CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4700
6.4 MEDIUM

The WP Table Builder – WordPress Table Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button element in all versions up …

May 21, 2024
CVE-2024-4695
6.4 MEDIUM

The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.3.1 …

May 21, 2024
CVE-2024-4553
6.4 MEDIUM

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_members' shortcode in all versions up …

May 21, 2024
CVE-2024-4435
5.9 MEDIUM

When storing unbounded types in a BTreeMap, a node is represented as a linked list of "memory chunks". It was discovered recently that when we …

May 21, 2024
CVE-2023-3939
10.0 CRITICAL

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in ZkTeco-based OEM devices allows OS Command Injection. Since all the …

May 21, 2024
CVE-2023-3938
4.6 MEDIUM

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ZkTeco-based OEM devices allows an attacker to authenticate under any user …

May 21, 2024
CVE-2024-4875
4.3 MEDIUM

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability …

May 21, 2024
CVE-2024-4566
7.1 HIGH

The ShopLentor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_dismiss function in all versions …

May 21, 2024
CVE-2024-3345
6.4 MEDIUM

The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woolentorsearch shortcode in all versions up to, and including, 2.8.8 due …

May 21, 2024
CVE-2024-4710
6.4 MEDIUM

The UberMenu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ubermenu-col, ubermenu_mobile_close_button, ubermenu_toggle, ubermenu-search shortcodes in all versions up to, and …

May 21, 2024
CVE-2024-4470
6.4 MEDIUM

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_slide_info' shortcode in all versions up …

May 21, 2024
CVE-2024-4442
9.1 CRITICAL

The Salon booking system plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 9.8. This is due to …

May 21, 2024
CVE-2024-4372
5.4 MEDIUM

The Carousel Slider WordPress plugin before 2.2.11 does not sanitise and escape some parameters, which could allow users with a role as low as editor …

May 21, 2024
CVE-2024-4290
7.1 HIGH

The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 21, 2024
CVE-2024-4289
6.1 MEDIUM

The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape various parameters before outputting them back in pages and attributes, leading to a …

May 21, 2024
CVE-2024-4061
4.8 MEDIUM

The Survey Maker WordPress plugin before 4.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 21, 2024
CVE-2024-2189
6.1 MEDIUM

The Social Icons Widget & Block by WPZOOM WordPress plugin before 4.2.18 does not sanitise and escape some of its Widget settings, which could allow …

May 21, 2024
CVE-2024-4943
6.4 MEDIUM

The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘has_field_link_rel’ parameter in all versions up to, and including, 2.0.46 due to …

May 21, 2024
CVE-2024-3155
6.4 MEDIUM

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

May 21, 2024
CVE-2024-0816
5.5 MEDIUM

The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denial of service (DoS) conditions by executing …

May 21, 2024
CVE-2023-37929
6.5 MEDIUM

The buffer overflow vulnerability in the CGI program of the VMG3625-T50B firmware version V5.50(ABPM.8)C0 could allow an authenticated remote attacker to cause denial of service …

May 21, 2024
CVE-2024-5145
6.3 MEDIUM

A vulnerability was found in SourceCodester Vehicle Management System up to 1.0 and classified as critical. This issue affects some unknown processing of the file …

May 20, 2024
CVE-2024-4985
9.8 CRITICAL

An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication with the optional encrypted assertions feature. This …

May 20, 2024
CVE-2024-34710
7.1 HIGH

Wiki.js is al wiki app built on Node.js. Client side template injection was discovered, that could allow an attacker to inject malicious JavaScript into the …

May 20, 2024
CVE-2024-35195
5.6 MEDIUM

Requests is a HTTP library. Prior to 2.32.0, when making requests through a Requests `Session`, if the first request is made with `verify=False` to disable …

May 20, 2024
CVE-2024-35194
5.3 MEDIUM

Minder is a software supply chain security platform. Prior to version 0.0.50, Minder engine is susceptible to a denial of service from memory exhaustion that …

May 20, 2024
CVE-2024-35192
5.5 MEDIUM

Trivy is a security scanner. Prior to 0.51.2, if a malicious actor is able to trigger Trivy to scan container images from a crafted malicious …

May 20, 2024
CVE-2024-35191
4.4 MEDIUM

Formie is a Craft CMS plugin for creating forms. Prior to 2.1.6, users with access to a form's settings can include malicious Twig code into …

May 20, 2024
CVE-2024-33901
6.5 MEDIUM

Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database via a …

May 20, 2024
CVE-2024-33900
6.5 MEDIUM

KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover cleartext credentials via a memory dump. NOTE: the vendor disputes this …

May 20, 2024
CVE-2024-29000
7.9 HIGH

The SolarWinds Platform was determined to be affected by a reflected cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is …

May 20, 2024
CVE-2024-35580
9.8 CRITICAL

Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.

May 20, 2024
CVE-2024-35579
7.7 HIGH

Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formSetIptv.

May 20, 2024
CVE-2024-35578
8.0 HIGH

Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv.

May 20, 2024
CVE-2024-35576
5.2 MEDIUM

Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formSetIptv.

May 20, 2024
CVE-2024-35571
9.8 CRITICAL

Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.

May 20, 2024
CVE-2024-34949
8.2 HIGH

SQL injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function OrderLogic::getOrderList function, exploited at the /admin/order/lists.html endpoint.

May 20, 2024
CVE-2024-34193
7.5 HIGH

smanga 3.2.7 does not filter the file parameter at the PHP/get file flow.php interface, resulting in a path traversal vulnerability that can cause arbitrary file …

May 20, 2024
CVE-2024-31714
7.5 HIGH

Buffer Overflow vulnerability in Waxlab wax v.0.9-3 and before allows an attacker to cause a denial of service via the Lua library component.

May 20, 2024
CVE-2024-29651
8.1 HIGH

A Prototype Pollution issue in API Dev Tools json-schema-ref-parser v.11.0.0 and v.11.1.0 allows a remote attacker to execute arbitrary code via the bundle()`, `parse()`, `resolve()`, …

May 20, 2024
CVE-2024-24293
8.8 HIGH

A Prototype Pollution issue in MiguelCastillo @bit/loader v.10.0.3 allows an attacker to execute arbitrary code via the M function e argument in index.js.

May 20, 2024
CVE-2023-49335
8.3 HIGH

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while getting file server details.

May 20, 2024
CVE-2023-49334
8.3 HIGH

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while exporting a full summary report.

May 20, 2024
CVE-2023-49333
8.3 HIGH

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the dashboard graph feature.

May 20, 2024
CVE-2023-49332
8.3 HIGH

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while adding file shares.

May 20, 2024
CVE-2023-49331
8.3 HIGH

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the aggregate reports search option.

May 20, 2024
CVE-2024-34948
7.5 HIGH

An issue in Quanxun Huiju Network Technology(Beijing) Co.,Ltd IK-Q3000 3.7.10 x64 Build202401261655 allows attackers to cause a Denial of Service (DoS) when attempting to make …

May 20, 2024
CVE-2024-34947
9.4 CRITICAL

Quanxun Huiju Network Technology (Beijing) Co.,Ltd IK-Q3000 3.7.10 x64 Build202401261655 was discovered to be vulnerable to an ICMP redirect attack.

May 20, 2024
CVE-2024-24294
9.8 CRITICAL

A Prototype Pollution issue in Blackprint @blackprint/engine v.0.9.0 allows an attacker to execute arbitrary code via the _utils.setDeepProperty function of engine.min.js.

May 20, 2024
CVE-2024-0401
7.2 HIGH

ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary operating system commands by …

May 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.