CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-36352
6.3 MEDIUM

Missing Authorization vulnerability in Profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects ProfileGrid – User Profiles, Memberships, Groups and Communities: from n/a …

Jan 8, 2024
CVE-2022-34344
5.4 MEDIUM

Missing Authorization vulnerability in Rymera Web Co Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More.This …

Jan 8, 2024
CVE-2023-52198
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michiel van Eerd Private Google Calendars allows Stored XSS.This issue affects Private Google …

Jan 8, 2024
CVE-2023-52197
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Impactpixel Ads Invalid Click Protection allows Stored XSS.This issue affects Ads Invalid Click …

Jan 8, 2024
CVE-2023-51508
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jordy Meow Database Cleaner: Clean, Optimize & Repair.This issue affects Database Cleaner: Clean, Optimize & …

Jan 8, 2024
CVE-2023-51490
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPMU DEV Defender Security – Malware Scanner, Login Security & Firewall.This issue affects Defender Security …

Jan 8, 2024
CVE-2023-51408
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StudioWombat WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce.This issue …

Jan 8, 2024
CVE-2023-51406
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team FastDup – Fastest WordPress Migration & Duplicator.This issue affects FastDup – Fastest WordPress …

Jan 8, 2024
CVE-2023-27739
6.1 MEDIUM

easyXDM 2.5 allows XSS via the xdm_e parameter.

Jan 8, 2024
CVE-2022-45354
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.

Jan 8, 2024
CVE-2023-52271
6.5 MEDIUM

The wsftprm.sys kernel driver 2.0.0.0 in Topaz Antifraud allows low-privileged attackers to kill any (Protected Process Light) process via an IOCTL (which will be named …

Jan 8, 2024
CVE-2023-52216
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Yevhen Kotelnytskyi JS & CSS Script Optimizer.This issue affects JS & CSS Script Optimizer: from n/a through 0.3.3.

Jan 8, 2024
CVE-2023-52203
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bastian Germann cformsII allows Stored XSS.This issue affects cformsII: from n/a …

Jan 8, 2024
CVE-2023-51246
5.4 MEDIUM

A Cross Site Scripting (XSS) vulnerability in GetSimple CMS 3.3.16 exists when using Source Code Mode as a backend user to add articles via the …

Jan 8, 2024
CVE-2023-6627
6.1 MEDIUM

The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.28 does not properly protect most of its REST API routes, which attackers can …

Jan 8, 2024
CVE-2023-6555
6.1 MEDIUM

The Email Subscription Popup WordPress plugin before 1.2.20 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jan 8, 2024
CVE-2023-6529
6.1 MEDIUM

The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, …

Jan 8, 2024
CVE-2023-6161
6.1 MEDIUM

The WP Crowdfunding WordPress plugin before 2.1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jan 8, 2024
CVE-2023-6141
5.4 MEDIUM

The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with …

Jan 8, 2024
CVE-2023-6139
6.5 MEDIUM

The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with …

Jan 8, 2024
CVE-2023-5911
4.8 MEDIUM

The WP Custom Cursors | WordPress Cursor Plugin WordPress plugin through 3.2 does not sanitise and escape some of its settings, which could allow high …

Jan 8, 2024
CVE-2023-52222
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 8.2.2.

Jan 8, 2024
CVE-2023-52208
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Constant Contact Constant Contact Forms.This issue affects Constant Contact Forms: from n/a through 2.4.2.

Jan 8, 2024
CVE-2023-1032
4.7 MEDIUM

The Linux kernel io_uring IORING_OP_SOCKET operation contained a double free in function __sys_socket_file() in file net/socket.c. This issue was introduced in da214a475f8bd1d3e9e7a19ddfeb4d1617551bab and fixed in …

Jan 8, 2024
CVE-2022-2602
5.3 MEDIUM

io_uring UAF, Unix SCM garbage collection

Jan 8, 2024
CVE-2022-2588
5.3 MEDIUM

It was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the hashtable before freeing it if …

