CVE Database

59503+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-3513
6.4 MEDIUM

The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the title tag (postTitleTag) parameter in all versions …

Jul 2, 2024
CVE-2024-38857
4.3 MEDIUM

Improper neutralization of input in Checkmk before versions 2.3.0p8, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows attackers to craft malicious links that can facilitate phishing attacks.

Jul 2, 2024
CVE-2024-37134
6.7 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability to gain …

Jul 2, 2024
CVE-2024-37133
6.7 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to …

Jul 2, 2024
CVE-2024-37132
6.7 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an incorrect privilege assignment vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, …

Jul 2, 2024
CVE-2024-37126
6.7 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to …

Jul 2, 2024
CVE-2023-41928
5.3 MEDIUM

The device is observed to accept deprecated TLS protocols, increasing the risk of cryptographic weaknesses.

Jul 2, 2024
CVE-2023-41927
5.3 MEDIUM

The server supports at least one cipher suite which is on the NCSC-NL list of cipher suites to be phased out, increasing the risk of …

Jul 2, 2024
CVE-2024-5219
6.4 MEDIUM

The Easy Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feature in all versions up to, and …

Jul 2, 2024
CVE-2024-32854
6.7 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privilege attacker could potentially exploit this vulnerability, leading to …

Jul 2, 2024
CVE-2024-32853
4.4 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.2 contain an execution with unnecessary privileges vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading …

Jul 2, 2024
CVE-2024-32852
5.9 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.0 contain use of a broken or risky cryptographic algorithm vulnerability. An unprivileged network malicious attacker could potentially exploit …

Jul 2, 2024
CVE-2024-0158
5.1 MEDIUM

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI …

Jul 2, 2024
CVE-2024-4627
5.4 MEDIUM

The Rank Math SEO WordPress plugin before 1.0.219 does not sanitise and escape some of its settings, which could allow users with access to the …

Jul 2, 2024
CVE-2024-3999
4.8 MEDIUM

The EazyDocs WordPress plugin before 2.5.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jul 2, 2024
CVE-2024-1427
6.4 MEDIUM

The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Jul 2, 2024
CVE-2024-5419
6.4 MEDIUM

The Void Contact Form 7 Widget For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cf7_redirect_page' attribute within the …

Jul 2, 2024
CVE-2024-5938
6.4 MEDIUM

The Boot Store theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter within the theme's Button shortcode in all versions up …

Jul 2, 2024
CVE-2024-2819
5.1 MEDIUM

Incorrect Default Permissions, Improper Preservation of Permissions vulnerability in Hitachi Ops Center Common Services allows File Manipulation.This issue affects Hitachi Ops Center Common Services: before …

Jul 2, 2024
CVE-2024-39314
4.7 MEDIUM

toy-blog is a headless content management system implementation. Starting in version 0.4.3 and prior to version 0.5.0, the administrative password was leaked through the command …

Jul 1, 2024
CVE-2024-39313
6.5 MEDIUM

toy-blog is a headless content management system implementation. Starting in version 0.5.4 and prior to version 0.6.1, articles with private visibility can be read if …

Jul 1, 2024
CVE-2024-39310
5.4 MEDIUM

The Basil recipe theme for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the `post_title` parameter in versions up to, and including, 2.0.4 due …

Jul 1, 2024
CVE-2024-37764
5.4 MEDIUM

MachForm up to version 19 is affected by an authenticated stored cross-site scripting.

Jul 1, 2024
CVE-2024-37763
5.4 MEDIUM

MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can view compiled forms results.

Jul 1, 2024
CVE-2024-23737
5.4 MEDIUM

Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Jira allows attackers to allows attackers to manipulate a user's S/MIME certificate of …

Jul 1, 2024
CVE-2024-39305
6.5 MEDIUM

Envoy is a cloud-native, open source edge and service proxy. Prior to versions 1.30.4, 1.29.7, 1.28.5, and 1.27.7. Envoy references already freed memory when route …

Jul 1, 2024
CVE-2024-32228
6.6 MEDIUM

FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end.

Jul 1, 2024
CVE-2024-39303
4.4 MEDIUM

Weblate is a web based localization tool. Prior to version 5.6.2, Weblate didn't correctly validate filenames when restoring project backup. It may be possible to …

Jul 1, 2024
CVE-2024-37146
6.1 MEDIUM

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting …

Jul 1, 2024
CVE-2024-37145
6.1 MEDIUM

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting …

Jul 1, 2024
CVE-2024-36423
6.1 MEDIUM

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting …

Jul 1, 2024
CVE-2024-36387
5.4 MEDIUM

Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.

Jul 1, 2024
CVE-2024-39879
5.0 MEDIUM

In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings

Jul 1, 2024
CVE-2024-39878
4.1 MEDIUM

In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection

Jul 1, 2024
CVE-2024-36996
5.3 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109, an attacker could determine whether or not another user …

Jul 1, 2024
CVE-2024-36995
5.4 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold …

Jul 1, 2024
CVE-2024-36994
5.4 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold …

Jul 1, 2024
CVE-2024-36993
5.4 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold …

Jul 1, 2024
CVE-2024-36992
5.4 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold …

Jul 1, 2024
CVE-2024-36990
6.5 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.2.2403.100, an authenticated, low-privileged user that does not hold the …

Jul 1, 2024
CVE-2024-36987
4.3 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, an authenticated, low-privileged user who does not hold the …

Jul 1, 2024
CVE-2024-36986
6.3 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, an authenticated user could run risky commands …

Jul 1, 2024
CVE-2024-20399
6.0 MEDIUM KEV

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root …

Jul 1, 2024
CVE-2024-36422
6.1 MEDIUM

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting …

Jul 1, 2024
CVE-2024-6375
5.4 MEDIUM

A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading …

Jul 1, 2024
CVE-2024-34696
4.5 MEDIUM

GeoServer is an open source server that allows users to share and edit geospatial data. Starting in version 2.10.0 and prior to versions 2.24.4 and …

Jul 1, 2024
CVE-2024-21482
6.8 MEDIUM

Memory corruption during the secure boot process, when the `bootm` command is used, it bypasses the authentication of the kernel/rootfs image.

Jul 1, 2024
CVE-2024-21466
6.5 MEDIUM

Information disclosure while parsing sub-IE length during new IE generation.

Jul 1, 2024
CVE-2024-21458
6.5 MEDIUM

Information disclosure while handling SA query action frame.

Jul 1, 2024
CVE-2024-21457
6.5 MEDIUM

INformation disclosure while handling Multi-link IE in beacon frame.

Jul 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.