CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-12507
6.4 MEDIUM

The Optio Dentistry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'optio-lightbox' shortcode in all versions up to, and including, 2.1 …

Dec 24, 2024
CVE-2024-12266
6.5 MEDIUM

The ELEX WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the …

Dec 24, 2024
CVE-2024-9427
5.4 MEDIUM

A vulnerability in Koji was found. An unsanitized input allows for an XSS attack. Javascript code from a malicious link could be reflected in the …

Dec 24, 2024
CVE-2018-25106
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in webuidesigning NebulaX Theme up to 5.0 on WordPress. This issue affects the function nebula_send_to_hubspot …

Dec 23, 2024
CVE-2024-56364
5.4 MEDIUM

SimpleXLSX is software for parsing and retrieving data from Excel XLSx files. Starting in 1.0.12 and ending in 1.1.13, when calling the extended toHTMLEx method, …

Dec 23, 2024
CVE-2024-23945
5.9 MEDIUM

Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authenticity and integrity. The signature helps prevent …

Dec 23, 2024
CVE-2024-11230
6.4 MEDIUM

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘size’ parameter in all versions up to, and …

Dec 23, 2024
CVE-2024-12901
5.3 MEDIUM

A vulnerability classified as critical was found in FoxCMS up to 1.2. Affected by this vulnerability is an unknown functionality of the file /app/api/controller/Site.php of …

Dec 23, 2024
CVE-2024-12900
6.3 MEDIUM

A vulnerability classified as critical has been found in FoxCMS up to 1.2. Affected is an unknown function of the file /install/installdb.php of the component …

Dec 23, 2024
CVE-2024-52321
5.9 MEDIUM

Multiple SHARP routers contain an improper authentication vulnerability in the configuration backup function. The product's backup files containing sensitive information may be retrieved by a …

Dec 23, 2024
CVE-2024-47864
5.3 MEDIUM

home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain a buffer overflow vulnerability in the hidden debug function. A remote unauthenticated attacker may …

Dec 23, 2024
CVE-2024-12898
6.3 MEDIUM

A vulnerability was found in 1000 Projects Attendance Tracking Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the …

Dec 23, 2024
CVE-2024-56378
4.3 MEDIUM

libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.

Dec 23, 2024
CVE-2024-12897
4.3 MEDIUM

A vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222. It has been …

Dec 23, 2024
CVE-2024-12896
5.3 MEDIUM

A vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222 and classified as …

Dec 22, 2024
CVE-2024-56314
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Project name of REDCap through 14.9.6 allows authenticated users to inject malicious scripts into the name field …

Dec 22, 2024
CVE-2024-56313
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Calendar feature of REDCap through 14.9.6 allows authenticated users to inject malicious scripts into the Notes field …

Dec 22, 2024
CVE-2024-56312
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Project Dashboard name of REDCap through 14.9.6 allows authenticated users to inject malicious scripts into the name …

Dec 22, 2024
CVE-2024-12895
6.3 MEDIUM

A vulnerability has been found in TreasureHuntGame TreasureHunt up to 963e0e0 and classified as critical. Affected by this vulnerability is the function console_log of the …

Dec 22, 2024
CVE-2024-12894
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in TreasureHuntGame TreasureHunt up to 963e0e0. Affected is an unknown function of the file TreasureHunt/acesso.php. The …

Dec 22, 2024
CVE-2024-12891
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Online Exam Mastering System 1.0. Affected is an unknown function of the file /account.php?q=quiz&step=2. The …

Dec 22, 2024
CVE-2024-12890
6.3 MEDIUM

A vulnerability was found in code-projects Online Exam Mastering System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Dec 22, 2024
CVE-2024-11852
4.3 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for WordPress is vulnerable to unauthorized access of data …

Dec 22, 2024
CVE-2024-51464
4.3 MEDIUM

IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions. By sending a specially crafted request, an authenticated attacker could …

