CVE Database

59714+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-32237
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem (Elementor), CodexThemes TheGem (WPBakery) allows Stored XSS.This issue affects TheGem (Elementor): …

Mar 26, 2024
CVE-2023-51416
6.5 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in EnvialoSimple EnvíaloSimple.This issue affects EnvíaloSimple: from n/a through 2.2.

Mar 26, 2024
CVE-2024-2889
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister Lite for Amazon wp-lister-for-amazon.This issue affects WP-Lister Lite for Amazon: …

Mar 26, 2024
CVE-2024-2888
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor …

Mar 26, 2024
CVE-2024-2303
6.4 MEDIUM

The Easy Textillate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'textillate' shortcode in all versions up to, and including, 2.01 …

Mar 26, 2024
CVE-2024-2170
6.4 MEDIUM

The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the child page index widget in all versions …

Mar 26, 2024
CVE-2024-1745
4.3 MEDIUM

The Testimonial Slider WordPress plugin before 2.3.7 does not properly ensure that a user has the necessary capabilities to edit certain sensitive Testimonial Slider WordPress …

Mar 26, 2024
CVE-2023-7232
5.3 MEDIUM

The Backup and Restore WordPress WordPress plugin through 1.45 does not protect some log files containing sensitive information such as site configuration etc, allowing unauthenticated …

Mar 26, 2024
CVE-2024-29195
6.0 MEDIUM

The azure-c-shared-utility is a C library for AMQP/MQTT communication to Azure Cloud Services. This library may be used by the Azure IoT C SDK for …

Mar 26, 2024
CVE-2024-2732
5.4 MEDIUM

The Themify Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'themify_post_slider shortcode in all versions up to, and including, 2.0.8 …

Mar 26, 2024
CVE-2024-21914
5.3 MEDIUM

A vulnerability exists in the affected product that allows a malicious user to restart the Rockwell Automation PanelView™ Plus 7 terminal remotely without security protections. …

Mar 25, 2024
CVE-2024-29179
4.8 MEDIUM

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. An attacker with admin privileges can upload an …

Mar 25, 2024
CVE-2024-29041
6.1 MEDIUM

Express.js minimalist web framework for node. Versions of Express.js prior to 4.19.0 and all pre-release alpha and beta versions of 5.0 are affected by an …

Mar 25, 2024
CVE-2024-29025
5.3 MEDIUM

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to …

Mar 25, 2024
CVE-2024-28246
5.5 MEDIUM

KaTeX is a JavaScript library for TeX math rendering on the web. Code that uses KaTeX's `trust` option, specifically that provides a function to blacklist …

Mar 25, 2024
CVE-2024-28245
6.3 MEDIUM

KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\includegraphics` …

Mar 25, 2024
CVE-2024-28244
6.5 MEDIUM

KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\def` …

Mar 25, 2024
CVE-2024-28243
6.5 MEDIUM

KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\edef` …

Mar 25, 2024
CVE-2024-28108
4.7 MEDIUM

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Due to insufficient validation on the `contentLink` parameter, …

Mar 25, 2024
CVE-2024-28106
4.3 MEDIUM

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. By manipulating the news parameter in a POST …

Mar 25, 2024
CVE-2024-27300
5.5 MEDIUM

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The `email` field in phpMyFAQ's user control panel …

Mar 25, 2024
CVE-2023-48296
4.3 MEDIUM

OroPlatform is a PHP Business Application Platform (BAP). Navigation history, most viewed and favorite navigation items are returned to storefront user in JSON navigation response …

Mar 25, 2024
CVE-2023-45824
4.3 MEDIUM

OroPlatform is a PHP Business Application Platform (BAP). A logged in user can access page state data of pinned pages of other users by pageId …

Mar 25, 2024
CVE-2024-30203
5.5 MEDIUM

In Emacs before 29.3, Gnus treats inline MIME contents as trusted.

Mar 25, 2024
CVE-2024-28183
6.1 MEDIUM

ESP-IDF is the development framework for Espressif SoCs supported on Windows, Linux and macOS. A Time-of-Check to Time-of-Use (TOCTOU) vulnerability was discovered in the implementation …

Mar 25, 2024
CVE-2024-25175
6.1 MEDIUM

An issue in Kickdler before v1.107.0 allows attackers to provide an XSS payload via a HTTP response splitting attack.

