CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-40745
5.5 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to weaker than expected security. IBM X-Force ID: 236452.

Apr 19, 2024
CVE-2024-32206
4.6 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the component \affiche\admin\index.php of WUZHICMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Apr 19, 2024
CVE-2024-31587
6.5 MEDIUM

SecuSTATION Camera V2.5.5.3116-S50-SMA-B20160811A and lower allows an unauthenticated attacker to download device configuration files via a crafted request.

Apr 19, 2024
CVE-2024-29183
6.1 MEDIUM

OpenRASP is a RASP solution that directly integrates its protection engine into the application server by instrumentation. There exists a reflected XSS in the /login …

Apr 19, 2024
CVE-2024-29029
6.1 MEDIUM

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal …

Apr 19, 2024
CVE-2024-27752
5.4 MEDIUM

Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the Default Keyword field in the settings function.

Apr 19, 2024
CVE-2023-22869
5.5 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 244119.

Apr 19, 2024
CVE-2024-3470
5.9 MEDIUM

An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use a deploy key pertaining to an organization to …

Apr 19, 2024
CVE-2024-32478
6.9 MEDIUM

Git Credential Manager (GCM) is a secure Git credential helper. Prior to 2.5.0, the Debian package does not set root ownership on installed files. This …

Apr 19, 2024
CVE-2024-29030
5.8 MEDIUM

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/resource that allows authenticated users to enumerate the internal …

Apr 19, 2024
CVE-2024-29028
5.8 MEDIUM

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthenticated users to enumerate the internal …

Apr 19, 2024
CVE-2023-49275
6.5 MEDIUM

Wazuh is a free and open source platform used for threat prevention, detection, and response. A NULL pointer dereference was detected during fuzzing of the …

Apr 19, 2024
CVE-2024-3654
6.3 MEDIUM

An XSS vulnerability has been found in Teimas Global's Teixo, version 1.42.42-stable. This vulnerability could allow an attacker to send a specially crafted JavaScript payload …

Apr 19, 2024
CVE-2024-32683
5.3 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through 2.2.5.

Apr 19, 2024
CVE-2024-1065
5.9 MEDIUM

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel …

Apr 19, 2024
CVE-2024-0671
6.8 MEDIUM

Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd …

Apr 19, 2024
CVE-2024-2761
6.8 MEDIUM

The Genesis Blocks WordPress plugin before 3.1.3 does not properly escape data input provided to some of its blocks, allowing using with at least contributor …

Apr 19, 2024
CVE-2024-29967
4.4 MEDIUM

In Brocade SANnav before Brocade SANnav v2.31 and v2.3.0a, it was observed that Docker instances inside the appliance have insecure mount points, allowing reading and …

Apr 19, 2024
CVE-2024-29965
6.8 MEDIUM

In Brocade SANnav before v2.3.1, and v2.3.0a, it is possible to back up the appliance from the web interface or the command line interface ("SSH"). …

Apr 19, 2024
CVE-2024-29964
5.7 MEDIUM

Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files. An unprivileged attacker who gains access to the server can …

Apr 19, 2024
CVE-2024-29962
5.5 MEDIUM

Brocade SANnav OVA before v2.3.1 and v2.3.0a have an insecure file permission setting that makes files world-readable. This could allow a local user without the …

Apr 19, 2024
CVE-2024-29960
6.8 MEDIUM

In Brocade SANnav server before v2.3.1 and v2.3.0a, the SSH keys inside the OVA image are identical in the VM every time SANnav is installed. …

Apr 19, 2024
CVE-2024-3818
5.4 MEDIUM

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "Social Icons" …

Apr 19, 2024
CVE-2024-3731
6.1 MEDIUM

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, …

Apr 19, 2024
CVE-2024-3615
6.1 MEDIUM

The Media Library Folders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 8.2.0 …

Apr 19, 2024
CVE-2024-3598
6.4 MEDIUM

The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Creative Button widget in all versions up to, and including, …

Apr 19, 2024
CVE-2024-3560
6.4 MEDIUM

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id value in all versions up to, and …

Apr 19, 2024
CVE-2024-27978
6.5 MEDIUM

A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks.

Apr 19, 2024
CVE-2024-24991
6.5 MEDIUM

A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks.

Apr 19, 2024
CVE-2024-23533
6.5 MEDIUM

An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an authenticated remote attacker to read sensitive information …

Apr 19, 2024
CVE-2024-21846
5.3 MEDIUM

An unauthenticated attacker can reset the board and stop transmitter operations by sending a specially-crafted GET request to the command.cgi gateway, resulting in a denial-of-service …

Apr 18, 2024
CVE-2024-32473
4.7 MEDIUM

Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. …

Apr 18, 2024
CVE-2024-30927
6.3 MEDIUM

Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the racer-results.php component.

Apr 18, 2024
CVE-2024-30926
4.6 MEDIUM

Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the ./inc/kiosks.inc component.

Apr 18, 2024
CVE-2024-30925
6.5 MEDIUM

Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the photo-thumbs.php component.

Apr 18, 2024
CVE-2024-30924
4.6 MEDIUM

Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component.

Apr 18, 2024
CVE-2024-30921
5.4 MEDIUM

Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the photo.php component.

Apr 18, 2024
CVE-2024-29987
6.5 MEDIUM

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Apr 18, 2024
CVE-2024-29986
5.4 MEDIUM

Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability

Apr 18, 2024
CVE-2024-32335
5.4 MEDIUM

TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Access Control under the Wireless Page.

Apr 18, 2024
CVE-2024-32334
6.5 MEDIUM

TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page.

Apr 18, 2024
CVE-2024-32333
4.3 MEDIUM

TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page.

Apr 18, 2024
CVE-2024-32332
6.1 MEDIUM

TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in WDS Settings under the Wireless Page.

Apr 18, 2024
CVE-2024-32327
5.5 MEDIUM

TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Port Forwarding under the Firewall Page.

Apr 18, 2024
CVE-2024-32326
6.8 MEDIUM

TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the key parameter in the setWiFiExtenderConfig function.

Apr 18, 2024
CVE-2024-32470
6.5 MEDIUM

Tolgee is an open-source localization platform. When API key created by admin user is used it bypasses the permission check at all. This error was …

Apr 18, 2024
CVE-2024-27306
6.1 MEDIUM

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is …

Apr 18, 2024
CVE-2024-3948
6.3 MEDIUM

A vulnerability was found in SourceCodester Home Clean Service System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Apr 18, 2024
CVE-2024-32689
4.3 MEDIUM

Missing Authorization vulnerability in GenialSouls WP Social Comments.This issue affects WP Social Comments: from n/a through 1.7.3.

Apr 18, 2024
CVE-2024-32686
5.3 MEDIUM

Insertion of Sensitive Information into Log File vulnerability in Inisev Backup Migration.This issue affects Backup Migration: from n/a through 1.4.3.

Apr 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.