CVE Database

39716+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-54209
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Awesome Shortcodes awesome-shortcodes allows Reflected XSS.This issue affects Awesome Shortcodes: from n/a …

Dec 6, 2024
CVE-2024-54208
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joni Halabi Block Controller block-controller allows Reflected XSS.This issue affects Block Controller: from …

Dec 6, 2024
CVE-2024-54205
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Paloma Paloma Widget postman-widget allows Cross Site Request Forgery.This issue affects Paloma Widget: from n/a through <= 1.14.

Dec 6, 2024
CVE-2024-53824
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in all_bootstrap_blocks All Bootstrap Blocks all-bootstrap-blocks allows PHP Local File …

Dec 6, 2024
CVE-2024-53821
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Genetech Pie Register Premium allows Reflected XSS.This issue affects Pie Register Premium: from …

Dec 6, 2024
CVE-2024-53817
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in acowebs Product Labels For Woocommerce aco-product-labels-for-woocommerce allows Blind SQL Injection.This issue …

Dec 6, 2024
CVE-2024-53815
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DOTonPAPER Pinpoint Booking System booking-system allows Blind SQL Injection.This issue affects …

Dec 6, 2024
CVE-2024-53812
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jacques Malgrange WP GeoNames wp-geonames allows Reflected XSS.This issue affects WP GeoNames: from …

Dec 6, 2024
CVE-2024-53808
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows SQL Injection.This issue affects NEX-Forms: from n/a …

Dec 6, 2024
CVE-2024-53807
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in brandtoss WP Mailster wp-mailster allows Blind SQL Injection.This issue affects WP …

Dec 6, 2024
CVE-2024-53805
7.5 HIGH

Missing Authorization vulnerability in brandtoss WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Mailster: from n/a through <= 1.8.16.0.

Dec 6, 2024
CVE-2024-53804
7.5 HIGH

Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster wp-mailster allows Retrieve Embedded Sensitive Data.This issue affects WP Mailster: from n/a through …

Dec 6, 2024
CVE-2024-21571
8.1 HIGH

Snyk has identified a remote code execution (RCE) vulnerability in all versions of Code Agent. The vulnerability enables an attacker to execute arbitrary code within …

Dec 6, 2024
CVE-2024-10516
8.1 HIGH

The Swift Performance Lite plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 2.3.7.1 via the 'ajaxify' …

Dec 6, 2024
CVE-2024-10776
8.2 HIGH

Lua apps can be deployed, removed, started, reloaded or stopped without authorization via AppManager. This allows an attacker to remove legitimate apps creating a DoS …

Dec 6, 2024
CVE-2024-10774
7.3 HIGH

Unauthenticated CROWN APIs allow access to critical functions. This leads to the accessibility of large parts of the web application without authentication.

Dec 6, 2024
CVE-2024-10772
8.8 HIGH

Since the firmware update is not validated, an attacker can install modified firmware on the device. This has a high impact on the availabilty, integrity …

Dec 6, 2024
CVE-2024-10771
8.8 HIGH

Due to missing input validation during one step of the firmware update process, the product is vulnerable to remote code execution. With network access and …

Dec 6, 2024
CVE-2024-53907
7.5 HIGH

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject …

Dec 6, 2024
CVE-2024-53142
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: initramfs: avoid filename buffer overrun The initramfs filename field is defined in Documentation/driver-api/early-userspace/buffer-format.rst as: 37 …

Dec 6, 2024
CVE-2024-53141
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: add missing range check in bitmap_ip_uadt When tb[IPSET_ATTR_IP_TO] is not present but tb[IPSET_ATTR_CIDR] …

Dec 6, 2024
CVE-2024-11728
7.5 HIGH

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'visit_type[service_id]' parameter of the tax_calculated_data AJAX …

Dec 6, 2024
CVE-2024-11460
7.5 HIGH

The Verowa Connect plugin for WordPress is vulnerable to SQL Injection via the 'search_string' parameter in all versions up to, and including, 3.0.1 due to …

