CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-45236
5.8 MEDIUM

EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and …

Jan 16, 2024
CVE-2023-45235
8.3 HIGH

EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be …

Jan 16, 2024
CVE-2023-45234
8.3 HIGH

EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited …

Jan 16, 2024
CVE-2023-45233
7.5 HIGH

EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can …

Jan 16, 2024
CVE-2023-45232
7.5 HIGH

EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be …

Jan 16, 2024
CVE-2023-45231
6.5 MEDIUM

EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to …

Jan 16, 2024
CVE-2023-45230
8.3 HIGH

EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by …

Jan 16, 2024
CVE-2023-45229
6.5 MEDIUM

EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can …

Jan 16, 2024
CVE-2023-3771
6.1 MEDIUM

The T1 WordPress theme through 19.0 is vulnerable to unauthenticated open redirect with which any attacker and redirect users to arbitrary websites.

Jan 16, 2024
CVE-2023-3647
4.8 MEDIUM

The IURNY by INDIGITALL WordPress plugin before 3.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jan 16, 2024
CVE-2023-3372
5.4 MEDIUM

The Lana Shortcodes WordPress plugin before 1.2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Jan 16, 2024
CVE-2023-3211
9.8 CRITICAL

The WordPress Database Administrator WordPress plugin through 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an …

Jan 16, 2024
CVE-2023-3178
4.3 MEDIUM

The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could allow attackers to make logged …

Jan 16, 2024
CVE-2023-37522
5.6 MEDIUM

HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower has missing or insecure tags that could allow an attacker to execute a malicious …

Jan 16, 2024
CVE-2023-37521
2.3 LOW

HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower can sometimes include sensitive information in a query string which could allow an attacker …

Jan 16, 2024
CVE-2023-2655
7.2 HIGH

The Contact Form by WD WordPress plugin through 1.13.23 does not properly sanitise and escape a parameter before using it in a SQL statement, leading …

Jan 16, 2024
CVE-2023-2252
2.7 LOW

The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files.

Jan 16, 2024
CVE-2023-1405
7.5 HIGH

The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is …

Jan 16, 2024
CVE-2023-0824
6.5 MEDIUM

The User registration & user profile WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as …

Jan 16, 2024
CVE-2023-0769
6.1 MEDIUM

The hiWeb Migration Simple WordPress plugin through 2.0.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jan 16, 2024
CVE-2023-0479
6.1 MEDIUM

The Print Invoice & Delivery Notes for WooCommerce WordPress plugin before 4.7.2 is vulnerable to reflected XSS by echoing a GET value in an admin …

Jan 16, 2024
CVE-2023-0389
4.8 MEDIUM

The Calculated Fields Form WordPress plugin before 1.1.151 does not sanitise and escape some of its form settings, which could allow high privilege users such …

Jan 16, 2024
CVE-2023-0376
5.4 MEDIUM

The Qubely WordPress plugin before 1.8.5 does not validate and escape some of its block options before outputting them back in a page/post where the …

Jan 16, 2024
CVE-2023-0224
9.8 CRITICAL

The GiveWP WordPress plugin before 2.24.1 does not properly escape user input before it reaches SQL queries, which could let unauthenticated attackers perform SQL Injection …

Jan 16, 2024
CVE-2023-0094
5.4 MEDIUM

The UpQode Google Maps WordPress plugin through 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post …

Jan 16, 2024
CVE-2023-0079
5.4 MEDIUM

The Customer Reviews for WooCommerce WordPress plugin before 5.17.0 does not validate and escape some of its shortcode attributes before outputting them back in a …

Jan 16, 2024
CVE-2022-3899
8.1 HIGH

The 3dprint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File Manager included with the plugin, allowing …

Jan 16, 2024
CVE-2022-3836
4.8 MEDIUM

The Seed Social WordPress plugin before 2.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jan 16, 2024
CVE-2022-3829
4.8 MEDIUM

The Font Awesome 4 Menus WordPress plugin through 4.7.0 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jan 16, 2024
CVE-2022-3764
7.2 HIGH

The plugin does not filter the "delete_entries" parameter from user requests, leading to an SQL Injection vulnerability.

Jan 16, 2024
CVE-2022-3739
5.4 MEDIUM

The WP Best Quiz WordPress plugin through 1.0 does not sanitize and escape some parameters, which could allow users with a role as low as …

Jan 16, 2024
CVE-2022-3604
7.8 HIGH

The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could lead to CSV injection.

Jan 16, 2024
CVE-2022-3194
5.4 MEDIUM

The Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allow them to run stored XSS attacks against …

Jan 16, 2024
CVE-2022-2413
5.4 MEDIUM

The Slide Anything WordPress plugin before 2.3.47 does not properly sanitize or escape the slide title before outputting it in the admin pages, allowing a …

Jan 16, 2024
CVE-2022-23180
4.3 MEDIUM

The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks, which could allow any authenticated users, such …

Jan 16, 2024
CVE-2022-23179
4.8 MEDIUM

The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.0 does not escape some of its form fields before outputting them in attributes, …

Jan 16, 2024
CVE-2022-1760
4.3 MEDIUM

The Core Control WordPress plugin through 1.2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Jan 16, 2024
CVE-2022-1618
6.1 MEDIUM

The Coru LFMember WordPress plugin through 1.0.2 does not have CSRF check in place when adding a new game, and is lacking sanitisation as well …

Jan 16, 2024
CVE-2022-1617
6.1 MEDIUM

The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as escaping …

Jan 16, 2024
CVE-2022-1609
9.8 CRITICAL

The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API handler, allowing an …

Jan 16, 2024
CVE-2022-1563
5.3 MEDIUM

The WPGraphQL WooCommerce WordPress plugin before 0.12.4 does not prevent unauthenticated attackers from enumerating a shop's coupon codes and values via GraphQL.

Jan 16, 2024
CVE-2022-1538
7.2 HIGH

Theme Demo Import WordPress plugin before 1.1.1 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as …

Jan 16, 2024
CVE-2022-0775
4.3 MEDIUM

The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as subscriber to …

Jan 16, 2024
CVE-2022-0402
6.1 MEDIUM

The Super Forms - Drag & Drop Form Builder WordPress plugin before 6.0.4 does not escape the bob_czy_panstwa_sprawa_zostala_rozwiazana parameter before outputting it back in an …

Jan 16, 2024
CVE-2021-4227
5.3 MEDIUM

The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing attackers to inject an iFrame in …

Jan 16, 2024
CVE-2021-25117
4.8 MEDIUM

The WP-PostRatings WordPress plugin before 1.86.1 does not sanitise the postratings_image parameter from its options page (wp-admin/admin.php?page=wp-postratings/postratings-options.php). Even though the page is only accessible to …

Jan 16, 2024
CVE-2021-24870
6.1 MEDIUM

The WP Fastest Cache WordPress plugin before 0.9.5 is lacking a CSRF check in its wpfc_save_cdn_integration AJAX action, and does not sanitise and escape some …

Jan 16, 2024
CVE-2021-24869
8.8 HIGH

The WP Fastest Cache WordPress plugin before 0.9.5 does not escape user input in the set_urls_with_terms method before using it in a SQL statement, leading …

Jan 16, 2024
CVE-2021-24567
5.4 MEDIUM

The Simple Post WordPress plugin through 1.1 does not sanitize user input when an authenticated user Text value, then it does not escape these values …

Jan 16, 2024
CVE-2021-24566
8.8 HIGH

The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortcode.

Jan 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.