CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-52543
6.5 MEDIUM

Dell NativeEdge, version(s) 2.1.0.0, contain(s) a Creation of Temporary File With Insecure Permissions vulnerability. A high privileged attacker with local access could potentially exploit this …

Dec 25, 2024
CVE-2024-52534
5.4 MEDIUM

Dell ECS, version(s) prior to ECS 3.8.1.3, contain(s) an Authentication Bypass by Capture-replay vulnerability. A low privileged attacker with remote access could potentially exploit this …

Dec 25, 2024
CVE-2024-52906
5.5 MEDIUM

IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause …

Dec 25, 2024
CVE-2024-47102
5.5 MEDIUM

IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to …

Dec 25, 2024
CVE-2024-39727
6.1 MEDIUM

IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 uses a web link with untrusted references to an external site. A remote attacker could …

Dec 25, 2024
CVE-2024-39725
5.3 MEDIUM

IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message …

Dec 25, 2024
CVE-2024-12335
4.3 MEDIUM

The Avada (Fusion) Builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.11.12 via the handle_clone_post() function and …

Dec 25, 2024
CVE-2024-10862
4.9 MEDIUM

The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to SQL Injection via the 'search_params' parameter in …

Dec 25, 2024
CVE-2024-10858
6.1 MEDIUM

The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leading to …

Dec 25, 2024
CVE-2024-12636
4.3 MEDIUM

The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all …

Dec 25, 2024
CVE-2024-12413
5.3 MEDIUM

The MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions like …

Dec 25, 2024
CVE-2024-12190
4.3 MEDIUM

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable …

Dec 25, 2024
CVE-2024-12032
6.5 MEDIUM

The Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking plugin for WordPress is vulnerable to SQL Injection via …

Dec 25, 2024
CVE-2022-21505
6.7 MEDIUM

In the linux kernel, if IMA appraisal is used with the "ima_appraise=log" boot param, lockdown can be defeated with kexec on any machine when Secure …

Dec 24, 2024
CVE-2024-53163
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: qat/qat_420xx - fix off by one in uof_get_name() This is called from uof_get_name_420xx() where …

Dec 24, 2024
CVE-2024-53161
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: EDAC/bluefield: Fix potential integer overflow The 64-bit argument for the "get DIMM info" SMC call …

Dec 24, 2024
CVE-2024-53160
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: rcu/kvfree: Fix data-race in __mod_timer / kvfree_call_rcu KCSAN reports a data race when access the …

Dec 24, 2024
CVE-2024-53158
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: soc: qcom: geni-se: fix array underflow in geni_se_clk_tbl_get() This loop is supposed to break if …

Dec 24, 2024
CVE-2024-53157
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scpi: Check the DVFS OPP count returned by the firmware Fix a kernel crash …

Dec 24, 2024
CVE-2024-53154
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: clk: clk-apple-nco: Add NULL check in applnco_probe Add NULL check in applnco_probe, to handle kernel …

Dec 24, 2024
CVE-2024-53153
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI: qcom-ep: Move controller cleanups to qcom_pcie_perst_deassert() Currently, the endpoint cleanup function dw_pcie_ep_cleanup() and EPF …

Dec 24, 2024
CVE-2024-53152
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI: tegra194: Move controller cleanups to pex_ep_event_pex_rst_deassert() Currently, the endpoint cleanup function dw_pcie_ep_cleanup() and EPF …

Dec 24, 2024
CVE-2024-53151
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: svcrdma: Address an integer overflow Dan Carpenter reports: > Commit 78147ca8b4a9 ("svcrdma: Add a "parsed …

Dec 24, 2024
CVE-2024-53149
4.6 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: glink: fix off-by-one in connector_status UCSI connector's indices start from 1 up …

Dec 24, 2024
CVE-2024-53148
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: comedi: Flush partial mappings in error case If some remap_pfn_range() calls succeeded before one failed, …

