CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-33938
6.5 MEDIUM

Missing Authorization vulnerability in codename065 Sliding Widgets allows Cross-Site Scripting (XSS).This issue affects Sliding Widgets: from n/a through 1.5.0.

May 14, 2024
CVE-2024-33876
5.7 MEDIUM

HDF5 Library through 1.14.3 has a heap buffer overflow in H5S__point_deserialize in H5Spoint.c.

May 14, 2024
CVE-2024-33875
5.7 MEDIUM

HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5O__layout_encode in H5Olayout.c, resulting in the corruption of the instruction pointer.

May 14, 2024
CVE-2024-33819
4.6 MEDIUM

Globitel KSA SpeechLog v8.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Save Query function.

May 14, 2024
CVE-2024-33774
6.5 MEDIUM

A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanSetup_Wizard allows remote authenticated users to trigger a denial of service (DoS) through …

May 14, 2024
CVE-2024-33773
6.5 MEDIUM

A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanGuestSetup allows remote authenticated users to trigger a denial of service (DoS) through …

May 14, 2024
CVE-2024-33772
5.7 MEDIUM

A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formTcpipSetup allows remote authenticated users to trigger a denial of service (DoS) through …

May 14, 2024
CVE-2024-33771
6.5 MEDIUM

A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via goform/formWPS, allows remote authenticated users to trigger a denial of service (DoS) through …

May 14, 2024
CVE-2024-33454
6.5 MEDIUM

Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the Bluetooth stack component.

May 14, 2024
CVE-2024-33433
4.8 MEDIUM

Cross Site Scripting vulnerability in TOTOLINK X2000R before v1.0.0-B20231213.1013 allows a remote attacker to execute arbitrary code via the Guest Access Control parameter in the …

May 14, 2024
CVE-2024-33263
4.0 MEDIUM

QuickJS commit 3b45d15 was discovered to contain an Assertion Failure via JS_FreeRuntime(JSRuntime *) at quickjs.c.

May 14, 2024
CVE-2024-32999
6.8 MEDIUM

Cracking vulnerability in the OS security module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32998
5.9 MEDIUM

NULL pointer access vulnerability in the clock module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32996
6.2 MEDIUM

Privilege escalation vulnerability in the account module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32995
6.2 MEDIUM

Denial of service (DoS) vulnerability in the AMS module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32993
5.6 MEDIUM

Out-of-bounds access vulnerability in the memory module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32990
6.1 MEDIUM

Permission verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32985
5.9 MEDIUM

Stellar-core is a reference implementation for the peer-to-peer agent that manages the Stellar network. Prior to 20.4.0, core nodes could be randomly crashed due to …

May 14, 2024
CVE-2024-32874
6.8 MEDIUM

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Below 0.13.2 Release, when uploading a file or retrieving the …

May 14, 2024
CVE-2024-32776
6.5 MEDIUM

Missing Authorization vulnerability in AppPresser Team AppPresser.This issue affects AppPresser: from n/a through 4.3.0.

May 14, 2024
CVE-2024-32730
6.5 MEDIUM

SAP Enable Now Manager does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker with …

May 14, 2024
CVE-2024-32719
5.3 MEDIUM

Missing Authorization vulnerability in WP Club Manager WP Club Manager wp-club-manager.This issue affects WP Club Manager: from n/a through <= 2.2.11.

May 14, 2024
CVE-2024-32717
6.5 MEDIUM

Missing Authorization vulnerability in WPDeveloper SchedulePress.This issue affects SchedulePress: from n/a through 5.0.8.

May 14, 2024
CVE-2024-32672
5.3 MEDIUM

A Segmentation Fault issue discovered in Samsung Open Source Escargot JavaScript engine allows remote attackers to cause a denial of service via crafted input. This …

May 14, 2024
CVE-2024-32669
5.3 MEDIUM

Improper Input Validation vulnerability in Samsung Open Source escargot JavaScript engine allows Overflow Buffers. However, it occurs in the test code and does not include …

May 14, 2024
CVE-2024-32610
5.7 MEDIUM

HDF5 Library through 1.14.3 has a SEGV in H5T_close_real in H5T.c, resulting in a corrupted instruction pointer.

