CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-11765
6.4 MEDIUM

The WordPress Portfolio Plugin – A Plugin for Making Filterable Portfolio Grid, Portfolio Slider and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Dec 12, 2024
CVE-2024-11757
6.4 MEDIUM

The WP GeoNames plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp-geonames' shortcode in all versions up to, and including, 1.9.0.1 …

Dec 12, 2024
CVE-2024-11359
6.1 MEDIUM

The Library Bookshelves plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in …

Dec 12, 2024
CVE-2024-10637
5.4 MEDIUM

The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.54 does not validate and escape some of its block options before outputting them …

Dec 12, 2024
CVE-2024-10568
4.7 MEDIUM

The Ajax Search Lite WordPress plugin before 4.12.4 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Dec 12, 2024
CVE-2024-10518
4.8 MEDIUM

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.15 does not sanitise and escape some …

Dec 12, 2024
CVE-2024-10517
4.8 MEDIUM

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.15 does not sanitise and escape some …

Dec 12, 2024
CVE-2024-10010
4.8 MEDIUM

The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Dec 12, 2024
CVE-2024-12526
4.3 MEDIUM

The Arena.IM – Live Blogging for real-time events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.4.1. …

Dec 12, 2024
CVE-2024-12463
6.4 MEDIUM

The Arena.IM – Live Blogging for real-time events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'arena_embed_amp' shortcode in all versions …

Dec 12, 2024
CVE-2024-12441
6.1 MEDIUM

The BP Email Assign Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, …

Dec 12, 2024
CVE-2024-12406
6.5 MEDIUM

The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via the 'owt7_borrow_books_id' parameter in all versions up …

Dec 12, 2024
CVE-2024-12162
6.1 MEDIUM

The Video & Photo Gallery for Ultimate Member plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up …

Dec 12, 2024
CVE-2024-12156
6.1 MEDIUM

The AI Content Writer, RSS Feed to Post, Autoblogging SEO Help plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in …

Dec 12, 2024
CVE-2024-11891
6.4 MEDIUM

The Perfect Font Awesome Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pfai' shortcode in all versions up to, and …

Dec 12, 2024
CVE-2024-11875
6.4 MEDIUM

The Add infos to the events calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fuss' shortcode in all versions up …

Dec 12, 2024
CVE-2024-11804
6.1 MEDIUM

The Planaday API plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 11.4 due …

Dec 12, 2024
CVE-2024-11750
6.4 MEDIUM

The ONLYOFFICE DocSpace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'onlyoffice-docspace' shortcode in all versions up to, and including, 2.1.1 …

Dec 12, 2024
CVE-2024-11723
6.1 MEDIUM

The kvCORE IDX plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via any parameter on pages with the kvcoreidx_listings_sitemap_ranges, kvcoreidx_listings_sitemap_page, kvcoreidx_agent_profile_sitemap, or kvcoreidx_agent_profile shortcode …

Dec 12, 2024
CVE-2024-11709
4.3 MEDIUM

The AI Post Generator | AutoWriter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ai_post_generator_delete_Post …

Dec 12, 2024
CVE-2024-11459
6.1 MEDIUM

The Country Blocker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ip' parameter in all versions up to, and including, 3.2 due …

Dec 12, 2024
CVE-2024-11410
6.4 MEDIUM

The Top and footer bars for announcements, notifications, advertisements, promotions – YooBar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Yoo Bar …

Dec 12, 2024
CVE-2024-11384
6.4 MEDIUM

The Arena.IM – Live Blogging for real-time events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'arenablog' shortcode in all versions …

Dec 12, 2024
CVE-2024-10182
6.4 MEDIUM

The Cognito Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 2.0.7 due …

Dec 12, 2024
CVE-2024-12461
6.4 MEDIUM

The WP-Revive Adserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprevive_async' shortcode in all versions up to, and including, 2.2.1 …

Dec 12, 2024
CVE-2024-12341
4.3 MEDIUM

The Custom Skins Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'cf7cs_action_callback' …

Dec 12, 2024
CVE-2024-12338
6.1 MEDIUM

The Website Toolbox Community plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘websitetoolbox_username’ parameter in all versions up to, and including, 2.0.1 …

Dec 12, 2024
CVE-2024-12260
6.1 MEDIUM

The Ultimate Endpoints With Rest Api plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and …

Dec 12, 2024
CVE-2024-12258
6.1 MEDIUM

The WP Service Payment Form With Authorize.net plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, …

Dec 12, 2024
CVE-2024-11914
6.4 MEDIUM

The Gutenberg Blocks and Page Layouts – Attire Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'attire-blocks/post-carousel' block in all versions …

Dec 12, 2024
CVE-2024-11901
6.4 MEDIUM

The PowerBI Embed Reports plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MO_API_POWER_BI' shortcode in all versions up to, and including, …

Dec 12, 2024
CVE-2024-11683
6.1 MEDIUM

The Newsletter Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'token_type' parameter in all versions up to, and including, 2.1 due …

Dec 12, 2024
CVE-2024-11442
6.4 MEDIUM

The Horizontal scroll image slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'horizontal-scroll-image-slideshow' shortcode in all versions up to, and …

Dec 12, 2024
CVE-2024-11433
6.4 MEDIUM

The Surbma | SalesAutopilot Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sa-form' shortcode in all versions up to, and …

Dec 12, 2024
CVE-2024-11430
6.5 MEDIUM

The SQL Chart Builder plugin for WordPress is vulnerable to SQL Injection via the 'arg1' arg of the 'gvn_schart_2' shortcode in all versions up to, …

Dec 12, 2024
CVE-2024-11427
6.4 MEDIUM

The Catch Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catch-popup' shortcode in all versions up to, and including, 1.4.4 …

Dec 12, 2024
CVE-2024-11419
6.1 MEDIUM

The Password for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to …

Dec 12, 2024
CVE-2024-11417
6.1 MEDIUM

The dejure.org Vernetzungsfunktion plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.97.5. This is due to missing …

Dec 12, 2024
CVE-2024-11413
6.4 MEDIUM

The HostFact bestelformulier integratie plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bestelformulier' shortcode in all versions up to, and including, …

Dec 12, 2024
CVE-2024-11279
6.1 MEDIUM

The Schema App Structured Data plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …

Dec 12, 2024
CVE-2024-55659
5.4 MEDIUM

SiYuan is a personal knowledge management system. Prior to version 3.1.16, the `/api/asset/upload` endpoint in Siyuan is vulnerable to both arbitrary file write to the …

Dec 12, 2024
CVE-2024-55652
6.5 MEDIUM

PenDoc is a penetration testing reporting application. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an attacker can write a malicious docx template containing expressions that escape the JavaScript …

Dec 12, 2024
CVE-2024-54531
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2. An app may be able to bypass kASLR.

Dec 12, 2024
CVE-2024-54527
5.5 MEDIUM

This issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura …

Dec 12, 2024
CVE-2024-54526
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura …

Dec 12, 2024
CVE-2024-54524
5.5 MEDIUM

A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.2. A malicious app may be able to access …

Dec 12, 2024
CVE-2024-54513
5.5 MEDIUM

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, …

Dec 12, 2024
CVE-2024-54510
5.1 MEDIUM

A race condition was addressed with improved locking. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma …

Dec 12, 2024
CVE-2024-54504
5.5 MEDIUM

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.2. An app may be …

Dec 12, 2024
CVE-2024-54503
4.2 MEDIUM

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.2 and iPadOS 18.2. Muting a call while …

Dec 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.