CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0508
6.4 MEDIUM

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table Elementor Widget in all versions up …

Feb 5, 2024
CVE-2024-0448
6.4 MEDIUM

The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget URL parameters in all versions up to, …

Feb 5, 2024
CVE-2024-0384
6.4 MEDIUM

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipe Notes in all versions up to, and including, 9.1.0 due …

Feb 5, 2024
CVE-2024-0382
6.4 MEDIUM

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 9.1.0 …

Feb 5, 2024
CVE-2024-0380
5.4 MEDIUM

The WP Recipe Maker plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 9.1.0 via the 'icon' attribute used …

Feb 5, 2024
CVE-2024-0374
4.3 MEDIUM

The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to Cross-Site Request Forgery in all …

Feb 5, 2024
CVE-2024-0373
4.3 MEDIUM

The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to Cross-Site Request Forgery in all …

Feb 5, 2024
CVE-2024-0372
4.3 MEDIUM

The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to unauthorized access of data due …

Feb 5, 2024
CVE-2024-0371
4.3 MEDIUM

The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to unauthorized modification of data due …

Feb 5, 2024
CVE-2024-0370
4.3 MEDIUM

The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to unauthorized modification of data due …

Feb 5, 2024
CVE-2024-0366
4.3 MEDIUM

The Starbox – the Author Box for Humans plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Feb 5, 2024
CVE-2024-0255
6.4 MEDIUM

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprm-recipe-text-share' shortcode in all versions up to, and including, …

Feb 5, 2024
CVE-2024-0254
6.4 MEDIUM

The (Simply) Guest Author Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's post meta in all versions up to, and …

Feb 5, 2024
CVE-2023-7029
6.4 MEDIUM

The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including …

Feb 5, 2024
CVE-2023-7014
5.3 MEDIUM

The Author Box, Guest Author and Co-Authors for Your Posts – Molongui plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up …

Feb 5, 2024
CVE-2023-6985
6.5 MEDIUM

The 10Web AI Assistant – AI content writing assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Feb 5, 2024
CVE-2023-6983
4.3 MEDIUM

The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Insecure Direct Object Reference in all …

Feb 5, 2024
CVE-2023-6982
6.4 MEDIUM

The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's …

Feb 5, 2024
CVE-2023-6963
5.3 MEDIUM

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 2.0.4. This makes it possible for …

Feb 5, 2024
CVE-2023-6959
4.3 MEDIUM

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the recaptcha_api_key_manage function …

Feb 5, 2024
CVE-2023-6953
4.9 MEDIUM

The PDF Generator For Fluent Forms – The Contact Form Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the header, PDF body …

Feb 5, 2024
CVE-2023-6884
6.4 MEDIUM

This plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.1 due to insufficient …

Feb 5, 2024
CVE-2023-6808
6.4 MEDIUM

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions …

Feb 5, 2024
CVE-2023-6807
6.4 MEDIUM

The GeneratePress Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom meta output in all versions up to, and including, …

Feb 5, 2024
CVE-2023-6701
6.4 MEDIUM

The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom text field in all versions up to, and …

Feb 5, 2024
CVE-2023-6557
5.3 MEDIUM

The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the route function …

Feb 5, 2024
CVE-2023-6526
6.4 MEDIUM

The Meta Box – WordPress Custom Fields Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom post meta values displayed through the …

Feb 5, 2024
CVE-2023-4637
4.3 MEDIUM

The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the restore() and get_restore_progress() function in …

Feb 5, 2024
CVE-2023-34042
4.1 MEDIUM

The spring-security.xsd file inside the spring-security-config jar is world writable which means that if it were extracted it could be written by anyone with access …

Feb 5, 2024
CVE-2023-22819
4.9 MEDIUM

An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting …

Feb 5, 2024
CVE-2023-22817
5.5 MEDIUM

Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL using another DNS address to point …

Feb 5, 2024
CVE-2024-24574
6.5 MEDIUM

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Unsafe echo of filename in phpMyFAQ\phpmyfaq\admin\attachments.php leads to …

Feb 5, 2024
CVE-2024-22208
6.5 MEDIUM

phpMyFAQ is an Open Source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The 'sharing FAQ' functionality allows any unauthenticated actor …

Feb 5, 2024
CVE-2024-0202
5.9 MEDIUM

A security vulnerability has been identified in the cryptlib cryptographic library when cryptlib is compiled with the support for RSA key exchange ciphersuites in TLS …

Feb 5, 2024
CVE-2023-27318
6.5 MEDIUM

StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.13 are susceptible to a Denial of Service (DoS) vulnerability. A successful exploit could lead to a crash …

Feb 5, 2024
CVE-2024-22202
5.7 MEDIUM

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. phpMyFAQ's user removal page allows an attacker to …

Feb 5, 2024
CVE-2024-24396
6.1 MEDIUM

Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the …

Feb 5, 2024
CVE-2023-6028
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in the SVG version of System Diagnostics Manager of B&R Automation Runtime versions <= G4.93 that enables a …

Feb 5, 2024
CVE-2024-0953
6.1 MEDIUM

When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified …

Feb 5, 2024
CVE-2024-24397
5.4 MEDIUM

Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the …

Feb 5, 2024
CVE-2024-24768
6.5 MEDIUM

1Panel is an open source Linux server operation and maintenance management panel. The HTTPS cookie that comes with the panel does not have the Secure …

Feb 5, 2024
CVE-2023-7216
5.3 MEDIUM

A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a …

Feb 5, 2024
CVE-2024-24864
5.3 MEDIUM

A race condition was found in the Linux kernel's media/dvb-core in dvbdmx_write() function. This can result in a null pointer dereference issue, possibly leading to …

Feb 5, 2024
CVE-2024-24860
4.6 MEDIUM

A race condition was found in the Linux kernel's bluetooth device driver in {min,max}_key_size_set() function. This can result in a null pointer dereference issue, possibly …

Feb 5, 2024
CVE-2024-24859
4.6 MEDIUM

A race condition was found in the Linux kernel's net/bluetooth in sniff_{min,max}_interval_set() function. This can result in a bluetooth sniffing exception issue, possibly leading denial …

Feb 5, 2024
CVE-2024-24858
4.6 MEDIUM

A race condition was found in the Linux kernel's net/bluetooth in {conn,adv}_{min,max}_interval_set() function. This can result in I2cap connection or broadcast abnormality issue, possibly leading …

Feb 5, 2024
CVE-2024-24857
4.6 MEDIUM

A race condition was found in the Linux kernel's net/bluetooth device driver in conn_info_{min,max}_age_set() function. This can result in integrity overflow issue, possibly leading to …

Feb 5, 2024
CVE-2024-24855
5.0 MEDIUM

A race condition was found in the Linux kernel's scsi device driver in lpfc_unregister_fcf_rescan() function. This can result in a null pointer dereference issue, possibly …

Feb 5, 2024
CVE-2024-23196
5.3 MEDIUM

A race condition was found in the Linux kernel's sound/hda device driver in snd_hdac_regmap_sync() function. This can result in a null pointer dereference issue, possibly …

Feb 5, 2024
CVE-2024-22386
5.3 MEDIUM

A race condition was found in the Linux kernel's drm/exynos device driver in exynos_drm_crtc_atomic_disable() function. This can result in a null pointer dereference issue, possibly …

Feb 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.