CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-33101
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the component /action/anti.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Apr 30, 2024
CVE-2020-5200
5.9 MEDIUM

Minerbabe through V4.16 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes …

Apr 30, 2024
CVE-2019-19754
5.7 MEDIUM

HiveOS through 0.6-102@191212 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes …

Apr 30, 2024
CVE-2019-19751
5.6 MEDIUM

easyMINE before 2019-12-05 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes …

Apr 30, 2024
CVE-2024-2877
5.5 MEDIUM

Vault Enterprise, when configured with performance standby nodes and a configured audit device, will inadvertently log request headers on the standby node. These logs may …

Apr 30, 2024
CVE-2023-38002
5.0 MEDIUM

IBM Storage Scale 5.1.0.0 through 5.1.9.2 could allow an authenticated user to steal or manipulate an active session to gain access to the system. IBM …

Apr 30, 2024
CVE-2024-23772
6.6 MEDIUM

An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file create vulnerability exists in the KSchedulerSvc.exe, KUserAlert.exe, and Runkbot.exe …

Apr 30, 2024
CVE-2023-50915
6.5 MEDIUM

An issue exists in GalaxyClientService.exe in GOG Galaxy (Beta) 2.0.67.2 through 2.0.71.2 that could allow authenticated users to overwrite and corrupt critical system files via …

Apr 30, 2024
CVE-2023-50914
6.7 MEDIUM

A Privilege Escalation issue in the inter-process communication procedure from GOG Galaxy (Beta) 2.0.67.2 through v2.0.71.2 allows authentictaed users to change the DACL of arbitrary …

Apr 30, 2024
CVE-2024-22405
5.5 MEDIUM

XADMaster is an objective-C library for archive and file unarchiving and extraction. When extracting a specially crafted zip archive XADMaster may not apply quarantine attribute …

Apr 30, 2024
CVE-2024-3072
4.3 MEDIUM

The ACF Front End Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_texts() function …

Apr 30, 2024
CVE-2024-1371
6.5 MEDIUM

The LeadConnector plugin for WordPress is vulnerable to unauthorized modification & loss of data due to a missing capability check on the lc_public_api_proxy() function in …

Apr 30, 2024
CVE-2024-0216
6.4 MEDIUM

The Google Doc Embedder plugin for WordPress is vulnerable to Server Side Request Forgery via the 'gview' shortcode in versions up to, and including, 2.6.4. …

Apr 30, 2024
CVE-2024-34047
4.3 MEDIUM

O-RAN RIC I-Release e2mgr lacks array size checks in RicServiceUpdateHandler.

Apr 30, 2024
CVE-2024-34044
5.3 MEDIUM

The O-RAN E2T I-Release buildPrometheusList function can have a NULL pointer dereference because peerInfo can be NULL.

Apr 30, 2024
CVE-2024-34043
5.3 MEDIUM

O-RAN RICAPP kpimon-go I-Release has a segmentation violation via a certain E2AP-PDU message.

Apr 30, 2024
CVE-2023-52728
5.5 MEDIUM

Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.25 allows an index out-of-range condition in putBitString.

Apr 30, 2024
CVE-2023-52726
6.5 MEDIUM

Open Networking Foundation SD-RAN ONOS onos-ric-sdk-go 0.8.12 allows infinite repetition of the processing of an error (in the Subscribe function implementation for the subscribed indication …

Apr 30, 2024
CVE-2023-52725
6.5 MEDIUM

Open Networking Foundation SD-RAN ONOS onos-kpimon 0.4.7 allows blocking of the errCh channel within the Start function of the monitoring package.

Apr 30, 2024
CVE-2024-33522
6.7 MEDIUM

In vulnerable versions of Calico (v3.27.2 and below), Calico Enterprise (v3.19.0-1, v3.18.1, v3.17.3 and below), and Calico Cloud (v19.2.0 and below), an attacker who has …

Apr 29, 2024
CVE-2024-33401
4.4 MEDIUM

Cross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote attacker to run arbitrary code via the mnum parameter.

Apr 29, 2024
CVE-2023-50433
6.5 MEDIUM

marshall in dhcp_packet.c in simple-dhcp-server through ec976d2 allows remote attackers to cause a denial of service by sending a malicious DHCP packet. The crash is …

Apr 29, 2024
CVE-2023-50432
5.3 MEDIUM

simple-dhcp-server through ec976d2 allows remote attackers to cause a denial of service (daemon crash) by sending a DHCP packet without any option fields, which causes …

Apr 29, 2024
CVE-2024-28294
6.5 MEDIUM

Limbas up to v5.2.14 was discovered to contain a SQL injection vulnerability via the ftid parameter.

Apr 29, 2024
CVE-2023-31889
5.5 MEDIUM

An issue discovered in httpd in ASUS RT-AC51U with firmware version up to and including 3.0.0.4.380.8591 allows local attackers to cause a denial of service …

Apr 29, 2024
CVE-2024-33272
6.8 MEDIUM

SQL injection vulnerability in KnowBand for PrestaShop autosuggest before 2.0.0 allows an attacker to run arbitrary SQL commands via the AutosuggestSearchModuleFrontController::initContent(), and AutosuggestSearchModuleFrontController::getKbProducts() components.

