CVE Database

53300+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6155
6.4 MEDIUM

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Authenticated (Subscriber+) Server-Side Request Forgery and Stored Cross Site Scripting in …

Jan 9, 2025
CVE-2024-5769
4.3 MEDIUM

The MIMO Woocommerce Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in …

Jan 9, 2025
CVE-2024-12819
6.4 MEDIUM

The Searchie plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sio_embed_media' shortcode in all versions up to, and including, 1.17.0 due …

Jan 9, 2025
CVE-2024-12621
6.4 MEDIUM

The Yumpu E-Paper publishing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'YUMPU' shortcode in all versions up to, and including, …

Jan 9, 2025
CVE-2024-12618
4.3 MEDIUM

The Newsletter2Go plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'resetStyles' AJAX action in all …

Jan 9, 2025
CVE-2024-12616
4.3 MEDIUM

The Bitly's WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in …

Jan 9, 2025
CVE-2024-12605
4.3 MEDIUM

The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is …

Jan 9, 2025
CVE-2024-12515
6.4 MEDIUM

The Muslim Prayer Time-Salah/Iqamah plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Masjid ID parameter in all versions up to, and including, …

Jan 9, 2025
CVE-2024-12514
6.4 MEDIUM

The 3DVieweronline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '3Dvo-model' shortcode in all versions up to, and including, 2.2.2 due …

Jan 9, 2025
CVE-2024-12496
6.4 MEDIUM

The Linear plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linear_block_buy_commissions' shortcode in all versions up to, and including, 2.7.12 due …

Jan 9, 2025
CVE-2024-12493
6.4 MEDIUM

The Files Download Delay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fddwrap' shortcode in all versions up to, and including, …

Jan 9, 2025
CVE-2024-12491
6.4 MEDIUM

The SimplyRETS Real Estate IDX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sr_search_form' shortcode in all versions up to, and …

Jan 9, 2025
CVE-2024-12394
6.1 MEDIUM

The Action Network plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.4.4 due …

Jan 9, 2025
CVE-2024-12285
6.1 MEDIUM

The SEMA API plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘catid’ parameter in all versions up to, and including, 5.27 due …

Jan 9, 2025
CVE-2024-12249
4.3 MEDIUM

The GS Insever Portfolio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_settings() function in …

Jan 9, 2025
CVE-2024-12222
6.1 MEDIUM

The Deliver via Shipos for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dvsfw_bulk_label_url’ parameter in all versions up to, and …

Jan 9, 2025
CVE-2024-12218
6.1 MEDIUM

The Woocommerce check pincode/zipcode for shipping plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.4. This is …

Jan 9, 2025
CVE-2024-12206
4.3 MEDIUM

The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.8. This …

Jan 9, 2025
CVE-2024-12122
6.1 MEDIUM

The ResAds plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions up to, and including, 2.0.6 due to insufficient …

Jan 9, 2025
CVE-2024-12067
6.5 MEDIUM

The WP Travel – Ultimate Travel Booking System, Tour Management Engine plugin for WordPress is vulnerable to SQL Injection via the 'booking_itinerary' parameter of the …

Jan 9, 2025
CVE-2024-11929
6.4 MEDIUM

The Responsive FlipBook Plugin Wordpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the rfbwp_save_settings() functionin all versions up to, and including, 2.5.0 …

Jan 9, 2025
CVE-2024-11907
6.4 MEDIUM

The Skyword API Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skyword_iframe' shortcode in all versions up to, and including, …

Jan 9, 2025
CVE-2024-11815
6.1 MEDIUM

The Pósturinn\'s Shipping with WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the printed_marked and nonprinted_marked parameters in all versions up to, …

Jan 9, 2025
CVE-2024-11686
6.1 MEDIUM

The WhatsApp 🚀 click to chat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'manycontacts_code' parameter in all versions up to, and …

Jan 9, 2025
CVE-2024-11328
6.1 MEDIUM

The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping …

Jan 9, 2025
CVE-2025-0346
4.7 MEDIUM

A vulnerability was found in code-projects Content Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/publishnews.php …

Jan 9, 2025
CVE-2025-0345
6.3 MEDIUM

A vulnerability was found in leiyuxi cy-fast 1.0 and classified as critical. Affected by this issue is the function listData of the file /sys/menu/listData. The …

Jan 9, 2025
CVE-2024-13153
6.4 MEDIUM

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.5.135 …

Jan 9, 2025
CVE-2025-0344
6.3 MEDIUM

A vulnerability has been found in leiyuxi cy-fast 1.0 and classified as critical. Affected by this vulnerability is the function listData of the file /commpara/listData. …

Jan 9, 2025
CVE-2025-0341
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in CampCodes Computer Laboratory Management System 1.0. Affected by this issue is some unknown functionality …

Jan 9, 2025
CVE-2024-12806
4.9 MEDIUM

A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file.

Jan 9, 2025
CVE-2025-20033
4.3 MEDIUM

Mattermost versions 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post types, which allows attackers to deny service to …

Jan 9, 2025
CVE-2025-0336
6.3 MEDIUM

A vulnerability was found in Codezips Project Management System 1.0. It has been classified as critical. This affects an unknown part of the file /pages/forms/teacher.php. …

Jan 9, 2025
CVE-2024-13041
4.2 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from …

Jan 9, 2025
CVE-2025-0335
6.3 MEDIUM

A vulnerability was found in code-projects Online Bike Rental System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Jan 9, 2025
CVE-2025-0334
6.3 MEDIUM

A vulnerability has been found in leiyuxi cy-fast 1.0 and classified as critical. Affected by this vulnerability is the function listData of the file /sys/user/listData. …

Jan 9, 2025
CVE-2024-6324
4.3 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from …

Jan 9, 2025
CVE-2024-12736
6.1 MEDIUM

The BU Section Editing WordPress plugin through 0.9.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jan 9, 2025
CVE-2024-12731
6.1 MEDIUM

The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jan 9, 2025
CVE-2024-12717
4.8 MEDIUM

The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jan 9, 2025
CVE-2024-12715
6.1 MEDIUM

The Asgard Security Scanner WordPress plugin through 0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jan 9, 2025
CVE-2024-12714
6.1 MEDIUM

The Backlink Monitoring Manager WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jan 9, 2025
CVE-2024-10815
4.2 MEDIUM

The PostLists WordPress plugin through 2.0.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site …

Jan 9, 2025
CVE-2025-0333
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in leiyuxi cy-fast 1.0. Affected is the function listData of the file /sys/role/listData. The manipulation of …

Jan 9, 2025
CVE-2025-0331
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in YunzMall up to 2.4.2. This issue affects the function changePwd of the file /app/platform/controllers/ResetpwdController.php …

Jan 9, 2025
CVE-2024-56827
5.6 MEDIUM

A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress …

Jan 9, 2025
CVE-2024-56826
5.6 MEDIUM

A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress …

Jan 9, 2025
CVE-2024-13212
6.3 MEDIUM

A vulnerability classified as critical has been found in SingMR HouseRent 1.0. This affects the function singleUpload/upload of the file src/main/java/com/house/wym/controller/AddHouseController.java. The manipulation of the …

Jan 9, 2025
CVE-2024-13211
6.3 MEDIUM

A vulnerability was found in SingMR HouseRent 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file …

Jan 9, 2025
CVE-2024-13210
4.7 MEDIUM

A vulnerability was found in donglight bookstore电商书城系统说明 1.0. It has been declared as critical. Affected by this vulnerability is the function uploadPicture of the file …

Jan 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.