CVE Database

53300+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-13583
6.4 MEDIUM

The Simple Gallery with Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'c2tw_sgwf' shortcode in all versions up to, and …

Jan 24, 2025
CVE-2024-12494
6.4 MEDIUM

The BMLT Meeting Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bmlt_meeting_map' shortcode in all versions up to, and including, …

Jan 24, 2025
CVE-2024-13683
4.3 MEDIUM

The Automate Hub Free by Sperse.IO plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.0. This is …

Jan 24, 2025
CVE-2024-13680
6.5 MEDIUM

The Form Builder CP plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'CP_EASY_FORM_WILL_APPEAR_HERE' shortcode in all versions up to, …

Jan 24, 2025
CVE-2024-13659
6.4 MEDIUM

The Listamester plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'listamester' shortcode in all versions up to, and including, 2.3.4 due …

Jan 24, 2025
CVE-2024-11931
6.4 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 …

Jan 24, 2025
CVE-2021-42718
4.9 MEDIUM

Information Disclosure in API in Replicated Replicated Classic versions prior to 2.53.1 on all platforms allows authenticated users with Admin Console access to retrieve sensitive …

Jan 23, 2025
CVE-2025-0693
5.3 MEDIUM

Variable response times in the AWS Sign-in IAM user login flow allowed for the use of brute force enumeration techniques to identify valid IAM usernames …

Jan 23, 2025
CVE-2024-57556
6.1 MEDIUM

Cross Site Scripting vulnerability in nbubna store v.2.14.2 and before allows a remote attacker to execute arbitrary code via the store.deep.js component

Jan 23, 2025
CVE-2024-57386
6.1 MEDIUM

Cross Site Scripting vulnerability in Wallos v.2.41.0 allows a remote attacker to execute arbitrary code via the profile picture function.

Jan 23, 2025
CVE-2024-57329
5.4 MEDIUM

HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers …

Jan 23, 2025
CVE-2024-57326
6.1 MEDIUM

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the search.php file of the Online Pizza Delivery System 1.0. The vulnerability allows an attacker to execute …

Jan 23, 2025
CVE-2024-50665
5.5 MEDIUM

gpac 2.4 contains a SEGV at src/isomedia/drm_sample.c:1562:96 in isom_cenc_get_sai_by_saiz_saio in MP4Box.

Jan 23, 2025
CVE-2025-24353
5.0 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.2.0, when sharing an item, a typical user can …

Jan 23, 2025
CVE-2025-23227
6.4 MEDIUM

IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.11 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code …

Jan 23, 2025
CVE-2024-55930
6.7 MEDIUM

Xerox Workplace Suite has weak default folder permissions that allow unauthorized users to access, modify, or delete files

Jan 23, 2025
CVE-2024-55929
5.3 MEDIUM

A mail spoofing vulnerability in Xerox Workplace Suite allows attackers to forge email headers, making it appear as though messages are sent from trusted sources.

Jan 23, 2025
CVE-2024-55928
6.5 MEDIUM

Xerox Workplace Suite exposes sensitive secrets in clear text, both locally and remotely. This vulnerability allows attackers to intercept or access secrets without encryption

Jan 23, 2025
CVE-2024-45672
6.0 MEDIUM

IBM Security Verify Bridge 1.0.0 through 1.0.15 could allow a local privileged user to overwrite files due to excessive privileges granted to the agent. which …

Jan 23, 2025
CVE-2024-52327
6.5 MEDIUM

The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry required to access the live video feed.