Dec 21, 2024
CVE-2024-51463
5.4 MEDIUM

IBM i 7.3, 7.4, and 7.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the …

Dec 21, 2024
CVE-2024-12883
4.3 MEDIUM

A vulnerability was found in code-projects Job Recruitment 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the …

Dec 21, 2024
CVE-2024-12875
4.9 MEDIUM

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and …

Dec 21, 2024
CVE-2024-12591
6.4 MEDIUM

The MagicPost plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wb_share_social shortcode in all versions up to, and including, 1.2.1 due …

Dec 21, 2024
CVE-2024-12558
6.5 MEDIUM

The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check …

Dec 21, 2024
CVE-2024-12408
6.1 MEDIUM

The WP on AWS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST data in all versions up to, and including, 5.2.1 due …

Dec 21, 2024
CVE-2024-11722
5.9 MEDIUM

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.25.1 …

Dec 21, 2024
CVE-2024-11688
6.1 MEDIUM

The LaTeX2HTML plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ver' or 'date' parameter in all versions up to, and including, 2.5.5 …

Dec 21, 2024
CVE-2024-10453
6.4 MEDIUM

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typography Settings …

Dec 21, 2024
CVE-2024-9545
6.4 MEDIUM

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aux_contact_box and aux_gmaps shortcodes in …

Dec 21, 2024
CVE-2024-12588
6.4 MEDIUM

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Staff widget in all versions …

Dec 21, 2024
CVE-2024-11808
6.1 MEDIUM

The Pingmeter Uptime Monitoring plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_wpnonce' parameter in all versions up to, and including, 1.0.3 …

Dec 21, 2024
CVE-2024-10797
4.3 MEDIUM

The Full Screen Menu for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.7 via the Full …

Dec 21, 2024
CVE-2024-12697
6.4 MEDIUM

The real.Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.1 due to insufficient input sanitization and …

Dec 21, 2024
CVE-2024-12635
6.5 MEDIUM

The WP Docs plugin for WordPress is vulnerable to time-based SQL Injection via the 'dir_id' parameter in all versions up to, and including, 2.2.0 due …

Dec 21, 2024
CVE-2024-12262
6.1 MEDIUM

The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'step' parameter in all versions up to, and including, 5.8001 due …

Dec 21, 2024
CVE-2024-11975
6.1 MEDIUM

The Reactflow Visitor Recording and Heatmaps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_wpnonce' parameter in all versions up to, and …

Dec 21, 2024
CVE-2024-11938
6.4 MEDIUM

The One Click Upsell Funnel for WooCommerce – Funnel Builder for WordPress, Create WooCommerce Upsell, Post-Purchase Upsell & Cross Sell Offers that Boost Sales & …

Dec 21, 2024
CVE-2024-11682
6.1 MEDIUM

The G Web Pro Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'q' parameter in all versions up to, and …

Dec 21, 2024
CVE-2024-11287
6.1 MEDIUM

The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in …

Dec 21, 2024
CVE-2024-11196
6.4 MEDIUM

The Multi-column Tag Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mctagmap shortcode in all versions up to, and including, …

Dec 21, 2024
CVE-2024-11607
6.1 MEDIUM

The GTPayment Donations WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Dec 21, 2024
CVE-2024-12846
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Emlog Pro up to 2.4.1. Affected by this issue is some unknown functionality of …

Dec 21, 2024
CVE-2023-31280
5.3 MEDIUM

An AirVantage online Warranty Checker tool vulnerability could allow an attacker to perform bulk enumeration of IMEI and Serial Numbers pairs. The AirVantage Warranty Checker …

Dec 21, 2024
CVE-2024-11811
6.1 MEDIUM

The Feedify – Web Push Notifications plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'platform', 'phone', 'email', and 'store_url' parameters. in all …

Dec 20, 2024
CVE-2021-40959
6.1 MEDIUM

A reflected cross-site scripting vulnerability in MONITORAPP Application Insight Web Application Firewall (AIWAF) <= 4.1.6 and <=5.0 was identified on the subpage `/process_management/process_status.xhr.php`. This vulnerability …

Dec 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.