CVE Database

59444+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-42262
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Fix potential memory leak in the performance extension If fetching of userspace memory fails …

Aug 17, 2024
CVE-2024-42261
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Validate passed in drm syncobj handles in the timestamp extension If userspace provides an …

Aug 17, 2024
CVE-2024-42260
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Validate passed in drm syncobj handles in the performance extension If userspace provides an …

Aug 17, 2024
CVE-2023-5505
6.8 MEDIUM

The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the job-specific backup folder. This allows authenticated …

Aug 17, 2024
CVE-2023-52889
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: apparmor: Fix null pointer deref when receiving skb during sock creation The panic below is …

Aug 17, 2024
CVE-2023-3409
5.4 MEDIUM

The Bricks theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.1. This is due to missing or incorrect …

Aug 17, 2024
CVE-2023-3408
4.3 MEDIUM

The Bricks theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.1. This is due to missing or incorrect …

Aug 17, 2024
CVE-2023-4730
5.3 MEDIUM

The LadiApp plugn for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init_endpoint() function hooked via 'init' …

Aug 17, 2024
CVE-2023-4604
6.1 MEDIUM

The Slideshow, Image Slider by 2J plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘post’ parameter in versions up to, and including, …

Aug 17, 2024
CVE-2023-4507
6.1 MEDIUM

The Admission AppManager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'q' parameter in versions up to, and including, 1.0.0 due to …

Aug 17, 2024
CVE-2023-4027
5.3 MEDIUM

The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_settings function in versions …

Aug 17, 2024
CVE-2023-4025
5.3 MEDIUM

The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_player function in versions …

Aug 17, 2024
CVE-2023-4024
5.3 MEDIUM

The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_player function in versions …

Aug 17, 2024
CVE-2023-1604
4.7 MEDIUM

The Short URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.8. This is due to missing or …

Aug 17, 2024
CVE-2022-4532
6.5 MEDIUM

The LOGIN AND REGISTRATION ATTEMPTS LIMIT plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1. This is due …

Aug 17, 2024
CVE-2024-43472
5.8 MEDIUM

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Aug 16, 2024
CVE-2024-43011
4.9 MEDIUM

An arbitrary file deletion vulnerability exists in the admin/del.php file at line 62 in ZZCMS 2023 and earlier. Due to insufficient validation and sanitization of …

Aug 16, 2024
CVE-2024-43009
4.7 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in user/login.php at line 24 in ZZCMS 2023 and earlier. The application directly inserts the value of the …

Aug 16, 2024
CVE-2024-43006
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in ZZCMS2023 in the ask/show.php file at line 21. An attacker can exploit this vulnerability by sending a …

Aug 16, 2024
CVE-2024-43005
4.7 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the component dl_liuyan_save.php of ZZCMS v2023 allows attackers to execute arbitrary code in the context of a user's …

Aug 16, 2024
CVE-2023-47728
6.5 MEDIUM

IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a remote attacker to obtain sensitive information …

Aug 16, 2024
CVE-2024-42849
6.5 MEDIUM

An issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function.

Aug 16, 2024
CVE-2024-42758
5.4 MEDIUM

A Cross-site Scripting (XSS) vulnerability exists in version v2024-01-05 of the indexmenu plugin when is used and enabled in Dokuwiki (Open Source Wiki Engine). A …

Aug 16, 2024
CVE-2024-25837
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in October CMS Bloghub Plugin v1.3.8 and lower allows attackers to execute arbitrary web scripts or HTML via a …

Aug 16, 2024
CVE-2024-6098
5.3 MEDIUM

When performing an online tag generation to devices which communicate using the ControlLogix protocol, a machine-in-the-middle, or a device that is not configured correctly, could …

Aug 16, 2024
CVE-2024-6004
6.5 MEDIUM

A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to deny printer connections until the …

Aug 16, 2024
CVE-2024-5210
6.5 MEDIUM

A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to prevent printer services from being …

Aug 16, 2024
CVE-2024-5209
6.5 MEDIUM

A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to deny printing capabilities until the …

Aug 16, 2024
CVE-2024-4782
6.5 MEDIUM

A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to disrupt the printer's functionality until …

Aug 16, 2024
CVE-2024-4781
6.5 MEDIUM

A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to crash printer communications until the …

Aug 16, 2024
CVE-2024-43810
4.6 MEDIUM

In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin

Aug 16, 2024
CVE-2024-43807
4.6 MEDIUM

In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page

Aug 16, 2024
CVE-2024-43381
5.0 MEDIUM

reNgine is an automated reconnaissance framework for web applications. Versions 2.1.2 and prior are susceptible to Stored Cross-Site Scripting (XSS) attacks. This vulnerability occurs when …

Aug 16, 2024
CVE-2024-42486
5.4 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In versions on the 1.15.x branch prior to 1.15.8 and the 1.16.x branch …

Aug 16, 2024
CVE-2024-7144
6.4 MEDIUM

The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'slide_id' parameters in all versions up to, and including, 2.6.20 …

Aug 16, 2024
CVE-2024-42464
6.5 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Utilizing REST's Trust in the System Resource to Obtain Sensitive Data.This issue …

Aug 16, 2024
CVE-2024-42463
6.5 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Utilizing REST's Trust in the System Resource to Obtain Sensitive Data.This issue …

Aug 16, 2024
CVE-2024-7147
6.4 MEDIUM

The JetBlocks for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple placeholder parameters in all versions up to, and including, 1.3.12 …

Aug 16, 2024
CVE-2024-7136
6.4 MEDIUM

The JetSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 3.5.2 due to …

Aug 16, 2024
CVE-2024-25008
6.8 MEDIUM

Ericsson RAN Compute and Site Controller 6610 contains a vulnerability in the Control System where Improper Input Validation can lead to arbitrary code execution, for …

Aug 16, 2024
CVE-2024-7501
4.2 MEDIUM

The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Aug 16, 2024
CVE-2024-7422
4.3 MEDIUM

The Theme My Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.1.7. This is due to …

Aug 16, 2024
CVE-2024-7630
5.3 MEDIUM

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.22.2 (Free) and 2.25.1 …

Aug 16, 2024
CVE-2023-7049
4.3 MEDIUM

The Custom Field For WP Job Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2 …

Aug 16, 2024
CVE-2022-3399
4.4 MEDIUM

The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cookie_notice_options[refuse_code_head]' parameter in versions up …

Aug 16, 2024
CVE-2024-7853
6.3 MEDIUM

A vulnerability was found in SourceCodester Yoga Class Registration System up to 1.0. It has been classified as critical. Affected is an unknown function of …

Aug 16, 2024
CVE-2024-7851
6.3 MEDIUM

A vulnerability has been found in SourceCodester Yoga Class Registration System 1.0 and classified as critical. This vulnerability affects unknown code of the file /classes/Users.php?f=save …

Aug 16, 2024
CVE-2024-7845
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Aug 16, 2024
CVE-2024-43374
4.5 MEDIUM

The UNIX editor Vim prior to version 9.1.0678 has a use-after-free error in argument list handling. When adding a new file to the argument list, …

Aug 16, 2024
CVE-2024-7843
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0. Affected is an unknown function of the file /tracking/admin/exportcs.php. …

Aug 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.