CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-3499
8.8 HIGH

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.0 via the generate_navigation_markup function …

May 2, 2024
CVE-2024-3047
7.2 HIGH

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.8.0 via …

May 2, 2024
CVE-2024-3045
7.2 HIGH

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and …

May 2, 2024
CVE-2024-2831
8.8 HIGH

The Calendar plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcodes in all versions up to, and including, 1.3.14 due to insufficient …

May 2, 2024
CVE-2024-2661
8.8 HIGH

The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. plugin for WordPress is vulnerable to …

May 2, 2024
CVE-2024-2417
8.8 HIGH

The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to privilege escalation due to a …

May 2, 2024
CVE-2024-2082
7.2 HIGH

The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in …

May 2, 2024
CVE-2024-25290
8.0 HIGH

An issue in Casa Systems NL1901ACV R6B032 allows a remote attacker to execute arbitrary code via the userName parameter of the add function.

May 2, 2024
CVE-2024-1945
7.1 HIGH

The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable to unauthorized loss of data due …

May 2, 2024
CVE-2024-1897
7.5 HIGH

The Grid Gallery – Photo Image Grid Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.3 …

May 2, 2024
CVE-2024-1896
7.5 HIGH

The Photo Gallery – Responsive Photo Gallery, Image Gallery, Portfolio Gallery, Logo Gallery And Team Gallery plugin for WordPress is vulnerable to PHP Object Injection …

May 2, 2024
CVE-2024-1797
8.8 HIGH

The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to SQL Injection via the 'status' and 'id' attributes of the …

May 2, 2024
CVE-2024-1567
8.2 HIGH

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type validation in the 'file_validity' function …

May 2, 2024
CVE-2024-1173
7.2 HIGH

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL …

May 2, 2024
CVE-2023-7064
7.5 HIGH

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.17.5 …

May 2, 2024
CVE-2023-6961
7.2 HIGH

The WP Meta SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Referer’ header in all versions up to, and including, 4.5.12 …

May 2, 2024
CVE-2023-6214
7.5 HIGH

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.6 …

May 2, 2024
CVE-2024-33530
7.5 HIGH

In Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make use of a lobby) leads to the disclosure of the meeting …

May 2, 2024
CVE-2024-31964
7.5 HIGH

A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit …

May 2, 2024
CVE-2024-29309
7.7 HIGH

An issue in Alfresco Content Services v.23.3.0.7 allows a remote attacker to execute arbitrary code via the Transfer Service.

May 2, 2024
CVE-2023-50685
7.5 HIGH

An issue in Hipcam Cameras RealServer v.1.0 allows a remote attacker to cause a denial of service via a crafted script to the client_port parameter.

May 2, 2024
CVE-2024-3544
7.5 HIGH

Unauthenticated attackers can perform actions, using SSH private keys, by knowing the IP address and having access to the same network of one of the …

May 2, 2024
CVE-2024-34145
8.8 HIGH

A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to …

May 2, 2024
CVE-2024-33303
8.2 HIGH

SourceCodester Product Show Room 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" under Add Users.

May 2, 2024
CVE-2024-30251
7.5 HIGH

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attacker can send a specially crafted POST (multipart/form-data) request. When …

May 2, 2024
CVE-2024-23459
7.1 HIGH

An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Mac allows a system file to be overwritten.This issue affects …

May 2, 2024
CVE-2024-33911
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar School Management Pro.This issue affects School Management Pro: from n/a …

May 2, 2024
CVE-2024-32114
8.5 HIGH

In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolokia JMX REST API and the Message REST API are …

May 2, 2024
CVE-2024-3476
8.8 HIGH

The Side Menu Lite WordPress plugin before 4.2.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in …

May 2, 2024
CVE-2024-3475
7.5 HIGH

The Sticky Buttons WordPress plugin before 3.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins …

May 2, 2024
CVE-2024-3474
8.8 HIGH

The Wow Skype Buttons WordPress plugin before 4.0.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in …

May 2, 2024
CVE-2024-33423
7.4 HIGH

Cross-Site Scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected …

May 1, 2024
CVE-2024-33306
7.4 HIGH

SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" parameter in Create User.

May 1, 2024
CVE-2024-33430
8.8 HIGH

An issue in phiola/src/afilter/pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via the a crafted .wav file.

May 1, 2024
CVE-2024-33429
7.1 HIGH

Buffer-Overflow vulnerability at pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via a crafted .wav file.

May 1, 2024
CVE-2024-33428
8.8 HIGH

Buffer-Overflow vulnerability at conv.c:68 of stsaz phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via the a crafted .wav file.

May 1, 2024
CVE-2024-33300
7.3 HIGH

Typora v1.0.0 through v1.7 version (below) Markdown editor has a cross-site scripting (XSS) vulnerability, which allows attackers to execute arbitrary code by uploading Markdown files.

May 1, 2024
CVE-2024-33292
8.2 HIGH

SQL Injection vulnerability in Realisation MGSD v.1.0 allows a remote attacker to obtain sensitive information via the id parameter.

May 1, 2024
CVE-2024-29011
7.5 HIGH

Use of hard-coded password in the GMS ECM endpoint leading to authentication bypass vulnerability. This issue affects GMS: 9.3.4 and earlier versions.

May 1, 2024
CVE-2024-26504
8.8 HIGH

An issue in Wifire Hotspot v.4.5.3 allows a local attacker to execute arbitrary code via a crafted payload to the dst parameter.

May 1, 2024
CVE-2024-25458
7.5 HIGH

An issue in CYCZCAM, SHIX ZHAO, SHIXCAM A9 Camera (circuit board identifier A9-48B-V1.0) firmware v.CYCAM_48B_BC01_v87_0903 allows a remote attacker to obtain sensitive information via a …

May 1, 2024
CVE-2024-25355
7.5 HIGH

s3-url-parser 1.0.3 is vulnerable to Denial of service via the regexes component.

May 1, 2024
CVE-2024-24313
7.5 HIGH

An issue in Vaales Technologies V_QRS v.2024-01-17 allows a remote attacker to obtain sensitive information via the Models/FormModel.php and QRModel.php component.

May 1, 2024
CVE-2024-24312
7.5 HIGH

SQL injection vulnerability in Vaales Technologies V_QRS v.2024-01-17 allows a remote attacker to obtain sensitive information via the Models/UserModel.php component.

May 1, 2024
CVE-2024-32212
8.1 HIGH

SQL Injection vulnerability in LOGINT LoMag Inventory Management v1.0.20.120 and before allows an attacker to execute arbitrary code via the ArticleGetGroups, DocAddDocument, ClassClickShop and frmSettings …

May 1, 2024
CVE-2024-29010
7.1 HIGH

The XML document processed in the GMS ECM URL endpoint is vulnerable to XML external entity (XXE) injection, potentially resulting in the disclosure of sensitive …

May 1, 2024
CVE-2024-25015
7.5 HIGH

IBM MQ 9.2 LTS, 9.3 LTS, and 9.3 CD Internet Pass-Thru could allow a remote user to cause a denial of service by sending HTTP …

May 1, 2024
CVE-2024-23480
7.5 HIGH

A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Client Connector on MacOS prior to 4.2.

May 1, 2024
CVE-2024-23457
7.8 HIGH

The anti-tampering functionality of the Zscaler Client Connector can be disabled under certain conditions when an uninstall password is enforced. This affects Zscaler Client Connector …

May 1, 2024
CVE-2024-20378
7.5 HIGH

A vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected …

May 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.