CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-33908
5.3 MEDIUM

Missing Authorization vulnerability in Themesgrove WidgetKit.This issue affects WidgetKit: from n/a through 2.5.0.

May 6, 2024
CVE-2024-33907
5.3 MEDIUM

Missing Authorization vulnerability in Michael Nelson Print My Blog print-my-blog.This issue affects Print My Blog: from n/a through <= 3.26.2.

May 6, 2024
CVE-2024-33600
5.9 MEDIUM

nscd: Null pointer crashes after notfound response If the Name Service Cache Daemon's (nscd) cache fails to add a not-found netgroup response to the cache, …

May 6, 2024
CVE-2024-33576
6.5 MEDIUM

Missing Authorization vulnerability in Ollybach WPPizza.This issue affects WPPizza: from n/a through 3.18.10.

May 6, 2024
CVE-2024-33570
4.3 MEDIUM

Missing Authorization vulnerability in Roxnor Metform metform.This issue affects Metform: from n/a through <= 3.8.3.

May 6, 2024
CVE-2024-33121
6.3 MEDIUM

Roothub v2.6 was discovered to contain a SQL injection vulnerability via the 's' parameter in the search() function.

May 6, 2024
CVE-2024-33117
5.3 MEDIUM

crmeb_java v1.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the mergeList method in class com.zbkj.front.pub.ImageMergeController.

May 6, 2024
CVE-2024-34390
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AddonMaster Post Grid Master allows Stored XSS.This issue affects Post Grid Master: from …

May 6, 2024
CVE-2024-34389
4.3 MEDIUM

Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4.

May 6, 2024
CVE-2024-34387
4.3 MEDIUM

Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4.

May 6, 2024
CVE-2024-34381
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.10.

May 6, 2024
CVE-2024-34380
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Stored XSS.This issue affects Conversational Forms for …

May 6, 2024
CVE-2024-34379
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Restaurant and Cafe.This issue affects Restaurant and Cafe: from n/a through 1.2.1.

May 6, 2024
CVE-2024-34377
4.3 MEDIUM

Missing Authorization vulnerability in A WP Life Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery.This issue affects Video Gallery – Api Gallery, YouTube …

May 6, 2024
CVE-2024-34376
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme Freesia Edge allows Stored XSS.This issue affects Edge: from n/a through 2.0.9.

May 6, 2024
CVE-2024-34375
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL Sheets To WP Table Live Sync allows Stored XSS.This issue affects Sheets …

May 6, 2024
CVE-2024-34374
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuomodoSoft ElementsReady Addons for Elementor allows Stored XSS.This issue affects ElementsReady Addons for …

May 6, 2024
CVE-2024-34373
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite the-plus-addons-for-elementor-page-builder.This issue affects The …

May 6, 2024
CVE-2024-34372
5.3 MEDIUM

Missing Authorization vulnerability in AddonMaster Post Grid Master.This issue affects Post Grid Master: from n/a through 3.4.7.

May 6, 2024
CVE-2024-34371
4.3 MEDIUM

Missing Authorization vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.7.18.

May 6, 2024
CVE-2024-34368
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Mooberry Dreams Mooberry Book Manager.This issue affects Mooberry Book Manager: from n/a through 4.15.12.

May 6, 2024
CVE-2024-34366
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AltText.Ai Download Alt Text AI allows Stored XSS.This issue affects Download Alt Text …

May 6, 2024
CVE-2024-33910
5.3 MEDIUM

Missing Authorization vulnerability in Supsystic Digital Publications by Supsystic.This issue affects Digital Publications by Supsystic: from n/a through 1.7.7.

May 6, 2024
CVE-2024-34383
5.3 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in The SEO Guys at SEOPress SEOPress.This issue affects SEOPress: from n/a through 7.7.1.

May 6, 2024
CVE-2024-34382
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in RoboSoft Robo Gallery.This issue affects Robo Gallery: from n/a through 3.2.18.

May 6, 2024
CVE-2024-33407
5.9 MEDIUM

SQL injection vulnerability in /model/delete_record.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.

