CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-3915
5.3 MEDIUM

The Swift Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sf_edit_directory_item() function in all …

May 14, 2024
CVE-2024-3903
7.1 HIGH

The Add Custom CSS and JS WordPress plugin through 1.20 does not have CSRF check in some places, and is missing sanitisation as well as …

May 14, 2024
CVE-2024-3831
6.4 MEDIUM

The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Heading widget in all versions …

May 14, 2024
CVE-2024-3828
8.8 HIGH

The Spectra Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.5. This is due to the plugin …

May 14, 2024
CVE-2024-3809
8.8 HIGH

The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.9 via the 'slideshow_type' …

May 14, 2024
CVE-2024-3808
8.8 HIGH

The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.0 via the 'porto_portfolios' …

May 14, 2024
CVE-2024-3807
8.8 HIGH

The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via 'porto_page_header_shortcode_type', 'slideshow_type' and 'post_layout' post …

May 14, 2024
CVE-2024-3806
9.8 CRITICAL

The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via the 'porto_ajax_posts' function. This makes …

May 14, 2024
CVE-2024-3796
4.8 MEDIUM

Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/BackupSchedule, description field. Exploitation of this vulnerability could allow a remote user …

May 14, 2024
CVE-2024-3795
4.8 MEDIUM

Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/BackupTemplate, name / description fields. Exploitation of this vulnerability could allow a …

May 14, 2024
CVE-2024-3794
4.8 MEDIUM

Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/AdvancedSystem, description field, all parameters. Exploitation of this vulnerability could allow a …

May 14, 2024
CVE-2024-3793
4.8 MEDIUM

Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/CloudAccounts, account name / user password / server fields, all parameters. Exploitation …

May 14, 2024
CVE-2024-3792
4.8 MEDIUM

Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/DeviceReplication, execution range field, all parameters. Exploitation of this vulnerability could allow …

May 14, 2024
CVE-2024-3791
4.8 MEDIUM

Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/SystemConfiguration, name / free memory limit fields , type / password parameters. …

May 14, 2024
CVE-2024-3790
4.8 MEDIUM

Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/SystemUsers, login / description fields, passwd1/ passwd2 parameters. Exploitation of this vulnerability …

May 14, 2024
CVE-2024-3789
6.5 MEDIUM

Uncontrolled resource consumption vulnerability in White Bear Solutions WBSAirback, version 21.02.04. This vulnerability could allow an attacker to send multiple command injection payloads to influence …

May 14, 2024
CVE-2024-3788
6.6 MEDIUM

Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through License (/admin/CDPUsers). Exploitation of this vulnerability could allow a remote user to …

May 14, 2024
CVE-2024-3787
6.6 MEDIUM

Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 disks (/admin/DeviceS3). Exploitation of this vulnerability could allow a remote user …

May 14, 2024
CVE-2024-3727
8.3 HIGH

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing …

May 14, 2024
CVE-2024-3722
5.4 MEDIUM

The Swift Performance Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ajax_handler() function in all versions …

May 14, 2024
CVE-2024-3680
6.4 MEDIUM

The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Animation Title widget's img tag …

May 14, 2024
CVE-2024-3595
6.4 MEDIUM

The Pure Chat – Live Chat Plugin & More! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the purechatwid and purechatwname parameter in …

May 14, 2024
CVE-2024-3590
6.1 MEDIUM

The LetterPress WordPress plugin through 1.2.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted …

May 14, 2024
CVE-2024-3582
4.8 MEDIUM

The UnGallery WordPress plugin through 2.2.4 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

May 14, 2024
CVE-2024-3547
6.1 MEDIUM

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'google_connect_error' parameter in all versions …

May 14, 2024
CVE-2024-3462
5.4 MEDIUM

Ant Media Server Community Edition in a default configuration is vulnerable to an improper HTTP header based authorization, leading to a possible use of non-administrative …

