CVE Database

53200+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-56882
5.4 MEDIUM

Sage DPW before 2024_12_000 is vulnerable to Cross Site Scripting (XSS). Low-privileged Sage users with employee role privileges can permanently store JavaScript code in the …

Feb 18, 2025
CVE-2024-49589
6.5 MEDIUM

Foundry Artifacts was found to be vulnerable to a Denial Of Service attack due to disk being potentially filled up based on an user supplied …

Feb 18, 2025
CVE-2024-39328
6.8 MEDIUM

Insecure Permissions in Atos Eviden IDRA and IDCA before 2.7.0. A highly trusted role (Config Admin) could exceed their configuration privileges in a multi-partition environment …

Feb 18, 2025
CVE-2022-41545
6.4 MEDIUM

The administrative web interface of a Netgear C7800 Router running firmware version 6.01.07 (and possibly others) authenticates users via basic authentication, with an HTTP header …

Feb 18, 2025
CVE-2024-13689
6.3 MEDIUM

The Uncode Core plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.9.1.6. This is due to the …

Feb 18, 2025
CVE-2025-1414
6.5 MEDIUM

Memory safety bugs present in Firefox 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of …

Feb 18, 2025
CVE-2025-1269
4.8 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HAVELSAN Liman MYS allows Cross-Site Flashing.This issue affects Liman MYS: before 2.1.1 - 1010.

Feb 18, 2025
CVE-2025-1035
5.7 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls.This …

Feb 18, 2025
CVE-2024-13783
4.3 MEDIUM

The FormCraft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in formcraft-main.php in all versions up to, …

Feb 18, 2025
CVE-2024-13691
6.5 MEDIUM

The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_recordMedia' function in all versions up to, …

Feb 18, 2025
CVE-2024-13667
5.4 MEDIUM

The Uncode theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mle-description’ parameter in all versions up to, and including, 2.9.1.6 due to …

Feb 18, 2025
CVE-2025-0981
6.1 MEDIUM

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's session by exploiting a Stored Cross Site Scripting (XSS) …

Feb 18, 2025
CVE-2024-13369
6.5 MEDIUM

The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to time-based SQL Injection via the ‘review_id’ parameter in all versions up …

Feb 18, 2025
CVE-2024-13718
4.3 MEDIUM

The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up …

Feb 18, 2025
CVE-2024-13395
6.4 MEDIUM

The Threepress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'threepress' shortcode in all versions up to, and including, 1.7.1 due …

Feb 18, 2025
CVE-2024-13316
5.3 MEDIUM

The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable to unauthorized access …

Feb 18, 2025
CVE-2025-0864
6.1 MEDIUM

The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcodes_set' parameter in …

Feb 18, 2025
CVE-2024-13795
4.3 MEDIUM

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.27. This …

Feb 18, 2025
CVE-2024-13575
6.4 MEDIUM

The Web Stories Enhancer – Level Up Your Web Stories plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'web_stories_enhancer' shortcode in …

Feb 18, 2025
CVE-2024-13465
6.4 MEDIUM

The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Table Of Content" Block, specifically in the "markerView" …

Feb 18, 2025
CVE-2024-11895
6.4 MEDIUM

The Online Payments – Get Paid with PayPal, Square & Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in …

Feb 18, 2025
CVE-2024-11376
6.1 MEDIUM

The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting …

Feb 18, 2025
CVE-2024-13523
6.1 MEDIUM

The MemorialDay plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing or …

Feb 18, 2025
CVE-2024-45320
6.5 MEDIUM

Out-of-bounds write vulnerability exists in DocuPrint CP225w 01.22.01 and earlier, DocuPrint CP228w 01.22.01 and earlier, DocuPrint CM225fw 01.10.01 and earlier, and DocuPrint CM228fw 01.10.01 and …

Feb 18, 2025
CVE-2024-13438
4.3 MEDIUM

The SpeedSize Image & Video AI-Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.1. This is …

Feb 18, 2025
CVE-2025-0805
6.4 MEDIUM

The Mortgage Calculator / Loan Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mlcalc' shortcode in all versions up to, …

Feb 18, 2025
CVE-2025-0796
4.3 MEDIUM

The Mortgage Lead Capture System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.2.11. This is due …

Feb 18, 2025
CVE-2024-13848
5.5 MEDIUM

The Reaction Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.6 due to …

Feb 18, 2025
CVE-2024-13687
4.3 MEDIUM

The Team Builder – Meet the Team plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Feb 18, 2025
CVE-2024-13609
5.9 MEDIUM

The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions …

Feb 18, 2025
CVE-2024-13595
6.5 MEDIUM

The Simple Signup Form plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'ssf' shortcode in all versions up to, …

Feb 18, 2025
CVE-2024-13588
6.4 MEDIUM

The Simplebooklet PDF Viewer and Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'simplebooklet' shortcode in all versions up to, …

Feb 18, 2025
CVE-2024-13587
6.4 MEDIUM

The Zigaform – Price Calculator & Cost Estimation Form Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zgfm_fvar' shortcode …

Feb 18, 2025
CVE-2024-13582
6.4 MEDIUM

The Simple Pricing Tables For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wdo_simple_pricing_table_free' shortcode in …

Feb 18, 2025
CVE-2024-13581
6.4 MEDIUM

The Simple Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'simple_chart' shortcode in all versions up to, and including, 1.0 …

Feb 18, 2025
CVE-2024-13579
6.4 MEDIUM

The WP-Asambleas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'polls_popup' shortcode in all versions up to, and including, 2.85.0 due …

Feb 18, 2025
CVE-2024-13578
6.4 MEDIUM

The WP-BibTeX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'WpBibTeX' shortcode in all versions up to, and including, 3.0.1 due …

Feb 18, 2025
CVE-2024-13577
6.4 MEDIUM

The CATS Job Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catsone' shortcode in all versions up to, and including, …

Feb 18, 2025
CVE-2024-13576
6.4 MEDIUM

The Gumlet Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gumlet' shortcode in all versions up to, and including, 1.0.3 …

Feb 18, 2025
CVE-2024-13573
6.4 MEDIUM

The Zigaform – Form Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zgfm_rfvar' shortcode in all versions up to, …

Feb 18, 2025
CVE-2024-13565
6.4 MEDIUM

The Simple Map No Api plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions up to, and including, …

Feb 18, 2025
CVE-2024-13555
5.3 MEDIUM

The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions …

Feb 18, 2025
CVE-2024-13540
5.3 MEDIUM

The WooODT Lite – Delivery & pickup date time location for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up …

Feb 18, 2025
CVE-2024-13538
5.3 MEDIUM

The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.0. This is …

Feb 18, 2025
CVE-2024-13535
5.3 MEDIUM

The Actionwear products sync plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.3.2. This is due the …

Feb 18, 2025
CVE-2024-13522
6.1 MEDIUM

The magayo Lottery Results plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.12. This is due to …

Feb 18, 2025
CVE-2024-13501
6.4 MEDIUM

The WP-FormAssembly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'formassembly' shortcode in all versions up to, and including, 2.0.11 due …

Feb 18, 2025
CVE-2024-13464
6.4 MEDIUM

The Library Bookshelves plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bookshelf' shortcode in all versions up to, and including, 5.10 …

Feb 18, 2025
CVE-2024-12813
6.4 MEDIUM

The Open Hours – Easy Opening Hours plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'open-hours-current-status' shortcode in all versions up …

Feb 18, 2025
CVE-2024-12525
6.4 MEDIUM

The Easy MLS Listings Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasap-featured-listings' shortcode in all versions up to, and …

Feb 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.