CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-53794
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryo Arkhe Blocks arkhe-blocks allows Stored XSS.This issue affects Arkhe Blocks: from n/a …

Dec 6, 2024
CVE-2024-4633
6.4 MEDIUM

The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘addExtraMimeType’ function in versions up to, and …

Dec 6, 2024
CVE-2024-11321
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hi e-learning Learning Management System (LMS) allows Reflected XSS.This issue affects …

Dec 6, 2024
CVE-2024-11022
5.6 MEDIUM

The authentication process to the web server uses a challenge response procedure which inludes the nonce and additional information. This challenge can be used several …

Dec 6, 2024
CVE-2024-11730
6.5 MEDIUM

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'sort[]' parameter of the static_data_list AJAX …

Dec 6, 2024
CVE-2024-11729
6.5 MEDIUM

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'service_list[0][service_id]' parameter of the get_widget_payment_options AJAX …

Dec 6, 2024
CVE-2024-10909
6.3 MEDIUM

The The Pojo Forms plugin for WordPress is vulnerable to arbitrary shortcode execution via form_preview_shortcode AJAX action in all versions up to, and including, 1.4.7. …

Dec 6, 2024
CVE-2024-10681
6.3 MEDIUM

The The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to arbitrary shortcode execution in …

Dec 6, 2024
CVE-2024-9872
5.4 MEDIUM

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Dec 6, 2024
CVE-2024-9866
5.4 MEDIUM

The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameters in all versions up to, and …

Dec 6, 2024
CVE-2024-9706
5.3 MEDIUM

The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ucsm_activate_lite_template_lite …

Dec 6, 2024
CVE-2024-9705
4.3 MEDIUM

The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ucsm_update_template_name_lite' …

Dec 6, 2024
CVE-2024-12110
4.3 MEDIUM

The Gold Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the activate() and …

Dec 6, 2024
CVE-2024-12060
6.1 MEDIUM

The WP Media Optimizer (.webp) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wpmowebp-css-resources’ and 'wpmowebp-js-resources' parameters in all versions up to, …

Dec 6, 2024
CVE-2024-12028
5.3 MEDIUM

The Friends plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several REST API endpoints in all versions up …

Dec 6, 2024
CVE-2024-12027
4.3 MEDIUM

The Message Filter for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Dec 6, 2024
CVE-2024-12003
6.1 MEDIUM

The WP System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing …

Dec 6, 2024
CVE-2024-11823
6.1 MEDIUM

The Folder Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'foldergallery' shortcode in all versions up to, and including, 1.7.4 …

Dec 6, 2024
CVE-2024-11687
6.1 MEDIUM

The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and …

Dec 6, 2024
CVE-2024-11450
6.4 MEDIUM

The ONLYOFFICE Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'onlyoffice' shortcode in all versions up to, and including, 2.0.0 …

Dec 6, 2024
CVE-2024-11444
4.3 MEDIUM

The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.13.2. This is due …

Dec 6, 2024
CVE-2024-11368
6.1 MEDIUM

The Splash Sync plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in …

Dec 6, 2024
CVE-2024-11352
6.4 MEDIUM

The TwentyTwenty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'twentytwenty' shortcode in all versions up to, and including, 1.0.1 due …

Dec 6, 2024
CVE-2024-11339
6.4 MEDIUM

The Smart PopUp Blaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spb-button' shortcode in all versions up to, and including, …

Dec 6, 2024
CVE-2024-11336
6.1 MEDIUM

The Clickbank WordPress Plugin (Storefront) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7. This is due …

Dec 6, 2024
CVE-2024-11292
5.3 MEDIUM

The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.1 via the WordPress …

Dec 6, 2024
CVE-2024-11276
6.1 MEDIUM

The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all …

Dec 6, 2024
CVE-2024-11204
6.1 MEDIUM

The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in all versions up to, …

Dec 6, 2024
CVE-2024-10879
6.1 MEDIUM

The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without …

Dec 6, 2024
CVE-2024-10849
6.4 MEDIUM

The NewsMash theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all versions up to, and including, 1.0.71 due …

Dec 6, 2024
CVE-2024-10692
4.3 MEDIUM

The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 …

Dec 6, 2024
CVE-2024-10689
4.3 MEDIUM

The XLTab – Accordions and Tabs for Elementor Page Builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, …

Dec 6, 2024
CVE-2024-10320
6.4 MEDIUM

The Cookielay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cookielay shortcode in all versions up to, and including, 1.2.0 due …

Dec 6, 2024
CVE-2024-11201
6.4 MEDIUM

The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification …

Dec 6, 2024
CVE-2024-10551
4.8 MEDIUM

The Sticky Social Icons WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Dec 6, 2024
CVE-2024-10480
4.3 MEDIUM

The 3DPrint Lite WordPress plugin before 2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Dec 6, 2024
CVE-2024-11379
6.1 MEDIUM

The Broadcast plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'do_check' parameter in all versions up to, and including, 51.01 due to …

Dec 6, 2024
CVE-2024-9769
4.4 MEDIUM

The Video Gallery – Best WordPress YouTube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, …

Dec 6, 2024
CVE-2024-10836
6.1 MEDIUM

The Flixita theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.0.82 due to …

Dec 6, 2024
CVE-2024-49041
4.3 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Dec 6, 2024
CVE-2018-9391
6.7 MEDIUM

In update_gps_sv and output_vzw_debug of vendor/mediatek/proprietary/hardware/connectivity/gps/gps_hal/src/gpshal_wor ker.c, there is a possible out of bounds write due to a missing bounds check. This could lead to …

Dec 5, 2024
CVE-2018-9390
6.7 MEDIUM

In procfile_write of gl_proc.c, there is a possible out of bounds read of a function pointer due to an incorrect bounds check. This could lead …

Dec 5, 2024
CVE-2018-9386
6.7 MEDIUM

In reboot_block_command of htc reboot_block driver, there is a possible stack buffer overflow due to a missing bounds check. This could lead to local escalation …

Dec 5, 2024
CVE-2024-53457
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to execute arbitrary web scripts or HTML …

Dec 5, 2024
CVE-2017-13308
6.7 MEDIUM

In tscpu_write_GPIO_out and mtkts_Abts_write of mtk_ts_Abts.c, there is a possible buffer overflow in an sscanf due to improper input validation. This could lead to a …

Dec 5, 2024
CVE-2024-10933
5.0 MEDIUM

In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir name validation to avoid unexpected directory traversal on …

Dec 5, 2024
CVE-2024-12235
6.3 MEDIUM

A vulnerability was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 1.0.0. It has been declared as critical. Affected by this vulnerability is …

Dec 5, 2024
CVE-2024-11158
6.7 MEDIUM

An “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force …

Dec 5, 2024
CVE-2024-54128
5.7 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. The Comment feature has implemented a filter to prevent users from adding …

Dec 5, 2024
CVE-2024-53846
5.5 MEDIUM

OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a number of ready-to-use components mainly written in Erlang, and a …

Dec 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.