CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-1044
5.3 MEDIUM

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'submit_review' function …

Feb 29, 2024
CVE-2024-1043
6.5 MEDIUM

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on …

Feb 29, 2024
CVE-2024-0984
4.3 MEDIUM

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the disableOptimization …

Feb 29, 2024
CVE-2024-0983
4.3 MEDIUM

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enableOptimization …

Feb 29, 2024
CVE-2024-0978
5.3 MEDIUM

The My Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.14 via the REST API. …

Feb 29, 2024
CVE-2024-0907
5.3 MEDIUM

The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to unauthorized access due to a missing capability …

Feb 29, 2024
CVE-2024-0838
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the side image URL parameter in the Age Gate in …

Feb 29, 2024
CVE-2024-0821
6.1 MEDIUM

The Cost of Goods Sold (COGS): Cost & Profit Calculator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'section' parameter …

Feb 29, 2024
CVE-2024-0792
6.4 MEDIUM

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, …

Feb 29, 2024
CVE-2024-0658
4.4 MEDIUM

The Insert PHP Code Snippet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user's name when accessing the insert-php-code-snippet-manage page in all …

Feb 29, 2024
CVE-2024-0656
4.4 MEDIUM

The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Feb 29, 2024
CVE-2024-0621
4.4 MEDIUM

The Simple Share Buttons Adder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.4.11 …

Feb 29, 2024
CVE-2024-0620
5.3 MEDIUM

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.9 via API. …

Feb 29, 2024
CVE-2024-0616
5.3 MEDIUM

The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.2 …

Feb 29, 2024
CVE-2024-0604
4.4 MEDIUM

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and …

Feb 29, 2024
CVE-2024-0602
4.4 MEDIUM

The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, …

Feb 29, 2024
CVE-2024-0590
6.1 MEDIUM

The Microsoft Clarity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.3. This is due to missing …

Feb 29, 2024
CVE-2024-0516
5.3 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized post metadata update due to a missing capability check on the wpr_update_form_action_meta …

Feb 29, 2024
CVE-2024-0515
4.3 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is …

Feb 29, 2024
CVE-2024-0514
4.3 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is …

Feb 29, 2024
CVE-2024-0513
4.3 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is …

Feb 29, 2024
CVE-2024-0512
4.3 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is …

Feb 29, 2024
CVE-2024-0506
6.4 MEDIUM

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $instance[alt] parameter in …

Feb 29, 2024
CVE-2024-0442
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via element URL parameters in all versions up to, and …

Feb 29, 2024
CVE-2024-0438
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wrapper link parameter in the Age Gate in all …

Feb 29, 2024
CVE-2024-0379
4.3 MEDIUM

The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up …

Feb 29, 2024
CVE-2023-7207
4.9 MEDIUM

Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since …

Feb 29, 2024
CVE-2023-7108
4.3 MEDIUM

A vulnerability classified as problematic has been found in code-projects E-Commerce Website 1.0. This affects an unknown part of the file user_signup.php. The manipulation of …

Feb 29, 2024
CVE-2023-7106
6.3 MEDIUM

A vulnerability was found in code-projects E-Commerce Website 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

Feb 29, 2024
CVE-2023-7105
4.7 MEDIUM

A vulnerability was found in code-projects E-Commerce Website 1.0. It has been classified as critical. Affected is an unknown function of the file index_search.php. The …

Feb 29, 2024
CVE-2023-6923
6.1 MEDIUM

The Matomo Analytics – Ethical Stats. Powerful Insights. plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the idsite parameter in all versions up …

Feb 29, 2024
CVE-2023-6806
6.4 MEDIUM

The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Job Settings user profile fields in all versions up to, and including, …

Feb 29, 2024
CVE-2023-6565
5.9 MEDIUM

The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. …

Feb 29, 2024
CVE-2023-6247
6.5 MEDIUM

The PKCS#7 parser in OpenVPN 3 Core Library versions through 3.8.3 did not properly validate the parsed data, which would result in the application crashing.

Feb 29, 2024
CVE-2023-51835
6.8 MEDIUM

An issue in TRENDnet TEW-822DRE v.1.03B02 allows a local attacker to execute arbitrary code via the parameters ipv4_ping in the /boafrm/formSystemCheck.

Feb 29, 2024
CVE-2023-51775
6.5 MEDIUM

The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

Feb 29, 2024
CVE-2023-50436
5.3 MEDIUM

An issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log file. The earliest affected version …

Feb 29, 2024
CVE-2023-49932
5.4 MEDIUM

An issue was discovered in Couchbase Server before 7.2.4. An attacker can bypass SQL++ N1QL cURL host restrictions.

Feb 29, 2024
CVE-2023-48653
4.3 MEDIUM

Concrete CMS before 8.5.14 and 9 before 9.2.3 allows Cross Site Request Forgery (CSRF) via ccm/calendar/dialogs/event/delete/submit. An attacker can force an admin to delete events …

Feb 29, 2024
CVE-2023-48651
4.3 MEDIUM

Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) at /ccm/system/dialogs/file/delete/1/submit.

Feb 29, 2024
CVE-2023-48650
4.8 MEDIUM

Concrete CMS before 8.5.14 and 9 before 9.2.3 is vulnerable to an admin adding a stored XSS payload via the Layout Preset name.

Feb 29, 2024
CVE-2023-45874
4.3 MEDIUM

An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (outage of reader threads).

Feb 29, 2024
CVE-2023-44347
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker could leverage this vulnerability …

Feb 29, 2024
CVE-2023-44346
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. …

Feb 29, 2024
CVE-2023-44345
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability …

Feb 29, 2024
CVE-2023-44344
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. …

Feb 29, 2024
CVE-2023-44343
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. …

Feb 29, 2024
CVE-2023-44342
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. …

Feb 29, 2024
CVE-2023-44341
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker could leverage this vulnerability …

Feb 29, 2024
CVE-2023-43769
6.3 MEDIUM

An issue was discovered in Couchbase Server through 7.1.4 before 7.1.5 and before 7.2.1. There are Unauthenticated RMI Service Ports Exposed in Analytics.

Feb 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.