CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-52121
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in NitroPack Inc. NitroPack – Cache & Speed Optimization for Core Web Vitals, Defer CSS & JavaScript, Lazy load Images.This …

Jan 5, 2024
CVE-2023-52120
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Basix NEX-Forms – Ultimate Form Builder – Contact forms and much more.This issue affects NEX-Forms – Ultimate Form Builder …

Jan 5, 2024
CVE-2023-52119
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Icegram Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building.This issue affects Icegram Engage …

Jan 5, 2024
CVE-2023-51678
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Doofinder Doofinder WP & WooCommerce Search.This issue affects Doofinder WP & WooCommerce Search: from n/a through 2.0.33.

Jan 5, 2024
CVE-2023-51673
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Designful Stylish Price List – Price Table Builder & QR Code Restaurant Menu.This issue affects Stylish Price List – …

Jan 5, 2024
CVE-2023-51668
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in WP Zone Inline Image Upload for BBPress.This issue affects Inline Image Upload for BBPress: from n/a through 1.1.18.

Jan 5, 2024
CVE-2023-51539
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Apollo13Themes Apollo13 Framework Extensions.This issue affects Apollo13 Framework Extensions: from n/a through 1.9.1.

Jan 5, 2024
CVE-2023-51538
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin.This issue affects Awesome Support – WordPress HelpDesk & …

Jan 5, 2024
CVE-2023-51535
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in СleanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affects Spam protection, Anti-Spam, FireWall by CleanTalk: from …

Jan 5, 2024
CVE-2023-52149
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Floating Button.This issue affects Floating Button: from n/a through 6.0.

Jan 5, 2024
CVE-2023-52145
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Marios Alexandrou Republish Old Posts.This issue affects Republish Old Posts: from n/a through 1.21.

Jan 5, 2024
CVE-2023-52136
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds – A Tweets Widget or X Feed Widget.This issue affects Custom Twitter Feeds – …

Jan 5, 2024
CVE-2023-52130
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager.This issue affects Affiliates Manager: from n/a through 2.9.31.

Jan 5, 2024
CVE-2023-52129
6.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Michael Winkler teachPress.This issue affects teachPress: from n/a through 9.0.4.

Jan 5, 2024
CVE-2023-52128
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in WhiteWP White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard.This issue affects White Label – WordPress …

Jan 5, 2024
CVE-2023-52127
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in WPClever WPC Product Bundles for WooCommerce.This issue affects WPC Product Bundles for WooCommerce: from n/a through 7.3.1.

Jan 5, 2024
CVE-2023-52123
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in WPChill Strong Testimonials.This issue affects Strong Testimonials: from n/a through 3.1.10.

Jan 5, 2024
CVE-2023-52184
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in WP Job Portal WP Job Portal – A Complete Job Board.This issue affects WP Job Portal – A Complete …

Jan 5, 2024
CVE-2023-52178
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MojofyWP WP Affiliate Disclosure allows Stored XSS.This issue affects WP Affiliate Disclosure: from …

Jan 5, 2024
CVE-2023-52323
5.9 MEDIUM

PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.

Jan 5, 2024
CVE-2024-22075
6.1 MEDIUM

Firefly III (aka firefly-iii) before 6.1.1 allows webhooks HTML Injection.

Jan 5, 2024
CVE-2023-6493
4.3 MEDIUM

The Depicter Slider – Responsive Image Slider, Video Slider & Post Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up …

Jan 5, 2024
CVE-2024-22049
5.3 MEDIUM

httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads …

Jan 4, 2024
CVE-2024-22048
6.1 MEDIUM

govuk_tech_docs versions from 2.0.2 to before 3.3.1 are vulnerable to a cross-site scripting vulnerability. Malicious JavaScript may be executed in the user's browser if a …

Jan 4, 2024
CVE-2024-21636
6.1 MEDIUM

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. Versions prior to 3.9.0 and 2.83.0 have a cross-site …

Jan 4, 2024
CVE-2023-6551
5.4 MEDIUM

As a simple library, class.upload.php does not perform an in-depth check on uploaded files, allowing a stored XSS vulnerability when the default configuration is used. …

Jan 4, 2024
CVE-2023-3726
6.9 MEDIUM

OCSInventory allow stored email template with special characters that lead to a Stored cross-site Scripting.