Mar 25, 2024
CVE-2024-28435
5.4 MEDIUM

The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload.

Mar 25, 2024
CVE-2023-27608
6.5 MEDIUM

Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce.This issue affects Points and Rewards for WooCommerce: from n/a through 1.5.0.

Mar 25, 2024
CVE-2023-25039
4.3 MEDIUM

Missing Authorization vulnerability in CodePeople Google Maps CP.This issue affects Google Maps CP: from n/a through 1.0.43.

Mar 25, 2024
CVE-2023-22699
5.4 MEDIUM

Missing Authorization vulnerability in MainWP MainWP Wordfence Extension.This issue affects MainWP Wordfence Extension: from n/a through 4.0.7.

Mar 25, 2024
CVE-2022-45851
5.4 MEDIUM

Missing Authorization vulnerability in ShareThis ShareThis Dashboard for Google Analytics.This issue affects ShareThis Dashboard for Google Analytics: from n/a through 3.1.4.

Mar 25, 2024
CVE-2022-45356
5.4 MEDIUM

Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1.

Mar 25, 2024
CVE-2022-45352
5.4 MEDIUM

Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1.

Mar 25, 2024
CVE-2022-45351
5.4 MEDIUM

Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1.

Mar 25, 2024
CVE-2022-45349
4.3 MEDIUM

Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1.

Mar 25, 2024
CVE-2022-44626
6.3 MEDIUM

Missing Authorization vulnerability in Squirrly SEO Plugin by Squirrly SEO.This issue affects SEO Plugin by Squirrly SEO: from n/a through 12.1.20.

Mar 25, 2024
CVE-2022-38057
6.5 MEDIUM

Missing Authorization vulnerability in ThemeHunk Advance WordPress Search Plugin.This issue affects Advance WordPress Search Plugin: from n/a through 1.2.1.

Mar 25, 2024
CVE-2021-47180
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: NFC: nci: fix memory leak in nci_allocate_device nfcmrvl_disconnect fails to free the hci_dev field in …

Mar 25, 2024
CVE-2021-47179
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: NFSv4: Fix a NULL pointer dereference in pnfs_mark_matching_lsegs_return() Commit de144ff4234f changes _pnfs_return_layout() to call pnfs_mark_matching_lsegs_return() …

Mar 25, 2024
CVE-2021-47178
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Avoid smp_processor_id() in preemptible code The BUG message "BUG: using smp_processor_id() in …

Mar 25, 2024
CVE-2021-47177
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix sysfs leak in alloc_iommu() iommu_device_sysfs_add() is called before, so is has to be …

Mar 25, 2024
CVE-2021-47176
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: s390/dasd: add missing discipline function Fix crash with illegal operation exception in dasd_device_tasklet. Commit b72949328869 …

Mar 25, 2024
CVE-2021-47174
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo_avx2: Add irq_fpu_usable() check, fallback to non-AVX2 version Arturo reported this backtrace: [709732.358791] WARNING: …

Mar 25, 2024
CVE-2021-47173
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: misc/uss720: fix memory leak in uss720_probe uss720_probe forgets to decrease the refcount of usbdev in …

Mar 25, 2024
CVE-2021-47172
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7124: Fix potential overflow due to non sequential channel numbers Channel numbering must …

Mar 25, 2024
CVE-2021-47171
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: usb: fix memory leak in smsc75xx_bind Syzbot reported memory leak in smsc75xx_bind(). The problem …

Mar 25, 2024
CVE-2021-47170
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: USB: usbfs: Don't WARN about excessively large memory allocations Syzbot found that the kernel generates …

Mar 25, 2024
CVE-2021-47169
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: serial: rp2: use 'request_firmware' instead of 'request_firmware_nowait' In 'rp2_probe', the driver registers 'rp2_uart_interrupt' then calls …

Mar 25, 2024
CVE-2021-47168
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: NFS: fix an incorrect limit in filelayout_decode_layout() The "sizeof(struct nfs_fh)" is two bytes too large …

Mar 25, 2024
CVE-2021-47167
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: NFS: Fix an Oopsable condition in __nfs_pageio_add_request() Ensure that nfs_pageio_error_cleanup() resets the mirror array contents, …

Mar 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.