CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0383
6.4 MEDIUM

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [wprm-recipe-instructions] and [wprm-recipe-ingredients] shortcodes in all versions up to, …

Jun 19, 2024
CVE-2023-6495
4.4 MEDIUM

The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to …

Jun 19, 2024
CVE-2024-0789
5.3 MEDIUM

The WP Maintenance plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 6.1.9.2 due to insufficient IP address …

Jun 19, 2024
CVE-2024-3894
6.4 MEDIUM

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an Image Title in all versions …

Jun 19, 2024
CVE-2024-37881
5.3 MEDIUM

SiteGuard WP Plugin provides a functionality to customize the path to the login page wp-login.php and implements a measure to avoid redirection from other URLs. …

Jun 19, 2024
CVE-2024-37387
4.0 MEDIUM

Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, files in the PC where the product …

Jun 19, 2024
CVE-2024-37124
9.8 CRITICAL

Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, an attacker may create an arbitrary file …

Jun 19, 2024
CVE-2024-36978
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: sched: sch_multiq: fix possible OOB write in multiq_tune() q->bands will be assigned to qopt->bands …

Jun 19, 2024
CVE-2024-36480
9.8 CRITICAL

Use of hard-coded credentials issue exists in Ricoh Streamline NX PC Client ver.3.7.2 and earlier. If this vulnerability is exploited, an attacker may obtain LocalSystem …

Jun 19, 2024
CVE-2024-36252
6.3 MEDIUM

Improper restriction of communication channel to intended endpoints issue exists in Ricoh Streamline NX PC Client ver.3.6.x and earlier. If this vulnerability is exploited, arbitrary …

Jun 19, 2024
CVE-2024-1407
5.4 MEDIUM

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up …

Jun 19, 2024
CVE-2024-6132
8.8 HIGH

The Pexels: Free Stock Photos plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'pexels_fsp_images_options_validate' function in …

Jun 19, 2024
CVE-2024-5853
9.9 CRITICAL

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the …

Jun 19, 2024
CVE-2024-5574
7.5 HIGH

The WP Magazine Modules Lite plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.2 via the 'blockLayout' …

Jun 19, 2024
CVE-2024-5343
8.8 HIGH

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Jun 19, 2024
CVE-2024-5208
6.5 MEDIUM

An uncontrolled resource consumption vulnerability exists in the `upload-link` endpoint of mintplex-labs/anything-llm. This vulnerability allows attackers to cause a denial of service (DOS) by shutting …

Jun 19, 2024
CVE-2023-6692
6.4 MEDIUM

The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's tab anchor metabox in all versions …

Jun 19, 2024
CVE-2024-3229
9.8 CRITICAL

The Salon booking system plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SLN_Action_Ajax_ImportAssistants function along with …

Jun 19, 2024
CVE-2024-35298
4.3 MEDIUM

Improper authorization in handler for custom URL scheme issue in 'ZOZOTOWN' App for Android versions prior to 7.39.6 allows an attacker to lead a user …

Jun 19, 2024
CVE-2024-5768
6.4 MEDIUM

The MIMO Woocommerce Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'mimo_update_provider' function …

Jun 19, 2024
CVE-2024-5724
8.8 HIGH

The Photo Video Gallery Master plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5.3 via deserialization of …

Jun 19, 2024
CVE-2024-5649
5.4 MEDIUM

The Universal Slider plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.5 via deserialization of untrusted input …

Jun 19, 2024
CVE-2024-5021
9.3 CRITICAL

The WordPress Picture / Portfolio / Media Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.0.1 …

Jun 19, 2024
CVE-2024-4873
4.3 MEDIUM

The Replace Image plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.10 via the image replacement …

Jun 19, 2024
CVE-2024-4787
5.8 MEDIUM

The Cost Calculator Builder PRO for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 3.1.75. This is due to …

Jun 19, 2024
CVE-2024-4663
6.4 MEDIUM

The OSM Map Widget for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in all versions up to, and …

Jun 19, 2024
CVE-2024-4623
6.4 MEDIUM

The Blogmentor – Blog Layouts for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pagination_style’ parameter in all versions up to, …

Jun 19, 2024
CVE-2024-4541
4.3 MEDIUM

The Custom Product List Table plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due …

Jun 19, 2024
CVE-2024-4450
6.3 MEDIUM

The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the …

Jun 19, 2024
CVE-2024-3984
6.4 MEDIUM

The EmbedSocial – Social Media Feeds, Reviews and Galleries plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'embedsocial_reviews' shortcode in all …

Jun 19, 2024
CVE-2024-2381
8.8 HIGH

The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_save_image function …

Jun 19, 2024
CVE-2024-6125
8.1 HIGH

The Login with phone number plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 1.7.34. This is due to …

Jun 19, 2024
CVE-2024-6146
8.8 HIGH

Actiontec WCB6200Q uh_get_postdata_withupload Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Actiontec WCB6200Q …

Jun 19, 2024
CVE-2024-6145
8.8 HIGH

Actiontec WCB6200Q Cookie Format String Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Actiontec WCB6200Q routers. …

Jun 19, 2024
CVE-2024-6144
8.8 HIGH

Actiontec WCB6200Q Multipart Boundary Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Actiontec …

Jun 19, 2024
CVE-2024-6143
8.8 HIGH

Actiontec WCB6200Q uh_tcp_recv_header Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Actiontec WCB6200Q routers. …

Jun 19, 2024
CVE-2024-6142
8.8 HIGH

Actiontec WCB6200Q uh_tcp_recv_content Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Actiontec WCB6200Q routers. …

Jun 19, 2024
CVE-2024-5970
6.4 MEDIUM

The MaxGalleria plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's maxgallery_thumb shortcode in all versions up to, and including, 6.4.4 due …

Jun 18, 2024
CVE-2024-6129
3.7 LOW

A vulnerability, which was classified as problematic, was found in spa-cartcms 1.9.0.6. Affected is an unknown function of the file /login of the component Username …

Jun 18, 2024
CVE-2024-6128
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in spa-cartcms 1.9.0.6. This issue affects some unknown processing of the file /checkout of the …

Jun 18, 2024
CVE-2024-38277
5.4 MEDIUM

A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between …

Jun 18, 2024
CVE-2024-38276
8.8 HIGH

Incorrect CSRF token checks resulted in multiple CSRF risks.

Jun 18, 2024
CVE-2024-38275
7.5 HIGH

The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to …

Jun 18, 2024
CVE-2024-38274
6.1 MEDIUM

Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt.

Jun 18, 2024
CVE-2024-38273
5.4 MEDIUM

Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.

Jun 18, 2024
CVE-2024-37821
8.8 HIGH

An arbitrary file upload vulnerability in the Upload Template function of Dolibarr ERP CRM up to v19.0.1 allows attackers to execute arbitrary code via uploading …

Jun 18, 2024
CVE-2024-36977
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: Wait unconditionally after issuing EndXfer command Currently all controller IP/revisions except DWC3_usb3 >= …

Jun 18, 2024
CVE-2024-36976
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Revert "media: v4l2-ctrls: show all owned controls in log_status" This reverts commit 9801b5b28c6929139d6fceeee8d739cc67bb2739. This patch …

Jun 18, 2024
CVE-2024-36975
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Do not use WARN when encode fails When asn1_encode_sequence() fails, WARN is not …

Jun 18, 2024
CVE-2024-36974
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/sched: taprio: always validate TCA_TAPRIO_ATTR_PRIOMAP If one TCA_TAPRIO_ATTR_PRIOMAP attribute has been provided, taprio_parse_mqprio_opt() must validate …

Jun 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.