CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8713
6.1 MEDIUM

The Kodex Posts likes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Sep 25, 2024
CVE-2024-8621
9.9 CRITICAL

The Daily Prayer Time plugin for WordPress is vulnerable to SQL Injection via the 'max_word' attribute of the 'quran_verse' shortcode in all versions up to, …

Sep 25, 2024
CVE-2024-8549
6.1 MEDIUM

The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping …

Sep 25, 2024
CVE-2024-8485
9.8 CRITICAL

The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versions up to, and including, 4.7.1 via …

Sep 25, 2024
CVE-2024-8484
7.5 HIGH

The REST API TO MiniProgram plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/watch-life-net/v1/comment/getcomments REST API endpoint in all …

Sep 25, 2024
CVE-2024-8483
4.3 MEDIUM

The MAS Static Content plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.8 via the static_content() function. This …

Sep 25, 2024
CVE-2024-8481
7.3 HIGH

The The Special Text Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 6.2.4. This is due …

Sep 25, 2024
CVE-2024-8476
4.3 MEDIUM

The Easy PayPal Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to …

Sep 25, 2024
CVE-2024-8434
4.3 MEDIUM

The Easy Mega Menu Plugin for WordPress – ThemeHunk plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several …

Sep 25, 2024
CVE-2024-8350
2.7 LOW

The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check on the /wp-json/ulgm_management/v1/add_user/ REST API …

Sep 25, 2024
CVE-2024-8349
7.2 HIGH

The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0.1. This is due to …

Sep 25, 2024
CVE-2024-7617
7.2 HIGH

The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 form fields in all versions up …

Sep 25, 2024
CVE-2024-7491
5.3 MEDIUM

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Sep 25, 2024
CVE-2024-7426
5.3 MEDIUM

The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, …

Sep 25, 2024
CVE-2024-7386
4.3 MEDIUM

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.1. …

Sep 25, 2024
CVE-2024-6590
6.3 MEDIUM

The Spreadsheet Integration – Automate Google Sheets With WordPress, WooCommerce & Most Popular Form Plugins. Also, Display Google sheet as a Table. plugin for WordPress …

Sep 25, 2024
CVE-2024-9148
9.6 CRITICAL

Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0.

Sep 25, 2024
CVE-2024-9142
9.8 CRITICAL

External Control of File Name or Path, : Incorrect Permission Assignment for Critical Resource vulnerability in Olgu Computer Systems e-Belediye allows Manipulating Web Input to …

Sep 25, 2024
CVE-2024-9141
5.4 MEDIUM

Cross-Site Scripting (XSS) vulnerability in the Oct8ne system. This flaw could allow an attacker to embed harmful JavaScript code into the body of a chat …

Sep 25, 2024
CVE-2024-9123
8.8 HIGH

Integer overflow in Skia in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform an out of bounds memory write via a crafted …

Sep 25, 2024
CVE-2024-9122
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform out of bounds memory access via a crafted HTML …

Sep 25, 2024
CVE-2024-9121
8.8 HIGH

Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to potentially perform out of bounds memory access via a crafted …

Sep 25, 2024
CVE-2024-9120
8.8 HIGH

Use after free in Dawn in Google Chrome on Windows prior to 129.0.6668.70 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Sep 25, 2024
CVE-2024-8942
6.3 MEDIUM

Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input validation, affecting the “id_form_msg_title” parameter, among others. …

Sep 25, 2024
CVE-2024-8941
7.5 HIGH

Path traversal vulnerability in Scriptcase version 9.4.019, in /scriptcase/devel/compat/nm_edit_php_edit.php (in the “subpage” parameter), which allows unauthenticated remote users to bypass SecurityManager's intended restrictions and list …

Sep 25, 2024
CVE-2024-8940
10.0 CRITICAL

Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ via a POST request. An attacker could upload …

Sep 25, 2024
CVE-2024-8919
6.4 MEDIUM

The Confetti Fall Animation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'confetti-fall-animation' shortcode in all versions up to, and including, …

Sep 25, 2024
CVE-2024-8917
6.4 MEDIUM

The AnWP Football Leagues plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.16.7 …

Sep 25, 2024
CVE-2024-8914
7.2 HIGH

The Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam plugin for WordPress is vulnerable to …

Sep 25, 2024
CVE-2024-8878
9.8 CRITICAL

The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin password and take over control of …

Sep 25, 2024
CVE-2024-8877
9.8 CRITICAL

Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database of measurement …

Sep 25, 2024
CVE-2024-8801
4.3 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.2 via the Content …

Sep 25, 2024
CVE-2024-8497
7.5 HIGH

Franklin Fueling Systems TS-550 EVO versions prior to 2.26.4.8967 possess a file that can be read arbitrarily that could allow an attacker obtain administrator credentials.

Sep 25, 2024
CVE-2024-8437
4.3 MEDIUM

The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions …

Sep 25, 2024
CVE-2024-8436
9.9 CRITICAL

The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_imageId' and 'edit_imageDelete' parameters in all versions …

Sep 25, 2024
CVE-2024-8291
4.8 MEDIUM

Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in Image Editor Background Color. A rogue admin could add malicious …

Sep 25, 2024
CVE-2024-8267
6.4 MEDIUM

The Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Sep 25, 2024
CVE-2024-8103
6.4 MEDIUM

The WP Category Dropdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' parameter in all versions up to, and including, 1.8 …

Sep 25, 2024
CVE-2024-8067

In versions of Helix Core prior to 2024.1 Patch 2 (2024.1/2655224) a Windows ANSI API Unicode "best fit" argument injection was identified.

Sep 25, 2024
CVE-2024-7398
5.4 MEDIUM

Concrete CMS versions 9 through 9.3.3 and versions below 8.5.19 are vulnerable to stored XSS in the calendar event addition feature because the calendar event …

Sep 25, 2024
CVE-2024-47048
5.4 MEDIUM

Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier allows stored XSS in the description and release notes of the marketplace and private apps.

Sep 25, 2024
CVE-2024-46957
9.8 CRITICAL

Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because the stanza type is not checked. This is fixed in …

Sep 25, 2024
CVE-2024-46936
7.5 HIGH

Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and before is vulnerable to a message forgery / impersonation issue. Attackers can abuse the UpdateOTRAck method to …

Sep 25, 2024
CVE-2024-46935
7.5 HIGH

Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers who craft messages with specific characters may crash …

Sep 25, 2024
CVE-2024-46934
6.1 MEDIUM

Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to DOM-based Cross-site Scripting (XSS). Attackers may be able to abuse the UpdateOTRAck method …

Sep 25, 2024
CVE-2024-46612
9.8 CRITICAL

IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication information.

Sep 25, 2024
CVE-2024-46610
7.5 HIGH

An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request …

Sep 25, 2024
CVE-2024-46609
7.5 HIGH

An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and returns all user information, …

Sep 25, 2024
CVE-2024-46607
7.6 HIGH

Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin …

Sep 25, 2024
CVE-2024-45599
3.8 LOW

Cursor is an artificial intelligence code editor. Prior to version 0.41.0, if a user on macOS has granted Cursor access to the camera or microphone, …

Sep 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.