CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-12271
4.4 MEDIUM

The 360 Javascript Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ref’ parameter in all versions up to, and including, 1.7.29 …

Dec 12, 2024
CVE-2024-9387
6.4 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could potentially …

Dec 12, 2024
CVE-2024-9367
4.3 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2, that allows an …

Dec 12, 2024
CVE-2024-8647
5.4 MEDIUM

An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted …

Dec 12, 2024
CVE-2024-8179
5.4 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. Improper output encoding …

Dec 12, 2024
CVE-2024-54117
6.2 MEDIUM

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Dec 12, 2024
CVE-2024-54116
4.3 MEDIUM

Out-of-bounds read vulnerability in the M3U8 module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Dec 12, 2024
CVE-2024-54115
4.3 MEDIUM

Out-of-bounds read vulnerability in the DASH module Impact: Successful exploitation of this vulnerability will affect availability.

Dec 12, 2024
CVE-2024-54114
4.4 MEDIUM

Out-of-bounds access vulnerability in playback in the DASH module Impact: Successful exploitation of this vulnerability will affect availability.

Dec 12, 2024
CVE-2024-54113
6.5 MEDIUM

Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect power consumption.

Dec 12, 2024
CVE-2024-54112
5.5 MEDIUM

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Dec 12, 2024
CVE-2024-54111
5.7 MEDIUM

Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

Dec 12, 2024
CVE-2024-54110
6.2 MEDIUM

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Dec 12, 2024
CVE-2024-54109
6.5 MEDIUM

Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

Dec 12, 2024
CVE-2024-54108
6.5 MEDIUM

Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

Dec 12, 2024
CVE-2024-54105
5.1 MEDIUM

Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

Dec 12, 2024
CVE-2024-54104
6.2 MEDIUM

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Dec 12, 2024
CVE-2024-54103
6.1 MEDIUM

Vulnerability of improper access control in the album module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Dec 12, 2024
CVE-2024-54102
6.1 MEDIUM

Race condition vulnerability in the DDR module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Dec 12, 2024
CVE-2024-54101
6.2 MEDIUM

Denial of service (DoS) vulnerability in the installation module Impact: Successful exploitation of this vulnerability will affect availability.

Dec 12, 2024
CVE-2024-54100
6.2 MEDIUM

Vulnerability of improper access control in the secure input module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Dec 12, 2024
CVE-2024-54099
6.7 MEDIUM

File replacement vulnerability on some devices Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

Dec 12, 2024
CVE-2024-54096
5.3 MEDIUM

Vulnerability of improper access control in the MTP module Impact: Successful exploitation of this vulnerability may affect integrity and accuracy.

Dec 12, 2024
CVE-2024-12570
6.7 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 …

Dec 12, 2024
CVE-2024-12292
4.0 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from …

Dec 12, 2024
CVE-2024-12401
4.4 MEDIUM

A flaw was found in the cert-manager package. This flaw allows an attacker who can modify PEM data that the cert-manager reads, for example, in …

Dec 12, 2024
CVE-2024-12333
6.5 MEDIUM

The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.0.3. This is due to the software …

Dec 12, 2024
CVE-2024-12160
6.1 MEDIUM

The Seraphinite Bulk Discounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on …

Dec 12, 2024
CVE-2024-11760
6.4 MEDIUM

The Currency Converter Widget ⚡ PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'currency-converter-widget-pro' shortcode in all versions up to, …

Dec 12, 2024
CVE-2024-12329
4.3 MEDIUM

The Essential Real Estate plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on several pages/post types in …

Dec 12, 2024
CVE-2024-12201
4.3 MEDIUM

The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check when creating …

Dec 12, 2024
CVE-2024-11727
4.4 MEDIUM

The NotificationX – Live Sales Notification, WooCommerce Sales Popup, FOMO, Social Proof, Announcement Banner & Floating Notification Top Bar plugin for WordPress is vulnerable to …

Dec 12, 2024
CVE-2024-11724
4.3 MEDIUM

The Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) plugin for WordPress is vulnerable to …

Dec 12, 2024
CVE-2024-11181
4.3 MEDIUM

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 9.9.9.3 via …

Dec 12, 2024
CVE-2024-10784
6.4 MEDIUM

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Tile Gallery' widget in all …

Dec 12, 2024
CVE-2024-10583
5.4 MEDIUM

The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Dec 12, 2024
CVE-2024-9881
4.8 MEDIUM

The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Dec 12, 2024
CVE-2024-9641
4.8 MEDIUM

The LuckyWP Table of Contents WordPress plugin before 2.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such …

Dec 12, 2024
CVE-2024-9428
4.8 MEDIUM

The Popup Builder WordPress plugin before 4.3.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Dec 12, 2024
CVE-2024-12265
5.3 MEDIUM

The Web3 Crypto Payments by DePay for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on …

Dec 12, 2024
CVE-2024-12263
4.3 MEDIUM

The Child Theme Creator by Orbisius plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cloud_delete() …

Dec 12, 2024
CVE-2024-12255
5.3 MEDIUM

The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5 via …

Dec 12, 2024
CVE-2024-12072
6.1 MEDIUM

The Analytics Cat – Google Analytics Made Easy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate …

Dec 12, 2024
CVE-2024-12059
4.3 MEDIUM

The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.1 via the eli_option_value …

Dec 12, 2024
CVE-2024-12018
4.3 MEDIUM

The Snippet Shortcodes plugin for WordPress is vulnerable to unauthorized Shortcode Deletion due to missing authorization in all versions up to, and including, 4.1.6. Note …

Dec 12, 2024
CVE-2024-11882
6.4 MEDIUM

The FAQ And Answers – Create Frequently Asked Questions Area on WP Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's …

Dec 12, 2024
CVE-2024-11871
6.4 MEDIUM

The Social Media Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'patreon' shortcode in all versions up to, and including, …

Dec 12, 2024
CVE-2024-11785
6.4 MEDIUM

The Integrate Firebase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'firebase_show' shortcode in all versions up to, and including, 0.9.3 …

Dec 12, 2024
CVE-2024-11781
6.4 MEDIUM

The Smart Agenda – Prise de rendez-vous en ligne plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'smartagenda' shortcode in all …

Dec 12, 2024
CVE-2024-11766
6.4 MEDIUM

The WordPress Book Plugin for Displaying Books in Grid, Flip, Slider, Popup Layout and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Dec 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.