CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-3061
7.2 HIGH

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.5.2 …

Mar 29, 2024
CVE-2023-52629
8.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: sh: push-switch: Reorder cleanup operations to avoid use-after-free bug The original code puts flush_work() before …

Mar 29, 2024
CVE-2024-2411
9.8 CRITICAL

The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'modal' parameter. This …

Mar 29, 2024
CVE-2024-2409
9.8 CRITICAL

The MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.1. This is due to insufficient validation …

Mar 29, 2024
CVE-2024-2250
6.4 MEDIUM

The 130+ Widgets | Best Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all …

Mar 29, 2024
CVE-2024-2970
4.3 MEDIUM

The News Wall plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing …

Mar 29, 2024
CVE-2024-2969
5.4 MEDIUM

The WP-Eggdrop plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1. This is due to missing or …

Mar 29, 2024
CVE-2024-2968
4.4 MEDIUM

The WP-Eggdrop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.1 due to insufficient …

Mar 29, 2024
CVE-2024-2964
5.4 MEDIUM

The Pocket News Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2.0. This is due to …

Mar 29, 2024
CVE-2024-2963
4.4 MEDIUM

The Pocket News Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings such as "Consumer Key" and "Access Token" in all …

Mar 29, 2024
CVE-2024-2476
4.3 MEDIUM

The OceanWP theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the load_theme_panel_pane function in all versions …

Mar 29, 2024
CVE-2024-2280
6.4 MEDIUM

The Better Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget link URL values in all versions up to, and …

Mar 29, 2024
CVE-2024-2116
6.1 MEDIUM

The Christmas Greetings plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the code parameter in all versions up to, and including, 1.2.5 due …

Mar 29, 2024
CVE-2024-2113
4.3 MEDIUM

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all …

Mar 29, 2024
CVE-2024-2108
4.6 MEDIUM

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an …

Mar 29, 2024
CVE-2024-1872
8.8 HIGH

The Button plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.27 via deserialization of untrusted input in …

Mar 29, 2024
CVE-2024-1858
5.4 MEDIUM

The Lightbox slider – Responsive Lightbox Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.9 via …

Mar 29, 2024
CVE-2024-0956
4.9 MEDIUM

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL …

Mar 29, 2024
CVE-2024-0913
7.2 HIGH

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL …

Mar 29, 2024
CVE-2024-0609
7.2 HIGH

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to Stored Cross-Site …

Mar 29, 2024
CVE-2024-0608
6.5 MEDIUM

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to union-based SQL …

Mar 29, 2024
CVE-2024-2936
6.4 MEDIUM

The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id attribute of widgets in all versions up to, and including, …

Mar 29, 2024
CVE-2024-2844
4.3 MEDIUM

The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient user validation on the ajax_cancel_appointment() function in all versions …

Mar 29, 2024
CVE-2024-2842
6.4 MEDIUM

The Easy Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ea_full_calendar' shortcode in all versions up to, and including, 3.11.18 …

Mar 29, 2024
CVE-2024-28960
8.2 HIGH

An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared …

Mar 29, 2024
CVE-2024-3077
6.8 MEDIUM

An malicious BLE device can crash BLE victim device by sending malformed gatt packet

Mar 29, 2024
CVE-2024-2841
6.4 MEDIUM

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's …

Mar 29, 2024
CVE-2024-2475
6.4 MEDIUM

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.13 …

Mar 29, 2024
CVE-2024-1729
5.9 MEDIUM

A timing attack vulnerability exists in the gradio-app/gradio repository, specifically within the login function in routes.py. The vulnerability arises from the use of a direct …

Mar 29, 2024
CVE-2024-29489
5.5 MEDIUM

Jerryscript 2.4.0 has SEGV at ./jerry-core/ecma/base/ecma-helpers.c:238:58 in ecma_get_object_type.

Mar 28, 2024
CVE-2024-29316
6.3 MEDIUM

NodeBB 3.6.7 is vulnerable to Incorrect Access Control, e.g., a low-privileged attacker can access the restricted tabs for the Admin group via "isadmin":true.

Mar 28, 2024
CVE-2024-28714
8.1 HIGH

SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the groupid parameter.

Mar 28, 2024
CVE-2024-28456
5.4 MEDIUM

Cross Site Scripting vulnerability in Campcodes Online Marriage Registration System v.1.0 allows a remote attacker to execute arbitrary code via the text fields in the …

Mar 28, 2024
CVE-2024-24407
5.3 MEDIUM

SQL Injection vulnerability in Best Courier management system v.1.0 allows a remote attacker to obtain sensitive information via print_pdets.php component.

Mar 28, 2024
CVE-2023-50969
9.8 CRITICAL

Thales Imperva SecureSphere WAF 14.7.0.40 allows remote attackers to bypass WAF rules via a crafted POST request, a different vulnerability than CVE-2021-45468.

Mar 28, 2024
CVE-2023-33528
6.1 MEDIUM

halo v1.6.0 is vulnerable to Cross Site Scripting (XSS).

Mar 28, 2024
CVE-2021-31156
7.5 HIGH

Allied Telesis AT-S115 1.2.0 devices before 1.00.024 with Boot Loader 1.00.006 allow Directory Traversal to achieve partial access to data.

Mar 28, 2024
CVE-2023-25341
6.5 MEDIUM

A Directory Traversal vulnerability in ladle dev server 2.5.1 and earlier allows an attacker on the same network to read files accessible to the user …

Mar 28, 2024
CVE-2024-23727
8.4 HIGH

The YI Smart Kami Vision com.kamivision.yismart application through 1.0.0_20231219 for Android allows a remote attacker to execute arbitrary JavaScript code via an implicit intent to …

Mar 28, 2024
CVE-2024-28091
6.1 MEDIUM

Technicolor TC8715D TC8715D-01.EF.04.38.00-180405-S-FF9-D RSE-TC8717T devices allow a remote attacker within Wi-Fi proximity to conduct stored XSS attacks via User Defined Service in managed_services_add.asp (the victim …

Mar 28, 2024
CVE-2024-28090
5.4 MEDIUM

Technicolor TC8715D TC8715D-01.EF.04.38.00-180405-S-FF9-D RSE-TC8717T devices allow a remote attacker within Wi-Fi proximity to conduct stored XSS attacks via User name in dyn_dns.asp.

Mar 28, 2024
CVE-2024-25506
6.5 MEDIUM

Cross Site Scripting vulnerability in Process Maker, Inc ProcessMaker before 4.0 allows a remote attacker to run arbitrary code via control of the pm_sys_sys cookie.

Mar 28, 2024
CVE-2024-3019
8.8 HIGH

A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the …

Mar 28, 2024
CVE-2024-31065
6.1 MEDIUM

Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the City input field.

Mar 28, 2024
CVE-2024-31064
6.1 MEDIUM

Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the First Name input field.

Mar 28, 2024
CVE-2024-31063
6.4 MEDIUM

Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Email input field.

Mar 28, 2024
CVE-2024-31062
6.3 MEDIUM

Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Street input field.

Mar 28, 2024
CVE-2024-31061
6.1 MEDIUM

Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Last Name input field.

Mar 28, 2024
CVE-2024-2947
7.3 HIGH

A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, …

Mar 28, 2024
CVE-2024-28713
9.8 CRITICAL

An issue in Mblog Blog system v.3.5.0 allows an attacker to execute arbitrary code via a crafted file to the theme management feature.

Mar 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.