CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-28755
6.5 MEDIUM

An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When an SSL context was reset with the mbedtls_ssl_session_reset() API, the maximum TLS version to …

Apr 3, 2024
CVE-2024-28219
6.7 MEDIUM

In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.

Apr 3, 2024
CVE-2024-26495
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbitrary code and obtain sensitive information via the BBCode …

Apr 3, 2024
CVE-2024-1327
6.4 MEDIUM

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image box widget in all versions up to, and …

Apr 3, 2024
CVE-2024-3225
6.3 MEDIUM

A vulnerability was found in SourceCodester PHP Task Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Apr 3, 2024
CVE-2024-3224
6.3 MEDIUM

A vulnerability has been found in SourceCodester PHP Task Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Apr 3, 2024
CVE-2024-3223
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester PHP Task Management System 1.0. Affected is an unknown function of the file admin-manage-user.php. …

Apr 3, 2024
CVE-2024-3222
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester PHP Task Management System 1.0. This issue affects some unknown processing of the …

Apr 3, 2024
CVE-2024-3221
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester PHP Task Management System 1.0. This vulnerability affects unknown code of the file attendance-info.php. The manipulation …

Apr 3, 2024
CVE-2024-3218
5.4 MEDIUM

A vulnerability classified as critical has been found in Shibang Communications IP Network Intercom Broadcasting System 1.0. This affects an unknown part of the file …

Apr 3, 2024
CVE-2024-3209
5.5 MEDIUM

A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the function get_ne64 of the file bele.h. …

Apr 2, 2024
CVE-2024-3207
5.5 MEDIUM

A vulnerability was found in ermig1979 Simd up to 6.0.134. It has been declared as critical. This vulnerability affects the function ReadUnsigned of the file …

Apr 2, 2024
CVE-2024-30370
4.3 MEDIUM

RARLAB WinRAR Mark-Of-The-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-Of-The-Web protection mechanism on affected installations of RARLAB WinRAR. User interaction is …

Apr 2, 2024
CVE-2024-30363
5.5 MEDIUM

Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit …

Apr 2, 2024
CVE-2024-25075
5.1 MEDIUM

An issue was discovered in Softing uaToolkit Embedded before 1.41.1. When a subscription with a very low MaxNotificationPerPublish parameter is created, a publish response is …

Apr 2, 2024
CVE-2024-29834
6.4 MEDIUM

This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as unloading topics and triggering compaction. These …

Apr 2, 2024
CVE-2024-30532
4.9 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Builderall Team Builderall Builder for WordPress.This issue affects Builderall Builder for WordPress: from n/a through 2.0.1.

Apr 2, 2024
CVE-2024-30531
4.9 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Nelio Software Nelio Content.This issue affects Nelio Content: from n/a through 3.2.0.

Apr 2, 2024
CVE-2024-24888
6.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks.This issue affects Gutenberg Blocks by Kadence Blocks: from n/a through <= 3.2.25.

Apr 2, 2024
CVE-2024-30806
6.5 MEDIUM

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated …

Apr 2, 2024
CVE-2024-3151
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Bdtask Multi-Store Inventory Management System up to 20240325. Affected is an unknown function of the …

Apr 2, 2024
CVE-2024-2435
4.3 MEDIUM

For an attacker with pre-existing access to send a signal to a workflow, the attacker can make the signal name a script that executes when …

Apr 2, 2024
CVE-2024-22247
4.8 MEDIUM

VMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability. A malicious actor with physical access to the SD-WAN Edge appliance during activation can …

Apr 2, 2024
CVE-2024-22780
6.1 MEDIUM

Cross Site Scripting vulnerability in CA17 TeamsACS v.1.0.1 allows a remote attacker to execute arbitrary code via a crafted script to the errmsg parameter.

Apr 2, 2024
CVE-2024-30946
5.5 MEDIUM

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/co_do.php.

Apr 2, 2024
CVE-2023-50313
5.3 MEDIUM

IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for outbound TLS connections caused by a failure to honor user configuration. …

Apr 2, 2024
CVE-2023-6951
6.6 MEDIUM

A Use of Weak Credentials vulnerability affecting the Wi-Fi network generated by a set of DJI drones could allow a remote attacker to derive the …

Apr 2, 2024
CVE-2023-6949
5.2 MEDIUM

A Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80 could …

Apr 2, 2024
CVE-2023-51456
6.8 MEDIUM

A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to …

Apr 2, 2024
CVE-2023-51455
6.8 MEDIUM

A Improper Validation of Array Index issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an …

Apr 2, 2024
CVE-2023-51454
6.8 MEDIUM

A Out-of-bounds Write issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to overwrite …

Apr 2, 2024
CVE-2024-1946
6.4 MEDIUM

The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block content in all versions up to, and including, 3.1.2 due …

Apr 2, 2024
CVE-2024-1807
6.5 MEDIUM

The Product Sort and Display for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Apr 2, 2024
CVE-2024-1732
5.3 MEDIUM

The Sharkdropship for AliExpress Dropshipping and Affiliate plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the …

Apr 2, 2024
CVE-2024-2931
4.3 MEDIUM

The WPFront User Role Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.1.11184 via the wpfront_user_role_editor_assign_roles_user_autocomplete …

Apr 2, 2024
CVE-2024-20799
5.4 MEDIUM

Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Apr 2, 2024
CVE-2024-1300
5.4 MEDIUM

A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. When processing an unknown SNI …

Apr 2, 2024
CVE-2024-2925
6.4 MEDIUM

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Widget in all versions up …

Apr 2, 2024
CVE-2024-2839
6.4 MEDIUM

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_post_title' shortcode in all versions up to, and including, …

Apr 2, 2024
CVE-2024-29074
6.5 MEDIUM

in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through improper input.

Apr 2, 2024
CVE-2024-28951
5.5 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free.

Apr 2, 2024
CVE-2024-26684
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: xgmac: fix handling of DPP safety error for DMA channels Commit 56e58d6c8a56 ("net: …

Apr 2, 2024
CVE-2024-26683
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: detect stuck ECSA element in probe resp We recently added some validation that …

Apr 2, 2024
CVE-2024-26682
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: improve CSA/ECSA connection refusal As mentioned in the previous commit, we pretty quickly …

Apr 2, 2024
CVE-2024-26681
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netdevsim: avoid potential loop in nsim_dev_trap_report_work() Many syzbot reports include the following trace [1] If …

Apr 2, 2024
CVE-2024-26680
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: atlantic: Fix DMA mapping for PTP hwts ring Function aq_ring_hwts_rx_alloc() maps extra AQ_CFG_RXDS_DEF bytes …

Apr 2, 2024
CVE-2024-26679
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: inet: read sk->sk_family once in inet_recv_error() inet_recv_error() is called without holding the socket lock. IPv6 …

Apr 2, 2024
CVE-2024-26678
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/efistub: Use 1:1 file:memory mapping for PE/COFF .compat section The .compat section is a dummy …

Apr 2, 2024
CVE-2024-26677
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix delayed ACKs to not set the reference serial number Fix the construction of …

Apr 2, 2024
CVE-2024-26676
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: af_unix: Call kfree_skb() for dead unix_(sk)->oob_skb in GC. syzbot reported a warning [0] in __unix_gc() …

Apr 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.