CVE Database

59714+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-32431
4.4 MEDIUM

Deserialization of Untrusted Data vulnerability in WP All Import Import Users from CSV.This issue affects Import Users from CSV: from n/a through 1.2.

Apr 15, 2024
CVE-2024-32430
4.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in ActiveCampaign.This issue affects ActiveCampaign: from n/a through 8.1.14.

Apr 15, 2024
CVE-2024-32454
4.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Wappointment Appointment Bookings for Zoom GoogleMeet and more – Wappointment.This issue affects Appointment Bookings for Zoom GoogleMeet and more …

Apr 15, 2024
CVE-2024-32453
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POEditor allows Stored XSS.This issue affects POEditor: from n/a through 0.9.8.

Apr 15, 2024
CVE-2024-32429
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPChill Remove Footer Credit allows Stored XSS.This issue affects Remove Footer Credit: from …

Apr 15, 2024
CVE-2024-32428
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moss Web Works MWW Disclaimer Buttons allows Stored XSS.This issue affects MWW Disclaimer …

Apr 15, 2024
CVE-2024-32147
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Form Plugin Team - GhozyLab Easy Contact Form Lite allows Stored XSS.This issue …

Apr 15, 2024
CVE-2024-32140
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in libsyn Libsyn Publisher Hub libsyn-podcasting.This issue affects Libsyn Publisher Hub: from n/a through …

Apr 15, 2024
CVE-2024-32079
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Dempfle Advanced iFrame allows Stored XSS.This issue affects Advanced iFrame: from n/a …

Apr 15, 2024
CVE-2023-52144
5.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RexTheme Product Feed Manager.This issue affects Product Feed Manager: from n/a through …

Apr 15, 2024
CVE-2024-3771
6.3 MEDIUM

A vulnerability was found in PHPGurukul Student Record System 3.20 and classified as critical. Affected by this issue is some unknown functionality of the file …

Apr 15, 2024
CVE-2024-32489
6.1 MEDIUM

TCPDF before 6.7.4 mishandles calls that use HTML syntax.

Apr 15, 2024
CVE-2024-3770
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Student Record System 3.20 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Apr 15, 2024
CVE-2024-2858
4.8 MEDIUM

The Simple Buttons Creator WordPress plugin through 1.04 does not have CSRF checks in some places, which could allow attackers to make logged in users …

Apr 15, 2024
CVE-2024-2857
6.1 MEDIUM

The Simple Buttons Creator WordPress plugin through 1.04 does not have any authorisation as well as CSRF in its add button function, allowing unauthenticated users …

Apr 15, 2024
CVE-2024-2836
4.8 MEDIUM

The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.64 does not sanitise and escape some of its settings, which could allow …

Apr 15, 2024
CVE-2024-1849
5.4 MEDIUM

The WP Customer Reviews WordPress plugin before 3.7.1 does not validate a parameter allowing contributor and above users to redirect a page to a malicious …

Apr 15, 2024
CVE-2024-1846
5.4 MEDIUM

The Responsive Tabs WordPress plugin before 4.0.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Apr 15, 2024
CVE-2024-1754
4.7 MEDIUM

The NPS computy WordPress plugin through 2.7.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Apr 15, 2024
CVE-2024-1746
5.4 MEDIUM

The Testimonial Slider WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Apr 15, 2024
CVE-2024-1712
4.7 MEDIUM

The Carousel Slider WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Apr 15, 2024
CVE-2024-1660
4.8 MEDIUM

The Top Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Apr 15, 2024
CVE-2024-1310
4.9 MEDIUM

The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. …

Apr 15, 2024
CVE-2024-1307
6.5 MEDIUM

The Smart Forms WordPress plugin before 2.6.94 does not have proper authorization in some actions, which could allow users with a role as low as …

Apr 15, 2024
CVE-2024-1306
5.4 MEDIUM

The Smart Forms WordPress plugin before 2.6.94 does not have CSRF checks in some places, which could allow attackers to make logged-in users perform unwanted …

Apr 15, 2024
CVE-2024-1204
4.3 MEDIUM

The Meta Box WordPress plugin before 5.9.4 does not prevent users with at least the contributor role from access arbitrary custom fields assigned to other …

