CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-3194
5.4 MEDIUM

The Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allow them to run stored XSS attacks against …

Jan 16, 2024
CVE-2022-2413
5.4 MEDIUM

The Slide Anything WordPress plugin before 2.3.47 does not properly sanitize or escape the slide title before outputting it in the admin pages, allowing a …

Jan 16, 2024
CVE-2022-23180
4.3 MEDIUM

The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks, which could allow any authenticated users, such …

Jan 16, 2024
CVE-2022-23179
4.8 MEDIUM

The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.0 does not escape some of its form fields before outputting them in attributes, …

Jan 16, 2024
CVE-2022-1760
4.3 MEDIUM

The Core Control WordPress plugin through 1.2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Jan 16, 2024
CVE-2022-1618
6.1 MEDIUM

The Coru LFMember WordPress plugin through 1.0.2 does not have CSRF check in place when adding a new game, and is lacking sanitisation as well …

Jan 16, 2024
CVE-2022-1617
6.1 MEDIUM

The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as escaping …

Jan 16, 2024
CVE-2022-1563
5.3 MEDIUM

The WPGraphQL WooCommerce WordPress plugin before 0.12.4 does not prevent unauthenticated attackers from enumerating a shop's coupon codes and values via GraphQL.

Jan 16, 2024
CVE-2022-0775
4.3 MEDIUM

The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as subscriber to …

Jan 16, 2024
CVE-2022-0402
6.1 MEDIUM

The Super Forms - Drag & Drop Form Builder WordPress plugin before 6.0.4 does not escape the bob_czy_panstwa_sprawa_zostala_rozwiazana parameter before outputting it back in an …

Jan 16, 2024
CVE-2021-4227
5.3 MEDIUM

The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing attackers to inject an iFrame in …

Jan 16, 2024
CVE-2021-25117
4.8 MEDIUM

The WP-PostRatings WordPress plugin before 1.86.1 does not sanitise the postratings_image parameter from its options page (wp-admin/admin.php?page=wp-postratings/postratings-options.php). Even though the page is only accessible to …

Jan 16, 2024
CVE-2021-24870
6.1 MEDIUM

The WP Fastest Cache WordPress plugin before 0.9.5 is lacking a CSRF check in its wpfc_save_cdn_integration AJAX action, and does not sanitise and escape some …

Jan 16, 2024
CVE-2021-24567
5.4 MEDIUM

The Simple Post WordPress plugin through 1.1 does not sanitize user input when an authenticated user Text value, then it does not escape these values …

Jan 16, 2024
CVE-2021-24559
5.4 MEDIUM

The Qyrr WordPress plugin before 0.7 does not escape the data-uri of the QR Code when outputting it in a src attribute, allowing for Cross-Site …

Jan 16, 2024
CVE-2021-24433
5.4 MEDIUM

The simple sort&search WordPress plugin through 0.0.3 does not make sure that the indexurl parameter of the shortcodes "category_sims", "order_sims", "orderby_sims", "period_sims", and "tag_sims" use …

Jan 16, 2024
CVE-2021-24432
6.1 MEDIUM

The Advanced AJAX Product Filters WordPress plugin does not sanitise the 'term_id' POST parameter before outputting it in the page, leading to reflected Cross-Site Scripting …

Jan 16, 2024
CVE-2023-6395
6.7 MEDIUM

The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling the execution of arbitrary code with root user privileges. This …

Jan 16, 2024
CVE-2021-4432
5.3 MEDIUM

A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as problematic. This affects an unknown part of the component USER Command …

Jan 16, 2024
CVE-2024-0581
4.0 MEDIUM

An Uncontrolled Resource Consumption vulnerability has been found on Sandsprite Scdbg.exe, affecting version 1.0. This vulnerability allows an attacker to send a specially crafted shellcode …

Jan 16, 2024
CVE-2024-0232
4.7 MEDIUM

A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim …

Jan 16, 2024
CVE-2024-0569
4.3 MEDIUM

A vulnerability classified as problematic has been found in Totolink T8 4.1.5cu.833_20220905. This affects the function getSysStatusCfg of the file /cgi-bin/cstecgi.cgi of the component Setting …

Jan 16, 2024
CVE-2024-0555
4.6 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability has been found on WIC1200, affecting version 1.1. An authenticated user could lead another user into executing unwanted actions …

Jan 16, 2024
CVE-2024-0554
5.5 MEDIUM

A Cross-site scripting (XSS) vulnerability has been found on WIC1200, affecting version 1.1. An authenticated user could store a malicious javascript payload in the device …

Jan 16, 2024
CVE-2023-52106
4.4 MEDIUM

Vulnerability of permission verification for APIs in the DownloadProviderMain module. Impact: Successful exploitation of this vulnerability will affect integrity and availability.

Jan 16, 2024
CVE-2023-52112
5.3 MEDIUM

Unauthorized file access vulnerability in the wallpaper service module. Successful exploitation of this vulnerability may cause features to perform abnormally.

