CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-32633
4.0 MEDIUM

An unsigned value can never be negative, so eMMC full disk test will always evaluate the same way.

Apr 16, 2024
CVE-2024-32632
6.6 MEDIUM

A value in ATCMD will be misinterpreted by printf, causing incorrect output and possibly out-of-bounds memory access

Apr 16, 2024
CVE-2024-32625
5.8 MEDIUM

In OffloadAMRWriter, a scalar field is not initialized so will contain an arbitrary value left over from earlier computations

Apr 16, 2024
CVE-2024-32557
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: …

Apr 16, 2024
CVE-2024-31784
6.1 MEDIUM

An issue in Typora v.1.8.10 and before, allows a local attacker to obtain sensitive information and execute arbitrary code via a crafted payload to the …

Apr 16, 2024
CVE-2024-31783
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Typora v.1.6.7 and before, allows a local attacker to obtain sensitive information via a crafted script during markdown file …

Apr 16, 2024
CVE-2024-31634
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Xunruicms versions 4.6.3 and before, allows remote attacker to execute arbitrary code via the Security.php file in the catalog …

Apr 16, 2024
CVE-2024-3575
6.1 MEDIUM

Cross-site Scripting (XSS) - Stored in mindsdb/mindsdb

Apr 16, 2024
CVE-2024-30567
6.3 MEDIUM

An issue in JNT Telecom JNT Liftcom UMS V1.J Core Version JM-V15 allows a remote attacker to execute arbitrary code via the Network Troubleshooting functionality.

Apr 16, 2024
CVE-2024-2260
4.2 MEDIUM

A session fixation vulnerability exists in the zenml-io/zenml application, where JWT tokens used for user authentication are not invalidated upon logout. This flaw allows an …

Apr 16, 2024
CVE-2024-1666
5.3 MEDIUM

In lunary-ai/lunary version 1.0.0, an authorization flaw exists that allows unauthorized radar creation. The vulnerability stems from the lack of server-side checks to verify if …

Apr 16, 2024
CVE-2024-1183
6.5 MEDIUM

An SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to scan and identify open ports within an internal network. By manipulating …

Apr 16, 2024
CVE-2024-27794
6.1 MEDIUM

Claris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to an improperly handled parameter in the FileMaker WebDirect login …

Apr 15, 2024
CVE-2020-22540
5.4 MEDIUM

Stored Cross-Site Scripting (XSS) vulnerability in Codoforum v4.9, allows attackers to execute arbitrary code and obtain sensitive information via crafted payload to Category name component.

Apr 15, 2024
CVE-2024-31651
6.1 MEDIUM

A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Apr 15, 2024
CVE-2024-31652
6.1 MEDIUM

A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Apr 15, 2024
CVE-2024-31649
5.4 MEDIUM

A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Apr 15, 2024
CVE-2024-31648
6.1 MEDIUM

Cross Site Scripting (XSS) in Insurance Management System v1.0, allows remote attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Apr 15, 2024
CVE-2024-23561
4.3 MEDIUM

HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfuscation of sensitive values.

Apr 15, 2024
CVE-2024-23558
6.3 MEDIUM

HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

Apr 15, 2024
CVE-2024-3804
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Vesystem Cloud Desktop up to 20240408. This issue affects some unknown processing of the …

Apr 15, 2024
CVE-2024-32036
5.3 MEDIUM

ImageSharp is a 2D graphics API. A data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker …

Apr 15, 2024
CVE-2024-32035
5.3 MEDIUM

ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory …

Apr 15, 2024
CVE-2024-31990
4.8 MEDIUM

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The API server does not enforce project sourceNamespaces which allows attackers to use the …

Apr 15, 2024
CVE-2024-31497
5.9 MEDIUM

In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick …

Apr 15, 2024
CVE-2024-30840
6.5 MEDIUM

A Stack Overflow vulnerability in Tenda AC15 v15.03.05.18 allows attackers to cause a denial of service via the LISTEN parameter in the fromDhcpListClient function.

