CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-12288
6.1 MEDIUM

The Simple add pages or posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.0. This is …

Jan 7, 2025
CVE-2024-12256
6.1 MEDIUM

The Simple Video Management System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'analytics_video' parameter in all versions up to, and including, …

Jan 7, 2025
CVE-2024-12214
6.1 MEDIUM

The WooCommerce HSS Extension for Streaming Video plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘videolink’ parameter in all versions up to, …

Jan 7, 2025
CVE-2024-12207
4.4 MEDIUM

The Toggles Shortcode and Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, …

Jan 7, 2025
CVE-2024-12176
5.3 MEDIUM

The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'wl_config_plugin' …

Jan 7, 2025
CVE-2024-12170
5.4 MEDIUM

The ViewMedica 9 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.15. This is due to missing …

Jan 7, 2025
CVE-2024-12159
5.3 MEDIUM

The Optimize Your Campaigns – Google Shopping – Google Ads – Google Adwords plugin for WordPress is vulnerable to Information Exposure in all versions up …

Jan 7, 2025
CVE-2024-12158
5.3 MEDIUM

The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on …

Jan 7, 2025
CVE-2024-12153
6.1 MEDIUM

The GDY Modular Content plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Jan 7, 2025
CVE-2024-12140
4.3 MEDIUM

The Elementor Addons AI Addons – 70 Widgets, Premium Templates, Ultimate Elements plugin for WordPress is vulnerable to Information Exposure in all versions up to, …

Jan 7, 2025
CVE-2024-12126
6.1 MEDIUM

The SEO Keywords plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘google_error’ parameter in all versions up to, and including, 1.1.3 due …

Jan 7, 2025
CVE-2024-12049
6.1 MEDIUM

The Woo Ukrposhta plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order', 'post', and 'idd' parameters in all versions up to, and …

Jan 7, 2025
CVE-2024-11810
6.1 MEDIUM

The PayGreen Payment Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message_id' parameter in all versions up to, and including, 1.0.26 …

Jan 7, 2025
CVE-2024-11690
6.1 MEDIUM

The Financial Stocks & Crypto Market Data Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'e' parameter in all versions up …

Jan 7, 2025
CVE-2024-11496
6.5 MEDIUM

The Infility Global plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the infility_global_ajax function in all …

Jan 7, 2025
CVE-2024-11445
6.4 MEDIUM

The Image Magnify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'image_magnify' shortcode in all versions up to, and including, 1.1 …

Jan 7, 2025
CVE-2024-11434
6.1 MEDIUM

The WP – Bulk SMS – by SMS.to plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up …

Jan 7, 2025
CVE-2024-11383
6.4 MEDIUM

The CC Canadian Mortgage Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cc-mortgage-canada' shortcode in all versions up to, and …

Jan 7, 2025
CVE-2024-11382
6.4 MEDIUM

The Common Ninja: Fully Customizable & Perfectly Responsive Free Widgets for WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's …

Jan 7, 2025
CVE-2024-11378
6.1 MEDIUM

The Bizapp for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'error' parameter in all versions up to, and including, 2.0.8 …

Jan 7, 2025
CVE-2024-11377
6.1 MEDIUM

The Automate Hub Free by Sperse.IO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in all versions up to, and …

Jan 7, 2025
CVE-2024-11375
6.1 MEDIUM

The WC1C plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all …

Jan 7, 2025
CVE-2024-11363
6.1 MEDIUM

The Same but Different – Related Posts by Taxonomy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & …

Jan 7, 2025
CVE-2024-11338
6.4 MEDIUM

The PIXNET Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gtm' and 'venue' parameters in all versions up to, and including, …

Jan 7, 2025
CVE-2024-11337
6.4 MEDIUM

The Horoscope And Tarot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'divine_horoscope' shortcode in all versions up to, and including, …

Jan 7, 2025
CVE-2024-11290
5.3 MEDIUM

The Member Access plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.6 via the WordPress core search …