May 14, 2024
CVE-2024-3461
6.2 MEDIUM

KioWare for Windows (versions all through 8.35) allows to brute force the PIN number, which protects the application from being closed, as there are no …

May 14, 2024
CVE-2024-3460
7.4 HIGH

In KioWare for Windows (versions all through 8.34) it is possible to exit this software and use other already opened applications utilizing a short time …

May 14, 2024
CVE-2024-3459
8.4 HIGH

KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened in an external …

May 14, 2024
CVE-2024-3263
9.8 CRITICAL

YMS VIS Pro is an information system for veterinary and food administration, veterinarians and farm. Due to a combination of improper method for system credentials …

May 14, 2024
CVE-2024-3239
5.4 MEDIUM

The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.0.2 does not validate and escape some of its block options before outputting …

May 14, 2024
CVE-2024-3070
9.8 CRITICAL

The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 via deserialization …

May 14, 2024
CVE-2024-3068
4.4 MEDIUM

The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cfs[fields][*][name]' parameter in all versions up to, and including, 2.6.5 …

May 14, 2024
CVE-2024-3055
8.8 HIGH

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions …

May 14, 2024
CVE-2024-3037
7.8 HIGH

An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first …

May 14, 2024
CVE-2024-3016
9.1 CRITICAL

NEC Platforms DT900 and DT900S Series 5.0.0.0 – v5.3.4.4, v5.4.0.0 – v5.6.0.20 allows an attacker to access a non-documented the system settings to change settings …

May 14, 2024
CVE-2024-35205
7.8 HIGH

The WPS Office (aka cn.wps.moffice_eng) application before 17.0.0 for Android fails to properly sanitize file names before processing them through external application interactions, leading to …

May 14, 2024
CVE-2024-35204
8.4 HIGH

Veritas System Recovery before 23.3_Hotfix has incorrect permissions for the Veritas System Recovery folder, and thus low-privileged users can conduct attacks.

May 14, 2024
CVE-2024-35172
4.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images.This issue affects ShortPixel Adaptive Images: from n/a through <= 3.8.3.

May 14, 2024
CVE-2024-35171
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Academy LMS academy.This issue affects Academy LMS: from n/a through 1.9.25.

May 14, 2024
CVE-2024-35170
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidden Depth Sticky banner allows Stored XSS.This issue affects Sticky banner: from n/a …

May 14, 2024
CVE-2024-35169
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in all_bootstrap_blocks All Bootstrap Blocks all-bootstrap-blocks.This issue affects All Bootstrap Blocks: from n/a through …

May 14, 2024
CVE-2024-35167
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo's Elementor Templates & Widgets for WooCommerce allows Stored XSS.This issue affects …

May 14, 2024
CVE-2024-35166
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team Filebird.This issue affects Filebird: from n/a through 5.6.3.

May 14, 2024
CVE-2024-35165
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gutenify.This issue affects Gutenify: from n/a through 1.4.0.

May 14, 2024
CVE-2024-35099
9.8 CRITICAL

TOTOLINK LR350 V9.3.5u.6698_B20230810 was discovered to contain a stack overflow via the password parameter in the function loginAuth.

May 14, 2024
CVE-2024-35050
8.8 HIGH

An issue in SurveyKing v1.3.1 allows attackers to escalate privileges via re-using the session ID of a user that was deleted by an Admin.

May 14, 2024
CVE-2024-35049
9.1 CRITICAL

SurveyKing v1.3.1 was discovered to keep users' sessions active after logout. Related to an incomplete fix for CVE-2022-25590.

May 14, 2024
CVE-2024-35048
4.3 MEDIUM

An issue in SurveyKing v1.3.1 allows attackers to execute a session replay attack after a user changes their password.

May 14, 2024
CVE-2024-34974
8.2 HIGH

Tenda AC18 v15.03.05.19 is vulnerable to Buffer Overflow in the formSetPPTPServer function via the endIp parameter.

May 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.