CVE Database

53300+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-12852
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_cmc_text' parameter of the Happy Mouse Cursor in all …

Jan 8, 2025
CVE-2024-12851
6.4 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jan 8, 2025
CVE-2024-12584
4.3 MEDIUM

The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and …

Jan 8, 2025
CVE-2024-12585
6.1 MEDIUM

The Property Hive WordPress plugin before 2.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jan 8, 2025
CVE-2024-10585
5.3 MEDIUM

The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 via the 'historyID' parameter of the …

Jan 8, 2025
CVE-2024-10151
5.4 MEDIUM

The Auto iFrame WordPress plugin before 2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Jan 8, 2025
CVE-2024-54731
4.0 MEDIUM

cpdf through 2.8 allows stack consumption via a crafted PDF document.

Jan 8, 2025
CVE-2024-12205
6.4 MEDIUM

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider Widget in all versions up to, …

Jan 8, 2025
CVE-2024-12030
6.5 MEDIUM

The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection via the 'key' attribute of the 'mdf_value' shortcode in …

Jan 8, 2025
CVE-2025-21603
4.8 MEDIUM

Cross-site scripting vulnerability exists in MZK-DP300N firmware versions 1.05 and earlier. If an attacker logs in to the affected product and manipulates the device settings, …

Jan 8, 2025
CVE-2024-56456
6.8 MEDIUM

Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-56455
5.5 MEDIUM

Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-56454
5.5 MEDIUM

Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-56453
6.8 MEDIUM

Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-56452
5.5 MEDIUM

Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-56450
6.3 MEDIUM

Buffer overflow vulnerability in the component driver module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-56449
6.6 MEDIUM

Privilege escalation vulnerability in the Account module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jan 8, 2025
CVE-2024-56448
6.7 MEDIUM

Vulnerability of improper access control in the home screen widget module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-54121
6.2 MEDIUM

Startup control vulnerability in the ability module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Jan 8, 2025
CVE-2024-12713
5.3 MEDIUM

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, …

Jan 8, 2025
CVE-2024-12521
6.4 MEDIUM

The Slotti Ajanvaraus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slotti-embed-ga' shortcode in all versions up to, and including, 1.3.1 …

Jan 8, 2025
CVE-2024-12112
6.4 MEDIUM

The Easy Form Builder – WordPress plugin form builder: contact form, survey form, payment form, and custom form builder plugin for WordPress is vulnerable to …

Jan 8, 2025
CVE-2024-56446
4.0 MEDIUM

Vulnerability of variables not being initialized in the notification module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-56445
4.3 MEDIUM

Instruction authentication bypass vulnerability in the Findnetwork module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Jan 8, 2025
CVE-2024-56443
6.2 MEDIUM

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jan 8, 2025
CVE-2024-56442
5.5 MEDIUM

Vulnerability of native APIs not being implemented in the NFC service module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Jan 8, 2025
CVE-2024-56441
4.1 MEDIUM

Race condition vulnerability in the Bastet module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jan 8, 2025
CVE-2024-56440
6.2 MEDIUM

Permission control vulnerability in the Connectivity module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Jan 8, 2025
CVE-2024-56438
6.0 MEDIUM

Vulnerability of improper memory address protection in the HUKS module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-56437
5.7 MEDIUM

Vulnerability of input parameters not being verified in the widget framework module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-54120
4.1 MEDIUM

Race condition vulnerability in the distributed notification module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Jan 8, 2025
CVE-2024-47934
5.3 MEDIUM

Improper Input Validation vulnerability in Management Program in TXOne Networks Portable Inspector and Portable Inspector Pro Edition allows remote attacker to crash management service. The …

Jan 8, 2025
CVE-2024-47239
6.5 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.9.0.0 contain an uncontrolled resource consumption vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to …

Jan 8, 2025
CVE-2023-52955
6.5 MEDIUM

Vulnerability of improper authentication in the ANS system service module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Jan 8, 2025
CVE-2023-52954
4.4 MEDIUM

Vulnerability of improper permission control in the Gallery module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2023-52953
6.2 MEDIUM

Path traversal vulnerability in the Medialibrary module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

Jan 8, 2025
CVE-2024-56436
5.5 MEDIUM

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jan 8, 2025
CVE-2024-56435
6.2 MEDIUM

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jan 8, 2025
CVE-2024-56434
4.4 MEDIUM

UAF vulnerability in the device node access module Impact: Successful exploitation of this vulnerability may cause service exceptions of the device.

Jan 8, 2025
CVE-2024-40679
5.5 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an information disclosure vulnerability as sensitive information may be included …

Jan 8, 2025
CVE-2025-0218
5.5 MEDIUM

When batch jobs are executed by pgAgent, a script is created in a temporary directory and then executed. In versions of pgAgent prior to 4.2.3, …

Jan 7, 2025
CVE-2024-55218
6.1 MEDIUM

IceWarp Server 10.2.1 is vulnerable to Cross Site Scripting (XSS) via the meta parameter.

Jan 7, 2025
CVE-2024-50659
6.1 MEDIUM

Cross Site Scripting vulnerability iPublish Media Solutions AdPortal 3.0.39 allows a remote attacker to escalate privileges via the shippingAsBilling parameter in updateuserinfo.html.

Jan 7, 2025
CVE-2024-44450
5.4 MEDIUM

Multiple functions are vulnerable to Authorization Bypass in AIMS eCrew. The issue was fixed in version JUN23 #190.

Jan 7, 2025
CVE-2025-22621
6.4 MEDIUM

In versions 1.0.67 and lower of the Splunk App for SOAR, the Splunk documentation for that app recommended adding the `admin_all_objects` capability to the `splunk_app_soar` …

Jan 7, 2025
CVE-2025-22500
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ali Ali Alpha Price Table For Elementor alpha-price-table-for-elementor allows DOM-Based XSS.This issue affects …

Jan 7, 2025
CVE-2025-22365
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric McNiece EMC2 Alert Boxes allows Stored XSS.This issue affects EMC2 Alert Boxes: …

Jan 7, 2025
CVE-2025-22363
5.3 MEDIUM

Missing Authorization vulnerability in Hermann LAHAMI Allada T-shirt Designer for Woocommerce allada-tshirt-designer-for-woocommerce.This issue affects Allada T-shirt Designer for Woocommerce: from n/a through <= 1.1.

Jan 7, 2025
CVE-2025-22354
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Code Themes Digi Store allows DOM-Based XSS.This issue affects Digi Store: from n/a …

Jan 7, 2025
CVE-2025-22334
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FilaThemes Education LMS allows Stored XSS.This issue affects Education LMS: from n/a through …

Jan 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.