CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-36236
4.8 MEDIUM

Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via a crafted SVG file uplad.

Jan 16, 2024
CVE-2023-48926
5.3 MEDIUM

An issue in 202 ecommerce Advanced Loyalty Program: Loyalty Points before v2.3.4 for PrestaShop allows unauthenticated attackers to arbitrarily change an order status.

Jan 16, 2024
CVE-2023-6335
6.4 MEDIUM

Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on Windows allows User-Controlled Filename.This issue affects Workforce Access: before 8.7.

Jan 16, 2024
CVE-2023-6334
5.3 MEDIUM

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HYPR Workforce Access on Windows allows Overflow Buffers.This issue affects Workforce Access: …

Jan 16, 2024
CVE-2024-22491
5.4 MEDIUM

A Stored Cross Site Scripting (XSS) vulnerability in beetl-bbs 2.0 allows attackers to run arbitrary code via the post/save content parameter.

Jan 16, 2024
CVE-2024-0507
6.5 MEDIUM

An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management …

Jan 16, 2024
CVE-2023-7234
5.3 MEDIUM

OPCUAServerToolkit will write a log message once an OPC UA client has successfully connected containing the client's self-defined description field.

Jan 16, 2024
CVE-2023-37523
5.6 MEDIUM

Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker to execute a malicious …

Jan 16, 2024
CVE-2024-0579
6.3 MEDIUM

A vulnerability classified as critical was found in Totolink X2000R 1.0.0-B20221212.1452. Affected by this vulnerability is the function formMapDelDevice of the file /boafrm/formMapDelDevice. The manipulation …

Jan 16, 2024
CVE-2023-4969
6.5 MEDIUM

A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local …

Jan 16, 2024
CVE-2024-0239
6.1 MEDIUM

The Contact Form 7 Connector WordPress plugin before 1.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to …

Jan 16, 2024
CVE-2024-0238
6.1 MEDIUM

The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not ensure that …

Jan 16, 2024
CVE-2024-0237
5.3 MEDIUM

The EventON WordPress plugin through 4.5.8, EventON WordPress plugin before 2.2.7 do not have authorisation in some AJAX actions, allowing unauthenticated users to update virtual …

Jan 16, 2024
CVE-2024-0236
5.3 MEDIUM

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve the …

Jan 16, 2024
CVE-2024-0235
5.3 MEDIUM

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email …

Jan 16, 2024
CVE-2024-0233
6.1 MEDIUM

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not properly sanitise and escape a parameter before outputting it back in pages, …

Jan 16, 2024
CVE-2024-0187
6.1 MEDIUM

The Community by PeepSo WordPress plugin before 6.3.1.2 does not sanitise and escape various parameters and generated URLs before outputting them back attributes, leading to …

Jan 16, 2024
CVE-2023-7154
4.8 MEDIUM

The Hubbub Lite (formerly Grow Social) WordPress plugin before 1.32.0 does not sanitise and escape some of its settings, which could allow high privilege users …

Jan 16, 2024
CVE-2023-7151
6.1 MEDIUM

The Product Enquiry for WooCommerce WordPress plugin before 3.2 does not sanitise and escape the page parameter before outputting it back in an attribute, leading …

Jan 16, 2024
CVE-2023-7125
4.3 MEDIUM

The Community by PeepSo WordPress plugin before 6.3.1.2 does not have CSRF check when creating a user post (visible on their wall in their profile …

Jan 16, 2024
CVE-2023-7084
5.4 MEDIUM

The Voting Record WordPress plugin through 2.0 is missing sanitisation as well as escaping, which could allow any authenticated users, such as subscriber to perform …

Jan 16, 2024
CVE-2023-7083
5.4 MEDIUM

The Voting Record WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Jan 16, 2024
CVE-2023-6824
6.5 MEDIUM

The WP Customer Area WordPress plugin before 8.2.1 does not properly validates user capabilities in some of its AJAX actions, allowing any users to retrieve …

Jan 16, 2024
CVE-2023-6741
4.3 MEDIUM

The WP Customer Area WordPress plugin before 8.2.1 does not properly validate users capabilities in some of its AJAX actions, allowing malicious users to edit …

Jan 16, 2024
CVE-2023-6732
4.8 MEDIUM

The Ultimate Maps by Supsystic WordPress plugin before 1.2.16 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jan 16, 2024
CVE-2023-6592
5.3 MEDIUM

The FastDup WordPress plugin before 2.2 does not prevent directory listing in sensitive directories containing export files.