Apr 15, 2024
CVE-2024-0902
4.8 MEDIUM

The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Apr 15, 2024
CVE-2023-7201
6.5 MEDIUM

The Everest Backup WordPress plugin before 2.2.5 does not properly validate backup files to be uploaded, allowing high privilege users such as admin to upload …

Apr 15, 2024
CVE-2023-6067
5.4 MEDIUM

The WP User Profile Avatar WordPress plugin through 1.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a …

Apr 15, 2024
CVE-2024-3776
6.1 MEDIUM

The parameter used in the login page of Netvision airPASS is not properly filtered for user input. An unauthenticated remote attacker can insert JavaScript code …

Apr 15, 2024
CVE-2024-3775
5.3 MEDIUM

aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not properly restrict user input. This allows attackers to pass arbitrary arguments to youtube-dl.exe, leading …

Apr 15, 2024
CVE-2024-3768
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul/itsourcecode News Portal 4.1. This issue affects some unknown processing of the file search.php. …

Apr 15, 2024
CVE-2024-3767
6.3 MEDIUM

A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. This vulnerability affects unknown code of the file /admin/edit-post.php. The manipulation of the …

Apr 15, 2024
CVE-2024-3774
5.3 MEDIUM

aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restrictions on a specific parameter, allowing attackers to modify this parameter to …

Apr 15, 2024
CVE-2024-3772
5.9 MEDIUM

Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string.

Apr 15, 2024
CVE-2024-3740
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in cym1102 nginxWebUI up to 3.9.9. This issue affects the function exec of the file …

Apr 13, 2024
CVE-2024-3739
6.3 MEDIUM

A vulnerability classified as critical was found in cym1102 nginxWebUI up to 3.9.9. This vulnerability affects unknown code of the file /adminPage/main/upload. The manipulation of …

Apr 13, 2024
CVE-2024-3737
6.3 MEDIUM

A vulnerability was found in cym1102 nginxWebUI up to 3.9.9. It has been rated as critical. Affected by this issue is the function findCountByQuery of …

Apr 13, 2024
CVE-2024-3736
4.3 MEDIUM

A vulnerability was found in cym1102 nginxWebUI up to 3.9.9. It has been declared as problematic. Affected by this vulnerability is the function upload of …

Apr 13, 2024
CVE-2024-3721
6.3 MEDIUM

A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing of the file …

Apr 13, 2024
CVE-2024-3720
6.3 MEDIUM

A vulnerability has been found in Tianwell Fire Intelligent Command Platform 1.1.1.1 and classified as critical. This vulnerability affects unknown code of the file /mfsNotice/page …

Apr 13, 2024
CVE-2024-26817
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: amdkfd: use calloc instead of kzalloc to avoid integer overflow This uses calloc instead of …

Apr 13, 2024
CVE-2024-3719
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Campcodes House Rental Management System 1.0. This affects an unknown part of the file ajax.php. …

Apr 13, 2024
CVE-2024-3662
4.3 MEDIUM

The WPZOOM Social Feed Widget & Block plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpzoom_instagram_clear_data() function …

Apr 13, 2024
CVE-2023-6494
4.4 MEDIUM

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and …

Apr 13, 2024
CVE-2024-2583
5.4 MEDIUM

The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.0.5 does not properly escape some of its shortcodes attributes before they are echoed back …

Apr 13, 2024
CVE-2024-3027
6.4 MEDIUM

The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the upload function in …

Apr 13, 2024
CVE-2024-1957
6.4 MEDIUM

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'give_form' shortcode in all versions …

Apr 13, 2024
CVE-2024-32028
4.1 MEDIUM

OpenTelemetry dotnet is a dotnet telemetry framework. In affected versions of `OpenTelemetry.Instrumentation.Http` and `OpenTelemetry.Instrumentation.AspNetCore` the `url.full` writes attribute/tag on spans (`Activity`) when tracing is enabled …

Apr 12, 2024
CVE-2024-31462
6.3 MEDIUM

stable-diffusion-webui is a web interface for Stable Diffusion, implemented using Gradio library. Stable-diffusion-webui 1.7.0 is vulnerable to a limited file write affecting Windows systems. The …

Apr 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.