Jan 7, 2025
CVE-2024-12592
6.4 MEDIUM

The Sellsy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'testSellsy' shortcode in all versions up to, and including, 2.3.3 due …

Jan 7, 2025
CVE-2024-12590
6.4 MEDIUM

The WP Youtube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 1.9 …

Jan 7, 2025
CVE-2024-12559
5.3 MEDIUM

The ClickDesigns plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'clickdesigns_add_api' and the 'clickdesigns_remove_api' functions …

Jan 7, 2025
CVE-2024-12557
6.1 MEDIUM

The Transporters.io plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing nonce …

Jan 7, 2025
CVE-2024-12541
5.4 MEDIUM

The Chative Live chat and Chatbot plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is …

Jan 7, 2025
CVE-2024-12538
4.3 MEDIUM

The Duplicate Post, Page and Any Custom Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.5 …

Jan 7, 2025
CVE-2024-12528
6.4 MEDIUM

The WordPress Survey & Poll – Quiz, Survey and Poll Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's …

Jan 7, 2025
CVE-2024-12419
6.5 MEDIUM

The The Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler plugin for WordPress is vulnerable to arbitrary shortcode execution in all …

Jan 7, 2025
CVE-2024-12098
6.1 MEDIUM

The ARS Affiliate Page Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'utm_keyword' parameter in all versions up to, and including, …

Jan 7, 2025
CVE-2024-11934
6.4 MEDIUM

The Formaloo Form Maker & Customer Analytics for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'formaloo' shortcode in …

Jan 7, 2025
CVE-2024-11899
6.4 MEDIUM

The Slider Pro Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sliderpro' shortcode in all versions up to, and including, …

Jan 7, 2025
CVE-2024-11777
6.4 MEDIUM

The Sell Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sell_media_search_form_gutenberg' shortcode in all versions up to, and including, 2.5.8.5 …

Jan 7, 2025
CVE-2024-11437
4.9 MEDIUM

The Timeline Designer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to, and including, 1.4 due to …

Jan 7, 2025
CVE-2024-54764
6.5 MEDIUM

An access control issue in the component /login/hostinfo2.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information without authentication.

Jan 6, 2025
CVE-2025-21616
5.4 MEDIUM

Plane is an open-source project management tool. A cross-site scripting (XSS) vulnerability has been identified in Plane versions prior to 0.23. The vulnerability allows authenticated …

Jan 6, 2025
CVE-2024-54763
6.5 MEDIUM

An access control issue in the component /login/hostinfo.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information without authentication.

Jan 6, 2025
CVE-2024-53936
6.3 MEDIUM

The com.asianmobile.callcolor (aka Color Phone Call Screen App) application through 24 for Android enables any application (with no permissions) to place phone calls without user …

Jan 6, 2025
CVE-2024-53935
6.5 MEDIUM

The com.callos14.callscreen.colorphone (aka iCall OS17 - Color Phone Flash) application through 4.3 for Android enables any application (with no permissions) to place phone calls without …

Jan 6, 2025
CVE-2024-53933
6.3 MEDIUM

The com.callerscreen.colorphone.themes.callflash (aka Color Call Theme & Call Screen) application through 1.0.7 for Android enables any application (with no permissions) to place phone calls without …

Jan 6, 2025
CVE-2024-51741
4.4 MEDIUM

Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, …

Jan 6, 2025
CVE-2024-55075
4.3 MEDIUM

Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such as calendar …

Jan 6, 2025
CVE-2024-55408
5.3 MEDIUM

An improper access control vulnerability in the AsusSAIO.sys driver may lead to the misuse of software functionality utilizing the driver when crafted IOCTL requests are …

Jan 6, 2025
CVE-2024-46209
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attackers to execute arbitrary web scripts or HTML via injecting …

Jan 6, 2025
CVE-2024-35498
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Grav v1.7.45 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Jan 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.