CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-45715
7.1 HIGH

The SolarWinds Platform was susceptible to a Cross-Site Scripting vulnerability when performing an edit function to existing elements.

Oct 16, 2024
CVE-2024-45714
4.8 MEDIUM

Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a variable with a payload.

Oct 16, 2024
CVE-2024-45711
7.5 HIGH

SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible depending on privileges given to the authenticated user. This issue …

Oct 16, 2024
CVE-2024-45710
7.8 HIGH

SolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This requires a low privilege account and local access to the …

Oct 16, 2024
CVE-2024-45693
8.0 HIGH

Users logged into the Apache CloudStack's web interface can be tricked to submit malicious CSRF requests due to missing validation of the origin of the …

Oct 16, 2024
CVE-2024-45462
6.3 MEDIUM

The logout operation in the CloudStack web interface does not expire the user session completely which is valid until expiry by time or restart of …

Oct 16, 2024
CVE-2024-45461
5.7 MEDIUM

The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources, and is disabled by default. In environments …

Oct 16, 2024
CVE-2024-45219
8.5 HIGH

Account users in Apache CloudStack by default are allowed to upload and register templates for deploying instances and volumes for attaching them as data disks …

Oct 16, 2024
CVE-2024-45217
8.1 HIGH

Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore command, which copy a configSet from the backup …

Oct 16, 2024
CVE-2024-45216
9.8 CRITICAL

Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authentication is used, are vulnerable to Authentication …

Oct 16, 2024
CVE-2023-7296
6.4 MEDIUM

The BigBlueButton plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the moderator code and viewer code fields in versions up to, and …

Oct 16, 2024
CVE-2023-7295
6.1 MEDIUM

The Video Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.21 due to …

Oct 16, 2024
CVE-2023-22649
8.4 HIGH

A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. [Rancher Audit Logging](https://ranchermanager.docs.rancher.com/how-to-guides/advanced-user-guides/enable-api-audit-log) is an opt-in feature, only …

Oct 16, 2024
CVE-2021-4452
7.1 HIGH

The Google Language Translator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions up to, and including, 6.0.9 due to …

Oct 16, 2024
CVE-2020-36842
8.8 HIGH

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvivid_upload_import_files and …

Oct 16, 2024
CVE-2020-36840
7.3 HIGH

The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_route_url() function …

Oct 16, 2024
CVE-2017-20194
5.3 MEDIUM

The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. …

Oct 16, 2024
CVE-2017-20193
4.7 MEDIUM

The Product Vendors is vulnerable to Reflected Cross-Site Scripting via the 'vendor_description' parameter in versions up to, and including, 2.0.35 due to insufficient input sanitization …

Oct 16, 2024
CVE-2016-15042
9.8 CRITICAL

The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to …

Oct 16, 2024
CVE-2024-9582
6.4 MEDIUM

The Accordion Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ attribute of an accordion slider in all versions up to, …

Oct 16, 2024
CVE-2024-8918
7.4 HIGH

The File Manager Pro plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 8.3.9. This is due …

Oct 16, 2024
CVE-2024-8746
7.5 HIGH

The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing file type validation via the 'mk_file_folder_manager_shortcode' …

Oct 16, 2024
CVE-2024-8507
8.8 HIGH

The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.3.9. This is due to …

Oct 16, 2024
CVE-2023-7294
7.1 HIGH

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the create_mollie_profile …

Oct 16, 2024
CVE-2023-7293
4.3 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the …

Oct 16, 2024
CVE-2023-7292
4.3 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized notification dismissal due to a missing capability check on the paytium_notice_dismiss …

Oct 16, 2024
CVE-2023-7291
7.1 HIGH

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Oct 16, 2024
CVE-2023-7290
4.3 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the …

Oct 16, 2024
CVE-2023-7289
5.4 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized API key update due to a missing capability check on the …

Oct 16, 2024
CVE-2023-7288
5.4 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_profile_preference …

Oct 16, 2024
CVE-2023-7287
5.4 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized subscription cancellation due to a missing capability check on the pt_cancel_subscription …

Oct 16, 2024
CVE-2023-7286
6.5 MEDIUM

The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.2.2. This makes it …

Oct 16, 2024
CVE-2022-4974
6.3 MEDIUM

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing …

Oct 16, 2024
CVE-2022-4973
4.9 MEDIUM

WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploited by users with access to the WordPress …

Oct 16, 2024
CVE-2022-4972
7.5 HIGH

The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in …

Oct 16, 2024
CVE-2022-4971
6.1 MEDIUM

The Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'urls' parameter called via the 'heateor_sss_sharing_count' AJAX action in versions …

Oct 16, 2024
CVE-2021-4451
6.6 MEDIUM

The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and including, 4.3.3. This allows authenticated attackers to perform phar …

Oct 16, 2024
CVE-2021-4450
8.8 HIGH

The Post Grid plugin for WordPress is vulnerable to blind SQL Injection via post metadata in versions up to, and including, 2.1.12 due to insufficient …

Oct 16, 2024
CVE-2021-4449
9.8 CRITICAL

The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'savepng.php' file in versions up to, …

Oct 16, 2024
CVE-2021-4448
7.3 HIGH

The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.0.1 due to insufficient capability checking …

Oct 16, 2024
CVE-2021-4447
8.8 HIGH

The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of …

Oct 16, 2024
CVE-2021-4446
6.3 MEDIUM

The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and including 4.6.4 due to missing capability checks …

Oct 16, 2024
CVE-2021-4445
6.5 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to Arbitrary Option Updates in versions up to, and including, 4.5.1. This is due to …

Oct 16, 2024
CVE-2021-4444
7.3 HIGH

The Product Filter by WooBeWoo plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.4.9 due to missing authorization checks …

Oct 16, 2024
CVE-2021-4443
9.8 CRITICAL

The WordPress Mega Menu plugin for WordPress is vulnerable to Arbitrary File Creation in versions up to, and including, 2.0.6 via the compiler_save AJAX action. …

Oct 16, 2024
CVE-2020-36839
8.3 HIGH

The WP Lead Plus X plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.99. This is due to …

Oct 16, 2024
CVE-2020-36838
7.4 HIGH

The Facebook Chat Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_update_options function in versions up to, …

Oct 16, 2024
CVE-2020-36837
9.9 CRITICAL

The ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability check on the reset_wizard_actions function in versions 1.3.4 …

Oct 16, 2024
CVE-2020-36836
8.0 HIGH

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and including, 0.9.0.2 due to a lack …

Oct 16, 2024
CVE-2020-36835
4.9 MEDIUM

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks …

Oct 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.