CVE Database

39807+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-49251
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Acnoo Maan Addons For Elementor maan-elementor-addons allows Local Code …

Oct 16, 2024
CVE-2024-49245
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in nahimsalami Ahime Image Printer ahime-image-printer.This issue affects Ahime Image Printer: from n/a …

Oct 16, 2024
CVE-2024-49226
8.8 HIGH

Deserialization of Untrusted Data vulnerability in taketin TAKETIN To WP Membership taketin-to-wp-membership allows Object Injection.This issue affects TAKETIN To WP Membership: from n/a through <= …

Oct 16, 2024
CVE-2024-48029
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hung Trang Si SB Random Posts Widget sb-random-posts-widget allows …

Oct 16, 2024
CVE-2024-47645
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Danish Ali Malik Top Bar – PopUps – by WPOptin wpoptin allows …

Oct 16, 2024
CVE-2024-47637
8.8 HIGH

Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue affects LiteSpeed Cache: from n/a through <= 6.4.1.

Oct 16, 2024
CVE-2024-47351
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The CSSIgniter Team MaxSlider maxslider allows Path Traversal.This issue affects MaxSlider: from …

Oct 16, 2024
CVE-2024-22030
8.0 HIGH

A vulnerability has been identified within Rancher that can be exploited in narrow circumstances through a man-in-the-middle (MITM) attack. An attacker would need to have …

Oct 16, 2024
CVE-2024-22029
7.8 HIGH

Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root

Oct 16, 2024
CVE-2023-32194
7.2 HIGH

A vulnerability has been identified when granting a create or * global role for a resource type of "namespaces"; no matter the API group, the …

Oct 16, 2024
CVE-2023-32193
8.3 HIGH

A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in Norman's public API endpoint can be exploited. This can lead to an attacker …

Oct 16, 2024
CVE-2023-32192
8.3 HIGH

A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in the API Server's public API endpoint can be exploited, allowing an attacker to …

Oct 16, 2024
CVE-2024-8040
7.7 HIGH

An authorization bypass through user-controlled key vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an authenticated attacker to access some unauthorized data.

Oct 16, 2024
CVE-2024-6380
8.7 HIGH

A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary …

Oct 16, 2024
CVE-2023-32190
7.8 HIGH

mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.

Oct 16, 2024
CVE-2024-9858
7.8 HIGH

There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windows installs. A local "m2cuser" was greated …

Oct 16, 2024
CVE-2023-22650
8.8 HIGH

A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from the configured authentication provider (AP). …

Oct 16, 2024
CVE-2024-9061
7.3 HIGH

The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary shortcode execution via the wp_ajax_nopriv_shortcode_Api_Add AJAX …

Oct 16, 2024
CVE-2024-45715
7.1 HIGH

The SolarWinds Platform was susceptible to a Cross-Site Scripting vulnerability when performing an edit function to existing elements.

Oct 16, 2024
CVE-2024-45711
7.5 HIGH

SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible depending on privileges given to the authenticated user. This issue …

Oct 16, 2024
CVE-2024-45710
7.8 HIGH

SolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This requires a low privilege account and local access to the …

Oct 16, 2024
CVE-2024-45693
8.0 HIGH

Users logged into the Apache CloudStack's web interface can be tricked to submit malicious CSRF requests due to missing validation of the origin of the …

Oct 16, 2024
CVE-2024-45219
8.5 HIGH

Account users in Apache CloudStack by default are allowed to upload and register templates for deploying instances and volumes for attaching them as data disks …

Oct 16, 2024
CVE-2024-45217
8.1 HIGH

Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore command, which copy a configSet from the backup …

Oct 16, 2024
CVE-2023-22649
8.4 HIGH

A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. [Rancher Audit Logging](https://ranchermanager.docs.rancher.com/how-to-guides/advanced-user-guides/enable-api-audit-log) is an opt-in feature, only …

Oct 16, 2024
CVE-2021-4452
7.1 HIGH

The Google Language Translator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions up to, and including, 6.0.9 due to …

Oct 16, 2024
CVE-2020-36842
8.8 HIGH

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvivid_upload_import_files and …

Oct 16, 2024
CVE-2020-36840
7.3 HIGH

The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_route_url() function …

Oct 16, 2024
CVE-2024-8918
7.4 HIGH

The File Manager Pro plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 8.3.9. This is due …

Oct 16, 2024
CVE-2024-8746
7.5 HIGH

The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing file type validation via the 'mk_file_folder_manager_shortcode' …

Oct 16, 2024
CVE-2024-8507
8.8 HIGH

The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.3.9. This is due to …

Oct 16, 2024
CVE-2023-7294
7.1 HIGH

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the create_mollie_profile …

Oct 16, 2024
CVE-2023-7291
7.1 HIGH

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Oct 16, 2024
CVE-2022-4972
7.5 HIGH

The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in …

Oct 16, 2024
CVE-2021-4450
8.8 HIGH

The Post Grid plugin for WordPress is vulnerable to blind SQL Injection via post metadata in versions up to, and including, 2.1.12 due to insufficient …

Oct 16, 2024
CVE-2021-4448
7.3 HIGH

The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.0.1 due to insufficient capability checking …

Oct 16, 2024
CVE-2021-4447
8.8 HIGH

The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of …

Oct 16, 2024
CVE-2021-4444
7.3 HIGH

The Product Filter by WooBeWoo plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.4.9 due to missing authorization checks …

Oct 16, 2024
CVE-2020-36839
8.3 HIGH

The WP Lead Plus X plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.99. This is due to …

Oct 16, 2024
CVE-2020-36838
7.4 HIGH

The Facebook Chat Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_update_options function in versions up to, …

Oct 16, 2024
CVE-2020-36836
8.0 HIGH

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and including, 0.9.0.2 due to a lack …

Oct 16, 2024
CVE-2019-25216
7.2 HIGH

The Rich Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the POST body 'update' parameter in versions up to, and including, 1.7.4 …

Oct 16, 2024
CVE-2019-25215
7.3 HIGH

The ARI-Adminer plugin for WordPress is vulnerable to authorization bypass due to a lack of file access controls in nearly every file of the plugin …

Oct 16, 2024
CVE-2019-25214
7.2 HIGH

The ShopWP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST API routes in versions up to, …

Oct 16, 2024
CVE-2017-20192
8.3 HIGH

The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before …

Oct 16, 2024
CVE-2016-15041
7.2 HIGH

The MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mwp_setup_purchase_username’ parameter …

Oct 16, 2024
CVE-2012-10018
8.3 HIGH

The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and including 6.1, 1.0 respectively. This makes …

Oct 16, 2024
CVE-2024-9305
8.1 HIGH

The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.4. …

Oct 16, 2024
CVE-2024-38204
7.5 HIGH

Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network.

Oct 15, 2024
CVE-2024-38190
8.6 HIGH

Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector.

Oct 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.