Jan 16, 2024
CVE-2023-6292
4.3 MEDIUM

The Ecwid Ecommerce Shopping Cart WordPress plugin before 6.12.5 does not have CSRF check in place when updating its settings, which could allow attackers to …

Jan 16, 2024
CVE-2023-6046
4.8 MEDIUM

The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jan 16, 2024
CVE-2023-6005
4.8 MEDIUM

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 does not sanitize and escape some of its settings, which could allow high privilege …

Jan 16, 2024
CVE-2023-5558
6.1 MEDIUM

The LearnPress WordPress plugin before 4.2.5.5 does not sanitise and escape user input before outputting it back in the page, leading to a Reflected Cross-Site …

Jan 16, 2024
CVE-2023-4757
5.4 MEDIUM

The Staff / Employee Business Directory for Active Directory WordPress plugin before 1.2.3 does not sanitize and escape data returned from the LDAP server before …

Jan 16, 2024
CVE-2023-45237
5.3 MEDIUM

EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and …

Jan 16, 2024
CVE-2023-45236
5.8 MEDIUM

EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and …

Jan 16, 2024
CVE-2023-45231
6.5 MEDIUM

EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to …

Jan 16, 2024
CVE-2023-45229
6.5 MEDIUM

EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can …

Jan 16, 2024
CVE-2023-3771
6.1 MEDIUM

The T1 WordPress theme through 19.0 is vulnerable to unauthenticated open redirect with which any attacker and redirect users to arbitrary websites.

Jan 16, 2024
CVE-2023-3647
4.8 MEDIUM

The IURNY by INDIGITALL WordPress plugin before 3.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jan 16, 2024
CVE-2023-3372
5.4 MEDIUM

The Lana Shortcodes WordPress plugin before 1.2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Jan 16, 2024
CVE-2023-3178
4.3 MEDIUM

The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could allow attackers to make logged …

Jan 16, 2024
CVE-2023-37522
5.6 MEDIUM

HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower has missing or insecure tags that could allow an attacker to execute a malicious …

Jan 16, 2024
CVE-2023-0824
6.5 MEDIUM

The User registration & user profile WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as …

Jan 16, 2024
CVE-2023-0769
6.1 MEDIUM

The hiWeb Migration Simple WordPress plugin through 2.0.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jan 16, 2024
CVE-2023-0479
6.1 MEDIUM

The Print Invoice & Delivery Notes for WooCommerce WordPress plugin before 4.7.2 is vulnerable to reflected XSS by echoing a GET value in an admin …

Jan 16, 2024
CVE-2023-0389
4.8 MEDIUM

The Calculated Fields Form WordPress plugin before 1.1.151 does not sanitise and escape some of its form settings, which could allow high privilege users such …

Jan 16, 2024
CVE-2023-0376
5.4 MEDIUM

The Qubely WordPress plugin before 1.8.5 does not validate and escape some of its block options before outputting them back in a page/post where the …

Jan 16, 2024
CVE-2023-0094
5.4 MEDIUM

The UpQode Google Maps WordPress plugin through 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post …

Jan 16, 2024
CVE-2023-0079
5.4 MEDIUM

The Customer Reviews for WooCommerce WordPress plugin before 5.17.0 does not validate and escape some of its shortcode attributes before outputting them back in a …

Jan 16, 2024
CVE-2022-3836
4.8 MEDIUM

The Seed Social WordPress plugin before 2.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jan 16, 2024
CVE-2022-3829
4.8 MEDIUM

The Font Awesome 4 Menus WordPress plugin through 4.7.0 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jan 16, 2024
CVE-2022-3739
5.4 MEDIUM

The WP Best Quiz WordPress plugin through 1.0 does not sanitize and escape some parameters, which could allow users with a role as low as …

Jan 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.