Apr 15, 2024
CVE-2024-23560
4.4 MEDIUM

HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type.

Apr 15, 2024
CVE-2023-45503
5.3 MEDIUM

SQL Injection vulnerability in Macrob7 Macs CMS 1.1.4f, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain …

Apr 15, 2024
CVE-2024-3803
6.3 MEDIUM

A vulnerability classified as critical was found in Vesystem Cloud Desktop up to 20240408. This vulnerability affects unknown code of the file /Public/webuploader/0.1.5/server/fileupload.php. The manipulation …

Apr 15, 2024
CVE-2024-24487
6.8 MEDIUM

An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to cause a denial of service via crafted UDP packets using the …

Apr 15, 2024
CVE-2024-31219
4.3 MEDIUM

Discourse-reactions is a plugin that allows user to add their reactions to the post. When whispers are enabled on a site via `whispers_allowed_groups` and reactions …

Apr 15, 2024
CVE-2024-23594
6.4 MEDIUM

A buffer overflow vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from …

Apr 15, 2024
CVE-2024-23593
6.7 MEDIUM

A vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from 2012 to …

Apr 15, 2024
CVE-2024-23559
6.1 MEDIUM

HCL DevOps Deploy / Launch is generating an obsolete HTTP header.

Apr 15, 2024
CVE-2023-45808
4.1 MEDIUM

iTop is an IT service management platform. When creating or updating an object, extkey values aren't checked to be in the current user silo. In …

Apr 15, 2024
CVE-2023-44396
6.8 MEDIUM

iTop is an IT service management platform. Dashlet edits ajax endpoints can be used to produce XSS. Fixed in iTop 2.7.10, 3.0.4, and 3.1.1.

Apr 15, 2024
CVE-2023-43790
5.7 MEDIUM

iTop is an IT service management platform. By manipulating HTTP queries, a user can inject malicious content in the fields used for the object friendlyname …

Apr 15, 2024
CVE-2023-38511
5.0 MEDIUM

iTop is an IT service management platform. Dashboard editor : can load multiple files and URL, and full path disclosure on dashboard config file. This …

Apr 15, 2024
CVE-2024-3797
6.3 MEDIUM

A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Apr 15, 2024
CVE-2024-3786
6.6 MEDIUM

Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Device Synchronizations (/admin/DeviceReplication). Exploitation of this vulnerability could allow a remote user …

Apr 15, 2024
CVE-2024-3785
6.6 MEDIUM

Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Device NAS shared section (/admin/DeviceNAS). Exploitation of this vulnerability could allow a …

Apr 15, 2024
CVE-2024-3784
6.6 MEDIUM

Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 Accounts (/admin/CloudAccounts). Exploitation of this vulnerability could allow a remote user …

Apr 15, 2024
CVE-2024-24898
6.0 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Leak Exposure. This vulnerability is associated with program files …

Apr 15, 2024
CVE-2024-24891
6.0 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Leak Exposure. This vulnerability is associated with program files …

Apr 15, 2024
CVE-2024-32129
4.7 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Freshworks Freshdesk (official).This issue affects Freshdesk (official): from n/a through 2.3.6.

Apr 15, 2024
CVE-2024-31421
4.3 MEDIUM

Missing Authorization vulnerability in supsystic Popup by Supsystic popup-by-supsystic.This issue affects Popup by Supsystic: from n/a through <= 1.10.27.

Apr 15, 2024
CVE-2024-31389
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Ertano MihanPanel.This issue affects MihanPanel: from n/a before 12.7.

Apr 15, 2024
CVE-2024-31388
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Pauple Table & Contact Form 7 Database – Tablesome.This issue affects Table & Contact Form 7 Database – Tablesome: …

Apr 15, 2024
CVE-2024-31385
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Reservation Diary ReDi Restaurant Reservation.This issue affects ReDi Restaurant Reservation: from n/a through 24.0128.

Apr 15, 2024
CVE-2024-31384
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Spa and Salon.This issue affects Spa and Salon: from n/a through 1.2.7.

Apr 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.