CVE Database

39716+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-39920
7.5 HIGH

Missing Authorization vulnerability in Themeisle Redirection for Contact Form 7 wpcf7-redirect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Redirection for Contact Form …

Dec 13, 2024
CVE-2023-38385
8.3 HIGH

Missing Authorization vulnerability in Artbees JupiterX Core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JupiterX Core: from 3.0.0 through 3.3.0.

Dec 13, 2024
CVE-2023-36510
7.3 HIGH

Missing Authorization vulnerability in Reservation Diary ReDi Restaurant Reservation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReDi Restaurant Reservation: from n/a through …

Dec 13, 2024
CVE-2023-35037
7.6 HIGH

Missing Authorization vulnerability in Surfer Surfer surferseo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Surfer: from n/a through <= 1.3.2.357.

Dec 13, 2024
CVE-2023-33996
8.8 HIGH

Missing Authorization vulnerability in СleanTalk - Anti-Spam Protection Spam protection, AntiSpam, FireWall by CleanTalk allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spam …

Dec 13, 2024
CVE-2023-32585
7.5 HIGH

Missing Authorization vulnerability in Total-Soft Portfolio Gallery – Responsive Image Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Portfolio Gallery – Responsive …

Dec 13, 2024
CVE-2023-32520
7.5 HIGH

Missing Authorization vulnerability in Webcodin WCP Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCP Contact Form: from n/a through 3.1.0.

Dec 13, 2024
CVE-2023-32507
7.3 HIGH

Missing Authorization vulnerability in wp3sixty Woo Custom Emails allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Woo Custom Emails: from n/a through 2.2.

Dec 13, 2024
CVE-2023-30490
7.5 HIGH

Missing Authorization vulnerability in Matthew Ruddy Easing Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easing Slider : from n/a through 3.0.8.

Dec 13, 2024
CVE-2023-25988
7.5 HIGH

Missing Authorization vulnerability in Video Gallery by Total-Soft Video Gallery – YouTube Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Video Gallery …

Dec 13, 2024
CVE-2024-22461
8.8 HIGH

Dell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A low privileged remote attacker could potentially exploit this vulnerability by running any …

Dec 13, 2024
CVE-2024-52066
7.8 HIGH

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Routing Service) allows Overflow Variables and Tags.This issue affects Connext …

Dec 13, 2024
CVE-2024-52065
7.1 HIGH

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional on non-Windows (Persistence Service) allows Buffer Overflow via Environment Variables.This …

Dec 13, 2024
CVE-2024-52064
7.1 HIGH

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext …

Dec 13, 2024
CVE-2024-52063
8.6 HIGH

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core Libraries, Routing Service) allows Overflow Variables and Tags.This issue …

Dec 13, 2024
CVE-2024-52062
7.8 HIGH

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext …

Dec 13, 2024
CVE-2024-52060
7.8 HIGH

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Routing Service, Recording Service, Queuing Service, Observability Collector Service, Cloud …

Dec 13, 2024
CVE-2024-52059
7.8 HIGH

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Heap-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in RTI Connext Professional (Security Plugins) allows …

Dec 13, 2024
CVE-2024-52058
7.8 HIGH

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in RTI Connext Professional (System Designer) allows OS Command Injection.This issue …

Dec 13, 2024
CVE-2024-10783
8.1 HIGH

The MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites plugin for WordPress is vulnerable to privilege escalation due to a …

Dec 13, 2024
CVE-2024-11839
7.5 HIGH

Deserialization of Untrusted Data vulnerability in PlexTrac (Runbooks modules) which allows Object Injection and arbitrary file writes.This issue affects PlexTrac: from 1.61.3 before 2.8.1.

Dec 13, 2024
CVE-2024-11836
7.5 HIGH

Server-Side Request Forgery (SSRF) vulnerability in PlexTrac allowing requests to internal system resources.This issue affects PlexTrac: from 1.61.3 before 2.8.1.

Dec 13, 2024
CVE-2024-11835
7.5 HIGH

Uncontrolled Resource Consumption vulnerability in PlexTrac allows WebSocket DoS.This issue affects PlexTrac: from 1.61.3 before 2.8.1.

