CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-3755
5.4 MEDIUM

The MF Gig Calendar WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 6, 2024
CVE-2024-3752
5.4 MEDIUM

The Crelly Slider WordPress plugin through 1.4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 6, 2024
CVE-2024-0904
5.9 MEDIUM

The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 6, 2024
CVE-2024-20060
5.9 MEDIUM

In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System …

May 6, 2024
CVE-2024-20059
6.7 MEDIUM

In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System …

May 6, 2024
CVE-2024-20058
4.4 MEDIUM

In keyInstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

May 6, 2024
CVE-2024-20056
6.7 MEDIUM

In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege with System …

May 6, 2024
CVE-2024-20021
6.7 MEDIUM

In atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error. This could lead to local …

May 6, 2024
CVE-2023-32873
6.7 MEDIUM

In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

May 6, 2024
CVE-2023-32871
5.3 MEDIUM

In DA, there is a possible permission bypass due to an incorrect status check. This could lead to local escalation of privilege with no additional …

May 6, 2024
CVE-2024-4511
6.3 MEDIUM

A vulnerability classified as critical has been found in Shanghai Sunfull Automation BACnet Server HMI1002-ARM 2.0.4. This affects an unknown part of the component Message …

May 6, 2024
CVE-2024-4510
4.7 MEDIUM

A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been rated as critical. Affected by this issue is some unknown functionality of …

May 6, 2024
CVE-2024-4509
4.7 MEDIUM

A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

May 6, 2024
CVE-2024-4508
4.7 MEDIUM

A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been classified as critical. Affected is an unknown function of the file /view/IPV6/ipv6StaticRoute/static_route_edit_ipv6.php. …

May 6, 2024
CVE-2024-4507
4.7 MEDIUM

A vulnerability was found in Ruijie RG-UAC up to 20240428 and classified as critical. This issue affects some unknown processing of the file /view/IPV6/ipv6StaticRoute/static_route_add_ipv6.php. The …

May 6, 2024
CVE-2024-34529
4.8 MEDIUM

Nebari through 2024.4.1 prints the temporary Keycloak root password.

May 6, 2024
CVE-2024-34525
5.3 MEDIUM

FileCodeBox 2.0 stores a OneDrive password and AWS key in a cleartext env file.

May 6, 2024
CVE-2024-4506
4.7 MEDIUM

A vulnerability has been found in Ruijie RG-UAC up to 20240428 and classified as critical. This vulnerability affects unknown code of the file /view/IPV6/ipv6Addr/ip_addr_edit_commit.php. The …

May 5, 2024
CVE-2024-4505
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in Ruijie RG-UAC up to 20240428. This affects an unknown part of the file /view/IPV6/ipv6Addr/ip_addr_add_commit.php. The …

May 5, 2024
CVE-2024-4504
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240428. Affected by this issue is some unknown functionality of …

May 5, 2024
CVE-2024-4503
4.7 MEDIUM

A vulnerability classified as critical was found in Ruijie RG-UAC up to 20240428. Affected by this vulnerability is an unknown functionality of the file /view/dhcp/dhcpConfig/dhcp_relay_commit.php. …

May 5, 2024
CVE-2024-4502
4.7 MEDIUM

A vulnerability classified as critical has been found in Ruijie RG-UAC up to 20240428. Affected is an unknown function of the file /view/dhcp/dhcpClient/dhcp_client_commit.php. The manipulation …

May 5, 2024
CVE-2024-34519
6.8 MEDIUM

Avantra Server 24.x before 24.0.7 and 24.1.x before 24.1.1 mishandles the security of dashboards, aka XAN-5367. If a user can create a dashboard with an …

May 5, 2024
CVE-2024-4501
4.7 MEDIUM

A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been rated as critical. This issue affects some unknown processing of the file …

May 5, 2024
CVE-2024-34509
5.3 MEDIUM

dcmdata in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message.

May 5, 2024
CVE-2024-34508
4.3 MEDIUM

dcmnet in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message.

May 5, 2024
CVE-2024-34500
6.1 MEDIUM

An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. XSS can occur through an interface …

May 5, 2024
CVE-2024-4500
6.3 MEDIUM

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /Employee/edit-photo.php. …

May 5, 2024
CVE-2024-34490
5.1 MEDIUM

In Maxima through 5.47.0 before 51704c, the plotting facilities make use of predictable names under /tmp. Thus, the contents may be controlled by a local …

May 5, 2024
CVE-2024-34484
5.3 MEDIUM

OFPBucket in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via action.len=0.

May 5, 2024
CVE-2024-34476
5.3 MEDIUM

Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: ogs_nas_encrypt in lib/nas/common/security.c for …

May 5, 2024
CVE-2024-34473
5.3 MEDIUM

An issue was discovered in appmgr in O-RAN Near-RT RIC I-Release. An attacker could register an unintended RMR message type during xApp registration to disrupt …

May 4, 2024
CVE-2024-34468
6.1 MEDIUM

Rukovoditel before 3.5.3 allows XSS via user_photo to My Page.

May 4, 2024
CVE-2024-34467
6.1 MEDIUM

ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl.

May 4, 2024
CVE-2024-34462
6.1 MEDIUM

Alinto SOGo through 5.10.0 allows XSS during attachment preview.

May 4, 2024
CVE-2023-27283
5.3 MEDIUM

IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies. IBM X-Force ID: 248545.

May 4, 2024
CVE-2024-1050
4.3 MEDIUM

The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

May 4, 2024
CVE-2023-7065
5.4 MEDIUM

The Stop Spammers Security | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

May 4, 2024
CVE-2024-34460
6.5 MEDIUM

The Tree Explorer tool from Organizer in Zenario before 9.5.60602 is affected by XSS. (This component was removed in 9.5.60602.)

May 4, 2024
CVE-2024-3237
5.4 MEDIUM

The ConvertPlug plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cp_dismiss_notice() function in all versions …

May 4, 2024
CVE-2024-3868
5.4 MEDIUM

The Folders Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's First Name and Last Name in all versions up to, …

May 4, 2024
CVE-2023-40695
6.3 MEDIUM

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the …

May 3, 2024
CVE-2022-22364
5.3 MEDIUM

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to external service interaction attack, caused by improper validation of user-supplied input. A remote attacker could …

May 3, 2024
CVE-2021-20451
6.0 MEDIUM

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the …

May 3, 2024
CVE-2024-34453
4.3 MEDIUM

TwoNav 2.1.13 contains an SSRF vulnerability via the url paramater to index.php?c=api&method=read_data&type=connectivity_test (which reaches /system/api.php).

May 3, 2024
CVE-2024-34075
6.2 MEDIUM

kurwov is a fast, dependency-free library for creating Markov Chains. An unsafe sanitization of dataset contents on the `MarkovData#getNext` method used in `Markov#generate` and `Markov#choose` …

May 3, 2024
CVE-2024-34068
6.4 MEDIUM

Pterodactyl wings is the server control plane for Pterodactyl Panel. An authenticated user who has access to a game server is able to bypass the …

May 3, 2024
CVE-2024-34067
6.1 MEDIUM

Pterodactyl is a free, open-source game server management panel built with PHP, React, and Go. Importing a malicious egg or gaining access to wings instance …

May 3, 2024
CVE-2023-40696
5.9 MEDIUM

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force …

May 3, 2024
CVE-2023-38724
6.3 MEDIUM

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the …

May 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.