Jan 16, 2024
CVE-2011-10005
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in EasyFTP 1.7.0.2. Affected is an unknown function of the component MKD Command Handler. The manipulation …

Jan 16, 2024
CVE-2023-6457
6.6 MEDIUM

Incorrect Default Permissions vulnerability in Hitachi Tuning Manager on Windows (Hitachi Tuning Manager server component) allows local users to read and write specific files.This issue …

Jan 16, 2024
CVE-2023-49107
5.3 MEDIUM

Generation of Error Message Containing Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent modules).This issue affects Hitachi Device Manager: before …

Jan 16, 2024
CVE-2023-49106
4.6 MEDIUM

Missing Password Field Masking vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent component).This issue affects Hitachi Device Manager: before 8.8.5-04.

Jan 16, 2024
CVE-2023-48104
6.1 MEDIUM

Alinto SOGo before 5.9.1 is vulnerable to HTML Injection.

Jan 16, 2024
CVE-2023-47459
6.5 MEDIUM

An issue in Knovos Discovery v.22.67.0 allows a remote attacker to obtain sensitive information via the /DiscoveryReview/Service/CaseManagement.svc/GetProductSiteName component.

Jan 16, 2024
CVE-2023-41619
6.1 MEDIUM

Emlog Pro v2.1.14 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/article.php?action=write.

Jan 16, 2024
CVE-2024-0565
6.8 MEDIUM

An out-of-bounds memory read flaw was found in receive_encrypted_standard in fs/smb/client/smb2ops.c in the SMB Client sub-component in the Linux Kernel. This issue occurs due to …

Jan 15, 2024
CVE-2024-0558
4.7 MEDIUM

A vulnerability has been found in DedeBIZ 6.3.0 and classified as critical. This vulnerability affects unknown code of the file /admin/makehtml_freelist_action.php. The manipulation of the …

Jan 15, 2024
CVE-2024-0320
5.4 MEDIUM

Cross-Site Scripting in FireEye Malware Analysis (AX) affecting version 9.0.3.936530. This vulnerability allows an attacker to send a specially crafted JavaScript payload in the application …

Jan 15, 2024
CVE-2024-0319
5.4 MEDIUM

Open Redirect vulnerability in FireEye HXTool affecting version 4.6, the exploitation of which could allow an attacker to redirect a legitimate user to a malicious …

Jan 15, 2024
CVE-2024-0318
5.4 MEDIUM

Cross-Site Scripting in FireEye HXTool affecting version 4.6. This vulnerability allows an attacker to store a specially crafted JavaScript payload in the 'Profile Name' and …

Jan 15, 2024
CVE-2024-0317
5.4 MEDIUM

Cross-Site Scripting in FireEye EX, affecting version 9.0.3.936727. Exploitation of this vulnerability allows an attacker to send a specially crafted JavaScript payload via the 'type' …

Jan 15, 2024
CVE-2024-22207
5.3 MEDIUM

fastify-swagger-ui is a Fastify plugin for serving Swagger UI. Prior to 2.1.0, the default configuration of `@fastify/swagger-ui` without `baseDir` set will lead to all files …

Jan 15, 2024
CVE-2024-0316
6.8 MEDIUM

Improper cleanup vulnerability in exceptions thrown in FireEye Endpoint Security, affecting version 5.2.0.958244. This vulnerability could allow an attacker to send multiple request packets to …

Jan 15, 2024
CVE-2024-0315
6.6 MEDIUM

Remote file inclusion vulnerability in FireEye Central Management affecting version 9.1.1.956704. This vulnerability allows an attacker to upload a malicious PDF file to the system …

Jan 15, 2024
CVE-2024-0314
5.4 MEDIUM

XSS vulnerability in FireEye Central Management affecting version 9.1.1.956704, which could allow an attacker to modify special HTML elements in the application and cause a …

Jan 15, 2024
CVE-2023-6941
4.8 MEDIUM

The Keap Official Opt-in Forms WordPress plugin through 1.0.11 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jan 15, 2024
CVE-2023-6843
4.3 MEDIUM

The easy.jobs- Best Recruitment Plugin for Job Board Listing, Manager, Career Page for Elementor & Gutenberg WordPress plugin before 2.4.7 does not properly secure some …

Jan 15, 2024
CVE-2023-6163
4.8 MEDIUM

The WP Crowdfunding WordPress plugin before 2.1.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jan 15, 2024
CVE-2023-6066
4.3 MEDIUM

The WP Custom Widget area WordPress plugin through 1.2.5 does not properly apply capability and nonce checks on any of its AJAX action callback functions, …

Jan 15, 2024
CVE-2023-6050
6.1 MEDIUM

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not sanitise and escape various parameters and generated URLs before outputting them back in attributes, …

Jan 15, 2024
CVE-2023-6048
6.5 MEDIUM

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not prevent user with low privileges on the site, like subscribers, from setting any of …

Jan 15, 2024
CVE-2023-4925
4.8 MEDIUM

The Easy Forms for Mailchimp WordPress plugin through 6.8.10 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jan 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.