Apr 29, 2024
CVE-2023-51710
4.2 MEDIUM

EMS SQL Manager 3.6.2 (build 55333) for Oracle allows DLL hijacking: a user can trigger the execution of arbitrary code every time the product is …

Apr 29, 2024
CVE-2024-33345
6.5 MEDIUM

D-Link DIR-823G A1V1.0.2B05 was found to contain a Null-pointer dereference in the main function of upload_firmware.cgi, which allows remote attackers to cause a Denial of …

Apr 29, 2024
CVE-2023-51254
6.1 MEDIUM

Cross Site Scripting vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the friendship link component.

Apr 29, 2024
CVE-2024-34020
6.5 MEDIUM

A stack-based buffer overflow was found in the putSDN() function of mail.c in hcode through 2.1.

Apr 29, 2024
CVE-2024-34011
6.8 MEDIUM

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 37758.

Apr 29, 2024
CVE-2024-23995
6.1 MEDIUM

Cross Site Scripting (XSS) in Beekeeper Studio 4.1.13 and earlier allows remote attackers to execute arbitrary code in the column name of a database table …

Apr 29, 2024
CVE-2024-4310
6.3 MEDIUM

Cross-site Scripting (XSS) vulnerability in HubBank affecting version 1.0.2. This vulnerability allows an attacker to send a specially crafted JavaScript payload to registration and profile …

Apr 29, 2024
CVE-2024-33588
5.4 MEDIUM

Missing Authorization vulnerability in codeSavory Knowledge Base documentation & wiki plugin – BasePress.This issue affects Knowledge Base documentation & wiki plugin – BasePress: from n/a …

Apr 29, 2024
CVE-2024-33587
5.3 MEDIUM

Missing Authorization vulnerability in Copy Content Protection Team Secure Copy Content Protection and Content Locking.This issue affects Secure Copy Content Protection and Content Locking: from …

Apr 29, 2024
CVE-2024-33586
5.3 MEDIUM

Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web.This issue affects Photo Gallery by 10Web: from n/a through 1.8.20.

Apr 29, 2024
CVE-2024-33585
4.3 MEDIUM

Missing Authorization vulnerability in Tyche Softwares Payment Gateway Based Fees and Discounts for WooCommerce.This issue affects Payment Gateway Based Fees and Discounts for WooCommerce: from …

Apr 29, 2024
CVE-2024-4304
5.4 MEDIUM

A Cross-Site Scripting XSS vulnerability has been detected on GT3 Soluciones SWAL. This vulnerability consists in a reflected XSS in the Titular parameter inside Gestion …

Apr 29, 2024
CVE-2024-33590
5.0 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in codeSavory Knowledge Base documentation & wiki plugin – BasePress.This issue affects Knowledge Base documentation & wiki plugin – BasePress: …

Apr 29, 2024
CVE-2024-33589
6.5 MEDIUM

Missing Authorization vulnerability in WPOmnia KB Support.This issue affects KB Support: from n/a through 1.6.0.

Apr 29, 2024
CVE-2024-33595
4.3 MEDIUM

Missing Authorization vulnerability in Jewel Theme Master Addons for Elementor.This issue affects Master Addons for Elementor: from n/a through 2.0.5.4.1.

Apr 29, 2024
CVE-2024-33593
4.3 MEDIUM

Missing Authorization vulnerability in RedNao Smart Forms.This issue affects Smart Forms: from n/a through 2.6.91.

Apr 29, 2024
CVE-2024-33684
6.5 MEDIUM

Missing Authorization vulnerability in Pdfcrowd Save as PDF plugin by Pdfcrowd allows Stored XSS.This issue affects Save as PDF plugin by Pdfcrowd: from n/a through …

Apr 29, 2024
CVE-2024-33636
5.4 MEDIUM

Missing Authorization vulnerability in Mahesh Vora WP Page Post Widget Clone.This issue affects WP Page Post Widget Clone: from n/a through 1.0.1.

Apr 29, 2024
CVE-2024-33596
5.3 MEDIUM

Missing Authorization vulnerability in Five Star Plugins Five Star Restaurant Reservations.This issue affects Five Star Restaurant Reservations: from n/a through 2.6.16.

Apr 29, 2024
CVE-2024-33558
6.5 MEDIUM

Missing Authorization vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5.

Apr 29, 2024
CVE-2024-28961
6.3 MEDIUM

Dell OpenManage Enterprise, versions 4.0.0 and 4.0.1, contains a sensitive information disclosure vulnerability. A local low privileged malicious user could potentially exploit this vulnerability to …

Apr 29, 2024
CVE-2024-33652
5.3 MEDIUM

Missing Authorization vulnerability in Real Big Plugins Client Dash.This issue affects Client Dash: from n/a through 2.2.1.

Apr 29, 2024
CVE-2024-33641
5.4 MEDIUM

Deserialization of Untrusted Data vulnerability in Team Yoast Custom field finder.This issue affects Custom field finder: from n/a through 0.3.

Apr 29, 2024
CVE-2024-33634
5.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Piotnet Piotnet Addons For Elementor Pro.This issue affects Piotnet Addons For Elementor Pro: from n/a through 7.1.17.

Apr 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.