CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-56271
4.3 MEDIUM

Missing Authorization vulnerability in SecureSubmit WP SecureSubmit securesubmit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP SecureSubmit: from n/a through <= 1.5.20.

Jan 7, 2025
CVE-2024-51651
5.3 MEDIUM

Missing Authorization vulnerability in Imran Tauqeer CubeWP Forms cubewp-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CubeWP Forms: from n/a through <= …

Jan 7, 2025
CVE-2024-49294
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation allows Cross Site Request Forgery.This issue affects Bus Ticket Booking with …

Jan 7, 2025
CVE-2024-12719
4.3 MEDIUM

The WordPress File Upload plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wfu_ajax_action_read_subfolders' function in …

Jan 7, 2025
CVE-2024-12699
6.4 MEDIUM

The Service Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.9 due to insufficient input sanitization …

Jan 7, 2025
CVE-2024-54030
4.4 MEDIUM

in OpenHarmony v4.1.2 and prior versions allow a local attacker cause DOS through use after free.

Jan 7, 2025
CVE-2024-45070
5.5 MEDIUM

in OpenHarmony v4.1.2 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

Jan 7, 2025
CVE-2024-12516
6.4 MEDIUM

The Coupon Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Coupon Code' parameter in all versions up to, and including, 1.2.1 …

Jan 7, 2025
CVE-2024-12077
6.1 MEDIUM

The Booking Calendar and Booking Calendar Pro plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the ‘calendar_id’ parameter in all versions up to, …

Jan 7, 2025
CVE-2024-11627
6.8 MEDIUM

: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 …

Jan 7, 2025
CVE-2024-10866
5.3 MEDIUM

The Export Import Menus plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dsp_export_import_menus() function in …

Jan 7, 2025
CVE-2024-9502
6.4 MEDIUM

The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Jan 7, 2025
CVE-2024-9354
6.1 MEDIUM

The Estatik Mortgage Calculator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'color' parameter in all versions up to, and including, 2.0.11 …

Jan 7, 2025
CVE-2024-12781
4.3 MEDIUM

The Aurum - WordPress & WooCommerce Shopping Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Jan 7, 2025
CVE-2024-12624
6.4 MEDIUM

The Sina Extension for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sina Image Differ widget in all versions up …

Jan 7, 2025
CVE-2024-12499
6.4 MEDIUM

The WP jQuery DataTable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_jdt' shortcode in all versions up to, and including, …

Jan 7, 2025
CVE-2024-12495
6.4 MEDIUM

The Bootstrap Blocks for WP Editor v2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gtb-bootstrap/column' block in all versions up to, …

Jan 7, 2025
CVE-2024-12437
6.4 MEDIUM

The Marketplace Items plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'envato' shortcode in all versions up to, and including, 1.5.5 …

Jan 7, 2025
CVE-2024-11764
6.4 MEDIUM

The Solar Wizard Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'solar_wizard' shortcode in all versions up to, and including, …

Jan 7, 2025
CVE-2024-11282
5.3 MEDIUM

The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.10 …

Jan 7, 2025
CVE-2024-9702
6.4 MEDIUM

The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'socialrocket-floating' shortcode in all versions up …

Jan 7, 2025
CVE-2024-9697
5.3 MEDIUM

The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Jan 7, 2025
CVE-2024-9638
4.8 MEDIUM

The Category Posts Widget WordPress plugin before 4.9.18 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jan 7, 2025
CVE-2024-8857
4.8 MEDIUM

The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jan 7, 2025
CVE-2024-7696
6.3 MEDIUM

Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for an authenticated malicious client to tamper with …

Jan 7, 2025
CVE-2024-12464
6.4 MEDIUM

The Chatroll Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'chatroll' shortcode in all versions up to, and including, …

Jan 7, 2025
CVE-2024-12440
6.4 MEDIUM

The Candifly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'candifly' shortcode in all versions up to, and including, 1.0.6 due …

Jan 7, 2025
CVE-2024-12439
6.4 MEDIUM

The Marketplace Items plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'marketplace' shortcode in all versions up to, and including, 1.5.5 …

Jan 7, 2025
CVE-2024-12438
6.1 MEDIUM

The WooCommerce Digital Content Delivery (incl. DRM) – FlickRocket plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'start_date’ and 'end_date' parameters in …

Jan 7, 2025
CVE-2024-12384
6.1 MEDIUM

The Binary MLM Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page’ parameter in all versions up to, and including, 2.0 …

Jan 7, 2025
CVE-2024-12383
6.1 MEDIUM

The Binary MLM Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0. This is due to …

Jan 7, 2025
CVE-2024-12261
6.1 MEDIUM

The SmartEmailing.cz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'se-lists-updated' parameter in all versions up to, and including, 2.2.0 due to …

Jan 7, 2025
CVE-2024-12073
6.4 MEDIUM

The Meteor Slides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slide_url_value' parameter in all versions up to, and including, 1.5.7 due …

Jan 7, 2025
CVE-2024-11887
6.4 MEDIUM

The Geo Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'geotargetlygeocontent' shortcode in all versions up to, and including, 6.0 …

Jan 7, 2025
CVE-2024-11756
6.4 MEDIUM

The SweepWidget Contests, Giveaways, Photo Contests, Competitions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sweepwidget' shortcode in all versions up …

Jan 7, 2025
CVE-2024-11749
6.4 MEDIUM

The App Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'appizy' shortcode in all versions up to, and including, 2.3.2 …

Jan 7, 2025
CVE-2024-11606
5.3 MEDIUM

The Tabs Shortcode WordPress plugin through 2.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Jan 7, 2025
CVE-2024-11369
6.1 MEDIUM

The Store credit / Gift cards for woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'coupon', 'start_date', and 'end_date' parameters in …

Jan 7, 2025
CVE-2024-10536
4.3 MEDIUM

The FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor plugin for WordPress is vulnerable to unauthorized access of …

Jan 7, 2025
CVE-2024-9208
6.1 MEDIUM

The Enable Accessibility plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the …

Jan 7, 2025
CVE-2024-12462
6.4 MEDIUM

The YOGO Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yogo-calendar' shortcode in all versions up to, and including, 1.6.2 …

Jan 7, 2025
CVE-2024-12457
6.4 MEDIUM

The Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Jan 7, 2025
CVE-2024-12453
6.4 MEDIUM

The Uptodown APK Download Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'utd-widget' shortcode in all versions up to, and …

Jan 7, 2025
CVE-2024-12445
6.4 MEDIUM

The RightMessage WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rm_area' shortcode in all versions up to, and including, 0.9.7 …

Jan 7, 2025
CVE-2024-12435
6.1 MEDIUM

The Compare Products for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s_feature’ parameter in all versions up to, and including, …

Jan 7, 2025
CVE-2024-12332
6.5 MEDIUM

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and including, …

Jan 7, 2025
CVE-2024-12327
4.3 MEDIUM

The LazyLoad Background Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pblzbg_save_settings() function in …

Jan 7, 2025
CVE-2024-12324
6.1 MEDIUM

The Unilevel MLM Plan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all versions up to, and including, 1.1.0 …

Jan 7, 2025
CVE-2024-12291
6.1 MEDIUM

The ViewMedica 9 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.17. This is due to missing …

Jan 7, 2025
CVE-2024-12290
6.1 MEDIUM

The Infility Global plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘set_type’ parameter in all versions up to, and including, 2.9.8 due …

Jan 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.