CVE Database

59526+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5221
6.4 MEDIUM

The Qi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file uploader in all versions up to, and including, 1.2.9 …

Jun 6, 2024
CVE-2024-5665
4.3 MEDIUM

The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check …

Jun 6, 2024
CVE-2024-3049
5.9 MEDIUM

A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to …

Jun 6, 2024
CVE-2024-5615
5.3 MEDIUM

The Open Graph plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.11.2 via the 'opengraph_default_description' function. This …

Jun 6, 2024
CVE-2024-5449
4.3 MEDIUM

The WP Dark Mode – WordPress Dark Mode Plugin for Improved Accessibility, Dark Theme, Night Mode, and Social Sharing plugin for WordPress is vulnerable to …

Jun 6, 2024
CVE-2024-5162
6.4 MEDIUM

The WordPress prettyPhoto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.2.3 due …

Jun 6, 2024
CVE-2024-5161
6.4 MEDIUM

The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Jun 6, 2024
CVE-2024-5152
6.4 MEDIUM

The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, …

Jun 6, 2024
CVE-2024-5141
6.4 MEDIUM

The Rotating Tweets (Twitter widget and shortcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's' 'rotatingtweets' in all versions up to, …

Jun 6, 2024
CVE-2024-4707
6.4 MEDIUM

The Materialis Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's materialis_contact_form shortcode in all versions up to, and including, 1.3.41 …

Jun 6, 2024
CVE-2024-4608
6.4 MEDIUM

The SellKit – Funnel builder and checkout optimizer for WooCommerce to sell more, faster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Jun 6, 2024
CVE-2024-4459
6.4 MEDIUM

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget's titles in all versions up to, and …

Jun 6, 2024
CVE-2024-4458
6.4 MEDIUM

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in several widgets via URL parameters in all versions up to, …

Jun 6, 2024
CVE-2024-4364
6.4 MEDIUM

The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button widgets in all versions up to, and …

Jun 6, 2024
CVE-2024-4212
6.4 MEDIUM

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's TF Group Image, TF Nav Menu, TF Posts, …

Jun 6, 2024
CVE-2024-2922
6.4 MEDIUM

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget tags in all versions up to, and including, 2.1.2 …

Jun 6, 2024
CVE-2024-1175
5.3 MEDIUM

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on …

Jun 6, 2024
CVE-2024-0972
5.3 MEDIUM

The BuddyPress Members Only plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.9 via the REST API. …

Jun 6, 2024
CVE-2024-2017
5.4 MEDIUM

The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the …

Jun 6, 2024
CVE-2024-5342
6.4 MEDIUM

The Simple Image Popup Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sips_popup' shortcode in all versions up to, and …

Jun 6, 2024
CVE-2024-5224
6.4 MEDIUM

The Easy Social Like Box – Popup – Sidebar Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cardoza_facebook_like_box' shortcode in …

Jun 6, 2024
CVE-2024-5001
6.4 MEDIUM

The Image Hover Effects for Elementor with Lightbox and Flipbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_id', 'oxi_addons_f_title_tag', and 'content_description_tag' …

Jun 6, 2024
CVE-2024-4942
4.4 MEDIUM

The Custom Dash plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.2 due to …

Jun 6, 2024
CVE-2024-4788
4.3 MEDIUM

The Boostify Header Footer Builder for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Jun 6, 2024
CVE-2024-4705
6.4 MEDIUM

The Testimonials Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonials shortcode in all versions up to, and including, 4.0.4 …

Jun 6, 2024
CVE-2024-4194
6.5 MEDIUM

The The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0. …

Jun 6, 2024
CVE-2024-2350
6.4 MEDIUM

The Clever Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the CAFE Icon, CAFE Team Member, and CAFE Slider widgets …

Jun 6, 2024
CVE-2024-0910
5.3 MEDIUM

The Restrict for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.7 due to improper restrictions …

Jun 6, 2024
CVE-2023-6956
6.1 MEDIUM

The EasyAzon – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘easyazon-cloaking-locale’ parameter in all versions up to, …

Jun 6, 2024
CVE-2024-0912
4.2 MEDIUM

Under certain circumstances the Microsoft® Internet Information Server (IIS) used to host the C•CURE 9000 Web Server will log Microsoft Windows credential details within logs. …

Jun 6, 2024
CVE-2024-28818
5.9 MEDIUM

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos …

Jun 5, 2024
CVE-2024-27382
6.0 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_send_action_frame(), there is …

Jun 5, 2024
CVE-2024-27381
6.0 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_send_action_frame_ut(), there is …

Jun 5, 2024
CVE-2024-27380
6.0 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_set_delayed_wakeup_type(), there is …

Jun 5, 2024
CVE-2024-27379
6.7 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_subscribe_get_nl_params(), there is …

Jun 5, 2024
CVE-2024-27378
6.0 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_send_action_frame_cert(), there is …

Jun 5, 2024
CVE-2024-27377
6.7 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_get_security_info_nl(), there is …

Jun 5, 2024
CVE-2024-27376
6.7 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_subscribe_get_nl_params(), there is …

Jun 5, 2024
CVE-2024-27375
6.7 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_followup_get_nl_params(), there is …

Jun 5, 2024
CVE-2024-27374
6.7 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_publish_get_nl_params(), there is …

Jun 5, 2024
CVE-2024-27373
6.7 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_config_get_nl_params(), there is …

Jun 5, 2024
CVE-2024-27372
6.7 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_config_get_nl_params(), there is …

Jun 5, 2024
CVE-2024-27371
6.7 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_followup_get_nl_params(), there is …

Jun 5, 2024
CVE-2024-27370
6.7 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_config_get_nl_params(), there is …

Jun 5, 2024
CVE-2023-49927
5.3 MEDIUM

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos …

Jun 5, 2024
CVE-2024-5184
6.5 MEDIUM

The EmailGPT service contains a prompt injection vulnerability. The service uses an API service that allows a malicious user to inject a direct prompt and …

Jun 5, 2024
CVE-2024-35674
4.3 MEDIUM

Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): …

Jun 5, 2024
CVE-2024-20405
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a stored XSS attack by exploiting an …

Jun 5, 2024
CVE-2024-24789
5.5 MEDIUM

The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to …

Jun 5, 2024
CVE-2024-5629
4.7 MEDIUM

An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception …

Jun 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.