May 6, 2024
CVE-2024-34471
5.4 MEDIUM

An issue was discovered in HSC Mailinspector 5.2.17-3. A Path Traversal vulnerability (resulting in file deletion) exists in the mliRealtimeEmails.php file. The filename parameter in …

May 6, 2024
CVE-2024-34250
6.2 MEDIUM

A heap buffer overflow vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause at least a denial of service …

May 6, 2024
CVE-2024-34093
5.3 MEDIUM

An issue was discovered in Archer Platform 6 before 2024.03. There is an X-Forwarded-For Header Bypass vulnerability. An unauthenticated attacker could potentially bypass intended whitelisting …

May 6, 2024
CVE-2024-26312
4.3 MEDIUM

Archer Platform 6 before 2024.03 contains a sensitive information disclosure vulnerability. An authenticated attacker could potentially obtain access to sensitive information via a popup warning …

May 6, 2024
CVE-2024-34472
5.5 MEDIUM

An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An authenticated blind SQL injection vulnerability exists in the mliRealtimeEmails.php file. The ordemGrid parameter in …

May 6, 2024
CVE-2024-34078
6.1 MEDIUM

html-sanitizer is an allowlist-based HTML cleaner. If using `keep_typographic_whitespace=False` (which is the default), the sanitizer normalizes unicode to the NFKC form at the end. Some …

May 6, 2024
CVE-2024-34064
5.4 MEDIUM

Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, …

May 6, 2024
CVE-2024-33113
5.3 MEDIUM

D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.

May 6, 2024
CVE-2024-33111
5.4 MEDIUM

D-Link DIR-845L router <=v1.01KRb03 is vulnerable to Cross Site Scripting (XSS) via /htdocs/webinc/js/bsc_sms_inbox.php.

May 6, 2024
CVE-2023-43530
5.9 MEDIUM

Memory corruption in HLOS while checking for the storage type.

May 6, 2024
CVE-2023-43528
6.1 MEDIUM

Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size.

May 6, 2024
CVE-2023-43527
6.8 MEDIUM

Information disclosure while parsing dts header atom in Video.

May 6, 2024
CVE-2023-43526
6.7 MEDIUM

Memory corruption while querying module parameters from Listen Sound model client in kernel from user space.

May 6, 2024
CVE-2023-43525
6.7 MEDIUM

Memory corruption while copying the sound model data from user to kernel buffer during sound model register.

May 6, 2024
CVE-2023-43524
6.7 MEDIUM

Memory corruption when the bandpass filter order received from AHAL is not within the expected range.

May 6, 2024
CVE-2023-43521
6.7 MEDIUM

Memory corruption when multiple listeners are being registered with the same file descriptor.

May 6, 2024
CVE-2024-33752
6.3 MEDIUM

An arbitrary file upload vulnerability exists in emlog pro 2.3.0 and pro 2.3.2 at admin/views/plugin.php that could be exploited by a remote attacker to submit …

May 6, 2024
CVE-2024-33829
5.4 MEDIUM

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=updateWebCache.

May 6, 2024
CVE-2023-49676
5.5 MEDIUM

An unauthenticated local attacker may trick a user to open corrupted project files to crash the system due to use after free vulnerability.

May 6, 2024
CVE-2023-6854
6.4 MEDIUM

The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom postmeta output in all versions up to, and including, 1.7.0 …

May 6, 2024
CVE-2024-23193
5.3 MEDIUM

E-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account. Users of the same …

May 6, 2024
CVE-2024-23188
6.5 MEDIUM

Maliciously crafted E-Mail attachment names could be used to temporarily execute script code in the context of the users browser session. Common user interaction is …

May 6, 2024
CVE-2024-23187
6.5 MEDIUM

Content-ID based embedding of resources in E-Mails could be abused to trigger client-side script code when using the "show more" option. Attackers could perform malicious …

May 6, 2024
CVE-2024-23186
6.5 MEDIUM

E-Mail containing malicious display-name information could trigger client-side script execution when using specific mobile devices. Attackers could perform malicious API requests or extract information from …

May 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.