Dec 13, 2024
CVE-2024-21544
8.6 HIGH

Versions of the package spatie/browsershot before 5.0.1 are vulnerable to Improper Input Validation due to improper URL validation in the setUrl method. An attacker can …

Dec 13, 2024
CVE-2024-21543
7.1 HIGH

Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to …

Dec 13, 2024
CVE-2024-9508
7.8 HIGH

Horner Automation Cscape contains a memory corruption vulnerability, which could allow an attacker to disclose information and execute arbitrary code.

Dec 13, 2024
CVE-2024-12212
7.8 HIGH

The vulnerability occurs in the parsing of CSP files. The issues result from the lack of proper validation of user-supplied data, which could allow reading …

Dec 13, 2024
CVE-2024-55888
7.1 HIGH

Hush Line is an open-source whistleblower management system. Starting in version 0.1.0 and prior to version 0.3.5, the productions server appeared to have been misconfigured …

Dec 12, 2024
CVE-2024-55885
7.5 HIGH

beego is an open-source web framework for the Go programming language. Versions of beego prior to 2.3.4 use MD5 as a hashing algorithm. MD5 is …

Dec 12, 2024
CVE-2024-47238
7.5 HIGH

Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit …

Dec 12, 2024
CVE-2024-21575
8.6 HIGH

ComfyUI-Impact-Pack is vulnerable to Path Traversal. The issue stems from missing validation of the `image.filename` field in a POST request sent to the `/upload/temp` endpoint …

Dec 12, 2024
CVE-2024-28146
8.4 HIGH

The application uses several hard-coded credentials to encrypt config files during backup, to decrypt the new firmware during an update and some passwords allow a …

Dec 12, 2024
CVE-2024-28143
8.4 HIGH

The password change function at /cgi/admin.cgi does not require the current/old password, which makes the application vulnerable to account takeover. An attacker can use this …

Dec 12, 2024
CVE-2024-8233
7.5 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions from 9.4 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could …

Dec 12, 2024
CVE-2024-54107
7.1 HIGH

Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

Dec 12, 2024
CVE-2024-54106
7.1 HIGH

Null pointer dereference vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

Dec 12, 2024
CVE-2024-54098
8.5 HIGH

Service logic error vulnerability in the system service module Impact: Successful exploitation of this vulnerability may affect service integrity.

Dec 12, 2024
CVE-2024-54097
7.3 HIGH

Security vulnerability in the HiView module Impact: Successful exploitation of this vulnerability may affect feature implementation and integrity.

Dec 12, 2024
CVE-2024-11274
8.7 HIGH

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from …

Dec 12, 2024
CVE-2024-12397
7.4 HIGH

A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct …

Dec 12, 2024
CVE-2024-12312
8.1 HIGH

The Print Science Designer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.152 via deserialization of untrusted …

Dec 12, 2024
CVE-2024-12172
7.5 HIGH

The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to unauthorized access due to a …

Dec 12, 2024
CVE-2024-12040
8.8 HIGH

The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, …

Dec 12, 2024
CVE-2024-11052
7.2 HIGH

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the calculations parameter …

Dec 12, 2024
CVE-2024-10499
7.2 HIGH

The AI Engine WordPress plugin before 2.6.5 does not sanitize and escape a parameter from one of its RESP API endpoint before using it in …

Dec 12, 2024
CVE-2024-10910
7.3 HIGH

The The Grid Plus – Unlimited grid layout plugin for WordPress is vulnerable to arbitrary shortcode execution via grid_plus_load_by_category AJAX action in all versions up …

Dec 12, 2024
CVE-2024-10590
8.8 HIGH

The Opt-In Downloads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the admin_upload() function in all versions …

Dec 12, 2024
CVE-2024-11689
8.8 HIGH

The HQ Rental Software plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.29. This is due to …

Dec 12, 2024
CVE-2024-11443
8.8 HIGH

The de:branding plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on …

Dec 12, 2024
CVE-2024-10111
8.1 HIGH

The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.26.3. …

Dec 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.