CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-52797
6.5 MEDIUM

Opencast is free and open source software for automated video capture and distribution. First noticed in Opencast 13 and 14, Opencast's Elasticsearch integration may generate …

Nov 21, 2024
CVE-2024-52067
4.9 MEDIUM

Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context values during the flow synchronization process. An authorized administrator …

Nov 21, 2024
CVE-2024-45663
6.5 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, 11.5, and 12.1 is vulnerable to a denial of service as the server …

Nov 21, 2024
CVE-2024-11456
6.1 MEDIUM

The Run Contests, Raffles, and Giveaways with ContestsWP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate …

Nov 21, 2024
CVE-2024-11455
6.4 MEDIUM

The Include Mastodon Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'include-mastodon-feed' shortcode in all versions up to, and including, …

Nov 21, 2024
CVE-2024-11447
6.1 MEDIUM

The Community by PeepSo – Download from PeepSo.com plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filter’ parameter in all versions up …

Nov 21, 2024
CVE-2024-11440
6.4 MEDIUM

The Grey Owl Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gol_button' shortcode in all versions up to, and including, …

Nov 21, 2024
CVE-2024-11438
6.4 MEDIUM

The StreamWeasels Online Status Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sw-status-bar' shortcode in all versions up to, and …

Nov 21, 2024
CVE-2024-11435
6.1 MEDIUM

The salavat counter Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 0.9.4 …

Nov 21, 2024
CVE-2024-11432
6.4 MEDIUM

The SuevaFree Essential Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'counter' shortcode in all versions up to, and including, …

Nov 21, 2024
CVE-2024-11428
6.4 MEDIUM

The Lazy load videos and sticky control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lazy-load-videos-and-sticky-control' shortcode in all versions up …

Nov 21, 2024
CVE-2024-11424
6.4 MEDIUM

The Slick Sitemap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slick-sitemap' shortcode in all versions up to, and including, 2.0.0 …

Nov 21, 2024
CVE-2024-11416
6.1 MEDIUM

The WIP Incoming Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to …

Nov 21, 2024
CVE-2024-11414
6.4 MEDIUM

The RecipePress Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipe Ingredients in all versions up to, and including, 2.12.0 due to …

Nov 21, 2024
CVE-2024-11412
6.4 MEDIUM

The Shine PDF Embeder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shinepdf' shortcode in all versions up to, and including, …

Nov 21, 2024
CVE-2024-11388
6.4 MEDIUM

The Dino Game – Embed Google Chrome Dinosaur Game in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dino-game' shortcode …

Nov 21, 2024
CVE-2024-11385
6.4 MEDIUM

The Pure CSS Circle Progress bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'circle_progress' shortcode in all versions up to, …

Nov 21, 2024
CVE-2024-11371
6.1 MEDIUM

The Theater for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Nov 21, 2024
CVE-2024-11370
6.1 MEDIUM

The Subaccounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Nov 21, 2024
CVE-2024-11365
6.1 MEDIUM

The Crypto and DeFi Widgets – Web3 Cryptocurrency Shortcodes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without …

Nov 21, 2024
CVE-2024-11360
6.1 MEDIUM

The Page Parts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in …

Nov 21, 2024
CVE-2024-11354
4.3 MEDIUM

The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Nov 21, 2024
CVE-2024-11334
4.3 MEDIUM

The My Contador lesr plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the exportar_registros() function in …

Nov 21, 2024
CVE-2024-11197
4.2 MEDIUM

The Lock User Account plugin for WordPress is vulnerable to user lock bypass in all versions up to, and including, 1.0.5. This is due to …

Nov 21, 2024
CVE-2024-10890
6.1 MEDIUM

The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping …

Nov 21, 2024
CVE-2024-10796
4.3 MEDIUM

The If-So Dynamic Content Personalization plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.2.1 via the 'ifso-show-post' shortcode …

Nov 21, 2024
CVE-2024-10792
6.1 MEDIUM

The Easiest Funnel Builder For WordPress & WooCommerce by WPFunnels plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_id' parameter in all …

Nov 21, 2024
CVE-2024-10785
6.4 MEDIUM

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Countdown' widget …

Nov 21, 2024
CVE-2024-10782
4.3 MEDIUM

The Theme Builder For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the 'elementor-template' shortcode …

Nov 21, 2024
CVE-2024-10726
6.1 MEDIUM

The Friendly Functions for Welcart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.4. This is due …

Nov 21, 2024
CVE-2024-10696
4.3 MEDIUM

The UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere Elementor Shortcode) plugin for WordPress is vulnerable to Insecure …

Nov 21, 2024
CVE-2024-10682
6.1 MEDIUM

The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg and remove_query_arg without …

Nov 21, 2024
CVE-2024-10675
6.1 MEDIUM

The affiliate-toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up to, and including, 3.6.7 due to insufficient …

Nov 21, 2024
CVE-2024-10671
4.3 MEDIUM

The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, …

Nov 21, 2024
CVE-2024-10623
6.1 MEDIUM

The ForumEngine theme for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up to, and including, 1.8 due to insufficient …

Nov 21, 2024
CVE-2024-10532
4.3 MEDIUM

The Bard Extra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bardxtra_import_xml() function in all …

Nov 21, 2024
CVE-2024-10528
4.3 MEDIUM

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized profile picture updates …

Nov 21, 2024
CVE-2024-10522
6.1 MEDIUM

The Co-marquage service-public.fr plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in …

Nov 21, 2024
CVE-2024-10482
5.4 MEDIUM

The Media File Rename, Find Unused File, Add Alt text, Caption, Desc For Image SEO WordPress plugin before 1.5.0 does not sanitise uploaded SVG files, …

Nov 21, 2024
CVE-2024-10393
5.3 MEDIUM

The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6. This is due to a …

Nov 21, 2024
CVE-2024-10316
4.3 MEDIUM

The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.4 in includes/templates/content-switcher.php. This …

Nov 21, 2024
CVE-2024-10177
6.4 MEDIUM

The Beds24 Online Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's beds24-link shortcode in all versions up to, and including, …

Nov 21, 2024
CVE-2024-10172
6.4 MEDIUM

The WPBakery Visual Composer WHMCS Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's void_wbwhmcse_laouts_search shortcode in all versions up to, …

Nov 21, 2024
CVE-2024-10164
6.4 MEDIUM

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdmpp_pay_link shortcode in all versions …

Nov 21, 2024
CVE-2022-43937
5.7 MEDIUM

Possible information exposure through log file vulnerability where sensitive fields are recorded in the debug-enabled logs when debugging is turned on in Brocade SANnav before …

Nov 21, 2024
CVE-2022-43936
6.8 MEDIUM

Brocade SANnav versions before 2.2.2 log Brocade Fabric OS switch passwords when debugging is enabled.

Nov 21, 2024
CVE-2022-43935
5.3 MEDIUM

An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where Brocade Fabric OS Switch passwords and authorization IDs are …

Nov 21, 2024
CVE-2022-43934
6.5 MEDIUM

Brocade SANnav before Brocade SANnav 2.2.2 supports key exchange algorithms, which are considered weak on ports 24, 6514, 18023, 19094, and 19095.

Nov 21, 2024
CVE-2022-43933
4.4 MEDIUM

An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where configuration secrets are logged in supportsave. Supportsave file is …

Nov 21, 2024
CVE-2024-52755
4.9 MEDIUM

D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the host_ip parameter in the ipsec_road_asp function.

Nov 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.