CVE Database

59503+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0845
6.4 MEDIUM

The PDF Viewer for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the render function in all versions up to, and including, …

Jun 18, 2024
CVE-2024-6083
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPVibe 11.0.46. Affected is an unknown function of the file /app/uploading/upload-mp3.php of the component Media …

Jun 18, 2024
CVE-2024-6067
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Music Class Enrollment System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jun 17, 2024
CVE-2024-6066
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. Affected is an unknown function of the file payment_report.php. …

Jun 17, 2024
CVE-2024-6064
5.3 MEDIUM

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been declared as problematic. This vulnerability affects the function xmt_node_end of the file src/scene_manager/loader_xmt.c of the …

Jun 17, 2024
CVE-2024-37828
4.8 MEDIUM

A stored cross-site scripting (XSS) in Vermeg Agile Reporter v23.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Jun 17, 2024
CVE-2024-37798
5.9 MEDIUM

Cross-site scripting (XSS) vulnerability in search-appointment.php in the Admin Panel in Phpgurukul Beauty Parlour Management System 1.0 allows remote attackers to inject arbitrary web script …

Jun 17, 2024
CVE-2024-37895
5.7 MEDIUM

Lobe Chat is an open-source LLMs/AI chat framework. In affected versions if an attacker can successfully authenticate through SSO/Access Code, they can obtain the real …

Jun 17, 2024
CVE-2024-37893
5.9 MEDIUM

Firefly III is a free and open source personal finance manager. In affected versions an MFA bypass in the Firefly III OAuth flow may allow …

Jun 17, 2024
CVE-2024-37891
4.4 MEDIUM

urllib3 is a user-friendly HTTP client library for Python. When using urllib3's proxy support with `ProxyManager`, the `Proxy-Authorization` header is only sent to the configured …

Jun 17, 2024
CVE-2024-37664
5.2 MEDIUM

Redmi router RB03 v1.0.57 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack …

Jun 17, 2024
CVE-2024-37663
4.1 MEDIUM

Redmi router RB03 v1.0.57 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic …

Jun 17, 2024
CVE-2024-37662
6.3 MEDIUM

TP-LINK TL-7DR5130 v1.0.23 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the …

Jun 17, 2024
CVE-2024-37661
6.3 MEDIUM

TP-LINK TL-7DR5130 v1.0.23 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic between …

Jun 17, 2024
CVE-2024-36527
6.5 MEDIUM

puppeteer-renderer v.3.2.0 and before is vulnerable to Directory Traversal. Attackers can exploit the URL parameter using the file protocol to read sensitive information from the …

Jun 17, 2024
CVE-2018-25103
5.3 MEDIUM

There exists use-after-free vulnerabilities in lighttpd <= 1.4.50 request parsing which might read from invalid pointers to memory used in the same request, not from …

Jun 17, 2024
CVE-2024-36578
5.9 MEDIUM

akbr update 1.0.0 is vulnerable to Prototype Pollution via update/index.js.

Jun 17, 2024
CVE-2024-36574
6.3 MEDIUM

A Prototype Pollution issue in flatten-json 1.0.1 allows an attacker to execute arbitrary code via module.exports.unflattenJSON (flatten-json/index.js:42)

Jun 17, 2024
CVE-2024-38470
6.1 MEDIUM

zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /own.php.

Jun 17, 2024
CVE-2024-38469
6.3 MEDIUM

zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /pay.php.

Jun 17, 2024
CVE-2024-37625
6.1 MEDIUM

zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /index.php.

Jun 17, 2024
CVE-2024-37624
6.1 MEDIUM

Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /chajian/inputChajian.php. component.

Jun 17, 2024
CVE-2024-37623
6.1 MEDIUM

Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /kaoqin/tpl_kaoqin_locationchange.html component.

Jun 17, 2024
CVE-2024-37622
6.1 MEDIUM

Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the num parameter at /flow/flow.php.

Jun 17, 2024
CVE-2024-37620
6.1 MEDIUM

PHPVOD v4.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /view/admin/view.php.