Jan 23, 2025
CVE-2024-12078
6.3 MEDIUM

ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated attacker within BLE range can control …

Jan 23, 2025
CVE-2024-10846
5.9 MEDIUM

The compose-go library component in versions v2.10-v2.4.0 allows an authorized user who sends malicious YAML payloads to cause the compose-go to consume excessive amount of …

Jan 23, 2025
CVE-2024-57947
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo: fix initial map fill The initial buffer has to be inited to all-ones, …

Jan 23, 2025
CVE-2024-10539
5.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uyumsoft Informatin Systems Uyumsoft ERP allows XSS Using Invalid Characters, Reflected …

Jan 23, 2025
CVE-2024-13422
6.1 MEDIUM

The SEO Blogger to WordPress Migration using 301 Redirection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter in all versions …

Jan 23, 2025
CVE-2024-13389
6.4 MEDIUM

The Cliptakes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cliptakes_input_email' shortcode in all versions up to, and including, 1.3.4 due …

Jan 23, 2025
CVE-2024-13340
6.4 MEDIUM

The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mdf_results_by_ajax' shortcode in all versions …

Jan 23, 2025
CVE-2024-13236
6.5 MEDIUM

The Tainacan plugin for WordPress is vulnerable to SQL Injection via the 'collection_id' parameter in all versions up to, and including, 0.21.12 due to insufficient …

Jan 23, 2025
CVE-2024-12504
6.4 MEDIUM

The Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's …

Jan 23, 2025
CVE-2024-12118
6.4 MEDIUM

The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Widget through the html_tag attribute in all …

Jan 23, 2025
CVE-2025-0648
4.9 MEDIUM

Unexpected server crash in database driver in M-Files Server before 25.1.14445.5 and before 24.8 LTS SR3 allows a highly privileged attacker to cause denial of …

Jan 23, 2025
CVE-2025-0619
4.9 MEDIUM

Unsafe password recovery from configuration in M-Files Server before 25.1 allows a highly privileged user to recover external connector passwords

Jan 23, 2025
CVE-2024-43708
6.5 MEDIUM

An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted payload to a number of …

Jan 23, 2025
CVE-2024-12043
6.4 MEDIUM

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider) plugin for WordPress is vulnerable to Stored …

Jan 23, 2025
CVE-2024-13511
4.3 MEDIUM

The Variation Swatches for WooCommerce plugin, in all versions starting at 1.0.8 up until 1.3.2, contains a vulnerability due to improper nonce verification in its …

Jan 23, 2025
CVE-2024-53299
6.5 MEDIUM

The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server …

Jan 23, 2025
CVE-2024-52972
6.5 MEDIUM

An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted request to /api/metrics/snapshot. This can …

Jan 23, 2025
CVE-2025-24530
6.4 MEDIUM

An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the check tables feature. A crafted table or database …

Jan 23, 2025
CVE-2025-24529
6.4 MEDIUM

An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the Insert tab.

Jan 23, 2025
CVE-2024-43710
4.3 MEDIUM

A server side request forgery vulnerability was identified in Kibana where the /api/fleet/health_check API could be used to send requests to internal endpoints. Due to …

Jan 23, 2025
CVE-2024-42187
5.3 MEDIUM

BigFix Patch Download Plug-ins are affected by path traversal vulnerability. The application could allow operators to download files from a local repository which is vulnerable …

Jan 23, 2025
CVE-2023-50309
6.4 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Jan 23, 2025
CVE-2023-32340
4.6 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …

Jan 23, 2025
CVE-2024-57724
6.5 MEDIUM

lunasvg v3.0.0 was discovered to contain a segmentation violation via the component gray_record_cell.

Jan 23, 2025
CVE-2024-57723
6.5 MEDIUM

lunasvg v3.0.0 was discovered to contain a segmentation violation via the component composition_source_over.

Jan 23, 2025
CVE-2024-57721
6.5 MEDIUM

lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_path_add_path.

Jan 23, 2025
CVE-2024-57720
6.5 MEDIUM

lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_blend.

Jan 23, 2025
CVE-2024-57719
6.5 MEDIUM

lunasvg v3.0.0 was discovered to contain a segmentation violation via the component blend_transformed_tiled_argb.isra.0.

Jan 23, 2025
CVE-2024-12477
6.4 MEDIUM

The Avada Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.11.11 due …

Jan 22, 2025
CVE-2024-56923
5.4 MEDIUM

Stored Cross-Site Scripting (XSS) Vulnerability in the Categorization Option of My Subscriptions Functionality in Silverpeas Core 6.3.1 <= 6.4.1 allows a remote attacker to execute …

Jan 22, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.