CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10788
7.2 HIGH

The Activity Log – Monitor & Record User Changes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the event parameters in all versions …

Nov 21, 2024
CVE-2024-10785
6.4 MEDIUM

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Countdown' widget …

Nov 21, 2024
CVE-2024-10782
4.3 MEDIUM

The Theme Builder For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the 'elementor-template' shortcode …

Nov 21, 2024
CVE-2024-10726
6.1 MEDIUM

The Friendly Functions for Welcart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.4. This is due …

Nov 21, 2024
CVE-2024-10696
4.3 MEDIUM

The UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere Elementor Shortcode) plugin for WordPress is vulnerable to Insecure …

Nov 21, 2024
CVE-2024-10682
6.1 MEDIUM

The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg and remove_query_arg without …

Nov 21, 2024
CVE-2024-10675
6.1 MEDIUM

The affiliate-toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up to, and including, 3.6.7 due to insufficient …

Nov 21, 2024
CVE-2024-10671
4.3 MEDIUM

The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, …

Nov 21, 2024
CVE-2024-10623
6.1 MEDIUM

The ForumEngine theme for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up to, and including, 1.8 due to insufficient …

Nov 21, 2024
CVE-2024-10532
4.3 MEDIUM

The Bard Extra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bardxtra_import_xml() function in all …

Nov 21, 2024
CVE-2024-10528
4.3 MEDIUM

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized profile picture updates …

Nov 21, 2024
CVE-2024-10522
6.1 MEDIUM

The Co-marquage service-public.fr plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in …

Nov 21, 2024
CVE-2024-10482
5.4 MEDIUM

The Media File Rename, Find Unused File, Add Alt text, Caption, Desc For Image SEO WordPress plugin before 1.5.0 does not sanitise uploaded SVG files, …

Nov 21, 2024
CVE-2024-10403
7.5 HIGH

Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFTP/FTP server password used for a firmware download …

Nov 21, 2024
CVE-2024-10400
7.5 HIGH

The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions up to, and including, 2.7.6 due to …

Nov 21, 2024
CVE-2024-10393
5.3 MEDIUM

The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6. This is due to a …

Nov 21, 2024
CVE-2024-10316
4.3 MEDIUM

The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.4 in includes/templates/content-switcher.php. This …

Nov 21, 2024
CVE-2024-10177
6.4 MEDIUM

The Beds24 Online Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's beds24-link shortcode in all versions up to, and including, …

Nov 21, 2024
CVE-2024-10172
6.4 MEDIUM

The WPBakery Visual Composer WHMCS Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's void_wbwhmcse_laouts_search shortcode in all versions up to, …

Nov 21, 2024
CVE-2024-10164
6.4 MEDIUM

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdmpp_pay_link shortcode in all versions …

Nov 21, 2024
CVE-2022-43937
5.7 MEDIUM

Possible information exposure through log file vulnerability where sensitive fields are recorded in the debug-enabled logs when debugging is turned on in Brocade SANnav before …

Nov 21, 2024
CVE-2022-43936
6.8 MEDIUM

Brocade SANnav versions before 2.2.2 log Brocade Fabric OS switch passwords when debugging is enabled.

Nov 21, 2024
CVE-2022-43935
5.3 MEDIUM

An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where Brocade Fabric OS Switch passwords and authorization IDs are …

Nov 21, 2024
CVE-2022-43934
6.5 MEDIUM

Brocade SANnav before Brocade SANnav 2.2.2 supports key exchange algorithms, which are considered weak on ports 24, 6514, 18023, 19094, and 19095.

Nov 21, 2024
CVE-2022-43933
4.4 MEDIUM

An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where configuration secrets are logged in supportsave. Supportsave file is …

Nov 21, 2024
CVE-2024-9875
7.1 HIGH

Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo command bundles feature is enabled. …

Nov 21, 2024
CVE-2024-52755
4.9 MEDIUM

D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the host_ip parameter in the ipsec_road_asp function.

Nov 21, 2024
CVE-2024-51151
9.8 CRITICAL

D-Link DI-8200 16.07.26A1 is vulnerable to remote command execution in the msp_info_htm function via the flag parameter and cmd parameter.

Nov 21, 2024
CVE-2024-52765
9.8 CRITICAL

H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code execution (RCE) via the aspForm parameter.

Nov 20, 2024
CVE-2024-52702
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the component install\index.php of MyBB v1.8.38 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Nov 20, 2024
CVE-2024-52701
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Configuration page of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Nov 20, 2024
CVE-2024-52677
9.8 CRITICAL

HkCms <= v2.3.2.240702 is vulnerable to file upload in the getFileName method in /app/common/library/Upload.php.

Nov 20, 2024
CVE-2024-52581
7.5 HIGH

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.13.0, the multipart form parser shipped with litestar expects the entire request body …

Nov 20, 2024
CVE-2024-49203

Querydsl 5.1.0 and OpenFeign Querydsl 6.8 allows SQL/HQL injection in orderBy in JPAQuery. NOTE: this is disputed by a Querydsl community member because the product …

Nov 20, 2024
CVE-2024-48986
7.5 HIGH

An issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci packets by reading a byte from …

Nov 20, 2024
CVE-2024-48984
9.8 CRITICAL

An issue was discovered in MBed OS 6.16.0. When parsing hci reports, the hci parsing software dynamically determines the length of a list of reports …

Nov 20, 2024
CVE-2024-48982
7.5 HIGH

An issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci packets by reading a byte from …

Nov 20, 2024
CVE-2024-48536
7.5 HIGH

Incorrect access control in eSoft Planner 3.24.08271-USA allow attackers to view all transactions performed by the company via supplying a crafted web request.

Nov 20, 2024
CVE-2024-48535
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into …

Nov 20, 2024
CVE-2024-48534
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability on the Camp Details module of eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary code in the context of …

Nov 20, 2024
CVE-2024-48533
5.3 MEDIUM

A discrepancy between responses for valid and invalid e-mail accounts in the Forgot your Login? module of eSoft Planner 3.24.08271-USA allows attackers to enumerate valid …

Nov 20, 2024
CVE-2024-48531
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability on the Rental Availability module of eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary code in the context of …

Nov 20, 2024
CVE-2024-48530
7.5 HIGH

An issue in the Instructor Appointment Availability module of eSoft Planner 3.24.08271-USA allows attackers to cause a Denial of Service (DoS) via a crafted POST …

Nov 20, 2024
CVE-2024-52757
4.9 MEDIUM

D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the notify parameter in the arp_sys_asp function.

Nov 20, 2024
CVE-2024-52754
4.9 MEDIUM

D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the fn parameter in the tgfile_htm function.

Nov 20, 2024
CVE-2024-48985
7.5 HIGH

An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet data by reading …

Nov 20, 2024
CVE-2024-48983
7.5 HIGH

An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet data by reading …

Nov 20, 2024
CVE-2024-48981
7.5 HIGH

An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet header by looking …

Nov 20, 2024
CVE-2024-45510
5.4 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) through 10.0. Zimbra Webmail (Modern UI) is vulnerable to a stored Cross-Site Scripting (XSS) attack due to …

Nov 20, 2024
CVE-2024-45511
5.4 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A reflected Cross-Site Scripting (XSS) issue exists through the Briefcase module due to improper sanitization …

Nov 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.