CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-52386
5.3 MEDIUM

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Classified Listing classified-listing allows PHP Local File Inclusion.This …

Nov 16, 2024
CVE-2024-9887
7.2 HIGH

The Login using WordPress Users ( WP as SAML IDP ) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in …

Nov 16, 2024
CVE-2024-11094
5.3 MEDIUM

The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.35.17 via the export feature. This …

Nov 16, 2024
CVE-2024-10592
6.4 MEDIUM

The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the popup class parameter in all versions up to, and including, …

Nov 16, 2024
CVE-2024-10645
7.5 HIGH

The Blogger 301 Redirect plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘br’ parameter in all versions up to, and including, …

Nov 16, 2024
CVE-2024-10614
4.3 MEDIUM

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cancel_import() function in all …

Nov 16, 2024
CVE-2024-8856
9.8 CRITICAL

The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the …

Nov 16, 2024
CVE-2024-10728
8.8 HIGH

The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability …

Nov 16, 2024
CVE-2024-9938
6.1 MEDIUM

The Bounce Handler MailPoet 3 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, …

Nov 16, 2024
CVE-2024-9935
7.5 HIGH

The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.0.0 via …

Nov 16, 2024
CVE-2024-9850
6.4 MEDIUM

The SVG Case Study plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0 …

Nov 16, 2024
CVE-2024-9849
8.8 HIGH

The Real3D Flipbook Lite – 3D FlipBook, PDF Viewer, PDF Embedder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type …

Nov 16, 2024
CVE-2024-9839
7.3 HIGH

The The Uix Slideshow plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.6.5. This is due to …

Nov 16, 2024
CVE-2024-9615
6.1 MEDIUM

The BulkPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all …

Nov 16, 2024
CVE-2024-9386
6.4 MEDIUM

The Exclusive Divi – Divi Preloader, Modules for Divi & Extra Theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads …

Nov 16, 2024
CVE-2024-9192
8.8 HIGH

The WordPress Video Robot - The Ultimate Video Importer plugin for WordPress is vulnerable to privilege escalation due to insufficient validation on user meta that …

Nov 16, 2024
CVE-2024-8873
6.1 MEDIUM

The PeproDev WooCommerce Receipt Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …

Nov 16, 2024
CVE-2024-6628
4.3 MEDIUM

The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up …

Nov 16, 2024
CVE-2024-11118
5.3 MEDIUM

The 404 Error Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to …

Nov 16, 2024
CVE-2024-11092
6.4 MEDIUM

The SVGPlus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.1.0 …

Nov 16, 2024
CVE-2024-11085
5.4 MEDIUM

The WP Log Viewer plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on several AJAX actions in …

Nov 16, 2024
CVE-2024-10884
6.1 MEDIUM

The SimpleForm Contact Form Submissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping …

Nov 16, 2024
CVE-2024-10883
6.1 MEDIUM

The SimpleForm – Contact form made simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without …

Nov 16, 2024
CVE-2024-10875
6.1 MEDIUM

The Gallery Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_Query_Arg without appropriate escaping on the URL in …

Nov 16, 2024
CVE-2024-10533
4.3 MEDIUM

The WP Chat App plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the ajax_install_plugin() function in all …

Nov 16, 2024
CVE-2024-10262
6.3 MEDIUM

The The Drop Shadow Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.7.14. This is due …

Nov 16, 2024
CVE-2024-10147
6.4 MEDIUM

The Steel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn shortcode in all versions up to, and including, 1.3.0 due …

Nov 16, 2024
CVE-2024-10017
6.4 MEDIUM

The PJW Mime Config plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0 …

Nov 16, 2024
CVE-2024-10015
6.4 MEDIUM

The ConvertCalculator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'type' parameters in all versions up to, and …

Nov 16, 2024
CVE-2024-10861
5.3 MEDIUM

The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Nov 16, 2024
CVE-2024-10795
4.3 MEDIUM

The Popularis Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.7 via the 'elementor-template' shortcode due to …

Nov 16, 2024
CVE-2024-10786
4.3 MEDIUM

The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the sla_clear_user_cache function in all …

Nov 16, 2024
CVE-2024-11263
9.3 CRITICAL

When the Global Pointer (GP) relative addressing is enabled (CONFIG_RISCV_GP=y), the gp reg points at 0x800 bytes past the start of the .sdata section which …

Nov 15, 2024
CVE-2024-11262
5.3 MEDIUM

A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as critical. Affected by this vulnerability is the function main of …

Nov 15, 2024
CVE-2024-9500
7.8 HIGH

A maliciously crafted DLL file when placed in temporary files and folders that are leveraged by the Autodesk Installer could lead to escalation of privileges …

Nov 15, 2024
CVE-2024-51765
5.5 MEDIUM

A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.

Nov 15, 2024
CVE-2024-51764
5.5 MEDIUM

A security vulnerability has been identified in HPE Data Management Framework (DMF) Suite (CXFS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.

Nov 15, 2024
CVE-2024-50983
5.4 MEDIUM

FlightPath 7.5 contains a Cross Site Scripting (XSS) vulnerability, which allows authenticated remote attackers with administrative rights to inject arbitrary JavaScript in the web browser …

Nov 15, 2024
CVE-2024-38370
5.3 MEDIUM

GLPI is a free asset and IT management software package. Starting in 9.2.0 and prior to 11.0.0, it is possible to download a document from …

Nov 15, 2024
CVE-2024-11261
5.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Student Record Management System 1.0. Affected is an unknown function of the file StudentRecordManagementSystem.cpp …

Nov 15, 2024
CVE-2017-13314
7.8 HIGH

In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This could lead to local escalation of privilege …

Nov 15, 2024
CVE-2017-13313
6.5 MEDIUM

In ElementaryStreamQueue::dequeueAccessUnitMPEG4Video of ESQueue.cpp, there is a possible infinite loop leading to resource exhaustion due to an incorrect bounds check. This could lead to remote …

Nov 15, 2024
CVE-2017-13312
7.8 HIGH

In createFromParcel of MediaCas.java, there is a possible parcel read/write mismatch due to improper input validation. This could lead to local escalation of privilege where …

Nov 15, 2024
CVE-2017-13311
6.7 MEDIUM

In the read() function of ProcessStats.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local escalation of …

Nov 15, 2024
CVE-2017-13310
7.8 HIGH

In createFromParcel of ViewPager.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local escalation of privilege where …

Nov 15, 2024
CVE-2024-49592
6.7 MEDIUM

Trial installer for McAfee Total Protection (legacy trial installer software) 16.0.53 allows local privilege escalation because of an Uncontrolled Search Path Element. The attacker could …

Nov 15, 2024
CVE-2024-49060
8.8 HIGH

Azure Stack HCI Elevation of Privilege Vulnerability

Nov 15, 2024
CVE-2024-45611
5.7 MEDIUM

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can …

Nov 15, 2024
CVE-2024-45610
6.5 MEDIUM

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An unauthenticated user can …

Nov 15, 2024
CVE-2024-44758
9.8 CRITICAL

An arbitrary file upload vulnerability in the component /Production/UploadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to execute arbitrary code via uploading crafted files.

Nov 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.