CVE Database

59526+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-2295
6.4 MEDIUM

The Contact Form Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [xyz-cfm-form] shortcode in all versions up to, and including, …

Jun 1, 2024
CVE-2024-2506
6.4 MEDIUM

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS functionality …

Jun 1, 2024
CVE-2024-1324
5.3 MEDIUM

The QQWorld Auto Save Images plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the save_remote_images_get_auto_saved_results() function …

Jun 1, 2024
CVE-2024-5501
6.4 MEDIUM

The Supreme Modules Lite – Divi Theme, Extra Theme and Divi Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_one_id’ parameter …

Jun 1, 2024
CVE-2024-4342
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image hotspot, image accordion, off canvas, woogrid, …

Jun 1, 2024
CVE-2024-4087
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Back to Top widget in all versions …

Jun 1, 2024
CVE-2023-6382
6.4 MEDIUM

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_slide' shortcode in all versions up …

Jun 1, 2024
CVE-2024-3565
6.4 MEDIUM

The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'content_block' shortcode in all versions up to, …

Jun 1, 2024
CVE-2024-4711
6.4 MEDIUM

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ajax_load_more shortcode in versions up to, …

Jun 1, 2024
CVE-2024-2933
6.4 MEDIUM

The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Social Profiles widget in all versions up …

Jun 1, 2024
CVE-2024-34006
4.3 MEDIUM

The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered.

May 31, 2024
CVE-2024-34005
6.5 MEDIUM

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore database …

May 31, 2024
CVE-2024-34004
6.5 MEDIUM

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore wiki …

May 31, 2024
CVE-2024-34003
5.9 MEDIUM

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore workshop …

May 31, 2024
CVE-2024-34002
6.5 MEDIUM

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore feedback …

May 31, 2024
CVE-2024-36845
4.3 MEDIUM

An invalid pointer in the modbus_receive() function of libmodbus v3.1.6 allows attackers to cause a Denial of Service (DoS) via a crafted message sent to …

May 31, 2024
CVE-2024-34000
4.3 MEDIUM

ID numbers displayed in the lesson overview report required additional sanitizing to prevent a stored XSS risk.

May 31, 2024
CVE-2024-33998
5.4 MEDIUM

Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features.

May 31, 2024
CVE-2024-33997
6.1 MEDIUM

Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation.

May 31, 2024
CVE-2024-33996
6.2 MEDIUM

Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not …

May 31, 2024
CVE-2024-22060
4.9 MEDIUM

An unrestricted file upload vulnerability in web component of Ivanti Neurons for ITSM allows a remote, authenticated, high privileged user to write arbitrary files into …

May 31, 2024
CVE-2021-44534
6.5 MEDIUM

Insufficient user input filtering leads to arbitrary file read by non-authenticated attacker, which results in sensitive information disclosure.

May 31, 2024
CVE-2022-25038
6.1 MEDIUM

wanEditor v4.7.11 was discovered to contain a cross-site scripting (XSS) vulnerability via the video upload function.

May 31, 2024
CVE-2022-25037
5.4 MEDIUM

An issue in wanEditor v4.7.11 and fixed in v.4.7.12 and v.5 was discovered to contain a cross-site scripting (XSS) vulnerability via the image upload function.

May 31, 2024
CVE-2023-7073
6.4 MEDIUM

The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.7 via …

May 31, 2024
CVE-2024-31908
6.4 MEDIUM

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web …

May 31, 2024
CVE-2024-31907
5.4 MEDIUM

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

May 31, 2024
CVE-2024-31889
5.4 MEDIUM

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

May 31, 2024
CVE-2024-22338
4.0 MEDIUM

IBM Security Verify Access OIDC Provider 22.09 through 23.03 could disclose sensitive information to a local user due to hazardous input validation. IBM X-Force ID: …

May 31, 2024
CVE-2024-5347
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'arrow' attribute within the plugin's Post Navigation widget in …

May 31, 2024
CVE-2024-5041
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ha-ia-content-button’ parameter in all versions up to, and including, …

May 31, 2024
CVE-2024-4160
6.4 MEDIUM

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' shortcode in all versions up to, and including, 3.2.90 …

May 31, 2024
CVE-2024-5524
5.3 MEDIUM

Information exposure vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows unregistered users to access all internal links of the application without providing any credentials.

May 31, 2024
CVE-2024-5427
6.4 MEDIUM

The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's …

May 31, 2024
CVE-2024-4379
5.4 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Global Tooltip widget in all versions up to, …

May 31, 2024
CVE-2024-4376
6.4 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fancy Text widget in all versions up to, …

May 31, 2024
CVE-2024-4205
4.3 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_template_content() function …

May 31, 2024
CVE-2024-23847
5.9 MEDIUM

Incorrect default permissions issue exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a …

May 31, 2024
CVE-2024-5418
6.4 MEDIUM

The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slitems' attribute within the plugin's De Product Tab & Slide …

May 31, 2024
CVE-2024-1298
6.0 MEDIUM

EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A …

May 30, 2024
CVE-2024-35189
6.5 MEDIUM

Fides is an open-source privacy engineering platform. The Fides webserver has a number of endpoints that retrieve `ConnectionConfiguration` records and their associated `secrets` which _can_ …

May 30, 2024
CVE-2024-32877
4.2 MEDIUM

Yii 2 is a PHP application framework. During internal penetration testing of a product based on Yii2, users discovered a Cross-site Scripting (XSS) vulnerability within …

May 30, 2024
CVE-2024-35228
5.5 MEDIUM

Wagtail is an open source content management system built on Django. Due to an improperly applied permission check in the `wagtail.contrib.settings` module, a user with …

May 30, 2024
CVE-2024-35468
5.4 MEDIUM

A SQL injection vulnerability in /hrm/index.php in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.

May 30, 2024
CVE-2024-35429
6.5 MEDIUM

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via eventRecord.

May 30, 2024
CVE-2024-35352
6.1 MEDIUM

A vulnerability has been discovered in Diño Physics School Assistant version 2.3. This vulnerability impacts unidentified code within the file /classes/Users.php?f=save. Manipulating the parameter middlename …

May 30, 2024
CVE-2024-35351
5.4 MEDIUM

A vulnerability has been discovered in Diño Physics School Assistant version 2.3. This vulnerability impacts unidentified code within the file /classes/SystemSettings.php?f=update_settings. Manipulating the parameter name …

May 30, 2024
CVE-2024-5518
6.3 MEDIUM

A vulnerability classified as critical has been found in itsourcecode Online Discussion Forum 1.0. This affects an unknown part of the file change_profile_picture.php. The manipulation …

May 30, 2024
CVE-2024-36959
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pinctrl: devicetree: fix refcount leak in pinctrl_dt_to_map() If we fail to allocate propname buffer, we …

May 30, 2024
CVE-2024-36958
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix nfsd4_encode_fattr4() crasher Ensure that args.acl is initialized early. It is used in an …

May 30, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.