CVE Database

59503+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-35156
6.5 MEDIUM

IBM MQ 9.3 LTS and 9.3 CD could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in …

Jun 28, 2024
CVE-2024-35116
5.9 MEDIUM

IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, and 9.3 CD is vulnerable to a denial of service attack caused by an error …

Jun 28, 2024
CVE-2024-25053
5.9 MEDIUM

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is vulnerable to improper certificate validation when using the IBM Planning Analytics Data …

Jun 28, 2024
CVE-2024-25041
5.4 MEDIUM

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is potentially vulnerable to cross site scripting (XSS). A remote attacker could execute …

Jun 28, 2024
CVE-2024-25031
6.5 MEDIUM

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 uses an inadequate account lockout setting that could allow an attacker on the network to brute …

Jun 28, 2024
CVE-2022-38383
4.0 MEDIUM

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Software Suite 1.10.12.0 through 1.10.21.0 allows web pages to be stored locally which …

Jun 28, 2024
CVE-2024-35155
6.5 MEDIUM

IBM MQ Console 9.3 LTS and 9.3 CD could disclose could allow a remote attacker to obtain sensitive information when a detailed technical error message …

Jun 28, 2024
CVE-2024-31919
5.9 MEDIUM

IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD, in certain configurations, is vulnerable to a denial of service attack caused …

Jun 28, 2024
CVE-2024-6403
6.5 MEDIUM

A vulnerability, which was classified as critical, has been found in Tenda A301 15.13.08.12. Affected by this issue is the function formWifiBasicSet of the file …

Jun 28, 2024
CVE-2024-6402
6.5 MEDIUM

A vulnerability classified as critical was found in Tenda A301 15.13.08.12. Affected by this vulnerability is the function fromSetWirelessRepeat of the file /goform/SetOnlineDevName. The manipulation …

Jun 28, 2024
CVE-2024-38522
6.3 MEDIUM

Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. The CSP policy applied on the `tips.hushline.app` website and bundled by default in …

Jun 28, 2024
CVE-2024-35139
6.2 MEDIUM

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from the container due to incorrect default permissions. …

Jun 28, 2024
CVE-2024-35137
6.2 MEDIUM

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. …

Jun 28, 2024
CVE-2024-29038
4.3 MEDIUM

tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by …

Jun 28, 2024
CVE-2024-3801
6.1 MEDIUM

Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in one of GET header parameters. Only a part …

Jun 28, 2024
CVE-2024-3800
6.1 MEDIUM

Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in requested file names. Only a part of observed …

Jun 28, 2024
CVE-2024-37741
5.4 MEDIUM

OpenPLC 3 through 9cd8f1b allows XSS via an SVG document as a profile picture.

Jun 28, 2024
CVE-2024-5737
6.1 MEDIUM

Script afGdStream.php in AdmirorFrames Joomla! extension doesn’t specify a content type and as a result default (text/html) is used. An attacker may embed HTML tags …

Jun 28, 2024
CVE-2024-5925
6.4 MEDIUM

The Theron Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up …

Jun 28, 2024
CVE-2024-5922
6.4 MEDIUM

The Scylla lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up …

Jun 28, 2024
CVE-2024-5662
6.4 MEDIUM

The Ultimate Post Kit Addons For Elementor – (Post Grid, Post Carousel, Post Slider, Category List, Post Tabs, Timeline, Post Ticker, Tag Cloud) plugin for …

Jun 28, 2024
CVE-2024-5424
6.4 MEDIUM

The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery plugin for WordPress is vulnerable to …

Jun 28, 2024
CVE-2024-6288
4.7 MEDIUM

The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site …

Jun 28, 2024
CVE-2024-5796
6.4 MEDIUM

The Infinite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘project_url’ parameter in all versions up to, and including, 1.1.2 due to …

Jun 28, 2024
CVE-2024-5788
6.4 MEDIUM

The Silesia theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ attribute within the theme's Button shortcode in all versions up to, …

Jun 28, 2024
CVE-2024-39347
5.9 MEDIUM

Incorrect default permissions vulnerability in firewall functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows man-in-the-middle attackers to access highly sensitive intranet resources …

Jun 28, 2024
CVE-2024-2795
5.3 MEDIUM

The SEO SIMPLE PACK plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.1 via META description. This makes …