Dec 6, 2024
CVE-2024-11289
8.1 HIGH

The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.5.9 via several functions like penci_archive_more_post_ajax_func, penci_more_post_ajax_func, …

Dec 6, 2024
CVE-2024-11323
8.8 HIGH

The AI Quiz | Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a …

Dec 6, 2024
CVE-2024-11178
8.1 HIGH

The Login With OTP plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.4.2. This is due to the plugin …

Dec 6, 2024
CVE-2024-11585
7.5 HIGH

The WP Hide & Security Enhancer plugin for WordPress is vulnerable to arbitrary file contents deletion due to a missing authorization and insufficient file path …

Dec 6, 2024
CVE-2024-10578
8.8 HIGH

The Pubnews theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the pubnews_importer_plugin_action_for_notice() function in all versions …

Dec 6, 2024
CVE-2024-10247
7.2 HIGH

The Video Gallery – Best WordPress YouTube Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the orderby parameter in all versions …

Dec 6, 2024
CVE-2024-11149
7.9 HIGH

In OpenBSD 7.4 before errata 014, vmm(4) did not restore GDTR limits properly on Intel (VMX) CPUs.

Dec 6, 2024
CVE-2024-38910
7.5 HIGH

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a use-after-free in the nav2_amcl process. This vulnerability is triggered …

Dec 5, 2024
CVE-2024-37862
7.3 HIGH

Buffer Overflow vulnerability in Open Robotic Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allows a local attacker to execute arbitrary code via a crafted …

Dec 5, 2024
CVE-2024-37860
7.3 HIGH

Buffer Overflow vulnerability in Open Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allows a local attacker to execute arbitrary code via a crafted .yaml …

Dec 5, 2024
CVE-2024-30964
7.8 HIGH

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via …

Dec 5, 2024
CVE-2024-30963
7.8 HIGH

Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via …

Dec 5, 2024
CVE-2024-30962
7.8 HIGH

Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via …

Dec 5, 2024
CVE-2024-30961
7.8 HIGH

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via …

Dec 5, 2024
CVE-2024-53523
7.5 HIGH

JSFinder commit d70ab9bc5221e016c08cffaf0d9ac79646c90645 is vulnerable to Directory Traversal in the find_by_file function.

Dec 5, 2024
CVE-2024-53589
8.4 HIGH

GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.

Dec 5, 2024
CVE-2024-11148
7.5 HIGH

In OpenBSD 7.4 before errata 006 and OpenBSD 7.3 before errata 020, httpd(8) is vulnerable to a NULL dereference when handling a malformed fastcgi request.

Dec 5, 2024
CVE-2024-12130
7.8 HIGH

An “out of bounds read” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file …

Dec 5, 2024
CVE-2024-11156
7.8 HIGH

An “out of bounds write” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries …

Dec 5, 2024
CVE-2024-11155
7.8 HIGH

A “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and …

Dec 5, 2024
CVE-2024-53490
7.5 HIGH

Favorites-web 1.3.0 favorites-web has a directory traversal vulnerability in SecurityFilter.java.

Dec 5, 2024
CVE-2024-12234
7.3 HIGH

A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been classified as critical. Affected is an unknown function of the …

Dec 5, 2024
CVE-2024-12233
7.3 HIGH

A vulnerability was found in code-projects Online Notice Board up to 1.0 and classified as critical. This issue affects some unknown processing of the file …

Dec 5, 2024
CVE-2024-53857
7.5 HIGH

rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows attackers to trigger resource exhaustion vulnerabilities in rpgp by providing crafted messages. …

Dec 5, 2024
CVE-2024-53856
7.5 HIGH

rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows an attacker to trigger rpgp crashes by providing crafted data. This vulnerability …

Dec 5, 2024
CVE-2024-53472
8.8 HIGH

WeGIA v3.2.0 was discovered to contain a Cross-Site Request Forgery (CSRF).

Dec 5, 2024
CVE-2024-12231
7.3 HIGH

A vulnerability, which was classified as critical, was found in CodeZips Project Management System 1.0. This affects an unknown part of the file /index.php. The …

Dec 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.