

May 14, 2024
CVE-2024-33494
6.5 MEDIUM

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC …

May 14, 2024
CVE-2024-33009
4.2 MEDIUM

SAP Global Label Management is vulnerable to SQL injection. On exploitation the attacker can use specially crafted inputs to modify database commands resulting in the …

May 14, 2024
CVE-2024-33008
4.9 MEDIUM

SAP Replication Server allows an attacker to use gateway for executing some commands to RSSD. This could result in crashing the Replication Server due to …

May 14, 2024
CVE-2024-33004
4.3 MEDIUM

SAP Business Objects Business Intelligence Platform is vulnerable to Insecure Storage as dynamic web pages are getting cached even after logging out. On successful exploitation, …

May 14, 2024
CVE-2024-33002
6.1 MEDIUM

Document Service handler (obsolete) in Data Provisioning Service does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability with low impact on Confidentiality …

May 14, 2024
CVE-2024-32733
6.1 MEDIUM

Due to missing input validation and output encoding of untrusted data, SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject …

May 14, 2024
CVE-2024-32731
5.5 MEDIUM

SAP My Travel Requests does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker can …

May 14, 2024
CVE-2024-32354
6.0 MEDIUM

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'timeout' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.

May 14, 2024
CVE-2024-32349
6.0 MEDIUM

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mtu" parameters in the "cstecgi.cgi" binary.

May 14, 2024
CVE-2024-32077
5.4 MEDIUM

Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs. Users are recommended to …

May 14, 2024
CVE-2024-31486
5.3 MEDIUM

A vulnerability has been identified in OPUPI0 AMQP/MQTT (All versions < V5.30). The affected devices stores MQTT client passwords without sufficient protection on the devices. …

May 14, 2024
CVE-2024-30208
6.3 MEDIUM

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC …

May 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.