May 14, 2024
CVE-2024-32607
5.7 MEDIUM

HDF5 Library through 1.14.3 has a SEGV in H5A__close in H5Aint.c, resulting in the corruption of the instruction pointer.

May 14, 2024
CVE-2024-32606
5.7 MEDIUM

HDF5 Library through 1.14.3 may attempt to dereference uninitialized values in h5tools_str_sprint in tools/lib/h5tools_str.c (called from h5tools_dump_simple_data in tools/lib/h5tools_dump.c).

May 14, 2024
CVE-2024-32476
6.5 MEDIUM

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. There is a Denial of Service (DoS) vulnerability via OOM using jq in ignoreDifferences. …

May 14, 2024
CVE-2024-32100
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.11.

May 14, 2024
CVE-2024-31953
6.7 MEDIUM

An issue was discovered in Samsung Magician 8.0.0 on macOS. Because it is possible to tamper with the directory and executable files used during the …

May 14, 2024
CVE-2024-31952
6.7 MEDIUM

An issue was discovered in Samsung Magician 8.0.0 on macOS. Because symlinks are used during the installation process, an attacker can escalate privileges via arbitrary …

May 14, 2024
CVE-2024-31803
6.2 MEDIUM

Buffer Overflow vulnerability in emp-ot v.0.2.4 allows a remote attacker to execute arbitrary code via the FerretCOT<T>::read_pre_data128_from_file function.

May 14, 2024
CVE-2024-31460
6.5 MEDIUM

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules.php` is not thoroughly checked and …

May 14, 2024
CVE-2024-31458
4.6 MEDIUM

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `form_save()` function in `graph_template_inputs.php` is not …

May 14, 2024
CVE-2024-31444
4.6 MEDIUM

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules_form_save()` function in `automation_tree_rules.php` is not …

May 14, 2024
CVE-2024-31443
5.7 MEDIUM

Cacti provides an operational monitoring and fault management framework. Prior to 1.2.27, some of the data stored in `form_save()` function in `data_queries.php` is not thoroughly …

May 14, 2024
CVE-2024-31113
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.11.

May 14, 2024
CVE-2024-30801
5.5 MEDIUM

SQL Injection vulnerability in Cloud based customer service management platform v.1.0.0 allows a local attacker to execute arbitrary code via a crafted payload to Login.asp …

May 14, 2024
CVE-2024-30268
6.1 MEDIUM

Cacti provides an operational monitoring and fault management framework. A reflected cross-site scripting vulnerability on the 1.3.x DEV branch allows attackers to obtain cookies of …

May 14, 2024
CVE-2024-30171
5.9 MEDIUM

An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of …

May 14, 2024
CVE-2024-30055
5.4 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

May 14, 2024
CVE-2024-2923
6.4 MEDIUM

The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

May 14, 2024
CVE-2024-2846
4.4 MEDIUM

The Visual Footer Credit Remover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'selector' parameter in all versions up to, and including, …

May 14, 2024
CVE-2024-2785
6.4 MEDIUM

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Age Gate widget in all versions up to, …

May 14, 2024
CVE-2024-2749
5.9 MEDIUM

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's access control mechanism fails to properly restrict access to its settings, permitting any users …

May 14, 2024
CVE-2024-2651
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 …

May 14, 2024
CVE-2024-2454
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting …

May 14, 2024
CVE-2024-2299
6.1 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability exists in the parisneo/lollms-webui application due to improper validation of uploaded files in the profile picture upload functionality. Attackers …

May 14, 2024
CVE-2024-29894
5.4 MEDIUM

Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 contain a residual cross-site scripting vulnerability caused by an incomplete …

May 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.