CVE Database

46624+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-4972
7.5 HIGH

The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in …

Oct 16, 2024
CVE-2021-4450
8.8 HIGH

The Post Grid plugin for WordPress is vulnerable to blind SQL Injection via post metadata in versions up to, and including, 2.1.12 due to insufficient …

Oct 16, 2024
CVE-2021-4448
7.3 HIGH

The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.0.1 due to insufficient capability checking …

Oct 16, 2024
CVE-2021-4447
8.8 HIGH

The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of …

Oct 16, 2024
CVE-2021-4444
7.3 HIGH

The Product Filter by WooBeWoo plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.4.9 due to missing authorization checks …

Oct 16, 2024
CVE-2020-36839
8.3 HIGH

The WP Lead Plus X plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.99. This is due to …

Oct 16, 2024
CVE-2020-36838
7.4 HIGH

The Facebook Chat Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_update_options function in versions up to, …

Oct 16, 2024
CVE-2020-36836
8.0 HIGH

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and including, 0.9.0.2 due to a lack …

Oct 16, 2024
CVE-2019-25216
7.2 HIGH

The Rich Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the POST body 'update' parameter in versions up to, and including, 1.7.4 …

Oct 16, 2024
CVE-2019-25215
7.3 HIGH

The ARI-Adminer plugin for WordPress is vulnerable to authorization bypass due to a lack of file access controls in nearly every file of the plugin …

Oct 16, 2024
CVE-2019-25214
7.2 HIGH

The ShopWP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST API routes in versions up to, …

Oct 16, 2024
CVE-2017-20192
8.3 HIGH

The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before …

Oct 16, 2024
CVE-2016-15041
7.2 HIGH

The MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mwp_setup_purchase_username’ parameter …

Oct 16, 2024
CVE-2012-10018
8.3 HIGH

The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and including 6.1, 1.0 respectively. This makes …

Oct 16, 2024
CVE-2024-9305
8.1 HIGH

The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.4. …

Oct 16, 2024
CVE-2024-38204
7.5 HIGH

Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network.

Oct 15, 2024
CVE-2024-38190
8.6 HIGH

Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector.

Oct 15, 2024
CVE-2024-38139
8.7 HIGH

Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.

Oct 15, 2024
CVE-2024-9965
8.8 HIGH

Insufficient data validation in DevTools in Google Chrome on Windows prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific …

Oct 15, 2024
CVE-2024-9961
8.8 HIGH

Use after free in ParcelTracking in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific …

Oct 15, 2024
CVE-2024-9960
7.5 HIGH

Use after free in Dawn in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Oct 15, 2024
CVE-2024-9959
8.8 HIGH

Use after free in DevTools in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who had compromised the renderer process to potentially exploit heap …

Oct 15, 2024
CVE-2024-9957
8.8 HIGH

Use after free in UI in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific …

Oct 15, 2024
CVE-2024-9956
7.8 HIGH

Inappropriate implementation in WebAuthentication in Google Chrome on Android prior to 130.0.6723.58 allowed a local attacker to perform privilege escalation via a crafted HTML page. …

Oct 15, 2024
CVE-2024-9955
8.8 HIGH

Use after free in WebAuthentication in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Oct 15, 2024
CVE-2024-9954
8.8 HIGH

Use after free in AI in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Oct 15, 2024
CVE-2024-48783
7.5 HIGH

An issue in Ruijie NBR3000D-E Gateway allows a remote attacker to obtain sensitive information via the /tool/shell/postgresql.conf component.

Oct 15, 2024
CVE-2024-44775
7.5 HIGH

kmqtt v0.2.7 is vulnerable to Denial of Service (DoS) due to a Null Pointer Exception. A remote attacker can cause the broker to crash by …

Oct 15, 2024
CVE-2024-41311
8.1 HIGH

In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and …

Oct 15, 2024
CVE-2024-21285
7.1 HIGH

Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is 14.5.0.12.0. Difficult to …

Oct 15, 2024
CVE-2024-21284
7.1 HIGH

Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is 14.5.0.12.0. Difficult to …

Oct 15, 2024
CVE-2024-21283
8.1 HIGH

Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Core product of Oracle PeopleSoft (component: Global Payroll for Core). Supported versions that are affected are 9.2.48-9.2.50. …

Oct 15, 2024
CVE-2024-21282
8.1 HIGH

Vulnerability in the Oracle Financials product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low …

Oct 15, 2024
CVE-2024-21280
8.1 HIGH

Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Authoring). Supported versions that are affected are 12.2.5-12.2.13. Easily exploitable vulnerability allows low …

Oct 15, 2024
CVE-2024-21279
8.1 HIGH

Vulnerability in the Oracle Sourcing product of Oracle E-Business Suite (component: Auctions). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged …

Oct 15, 2024
CVE-2024-21278
8.1 HIGH

Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: Award Processes). Supported versions that are affected are 12.2.3-12.2.13. …

Oct 15, 2024
CVE-2024-21277
8.1 HIGH

Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Device Integration). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable …

Oct 15, 2024
CVE-2024-21276
8.1 HIGH

Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Messages). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows …

Oct 15, 2024
CVE-2024-21275
8.1 HIGH

Vulnerability in the Oracle Quoting product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.7-12.2.13. Easily exploitable vulnerability allows low …

Oct 15, 2024
CVE-2024-21274
7.5 HIGH

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability …

Oct 15, 2024
CVE-2024-21272
7.5 HIGH

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0 and prior. Difficult to exploit vulnerability allows …

Oct 15, 2024
CVE-2024-21271
8.1 HIGH

Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Field Service Engineer Portal). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable …

Oct 15, 2024
CVE-2024-21270
8.1 HIGH

Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Tasks). Supported versions that are affected are 12.2.6-12.2.13. Easily exploitable vulnerability allows …

Oct 15, 2024
CVE-2024-21269
8.1 HIGH

Vulnerability in the Oracle Incentive Compensation product of Oracle E-Business Suite (component: Compensation Plan). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows …

Oct 15, 2024
CVE-2024-21268
8.1 HIGH

Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are 12.2.11-12.2.13. Easily exploitable vulnerability allows low …

Oct 15, 2024
CVE-2024-21267
8.1 HIGH

Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.12-12.2.13. Easily exploitable vulnerability allows …

Oct 15, 2024
CVE-2024-21266
8.1 HIGH

Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Price List). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows …

Oct 15, 2024
CVE-2024-21265
8.1 HIGH

Vulnerability in the Oracle Site Hub product of Oracle E-Business Suite (component: Site Hierarchy Flows). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability …

Oct 15, 2024
CVE-2024-21260
7.5 HIGH

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability …

Oct 15, 2024
CVE-2024-21259
7.5 HIGH

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.22 and prior to 7.1.2. …

Oct 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.