CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-56087
5.9 MEDIUM

An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template Dashboard. These are executed, leading to Server-Side Template …

Dec 16, 2024
CVE-2024-56085
5.9 MEDIUM

An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard. These are executed, leading to Server-Side Template …

Dec 16, 2024
CVE-2024-11841
5.4 MEDIUM

The Tithe.ly Giving Button WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post …

Dec 16, 2024
CVE-2024-8650
5.3 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that …

Dec 16, 2024
CVE-2024-8116
5.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a …

Dec 16, 2024
CVE-2024-56074
5.5 MEDIUM

gitingest before 9996a06 mishandles symbolic links that point outside of the base directory.

Dec 15, 2024
CVE-2024-12628
4.4 MEDIUM

The bodi0`s Easy cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cache-folder' parameter in all versions up to, and including, 0.8 …

Dec 14, 2024
CVE-2024-12446
6.4 MEDIUM

The Post to Pdf plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gmptp_single_post' shortcode in all versions up to, and including, …

Dec 14, 2024
CVE-2024-11715
4.8 MEDIUM

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access due to …

Dec 14, 2024
CVE-2024-11714
4.9 MEDIUM

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the …

Dec 14, 2024
CVE-2024-11713
4.9 MEDIUM

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the …

Dec 14, 2024
CVE-2024-11712
5.3 MEDIUM

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access of data …

Dec 14, 2024
CVE-2024-11710
4.9 MEDIUM

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the …

Dec 14, 2024
CVE-2024-12501
6.4 MEDIUM

The Simple Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 2.0.3 due …

Dec 14, 2024
CVE-2024-12474
6.4 MEDIUM

The GeoDataSource Country Region DropDown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gds-country-dropdown' shortcode in all versions up to, and …

Dec 14, 2024
CVE-2024-12459
6.4 MEDIUM

The Ganohrs Toggle Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'toggle' shortcode in all versions up to, and including, …

Dec 14, 2024
CVE-2024-12422
6.1 MEDIUM

The Import Eventbrite Events plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.7.4 …

Dec 14, 2024
CVE-2024-11752
6.4 MEDIUM

The Eveeno plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'eveeno' shortcode in all versions up to, and including, 1.7 due …

Dec 14, 2024
CVE-2024-10690
4.3 MEDIUM

The Shortcodes for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.4 via the 'SHORTCODE_ELEMENTOR' shortcode due …

Dec 14, 2024
CVE-2024-12578
5.3 MEDIUM

The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.5.4.8 via the 'tickera_tickets_info' …

Dec 14, 2024
CVE-2024-12555
6.1 MEDIUM

The SIP Calculator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing …

Dec 14, 2024
CVE-2024-12523
6.4 MEDIUM

The States Map US plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'states_map' shortcode in all versions up to, and including, …

Dec 14, 2024
CVE-2024-12517
6.4 MEDIUM

The WooCommerce Cart Count Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cart_button' shortcode in all versions up to, and …

Dec 14, 2024
CVE-2024-12502
6.4 MEDIUM

The My IDX Home Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasap-idx-landing' shortcode in all versions up to, and …

Dec 14, 2024
CVE-2024-12458
6.4 MEDIUM

The Smart PopUp Blaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spb-button' shortcode in all versions up to, and including, …

Dec 14, 2024
CVE-2024-12448
6.4 MEDIUM

The Posts and Products Views for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'papvfwc_views' shortcode in all versions up …

Dec 14, 2024
CVE-2024-12447
4.3 MEDIUM

The Get Post Content Shortcode plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 0.4 via the …

Dec 14, 2024
CVE-2024-12411
6.1 MEDIUM

The WP Ad Guru – Banner ad, Responsive popup, Popup maker, Ad rotator & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Dec 14, 2024
CVE-2024-11894
6.4 MEDIUM

The The Permalinker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'permalink' shortcode in all versions up to, and including, 1.8.1 …

Dec 14, 2024
CVE-2024-11889
6.4 MEDIUM

The My IDX Home Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasap-idx-search' shortcode in all versions up to, and …

Dec 14, 2024
CVE-2024-11888
6.4 MEDIUM

The IDer Login for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ider_login_button' shortcode in all versions up to, and …

Dec 14, 2024
CVE-2024-11884
6.4 MEDIUM

The Wp photo text slider 50 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp-photo-slider' shortcode in all versions up to, …

Dec 14, 2024
CVE-2024-11883
6.4 MEDIUM

The Connatix Video Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cnx_script_code' shortcode in all versions up to, and including, …

Dec 14, 2024
CVE-2024-11877
6.4 MEDIUM

The Cricket Live Score plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cricket_score' shortcode in all versions up to, and including, …

Dec 14, 2024
CVE-2024-11876
6.4 MEDIUM

The Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Dec 14, 2024
CVE-2024-11873
6.4 MEDIUM

The glomex oEmbed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'glomex_integration' shortcode in all versions up to, and including, 0.9.1 …

Dec 14, 2024
CVE-2024-11869
6.4 MEDIUM

The Buk for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'buk' shortcode in all versions up to, and including, …

Dec 14, 2024
CVE-2024-11867
6.4 MEDIUM

The Companion Portfolio – Responsive Portfolio Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'companion-portfolio' shortcode in all versions up …

Dec 14, 2024
CVE-2024-11865
6.4 MEDIUM

The Tabs Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 due to insufficient input sanitization and …

Dec 14, 2024
CVE-2024-11855
6.4 MEDIUM

The Koalendar – Events & Appointments Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘height’ parameter in all versions up …

Dec 14, 2024
CVE-2024-11770
6.4 MEDIUM

The Post Carousel & Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'post-cs' shortcode in all versions up to, and …

Dec 14, 2024
CVE-2024-11763
6.4 MEDIUM

The Plezi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'plezi' shortcode in all versions up to, and including, 1.0.6 due …

Dec 14, 2024
CVE-2024-11759
6.4 MEDIUM

The Bukza plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bukza' shortcode in all versions up to, and including, 2.0.0 due …

Dec 14, 2024
CVE-2024-11755
6.4 MEDIUM

The IMS Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown post settings in all versions up to, and including, 1.3.5 …

Dec 14, 2024
CVE-2024-11751
6.4 MEDIUM

The TCBD Popover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbd-popover-image ' shortcode in all versions up to, and including, …

Dec 14, 2024
CVE-2024-11462
6.1 MEDIUM

The Filestack Official plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'fstab' and 'filestack_options' parameters in all versions up to, and including, …

Dec 14, 2024
CVE-2024-11095
6.4 MEDIUM

The Visualmodo Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, …

Dec 14, 2024
CVE-2024-12553
6.5 MEDIUM

GeoVision GV-ASManager Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of GeoVision GV-ASManager. Although authentication is …

Dec 13, 2024
CVE-2024-9945
5.3 MEDIUM

An information-disclosure vulnerability exists in Fortra's GoAnywhere MFT application prior to version 7.7.0 that allows external access to the resources in certain admin root folders.

Dec 13, 2024
CVE-2024-54349
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mashiurz Plain Post plain-post allows Stored XSS.This issue affects Plain Post: from n/a …

Dec 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.