CVE Database

59927+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0792
6.4 MEDIUM

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, …

Feb 29, 2024
CVE-2024-0658
4.4 MEDIUM

The Insert PHP Code Snippet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user's name when accessing the insert-php-code-snippet-manage page in all …

Feb 29, 2024
CVE-2024-0656
4.4 MEDIUM

The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Feb 29, 2024
CVE-2024-0621
4.4 MEDIUM

The Simple Share Buttons Adder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.4.11 …

Feb 29, 2024
CVE-2024-0620
5.3 MEDIUM

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.9 via API. …

Feb 29, 2024
CVE-2024-0616
5.3 MEDIUM

The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.2 …

Feb 29, 2024
CVE-2024-0604
4.4 MEDIUM

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and …

Feb 29, 2024
CVE-2024-0602
4.4 MEDIUM

The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, …

Feb 29, 2024
CVE-2024-0590
6.1 MEDIUM

The Microsoft Clarity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.3. This is due to missing …

Feb 29, 2024
CVE-2024-0516
5.3 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized post metadata update due to a missing capability check on the wpr_update_form_action_meta …

Feb 29, 2024
CVE-2024-0515
4.3 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is …

Feb 29, 2024
CVE-2024-0514
4.3 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is …

Feb 29, 2024
CVE-2024-0513
4.3 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is …

Feb 29, 2024
CVE-2024-0512
4.3 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is …

Feb 29, 2024
CVE-2024-0506
6.4 MEDIUM

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $instance[alt] parameter in …

Feb 29, 2024
CVE-2024-0442
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via element URL parameters in all versions up to, and …

Feb 29, 2024
CVE-2024-0438
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wrapper link parameter in the Age Gate in all …

Feb 29, 2024
CVE-2024-0379
4.3 MEDIUM

The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up …

Feb 29, 2024
CVE-2023-7207
4.9 MEDIUM

Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since …

Feb 29, 2024
CVE-2023-7108
4.3 MEDIUM

A vulnerability classified as problematic has been found in code-projects E-Commerce Website 1.0. This affects an unknown part of the file user_signup.php. The manipulation of …

Feb 29, 2024
CVE-2023-7106
6.3 MEDIUM

A vulnerability was found in code-projects E-Commerce Website 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

Feb 29, 2024
CVE-2023-7105
4.7 MEDIUM

A vulnerability was found in code-projects E-Commerce Website 1.0. It has been classified as critical. Affected is an unknown function of the file index_search.php. The …

Feb 29, 2024
CVE-2023-6923
6.1 MEDIUM

The Matomo Analytics – Ethical Stats. Powerful Insights. plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the idsite parameter in all versions up …

Feb 29, 2024
CVE-2023-6806
6.4 MEDIUM

The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Job Settings user profile fields in all versions up to, and including, …

Feb 29, 2024
CVE-2023-6565
5.9 MEDIUM

The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. …

Feb 29, 2024
CVE-2023-6247
6.5 MEDIUM

The PKCS#7 parser in OpenVPN 3 Core Library versions through 3.8.3 did not properly validate the parsed data, which would result in the application crashing.

Feb 29, 2024
CVE-2023-51835
6.8 MEDIUM

An issue in TRENDnet TEW-822DRE v.1.03B02 allows a local attacker to execute arbitrary code via the parameters ipv4_ping in the /boafrm/formSystemCheck.

Feb 29, 2024
CVE-2023-51775
6.5 MEDIUM

The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

Feb 29, 2024
CVE-2023-50436
5.3 MEDIUM

An issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log file. The earliest affected version …

Feb 29, 2024
CVE-2023-49932
5.4 MEDIUM

An issue was discovered in Couchbase Server before 7.2.4. An attacker can bypass SQL++ N1QL cURL host restrictions.

Feb 29, 2024
CVE-2023-48653
4.3 MEDIUM

Concrete CMS before 8.5.14 and 9 before 9.2.3 allows Cross Site Request Forgery (CSRF) via ccm/calendar/dialogs/event/delete/submit. An attacker can force an admin to delete events …

Feb 29, 2024
CVE-2023-48651
4.3 MEDIUM

Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) at /ccm/system/dialogs/file/delete/1/submit.

Feb 29, 2024
CVE-2023-48650
4.8 MEDIUM

Concrete CMS before 8.5.14 and 9 before 9.2.3 is vulnerable to an admin adding a stored XSS payload via the Layout Preset name.

Feb 29, 2024
CVE-2023-45874
4.3 MEDIUM

An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (outage of reader threads).

Feb 29, 2024
CVE-2023-44347
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker could leverage this vulnerability …

Feb 29, 2024
CVE-2023-44346
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. …

Feb 29, 2024
CVE-2023-44345
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability …

Feb 29, 2024
CVE-2023-44344
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. …

Feb 29, 2024
CVE-2023-44343
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. …

Feb 29, 2024
CVE-2023-44342
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. …

Feb 29, 2024
CVE-2023-44341
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker could leverage this vulnerability …

Feb 29, 2024
CVE-2023-43769
6.3 MEDIUM

An issue was discovered in Couchbase Server through 7.1.4 before 7.1.5 and before 7.2.1. There are Unauthenticated RMI Service Ports Exposed in Analytics.

Feb 29, 2024
CVE-2023-41165
4.8 MEDIUM

An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.38 before 3.7.39, 3.10.0 through 3.11.26 before 3.11.27, 4.0 through 4.3.21 before 4.3.22, and …

Feb 29, 2024
CVE-2023-38372
5.9 MEDIUM

An unauthorized attacker who has obtained an IBM Watson IoT Platform 1.0 security authentication token can use it to impersonate an authorized platform user. IBM …

Feb 29, 2024
CVE-2023-37495
5.9 MEDIUM

Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino® …

Feb 29, 2024
CVE-2023-27151
6.1 MEDIUM

openCRX 5.2.0 was discovered to contain an HTML injection vulnerability for Search Criteria-Activity Number (in the Saved Search Activity) via the Name, Description, or Activity …

Feb 29, 2024
CVE-2023-25926
5.5 MEDIUM

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML …

Feb 29, 2024
CVE-2022-36677
6.1 MEDIUM

Obsidian Mind Map v1.1.0 allows attackers to execute arbitrary code via a crafted payload injected into an uploaded document.

Feb 29, 2024
CVE-2024-26146
5.3 MEDIUM

Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a …

Feb 29, 2024
CVE-2024-26141
5.8 MEDIUM

Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Responding with …

Feb 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.