CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-21663
9.9 CRITICAL

Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a discord server. Discord-Recon is vulnerable to remote …

Jan 9, 2024
CVE-2024-21651
7.5 HIGH

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user able to attach a file to …

Jan 9, 2024
CVE-2024-21648
8.0 HIGH

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The rollback action is missing a right protection, …

Jan 9, 2024
CVE-2023-50162
7.2 HIGH

SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the DoExecSql function.

Jan 9, 2024
CVE-2023-52074
8.8 HIGH

FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component system/site/webconfig_updagte.

Jan 8, 2024
CVE-2023-52073
8.8 HIGH

FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /system/site/config_footer_updagte.

Jan 8, 2024
CVE-2023-52072
8.8 HIGH

FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /system/site/userconfig_updagte.

Jan 8, 2024
CVE-2022-40696
3.7 LOW

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Engine Advanced Custom Fields (ACF).This issue affects Advanced Custom Fields (ACF): from 3.1.1 through …

Jan 8, 2024
CVE-2022-36352
6.3 MEDIUM

Missing Authorization vulnerability in Profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects ProfileGrid – User Profiles, Memberships, Groups and Communities: from n/a …

Jan 8, 2024
CVE-2022-34344
5.4 MEDIUM

Missing Authorization vulnerability in Rymera Web Co Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More.This …

Jan 8, 2024
CVE-2022-29409

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jan 8, 2024
CVE-2023-7218
7.2 HIGH

A vulnerability, which was classified as critical, was found in Totolink N350RT 9.3.5u.6139_B202012. Affected is the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Jan 8, 2024
CVE-2023-52202
9.1 CRITICAL

Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Folder Feedburner Playlist Free.This issue affects HTML5 MP3 Player with Folder Feedburner Playlist …

Jan 8, 2024
CVE-2023-52201
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brian D. Goad pTypeConverter.This issue affects pTypeConverter: from n/a through 0.2.8.1.

Jan 8, 2024
CVE-2023-52198
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michiel van Eerd Private Google Calendars allows Stored XSS.This issue affects Private Google …

Jan 8, 2024
CVE-2023-52197
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Impactpixel Ads Invalid Click Protection allows Stored XSS.This issue affects Ads Invalid Click …

Jan 8, 2024
CVE-2023-52196
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phil Ewels CPT Bootstrap Carousel allows Reflected XSS.This issue affects CPT Bootstrap Carousel: …

Jan 8, 2024
CVE-2023-52142
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cool Plugins Events Shortcodes For The Events Calendar.This issue affects Events …

Jan 8, 2024
CVE-2023-51508
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jordy Meow Database Cleaner: Clean, Optimize & Repair.This issue affects Database Cleaner: Clean, Optimize & …

Jan 8, 2024
CVE-2023-51490
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPMU DEV Defender Security – Malware Scanner, Login Security & Firewall.This issue affects Defender Security …

Jan 8, 2024
CVE-2023-51408
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StudioWombat WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce.This issue …

Jan 8, 2024
CVE-2023-51406
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team FastDup – Fastest WordPress Migration & Duplicator.This issue affects FastDup – Fastest WordPress …

Jan 8, 2024
CVE-2023-49961
7.5 HIGH

WALLIX Bastion 7.x, 8.x, 9.x and 10.x and WALLIX Access Manager 3.x and 4.x have Incorrect Access Control which can lead to sensitive data exposure.

Jan 8, 2024
CVE-2023-27739
6.1 MEDIUM

easyXDM 2.5 allows XSS via the xdm_e parameter.

Jan 8, 2024
CVE-2022-45354
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.

Jan 8, 2024
CVE-2023-52271
6.5 MEDIUM

The wsftprm.sys kernel driver 2.0.0.0 in Topaz Antifraud allows low-privileged attackers to kill any (Protected Process Light) process via an IOCTL (which will be named …

Jan 8, 2024
CVE-2023-52216
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Yevhen Kotelnytskyi JS & CSS Script Optimizer.This issue affects JS & CSS Script Optimizer: from n/a through 0.3.3.

Jan 8, 2024
CVE-2023-52213
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VideoWhisper Rate Star Review – AJAX Reviews for Content, with Star Ratings allows …

Jan 8, 2024
CVE-2023-52206
7.7 HIGH

Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder.This issue affects Page Builder: Live Composer: from n/a through 1.5.25.

Jan 8, 2024
CVE-2023-52205
9.1 CRITICAL

Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 SoundCloud Player with Playlist Free.This issue affects HTML5 SoundCloud Player with Playlist Free: from n/a through …

Jan 8, 2024
CVE-2023-52204
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Javik Randomize.This issue affects Randomize: from n/a through 1.4.3.

Jan 8, 2024
CVE-2023-52203
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bastian Germann cformsII allows Stored XSS.This issue affects cformsII: from n/a …

Jan 8, 2024
CVE-2023-52200
9.6 CRITICAL

Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup.This …

Jan 8, 2024
CVE-2023-51246
5.4 MEDIUM

A Cross Site Scripting (XSS) vulnerability in GetSimple CMS 3.3.16 exists when using Source Code Mode as a backend user to add articles via the …

Jan 8, 2024
CVE-2023-50982
9.0 CRITICAL

Stud.IP 5.x through 5.3.3 allows XSS with resultant upload of executable files, because upload_action and edit_action in Admin_SmileysController do not check the file extension. This …

Jan 8, 2024
CVE-2023-47890
8.8 HIGH

pyLoad 0.5.0 is vulnerable to Unrestricted File Upload.

Jan 8, 2024
CVE-2023-6845
8.8 HIGH

The CommentTweets WordPress plugin through 0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted …

Jan 8, 2024
CVE-2023-6750
7.5 HIGH

The Clone WordPress plugin before 2.4.3 uses buffer files to store in-progress backup informations, which is stored at a publicly accessible, statically defined file path.

Jan 8, 2024
CVE-2023-6631
7.8 HIGH

PowerSYSTEM Center versions 2020 Update 16 and prior contain a vulnerability that may allow an authorized local user to insert arbitrary code into the unquoted …

Jan 8, 2024
CVE-2023-6627
6.1 MEDIUM

The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.28 does not properly protect most of its REST API routes, which attackers can …

Jan 8, 2024
CVE-2023-6555
6.1 MEDIUM

The Email Subscription Popup WordPress plugin before 1.2.20 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jan 8, 2024
CVE-2023-6532
8.8 HIGH

The WP Blogs' Planetarium WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Jan 8, 2024
CVE-2023-6529
6.1 MEDIUM

The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, …

Jan 8, 2024
CVE-2023-6528
8.8 HIGH

The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially …

Jan 8, 2024
CVE-2023-6505
7.5 HIGH

The Migrate WordPress Website & Backups WordPress plugin before 1.9.3 does not prevent directory listing in sensitive directories containing export files.

Jan 8, 2024
CVE-2023-6383
7.5 HIGH

The Debug Log Manager WordPress plugin before 2.3.0 contains a Directory listing vulnerability was discovered, which allows you to download the debug log without authorization …

Jan 8, 2024
CVE-2023-6161
6.1 MEDIUM

The WP Crowdfunding WordPress plugin before 2.1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jan 8, 2024
CVE-2023-6141
5.4 MEDIUM

The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with …

Jan 8, 2024
CVE-2023-6140
8.8 HIGH

The Essential Real Estate WordPress plugin before 4.4.0 does not prevent users with limited privileges on the site, like subscribers, from momentarily uploading malicious PHP …

Jan 8, 2024
CVE-2023-6139
6.5 MEDIUM

The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with …

Jan 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.