CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-45826
5.4 MEDIUM

Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through …

Dec 13, 2024
CVE-2022-45806
4.3 MEDIUM

Missing Authorization vulnerability in Strategy11 Form Builder Team Formidable Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Formidable Forms: from n/a through …

Dec 13, 2024
CVE-2022-44578
5.3 MEDIUM

Missing Authorization vulnerability in Pierre JEHAN Owl Carousel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Owl Carousel: from n/a through 0.5.3.

Dec 13, 2024
CVE-2022-43472
4.3 MEDIUM

Missing Authorization vulnerability in StylemixThemes eRoom – Zoom Meetings & Webinar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects eRoom – Zoom Meetings …

Dec 13, 2024
CVE-2024-55889
4.9 MEDIUM

phpMyFAQ is an open source FAQ web application. Prior to version 3.2.10, a vulnerability exists in the FAQ Record component where a privileged attacker can …

Dec 13, 2024
CVE-2024-48008
5.3 MEDIUM

Dell RecoverPoint for Virtual Machines 6.0.x contains a OS Command Injection vulnerability. An Low privileged remote attacker could potentially exploit this vulnerability leading to information …

Dec 13, 2024
CVE-2024-48007
5.3 MEDIUM

Dell RecoverPoint for Virtual Machines 6.0.x contains use of hard-coded credentials vulnerability. A Remote unauthenticated attacker could potentially exploit this vulnerability by gaining access to …

Dec 13, 2024
CVE-2024-38488
6.5 MEDIUM

Dell RecoverPoint for Virtual Machines 6.0.x contains a vulnerability. An improper Restriction of Excessive Authentication vulnerability where a Network attacker could potentially exploit this vulnerability, …

Dec 13, 2024
CVE-2024-9608
6.1 MEDIUM

The MyParcel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all …

Dec 13, 2024
CVE-2024-11827
6.4 MEDIUM

The Out of the Block: OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ootb_query shortcode in all versions up to, …

Dec 13, 2024
CVE-2024-11012
6.3 MEDIUM

The The Notibar – Notification Bar for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via njt_nofi_text AJAX action in all versions up …

Dec 13, 2024
CVE-2024-12465
6.4 MEDIUM

The Property Hive Stamp Duty Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stamp_duty_calculator_scotland' shortcode in all versions up to, …

Dec 13, 2024
CVE-2024-12421
6.5 MEDIUM

The The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, …

Dec 13, 2024
CVE-2024-12420
6.5 MEDIUM

The The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, …

Dec 13, 2024
CVE-2024-12417
6.5 MEDIUM

The The Simple Link Directory plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.4.5. This is due …

Dec 13, 2024
CVE-2024-12414
4.3 MEDIUM

The Themify Store Locator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.9. This is due to …

Dec 13, 2024
CVE-2024-12309
5.3 MEDIUM

The Rate My Post – Star Rating Plugin by FeedbackWP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, …

Dec 13, 2024
CVE-2024-12042
5.4 MEDIUM

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the profile …

Dec 13, 2024
CVE-2024-11911
4.3 MEDIUM

The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the install_woocommerce_plugin() function action in all …

Dec 13, 2024
CVE-2024-11910
6.4 MEDIUM

The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wp-crowdfunding/search block in all versions up to, and including, 2.1.15 due …

Dec 13, 2024
CVE-2024-11832
6.4 MEDIUM

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JavaScript row settings in all versions …

Dec 13, 2024
CVE-2024-11754
6.4 MEDIUM

The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'trafftbooking' shortcode in all versions up to, and including, …

Dec 13, 2024
CVE-2024-11275
4.3 MEDIUM

The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing …

Dec 13, 2024
CVE-2024-55918
5.3 MEDIUM

An issue was discovered in the Graphics::ColorNames package before 3.2.0 for Perl. There is an ambiguity between modules and filenames that can lead to HTML …

Dec 13, 2024
CVE-2024-12581
4.4 MEDIUM

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in …

Dec 13, 2024
CVE-2024-10939
4.8 MEDIUM

The Image Widget WordPress plugin before 4.4.11 does not sanitise and escape some of its Image Widget settings, which could allow high privilege users such …

Dec 13, 2024
CVE-2024-10678
5.4 MEDIUM

The Ultimate Blocks WordPress plugin before 3.2.4 does not validate and escape some of its block options before outputting them back in a page/post where …

Dec 13, 2024
CVE-2024-12579
5.3 MEDIUM

The Minify HTML plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in all versions up to, and including, 2.1.10. This is …

Dec 13, 2024
CVE-2024-12574
5.4 MEDIUM

The SVG Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.1 due …

Dec 13, 2024
CVE-2024-11809
6.1 MEDIUM

The Primer MyData for Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'img_src' parameter in all versions up to, and including, …

Dec 13, 2024
CVE-2024-11767
6.4 MEDIUM

The NewsmanApp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'newsman_subscribe_widget' shortcode in all versions up to, and including, 2.7.6 due …

Dec 13, 2024
CVE-2024-12572
6.1 MEDIUM

The Hello In All Languages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6. This is due …

Dec 13, 2024
CVE-2019-25221
6.5 MEDIUM

The Responsive Filterable Portfolio plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.8 due …

Dec 13, 2024
CVE-2024-12289
5.9 MEDIUM

Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initialization of the Boundary controller, which may cause the Boundary server to …

Dec 12, 2024
CVE-2024-55886
6.9 MEDIUM

OpenSearch Data Prepper is a component of the OpenSearch project that accepts, filters, transforms, enriches, and routes data at scale. A vulnerability exists in the …

Dec 12, 2024
CVE-2024-55878
6.8 MEDIUM

SimpleXLSX is software for parsing and retrieving data from Excel XLSx files. Starting in version 1.0.12 and prior to version 1.1.12, when calling the extended …

Dec 12, 2024
CVE-2024-55876
5.4 MEDIUM

XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0, any user with an account on the …

Dec 12, 2024
CVE-2024-49071
6.5 MEDIUM

Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over …

Dec 12, 2024
CVE-2024-31670
6.3 MEDIUM

rizin before v0.6.3 is vulnerable to Buffer Overflow via create_cache_bins, read_cache_accel, and rz_dyldcache_new_buf functions in librz/bin/format/mach0/dyldcache.c.

Dec 12, 2024
CVE-2024-52901
6.5 MEDIUM

IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to improper input validation.

Dec 12, 2024
CVE-2024-55633
6.5 MEDIUM

Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed SQL DML statement that is …

Dec 12, 2024
CVE-2024-50584
4.4 MEDIUM

An authenticated attacker with the user/role "Poweruser" can perform an SQL injection by accessing the /class/template_io.php file and supplying malicious GET parameters. The "templates" parameter …

Dec 12, 2024
CVE-2024-28145
5.9 MEDIUM

An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, …

Dec 12, 2024
CVE-2024-28144
5.5 MEDIUM

An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the session because of flaws in the self-developed …

Dec 12, 2024
CVE-2024-54122
6.2 MEDIUM

Concurrent variable access vulnerability in the ability module Impact: Successful exploitation of this vulnerability may affect availability.

Dec 12, 2024
CVE-2024-54119
6.2 MEDIUM

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Dec 12, 2024
CVE-2024-47947
4.7 MEDIUM

Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The "Edit Disclaimer Text" …

Dec 12, 2024
CVE-2024-36498
4.7 MEDIUM

Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The "Edit Disclaimer Text" …

Dec 12, 2024
CVE-2024-36494
4.7 MEDIUM

Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The login page at …

Dec 12, 2024
CVE-2024-28142
4.7 MEDIUM

Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The "File Name" page …

Dec 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.