CVE Database

52888+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6713
4.8 MEDIUM

The PVN Auth Popup WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-6712
6.1 MEDIUM

The MapFig Studio WordPress plugin through 0.2.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

May 15, 2025
CVE-2024-6708
4.8 MEDIUM

The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting its content on the admin area, which allows …

May 15, 2025
CVE-2024-6693
4.8 MEDIUM

The wccp-pro WordPress plugin before 15.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 15, 2025
CVE-2024-6690
6.1 MEDIUM

The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirection of users to external sites

May 15, 2025
CVE-2024-6668
5.4 MEDIUM

The ProfilePro WordPress plugin through 1.3 does not sanitise and escape some parameters and lacks proper access controls, which could allow users with a role …

May 15, 2025
CVE-2024-6667
6.1 MEDIUM

The KBucket: Your Curated Content in WordPress plugin before 4.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading …

May 15, 2025
CVE-2024-6665
4.8 MEDIUM

The KBucket: Your Curated Content in WordPress plugin before 4.1.6 does not sanitise and escape some of its settings, which could allow high privilege users …

May 15, 2025
CVE-2024-6478
4.8 MEDIUM

The CTT Expresso para WooCommerce WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, which could allow high privilege users such …

May 15, 2025
CVE-2024-6462
4.8 MEDIUM

The DL Yandex Metrika WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-6335
4.8 MEDIUM

The Tracking Code Manager WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-5440
5.4 MEDIUM

The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.3 does not validate and escape some of its shortcode attributes before outputting them back in a …

May 15, 2025
CVE-2024-5026
4.8 MEDIUM

The CM Tooltip Glossary WordPress plugin before 4.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-4665
6.4 MEDIUM

The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing users to change/cancel bookings for other users. Additionally, the feature …

May 15, 2025
CVE-2024-3901
6.8 MEDIUM

The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blocks, making it possible for users allowed …

May 15, 2025
CVE-2024-3062
4.8 MEDIUM

The Save as Image Plugin by Pdfcrowd WordPress plugin before 3.2.2 does not sanitise and escape some of its settings, which could allow high privilege …

May 15, 2025
CVE-2024-2869
4.8 MEDIUM

The Easy Property Listings WordPress plugin before 3.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-2643
4.8 MEDIUM

The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.6.8 does not sanitise and escape some …

May 15, 2025
CVE-2024-1663
4.8 MEDIUM

The Ultimate Noindex Nofollow Tool II WordPress plugin before 1.3.6 does not sanitise and escape some of its settings, which could allow high privilege users …

May 15, 2025
CVE-2024-13865
6.1 MEDIUM

The S3Player WordPress plugin through 4.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

May 15, 2025
CVE-2024-13828
6.1 MEDIUM

The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

May 15, 2025
CVE-2024-13823
6.1 MEDIUM

The 360 Product Rotation WordPress plugin through 1.5.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

May 15, 2025
CVE-2024-13730
4.8 MEDIUM

The Podlove Podcast Publisher WordPress plugin before 4.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-13729
4.8 MEDIUM

The Podlove Podcast Publisher WordPress plugin before 4.1.24 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-13727
6.1 MEDIUM

The MemberSpace WordPress plugin before 2.1.14 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

May 15, 2025
CVE-2024-13621
4.8 MEDIUM

The GDPR Framework By Data443 WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such …

May 15, 2025
CVE-2024-13619
6.1 MEDIUM

The LifterLMS WordPress plugin before 8.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

May 15, 2025
CVE-2024-13616
4.8 MEDIUM

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.7.2 does not sanitise and escape some of its settings, which could allow high privilege …

May 15, 2025
CVE-2024-13486
4.8 MEDIUM

The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-13482
4.8 MEDIUM

The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-13384
4.8 MEDIUM

The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.24 does not sanitise and escape some of its settings, which could allow …

May 15, 2025
CVE-2024-13383
4.8 MEDIUM

The HD Quiz WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-13382
4.8 MEDIUM

The Calculated Fields Form WordPress plugin before 5.2.64 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-13357
4.8 MEDIUM

The Ditty WordPress plugin before 3.1.52 does not sanitise and escape some of its settings, which could allow high privilege users such as author to …

May 15, 2025
CVE-2024-13313
4.8 MEDIUM

The AWeber WordPress plugin through 7.3.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 15, 2025
CVE-2024-13128
4.8 MEDIUM

The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 15, 2025
CVE-2024-13127
4.8 MEDIUM

The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 15, 2025
CVE-2024-13053
4.8 MEDIUM

The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such …

May 15, 2025
CVE-2024-12874
4.8 MEDIUM

The Top Comments WordPress plugin through 1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-12873
6.1 MEDIUM

The Custom Field Manager WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

May 15, 2025
CVE-2024-12808
4.8 MEDIUM

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 does not sanitise and …

May 15, 2025
CVE-2024-12800
4.8 MEDIUM

The IP Based Login WordPress plugin before 2.4.1 does not sanitise values when importing, which could allow high privilege users such as admin to perform …

May 15, 2025
CVE-2024-12770
4.8 MEDIUM

The WP ULike WordPress plugin before 4.7.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2024-12750
4.3 MEDIUM

The Competition Form WordPress plugin through 2.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

May 15, 2025
CVE-2024-12743
4.8 MEDIUM

The MailPoet WordPress plugin before 5.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 15, 2025
CVE-2024-12739
4.8 MEDIUM

The Mobile Contact Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 15, 2025
CVE-2024-12734
6.1 MEDIUM

The Advance Post Prefix WordPress plugin through 1.1.1, Advance Post Prefix WordPress plugin through 1.1.1 does not sanitise and escape a parameter before outputting it …

May 15, 2025
CVE-2024-12733
6.1 MEDIUM

The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

May 15, 2025
CVE-2024-12732
6.1 MEDIUM

The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

May 15, 2025
CVE-2024-12726
6.1 MEDIUM

The ClipArt WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

May 15, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.