Jan 8, 2024
CVE-2022-2586
5.3 MEDIUM KEV

It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that …

Jan 8, 2024
CVE-2022-2585
5.3 MEDIUM

It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a …

Jan 8, 2024
CVE-2024-21745
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Laybuy Laybuy Payment Extension for WooCommerce allows Stored XSS.This issue affects Laybuy Payment …

Jan 8, 2024
CVE-2024-21744
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mapster Technology Inc. Mapster WP Maps allows Stored XSS.This issue affects Mapster WP …

Jan 8, 2024
CVE-2024-21647
5.9 MEDIUM

Puma is a web server for Ruby/Rack applications built for parallelism. Prior to version 6.4.2, puma exhibited incorrect behavior when parsing chunked transfer encoding bodies …

Jan 8, 2024
CVE-2024-21645
5.3 MEDIUM

pyLoad is the free and open-source Download Manager written in pure Python. A log injection vulnerability was identified in `pyload` allowing any unauthenticated actor to …

Jan 8, 2024
CVE-2023-51701
5.3 MEDIUM

fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. A reverse proxy server built with `@fastify/reply-from` could misinterpret the incoming …

Jan 8, 2024
CVE-2023-6552
6.1 MEDIUM

Lack of "current" GET parameter validation during the action of changing a language leads to an open redirect vulnerability.

Jan 8, 2024
CVE-2024-0308
6.3 MEDIUM

A vulnerability was found in Inis up to 2.0.1. It has been rated as critical. This issue affects some unknown processing of the file app/api/controller/default/Proxy.php. …

Jan 8, 2024
CVE-2023-5091
5.5 MEDIUM

Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GPU processing operations to gain access …

Jan 8, 2024
CVE-2024-0305
5.3 MEDIUM

A vulnerability was found in Guangzhou Yingke Electronic Technology Ncast up to 2017 and classified as problematic. Affected by this issue is some unknown functionality …

Jan 8, 2024
CVE-2023-41710
5.4 MEDIUM

User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. Attackers could …

Jan 8, 2024
CVE-2023-29052
5.4 MEDIUM

Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly. Attackers could lure …

Jan 8, 2024
CVE-2023-29049
5.4 MEDIUM

The "upsell" widget at the portal page could be abused to inject arbitrary script code. Attackers that manage to lure users to a compromised account, …

Jan 8, 2024
CVE-2024-0304
6.3 MEDIUM

A vulnerability has been found in Youke365 up to 1.5.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the file …

Jan 8, 2024
CVE-2024-0303
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Youke365 up to 1.5.3. Affected is an unknown function of the file /app/api/controller/caiji.php of the …

Jan 8, 2024
CVE-2024-0302
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in fhs-opensource iparking 1.5.22.RELEASE. This issue affects some unknown processing of the file /vueLogin. The …

Jan 8, 2024
CVE-2024-0301
6.3 MEDIUM

A vulnerability classified as critical was found in fhs-opensource iparking 1.5.22.RELEASE. This vulnerability affects the function getData of the file src/main/java/com/xhb/pay/action/PayTempOrderAction.java. The manipulation leads to …

Jan 8, 2024
CVE-2024-0300
6.3 MEDIUM

A vulnerability was found in Byzoro Smart S150 Management Platform up to 20240101. It has been rated as critical. Affected by this issue is some …

Jan 8, 2024
CVE-2024-0293
6.3 MEDIUM

A vulnerability classified as critical was found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected by this vulnerability is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation …

Jan 8, 2024
CVE-2023-47140
4.0 MEDIUM

IBM CICS Transaction Gateway 9.3 could allow a user to transfer or view files due to improper access controls.

Jan 8, 2024
CVE-2024-0292
6.3 MEDIUM

A vulnerability classified as critical has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected is the function setOpModeCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Jan 8, 2024
CVE-2023-50948
6.5 MEDIUM

IBM Storage Fusion HCI 2.1.0 through 2.6.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, …

Jan 8, 2024
CVE-2024-0291
6.3 MEDIUM

A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been rated as critical. This issue affects the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi. The …

Jan 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.