CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9119
6.4 MEDIUM

The SVG Complete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.2 due …

Oct 1, 2024
CVE-2024-9108
9.8 CRITICAL

The Wechat Social login plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'convert_remoteimage_to_local' function in versions …

Oct 1, 2024
CVE-2024-9106
9.8 CRITICAL

The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.3.0. This is due to insufficient verification …

Oct 1, 2024
CVE-2024-8990
6.4 MEDIUM

The Geo Mashup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's geo_mashup_visible_posts_list shortcode in all versions up to, and including, 1.13.13 …

Oct 1, 2024
CVE-2024-8989
6.4 MEDIUM

The Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's …

Oct 1, 2024
CVE-2024-8728
6.1 MEDIUM

The Easy Load More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Oct 1, 2024
CVE-2024-8727
6.1 MEDIUM

The DK PDF plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in …

Oct 1, 2024
CVE-2024-8720
6.4 MEDIUM

The RumbleTalk Live Group Chat – HTML5 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rumbletalk-admin-button' shortcode in all versions up …

Oct 1, 2024
CVE-2024-8718
6.1 MEDIUM

The Gravity Forms Toolbar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 1.7.0 …

Oct 1, 2024
CVE-2024-8675
4.3 MEDIUM

The Soumettre.fr plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the soumettre_disconnect_gateway function in all versions …

Oct 1, 2024
CVE-2024-8632
6.5 MEDIUM

The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized access and modification of data due to a …

Oct 1, 2024
CVE-2024-8548
8.1 HIGH

The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a …

Oct 1, 2024
CVE-2024-7869
7.2 HIGH

The 123.chat - Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.1 due to insufficient …

Oct 1, 2024
CVE-2024-7434
8.8 HIGH

The UltraPress theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.2 via deserialization of untrusted input. This …

Oct 1, 2024
CVE-2024-7433
8.8 HIGH

The Empowerment theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.2 via deserialization of untrusted input. This …

Oct 1, 2024
CVE-2024-7432
8.8 HIGH

The Unseen Blog theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 via deserialization of untrusted input. …

Oct 1, 2024
CVE-2024-8107
6.4 MEDIUM

The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7.18 due …

Oct 1, 2024
CVE-2024-8421

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.

Oct 1, 2024
CVE-2024-21531
5.3 MEDIUM

All versions of the package git-shallow-clone are vulnerable to Command injection due to missing sanitization or mitigation flags in the process variable of the gitShallowClone …

Oct 1, 2024
CVE-2024-21489
8.2 HIGH

Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to missing check if the attribute resolves to …

Oct 1, 2024
CVE-2024-0116
4.9 MEDIUM

NVIDIA Triton Inference Server contains a vulnerability where a user may cause an out-of-bounds read issue by releasing a shared memory region while it is …

Oct 1, 2024
CVE-2024-47295
8.1 HIGH

Insecure initial password configuration issue in SEIKO EPSON Web Config allows a remote unauthenticated attacker to set an arbitrary password and operate the device with …

Oct 1, 2024
CVE-2024-9360
7.3 HIGH

A vulnerability was found in code-projects Restaurant Reservation System 1.0. It has been classified as critical. This affects an unknown part of the file /updatebal.php. …

Oct 1, 2024
CVE-2024-8981
7.1 HIGH

The Broken Link Checker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg in /app/admin-notices/features/class-view.php without appropriate escaping on …

Oct 1, 2024
CVE-2024-9359
7.3 HIGH

A vulnerability was found in code-projects Restaurant Reservation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Oct 1, 2024
CVE-2024-9358
5.3 MEDIUM

A vulnerability has been found in ThingsBoard up to 3.7.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component …

Oct 1, 2024
CVE-2024-47560
7.8 HIGH

RevoWorks Cloud Client 3.0.91 and earlier contains an incorrect authorization vulnerability. If this vulnerability is exploited, unintended processes may be executed in the sandbox environment. …

Oct 1, 2024
CVE-2024-47396
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moveaddons Move Addons for Elementor move-addons allows Stored XSS.This issue affects Move Addons …

Oct 1, 2024
CVE-2024-9194
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Linux and Microsoft Windows Octopus Server on Windows, Linux allows SQL …

Sep 30, 2024
CVE-2024-45073
4.8 MEDIUM

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in …

Sep 30, 2024
CVE-2024-7675
7.8 HIGH

A maliciously crafted DWF file, when parsed in w3dtk.dll through Autodesk Navisworks, can force a Use-After-Free. A malicious actor can leverage this vulnerability to cause …

Sep 30, 2024
CVE-2024-7674
7.8 HIGH

A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, can force a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability …

Sep 30, 2024
CVE-2024-7673
7.8 HIGH

A maliciously crafted DWFX file, when parsed in w3dtk.dll through Autodesk Navisworks, can force a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability …

Sep 30, 2024
CVE-2024-7672
7.8 HIGH

A maliciously crafted DWF file, when parsed in dwfcore.dll through Autodesk Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this …

Sep 30, 2024
CVE-2024-7671
7.8 HIGH

A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability …

Sep 30, 2024
CVE-2024-7670
7.8 HIGH

A maliciously crafted DWFX file, when parsed in w3dtk.dll through Autodesk Navisworks, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to …

Sep 30, 2024
CVE-2024-46503

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Sep 30, 2024
CVE-2024-28808
2.7 LOW

An issue was discovered in Infinera hiT 7300 5.60.50. Hidden functionality in the web interface allows a remote authenticated attacker to access reserved information by …

Sep 30, 2024
CVE-2024-28807
6.5 MEDIUM

An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @CT desktop management application allows guest …

Sep 30, 2024
CVE-2024-28813
8.4 HIGH

An issue was discovered in Infinera hiT 7300 5.60.50. Undocumented privileged functions in the @CT management application allow an attacker to activate remote SSH access …

Sep 30, 2024
CVE-2024-28812
8.8 HIGH

An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) with hardcoded credentials allows attackers to …

Sep 30, 2024
CVE-2024-28811
3.3 LOW

An issue was discovered in Infinera hiT 7300 5.60.50. A web application allows a remote privileged attacker to execute applications contained in a specific OS …

Sep 30, 2024
CVE-2024-28810
6.6 MEDIUM

An issue was discovered in Infinera hiT 7300 5.60.50. Sensitive information inside diagnostic files (exported by the @CT application) allows an attacker to achieve loss …

Sep 30, 2024
CVE-2024-46635
5.9 MEDIUM

An issue in the API endpoint /AccountMaster/GetCurrentUserInfo of INROAD before v202402060 allows attackers to access sensitive information via a crafted payload to the UserNameOrPhoneNumber parameter.

Sep 30, 2024
CVE-2024-46511
7.5 HIGH

LoadZilla LLC LoadLogic v1.4.3 was discovered to contain insecure permissions vulnerability which allows a remote attacker to execute arbitrary code via the LogicLoadEc2DeployLambda and CredsGenFunction …

Sep 30, 2024
CVE-2024-42017
10.0 CRITICAL

An issue was discovered in Atos Eviden iCare 2.7.1 through 2.7.11. The application exposes a web interface locally. In the worst-case scenario, if the application …

Sep 30, 2024
CVE-2024-35495
4.3 MEDIUM

An Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Build 220930 Rel.143947 allows attackers to observe device …

Sep 30, 2024
CVE-2024-28809
8.8 HIGH

An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access various appliance services …

Sep 30, 2024
CVE-2024-9158
8.4 HIGH

A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI …

Sep 30, 2024
CVE-2024-47536
5.4 MEDIUM

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. A user with the editmyprivateinfo right or who can otherwise change their …

Sep 30, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.