CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4281
6.4 MEDIUM

The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'link-library' shortcode in all versions up to, and including, 7.6.11 …

May 8, 2024
CVE-2024-4135
5.4 MEDIUM

The WP Latest Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.7. This is due to …

May 8, 2024
CVE-2024-34572
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePrix Fancy Elementor Flipbox fancy-elementor-flipbox allows Stored XSS.This issue affects Fancy Elementor Flipbox: …

May 8, 2024
CVE-2024-34571
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGrill Himalayas allows Stored XSS.This issue affects Himalayas: from n/a through 1.3.0.

May 8, 2024
CVE-2024-34574
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpsoul Table Maker allows Stored XSS.This issue affects Table Maker: from n/a through …

May 8, 2024
CVE-2024-34573
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pootlepress Pootle Pagebuilder – WordPress Page builder allows Stored XSS.This issue affects Pootle …

May 8, 2024
CVE-2023-41651
6.5 MEDIUM

Missing Authorization vulnerability in Multi-column Tag Map.This issue affects Multi-column Tag Map: from n/a through 17.0.26.

May 8, 2024
CVE-2024-3494
6.4 MEDIUM

The Mesmerize Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mesmerize_contact_form' shortcode in all versions up to, and including, 1.6.148 …

May 8, 2024
CVE-2024-1076
6.5 MEDIUM

The SSL Zen WordPress plugin before 4.6.0 does not properly prevent directory listing of the private keys folder, as it only relies on the use …

May 8, 2024
CVE-2024-32674
5.4 MEDIUM

Heateor Social Login WordPress prior to 1.1.32 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the …

May 8, 2024
CVE-2024-22266
6.5 MEDIUM

VMware Avi Load Balancer contains an information disclosure vulnerability. A malicious actor with access to the system logs can view cloud connection credentials in plaintext.

May 8, 2024
CVE-2024-4418
6.2 MEDIUM

A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer …

May 8, 2024
CVE-2024-4162
4.4 MEDIUM

A buffer error in Panasonic KW Watcher versions 1.00 through 2.83 may allow attackers malicious read access to memory.

May 8, 2024
CVE-2024-1930
6.5 MEDIUM

No Limit on Number of Open Sessions / Bad Session Close Behaviour in dnf5daemon-server before 5.1.17 allows a malicious user to impact Availability via No …

May 8, 2024
CVE-2024-4456
4.1 MEDIUM

In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting payload on the audit page.

May 8, 2024
CVE-2023-37325
5.4 MEDIUM

D-Link DAP-2622 DDP Set SSID List Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to make unauthorized changes to device configuration on affected installations of …

May 7, 2024
CVE-2022-43656
5.5 MEDIUM

Bentley View FBX File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View. …

May 7, 2024
CVE-2022-43652
5.5 MEDIUM

Bentley View SKP File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View. User …

May 7, 2024
CVE-2021-35001
6.5 MEDIUM

BMC Track-It! GetData Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It!. Authentication is …

May 7, 2024
CVE-2021-34999
5.5 MEDIUM

OpenBSD Kernel Multicast Routing Uninitialized Memory Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of OpenBSD Kernel. An …

May 7, 2024
CVE-2021-34983
6.5 MEDIUM

NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of …

May 7, 2024
CVE-2021-34981
6.7 MEDIUM

Linux Kernel Bluetooth CMTP Module Double Free Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An …

May 7, 2024
CVE-2021-34976
5.5 MEDIUM

Foxit PDF Reader PDF File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34973
5.5 MEDIUM

Foxit PDF Reader PDF File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34972
5.5 MEDIUM

Foxit PDF Reader AcroForm Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User …

May 7, 2024
CVE-2021-34970
5.5 MEDIUM

Foxit PDF Reader print Method Use of Externally-Controlled Format String Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations …

May 7, 2024
CVE-2021-34969
5.5 MEDIUM

Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User …

May 7, 2024
CVE-2021-34949
5.5 MEDIUM

Foxit PDF Reader Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. …

May 7, 2024
CVE-2024-23551
6.5 MEDIUM

Database scanning using username and password stores the credentials in plaintext or encoded format within files at the endpoint. This has been identified as a …

May 7, 2024
CVE-2024-23712
5.5 MEDIUM

In multiple functions of AppOpsService.java, there is a possible way to saturate the content of /data/system/appops_accesses.xml due to resource exhaustion. This could lead to local …

May 7, 2024
CVE-2024-23709
6.5 MEDIUM

In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with …

May 7, 2024
CVE-2024-0027
5.5 MEDIUM

In multiple functions of SnoozeHelper.java, there is a possible way to cause a boot loop due to resource exhaustion. This could lead to local denial …

May 7, 2024
CVE-2024-0026
5.5 MEDIUM

In multiple functions of SnoozeHelper.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service …

May 7, 2024
CVE-2024-0022
5.5 MEDIUM

In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profile due to improper input validation. This could lead to local …

May 7, 2024
CVE-2023-40694
6.2 MEDIUM

IBM Watson CP4D Data Stores 4.0.0 through 4.8.4 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force …

May 7, 2024
CVE-2024-4559
6.5 MEDIUM

Heap buffer overflow in WebAudio in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

May 7, 2024
CVE-2024-34314
4.9 MEDIUM

CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the fetch_action method of /admin/template_admin.php. This vulnerability allows attackers …

May 7, 2024
CVE-2024-34517
6.5 MEDIUM

The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.

May 7, 2024
CVE-2024-34397
5.2 MEDIUM

An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted …

May 7, 2024
CVE-2023-42757
4.2 MEDIUM

Process Explorer before 17.04 allows attackers to make it functionally unavailable (a denial of service for analysis) by renaming an executable file to a new …

May 7, 2024
CVE-2024-33860
6.5 MEDIUM

An issue was discovered in Logpoint before 7.4.0. It allows Local File Inclusion (LFI) when an arbitrary File Path is used within the File System …

May 7, 2024
CVE-2024-33859
6.1 MEDIUM

An issue was discovered in Logpoint before 7.4.0. HTML code sent through logs wasn't being escaped in the "Interesting Field" Web UI, leading to XSS.

May 7, 2024
CVE-2024-33161
5.3 MEDIUM

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the unallocatedList() function.

May 7, 2024
CVE-2024-29209
6.0 MEDIUM

A medium severity vulnerability has been identified in the update mechanism of the Phish Alert Button for Outlook, which could allow an attacker to remotely …

May 7, 2024
CVE-2024-27982
6.5 MEDIUM

The team has identified a critical vulnerability in the http server of the most recent version of Node, where malformed headers can lead to HTTP …

May 7, 2024
CVE-2024-34341
5.4 MEDIUM

Trix is a rich text editor. The Trix editor, versions prior to 2.1.1, is vulnerable to arbitrary code execution when copying and pasting content from …

May 7, 2024
CVE-2024-33858
5.3 MEDIUM

An issue was discovered in Logpoint before 7.4.0. A path injection vulnerability is seen while adding a CSV enrichment source. The source_name parameter could be …

May 7, 2024
CVE-2024-33856
5.3 MEDIUM

An issue was discovered in Logpoint before 7.4.0. An attacker can enumerate a valid list of usernames by observing the response time at the Forgot …

May 7, 2024
CVE-2024-33748
4.1 MEDIUM

Cross-site scripting (XSS) vulnerability in the search function in Maven net.mingsoft MS Basic 2.1.13.4 and earlier.

May 7, 2024
CVE-2024-4595
6.3 MEDIUM

A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is the function locate of the file …

May 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.