Jun 17, 2024
CVE-2024-37619
6.1 MEDIUM

StrongShop v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the spec_group_id parameter at /spec/index.blade.php.

Jun 17, 2024
CVE-2024-6055
4.7 MEDIUM

Improper removal of sensitive information in data source export feature in Devolutions Remote Desktop Manager 2024.1.32.0 and earlier on Windows allows an attacker that obtains …

Jun 17, 2024
CVE-2024-5741
6.5 MEDIUM

Stored XSS in inventory tree rendering in Checkmk before 2.3.0p7, 2.2.0p28, 2.1.0p45 and 2.0.0 (EOL)

Jun 17, 2024
CVE-2024-36289
5.3 MEDIUM

Reusing a nonce, key pair in encryption issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. If …

Jun 17, 2024
CVE-2024-36279
5.3 MEDIUM

Reliance on obfuscation or encryption of security-relevant inputs without integrity checking issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for …

Jun 17, 2024
CVE-2024-36277
5.3 MEDIUM

Improper verification of cryptographic signature issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. The affected app …

Jun 17, 2024
CVE-2024-4305
6.8 MEDIUM

The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.1.0 does not validate and escape some of its block options before outputting …

Jun 17, 2024
CVE-2024-3236
5.4 MEDIUM

The Popup Builder WordPress plugin before 1.1.33 does not sanitise and escape some of its Notification fields, which could allow users such as contributor and …

Jun 17, 2024
CVE-2024-6044
6.5 MEDIUM

Certain models of D-Link wireless routers have a path traversal vulnerability. Unauthenticated attackers on the same local area network can read arbitrary system files by …

Jun 17, 2024
CVE-2024-6041
6.3 MEDIUM

A vulnerability was found in itsourcecode Gym Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jun 16, 2024
CVE-2024-6039
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Feng Office 3.11.1.2. Affected is an unknown function of the component Workspaces. The manipulation of …

Jun 16, 2024
CVE-2023-27636
5.4 MEDIUM

Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.

Jun 16, 2024
CVE-2024-38465
5.3 MEDIUM

Shenzhen Guoxin Synthesis image system before 8.3.0 allows username enumeration because of the response discrepancy of incorrect versus error.

Jun 16, 2024
CVE-2024-38460
4.9 MEDIUM

In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL …

Jun 16, 2024
CVE-2024-38454
6.1 MEDIUM

ExpressionEngine before 7.4.11 allows XSS.

Jun 16, 2024
CVE-2024-38443
6.2 MEDIUM

C/sorting/binary_insertion_sort.c in The Algorithms - C through e5dad3f has a segmentation fault for deep recursion, which may affect common use cases such as sorting an …

Jun 16, 2024
CVE-2024-36397
6.1 MEDIUM

Vantiva - MediaAccess DGA2232 v19.4 - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Jun 16, 2024
CVE-2024-38394
4.3 MEDIUM

Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kernel's underlying device matching logic allow a physically proximate …

Jun 16, 2024
CVE-2024-6016
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in itsourcecode Online Laundry Management System 1.0. Affected by this issue is some unknown functionality …

Jun 15, 2024
CVE-2024-6015
6.3 MEDIUM

A vulnerability classified as critical was found in itsourcecode Online House Rental System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jun 15, 2024
CVE-2024-6014
6.3 MEDIUM

A vulnerability classified as critical has been found in itsourcecode Document Management System 1.0. Affected is an unknown function of the file edithis.php. The manipulation …

Jun 15, 2024
CVE-2024-6013
6.3 MEDIUM

A vulnerability was found in itsourcecode Online Book Store 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Jun 15, 2024
CVE-2024-6009
6.3 MEDIUM

A vulnerability has been found in itsourcecode Event Calendar 1.0 and classified as critical. Affected by this vulnerability is the function regConfirm/regDelete of the file …

Jun 15, 2024
CVE-2024-6008
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Online Book Store up to 1.0. Affected is an unknown function of the file …

Jun 15, 2024
CVE-2024-6007
6.3 MEDIUM

A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /protocol/iscgwtunnel/deleteiscgwrouteconf.php. The …

Jun 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.