Jan 4, 2024
CVE-2023-6992
4.0 MEDIUM

Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algorithm implementation (deflate.c). The issues resulted from improper …

Jan 4, 2024
CVE-2023-7044
6.4 MEDIUM

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom …

Jan 4, 2024
CVE-2023-6944
5.7 MEDIUM

A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded …

Jan 4, 2024
CVE-2022-3864
4.5 MEDIUM

A vulnerability exists in the Relion update package signature validation. A tampered update package could cause the IED to restart. After restart the device is …

Jan 4, 2024
CVE-2023-50630
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in xiweicheng TMS v.2.28.0 allows a remote attacker to execute arbitrary code via a crafted script to the click here …

Jan 4, 2024
CVE-2023-41784
6.6 MEDIUM

Permissions and Access Control Vulnerability in ZTE Red Magic 8 Pro

Jan 4, 2024
CVE-2023-52322
6.1 MEDIUM

ecrire/public/assembler.php in SPIP before 4.1.13 and 4.2.x before 4.2.7 allows XSS because input from _request() is not restricted to safe characters such as alphanumerics.

Jan 4, 2024
CVE-2023-29962
6.5 MEDIUM

S-CMS v5.0 was discovered to contain an arbitrary file read vulnerability.

Jan 4, 2024
CVE-2023-6738
5.4 MEDIUM

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pagelayer_header_code', 'pagelayer_body_open_code', and 'pagelayer_footer_code' …

Jan 4, 2024
CVE-2023-6733
6.5 MEDIUM

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via the wpmem_field shortcode. …

Jan 4, 2024
CVE-2023-6498
4.4 MEDIUM

The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including …

Jan 4, 2024
CVE-2024-20809
4.0 MEDIUM

Improper access control vulnerability in Nearby device scanning prior version 11.1.14.7 allows local attacker to access data.

Jan 4, 2024
CVE-2024-20808
4.0 MEDIUM

Improper access control vulnerability in Nearby device scanning prior version 11.1.14.7 allows local attacker to access data.

Jan 4, 2024
CVE-2024-20806
6.2 MEDIUM

Improper access control in Notification service prior to SMR Jan-2024 Release 1 allows local attacker to access notification data.

Jan 4, 2024
CVE-2024-20804
4.0 MEDIUM

Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 …

Jan 4, 2024
CVE-2024-20803
6.8 MEDIUM

Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attackers to establish pairing process without user interaction.

Jan 4, 2024
CVE-2024-20802
4.6 MEDIUM

Improper access control vulnerability in Samsung DeX prior to SMR Jan-2024 Release 1 allows owner to access other users' notification in a multi-user environment.

Jan 4, 2024
CVE-2023-5138
6.8 MEDIUM

Glitch detection is not enabled by default for the CortexM33 core in Silicon Labs secure vault high parts EFx32xG2xB, except EFR32xG21B.

Jan 3, 2024
CVE-2023-6540
6.5 MEDIUM

A vulnerability was reported in the Lenovo Browser Mobile and Lenovo Browser HD Apps for Android that could allow an attacker to craft a payload …

Jan 3, 2024
CVE-2023-5879
6.8 MEDIUM

Users’ product account authentication data was stored in clear text in The Genie Company Aladdin Connect Mobile Application Version 5.65 Build 2075 (and below) on …

Jan 3, 2024
CVE-2024-21631
6.5 MEDIUM

Vapor is an HTTP web framework for Swift. Prior to version 4.90.0, Vapor's `vapor_urlparser_parse` function uses `uint16_t` indexes when parsing a URI's components, which may …

Jan 3, 2024
CVE-2024-21622
5.4 MEDIUM

Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft starting in 3.x prior to 3.9.6 …

Jan 3, 2024
CVE-2023-6004
4.8 MEDIUM

A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syntax on the client. This issue may …

Jan 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.