Dec 24, 2024
CVE-2024-53146
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent a potential integer overflow If the tag length is >= U32_MAX - 3 …

Dec 24, 2024
CVE-2024-53145
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: um: Fix potential integer overflow during physmem setup This issue happens when the real map …

Dec 24, 2024
CVE-2024-12268
6.4 MEDIUM

The Responsive Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'responsive-block-editor-addons/portfolio' block in all versions up to, …

Dec 24, 2024
CVE-2024-11726
6.5 MEDIUM

The Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress plugin for WordPress is vulnerable to SQL Injection via the 'category' parameter of the 'bookingpress_form' …

Dec 24, 2024
CVE-2024-10856
6.5 MEDIUM

The Booking Calendar WpDevArt plugin is vulnerable to time-based, blind SQL injection via the `id` parameter in the “wpdevart_booking_calendar” shortcode in versions up to, and …

Dec 24, 2024
CVE-2024-10584
5.4 MEDIUM

The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions …

Dec 24, 2024
CVE-2024-8721
6.4 MEDIUM

The Tracking Code Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tracking code field in all versions up to, and including, …

Dec 24, 2024
CVE-2024-53241
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/xen: don't do PV iret hypercall through hypercall page Instead of jumping to the Xen …

Dec 24, 2024
CVE-2024-53240
5.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xen/netfront: fix crash when removing device When removing a netfront device directly after a suspend/resume …

Dec 24, 2024
CVE-2024-12850
4.9 MEDIUM

The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, …

Dec 24, 2024
CVE-2024-12103
5.3 MEDIUM

The Content No Cache: prevent specific content from being cached plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, …

Dec 24, 2024
CVE-2024-12031
6.5 MEDIUM

The Advanced Floating Content plugin for WordPress is vulnerable to SQL Injection via the 'floating_content_duplicate_post' function in all versions up to, and including, 3.8.2 due …

Dec 24, 2024
CVE-2024-12468
6.1 MEDIUM

The WP Datepicker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpdp_get_selected_datepicker' parameter in all versions up to, and including, 2.1.4 due …

Dec 24, 2024
CVE-2024-11896
6.4 MEDIUM

The Text Prompter – Unlimited chatgpt text prompts for openai tasks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'text_prompter' shortcode …

Dec 24, 2024
CVE-2024-12814
6.4 MEDIUM

The Loan Comparison plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'loancomparison' shortcode in all versions up to, and including, 2.0 …

Dec 24, 2024
CVE-2024-12622
6.4 MEDIUM

The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_cart_button' and 'wp_cart_display_product' shortcodes in all versions up …

Dec 24, 2024
CVE-2024-12405
6.1 MEDIUM

The Export Customers Data plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 't' parameter in all versions up to, and including, 1.2.3 …

Dec 24, 2024
CVE-2024-12210
4.3 MEDIUM

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Dec 24, 2024
CVE-2024-12100
6.1 MEDIUM

The Bitcoin Lightning Publisher for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on …

Dec 24, 2024
CVE-2024-12096
6.1 MEDIUM

The Exhibit to WP Gallery WordPress plugin through 0.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to …

Dec 24, 2024
CVE-2024-12034
5.3 MEDIUM

The Advanced Google reCAPTCHA plugin for WordPress is vulnerable to IP unblocking in all versions up to, and including, 1.25. This is due to the …

Dec 24, 2024
CVE-2024-11885
6.4 MEDIUM

The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'njtele_button shortcode in all versions up to, and …

Dec 24, 2024
CVE-2024-12710
6.1 MEDIUM

The WP-Appbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 4.5.3 due to …

Dec 24, 2024
CVE-2024-12617
5.4 MEDIUM

The WC Price History for Omnibus plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX actions in …

Dec 24, 2024
CVE-2024-12518
6.4 MEDIUM

The ShMapper by Teplitsa plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shmMap' shortcode in all versions up to, and including, …

Dec 24, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.