Jun 28, 2024
CVE-2024-5730
6.1 MEDIUM

The Pagerank tools WordPress plugin through 1.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jun 28, 2024
CVE-2024-5729
6.1 MEDIUM

The Simple AL Slider WordPress plugin through 1.2.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jun 28, 2024
CVE-2024-5728
5.4 MEDIUM

The Animated AL List WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jun 28, 2024
CVE-2024-5727
4.7 MEDIUM

The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jun 28, 2024
CVE-2024-5570
6.5 MEDIUM

The Simple Photoswipe WordPress plugin through 0.1 does not have authorisation check when updating its settings, which could allow any authenticated users, such as subscriber …

Jun 28, 2024
CVE-2024-39352
4.9 MEDIUM

A vulnerability regarding incorrect authorization is found in the firmware upgrade functionality. This allows remote authenticated users with administrator privileges to bypass firmware integrity check …

Jun 28, 2024
CVE-2023-47803
5.3 MEDIUM

A vulnerability regarding improper limitation of a pathname to a restricted directory ('Path Traversal') is found in the Language Settings functionality. This allows remote attackers …

Jun 28, 2024
CVE-2024-6296
6.4 MEDIUM

The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-caption’ parameter in all versions up to, …

Jun 28, 2024
CVE-2024-5864
4.3 MEDIUM

The Easy Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the eafl_reset_settings AJAX action …

Jun 28, 2024
CVE-2024-5863
5.4 MEDIUM

The Easy Image Collage plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the ajax_image_collage() function in …

Jun 28, 2024
CVE-2024-5642
6.5 MEDIUM

CPython 3.9 and earlier doesn't disallow configuring an empty list ("[]") for SSLContext.set_npn_protocols() which is an invalid value for the underlying OpenSSL API. This results …

Jun 27, 2024
CVE-2024-39209
6.3 MEDIUM

luci-app-sms-tool v1.9-6 was discovered to contain a command injection vulnerability via the score parameter.

Jun 27, 2024
CVE-2024-39132
6.5 MEDIUM

A NULL Pointer Dereference vulnerability in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the function VerifyCommandLine() at /src/DumpTS.cpp.

Jun 27, 2024
CVE-2024-36755
6.8 MEDIUM

D-Link DIR-1950 up to v1.11B03 does not validate SSL certificates when requesting the latest firmware version and downloading URL. This can allow attackers to downgrade …

Jun 27, 2024
CVE-2024-36075
6.5 MEDIUM

The CoSoSys Endpoint Protector through 5.9.3 and Unify agent through 7.0.6 is susceptible to an arbitrary code execution vulnerability due to the way an archive …

Jun 27, 2024
CVE-2024-22276
5.3 MEDIUM

VMware Cloud Director Object Storage Extension contains an Insertion of Sensitive Information vulnerability. A malicious actor with adjacent access to web/proxy server logging may be …

Jun 27, 2024
CVE-2024-22272
4.9 MEDIUM

VMware Cloud Director contains an Improper Privilege Management vulnerability. An authenticated tenant administrator for a given organization within VMware Cloud Director may be able to …

Jun 27, 2024
CVE-2024-22260
6.8 MEDIUM

VMware Workspace One UEM update addresses an information exposure vulnerability. A malicious actor with network access to the Workspace One UEM may be able to …

Jun 27, 2024
CVE-2024-39133
4.3 MEDIUM

Heap Buffer Overflow vulnerability in zziplib v0.13.77 allows attackers to cause a denial of service via the __zzip_parse_root_directory() function at /zzip/zip.c.

Jun 27, 2024
CVE-2024-39129
5.3 MEDIUM

Heap Buffer Overflow vulnerability in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the function PushTSBuf() at /src/PayloadBuf.cpp.

Jun 27, 2024
CVE-2024-31802
6.3 MEDIUM

DESIGNA ABACUS v.18 and before allows an attacker to bypass the payment process via a crafted QR code.

Jun 27, 2024
CVE-2024-6086
4.3 MEDIUM

In version 1.2.7 of lunary-ai/lunary, any authenticated user, regardless of their role, can change the name of an organization due to improper access control. The …

Jun 27, 2024
CVE-2024-5936
6.1 MEDIUM

An open redirect vulnerability exists in imartinez/privategpt version 0.5.0 due to improper handling of the 'file' parameter. This vulnerability allows attackers to redirect users to …

Jun 27, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.