CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5992
6.5 MEDIUM

The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_chatbot_token' and 'update_chatbot_position' …

Jul 9, 2024
CVE-2024-5937
6.4 MEDIUM

The Simple Alert Boxes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Alert shortcode in all versions up to, and including, …

Jul 9, 2024
CVE-2024-5856
4.3 MEDIUM

The Comment Images Reloaded plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the cir_delete_image AJAX action …

Jul 9, 2024
CVE-2024-5810
5.3 MEDIUM

The WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.1. …

Jul 9, 2024
CVE-2024-5704
4.3 MEDIUM

The XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Jul 9, 2024
CVE-2024-5669
6.4 MEDIUM

The XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Jul 9, 2024
CVE-2024-5648
5.4 MEDIUM

The LearnDash LMS – Reports plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions (i.e. …

Jul 9, 2024
CVE-2024-5600
5.4 MEDIUM

The SCSS Happy Compiler – Compile SCSS to CSS & Automatic Enqueue plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing …

Jul 9, 2024
CVE-2024-5479
7.2 HIGH

The Easy Pixels plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all versions up to, and including, 2.13 due to …

Jul 9, 2024
CVE-2024-5457
6.4 MEDIUM

The Panda Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.4.0 due …

Jul 9, 2024
CVE-2024-5456
8.8 HIGH

The Panda Video plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.0 via the 'selected_button' parameter. This …

Jul 9, 2024
CVE-2024-4868
6.4 MEDIUM

The Extensions for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's EE Events and EE Flipbox widgets in all versions …

Jul 9, 2024
CVE-2024-4102
5.4 MEDIUM

The Pricing Table plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all …

Jul 9, 2024
CVE-2024-4100
5.3 MEDIUM

The Pricing Table plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.1. This is due to missing …

Jul 9, 2024
CVE-2024-3608
5.3 MEDIUM

The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the product_designer_ajax_delete_attach_id() function in all …

Jul 9, 2024
CVE-2024-3604
9.9 CRITICAL

The OSM – OpenStreetMap plugin for WordPress is vulnerable to SQL Injection via the 'tagged_filter' attribute of the 'osm_map_v3' shortcode in all versions up to, …

Jul 9, 2024
CVE-2024-3603
6.4 MEDIUM

The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'osm_map' shortcode in all versions up to, and including, …

Jul 9, 2024
CVE-2024-3563
6.4 MEDIUM

The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sharing block in all versions up to, and including, 3.1.3 …

Jul 9, 2024
CVE-2024-3228
5.3 MEDIUM

The Social Sharing Plugin – Kiwi plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.1.7 via the 'kiwi-nw-pinterest' …

Jul 9, 2024
CVE-2024-37502
5.4 MEDIUM

Deserialization of Untrusted Data vulnerability in wpweb WooCommerce Social Login woo-social-login.This issue affects WooCommerce Social Login: from n/a through <= 2.6.3.

Jul 9, 2024
CVE-2024-37494
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in KaineLabs Youzify.This issue affects Youzify: from n/a through 1.2.5.

Jul 9, 2024
CVE-2024-37486
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through …

Jul 9, 2024
CVE-2024-37256
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.1.

Jul 9, 2024
CVE-2024-37225
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho Marketing Automation.This issue affects Zoho Marketing Automation: from n/a through …

Jul 9, 2024
CVE-2024-37112
10.0 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from …

Jul 9, 2024
CVE-2024-6321
8.8 HIGH

The ScrollTo Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 1.1.1. This is …

Jul 9, 2024
CVE-2024-6320
8.8 HIGH

The ScrollTo Top plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 1.2.2. This is …

Jul 9, 2024
CVE-2024-6317
8.8 HIGH

The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and …

Jul 9, 2024
CVE-2024-6316
8.8 HIGH

The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and …

Jul 9, 2024
CVE-2024-6314
9.8 CRITICAL

The IQ Testimonials plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'process_image_upload' function in versions up …

Jul 9, 2024
CVE-2024-6313
9.8 CRITICAL

The Gutenberg Forms plugin for WordPress is vulnerable to arbitrary file uploads due to the users can specify the allowed file types in the 'upload' …

Jul 9, 2024
CVE-2024-6310
8.8 HIGH

The Advanced AJAX Page Loader plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 2.7.7. …

Jul 9, 2024
CVE-2024-6309
8.8 HIGH

The Attachment File Icons (AF Icons) plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, …

Jul 9, 2024
CVE-2024-6180
7.2 HIGH

The EventON plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'eventon_import_settings' ajax action in all …

Jul 9, 2024
CVE-2024-6161
8.8 HIGH

The Default Thumbnail Plus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'get_cache_image' function in all …

Jul 9, 2024
CVE-2024-6123
7.2 HIGH

The Bit Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'iconUpload' function in all versions …

Jul 9, 2024
CVE-2024-5881
6.4 MEDIUM

The Webico Slider Flatsome Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wbc_image shortcode in all versions up to, and …

Jul 9, 2024
CVE-2024-37923
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in cliengo Cliengo – Chatbot cliengo allows Cross Site Request Forgery.This issue affects Cliengo – Chatbot: from n/a through <= …

Jul 9, 2024
CVE-2024-37555
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in ZealousWeb Generate PDF using Contact Form 7 generate-pdf-using-contact-form-7.This issue affects Generate PDF using Contact Form 7: …

Jul 9, 2024
CVE-2024-28751
9.1 CRITICAL

An high privileged remote attacker can enable telnet access that accepts hardcoded credentials.

Jul 9, 2024
CVE-2024-28750
7.2 HIGH

A remote attacker with high privileges may use a deleting file function to inject OS commands.

Jul 9, 2024
CVE-2024-28749
7.2 HIGH

A remote attacker with high privileges may use a writing file function to inject OS commands.

Jul 9, 2024
CVE-2024-28748
7.2 HIGH

A remote attacker with high privileges may use a reading file function to inject OS commands.

Jul 9, 2024
CVE-2024-28747
9.8 CRITICAL

An unauthenticated remote attacker can use the hard-coded credentials to access the SmartSPS devices with high privileges.

Jul 9, 2024
CVE-2024-22062
6.3 MEDIUM

There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permissions to administrator permissions by modifying the configuration.

Jul 9, 2024
CVE-2024-6334
6.1 MEDIUM

The Easy Table of Contents WordPress plugin before 2.0.67.1 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jul 9, 2024
CVE-2024-5802
4.8 MEDIUM

The URL Shortener by Myhop WordPress plugin through 1.0.17 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jul 9, 2024
CVE-2024-5488
9.8 CRITICAL

The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow …

Jul 9, 2024
CVE-2024-5441
8.8 HIGH

The Modern Events Calendar plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_featured_image function in all …

Jul 9, 2024
CVE-2024-3410
4.3 MEDIUM

The DN Footer Contacts WordPress plugin before 1.6.3 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jul 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.