CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2017-20193
4.7 MEDIUM

The Product Vendors is vulnerable to Reflected Cross-Site Scripting via the 'vendor_description' parameter in versions up to, and including, 2.0.35 due to insufficient input sanitization …

Oct 16, 2024
CVE-2024-9582
6.4 MEDIUM

The Accordion Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ attribute of an accordion slider in all versions up to, …

Oct 16, 2024
CVE-2023-7293
4.3 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the …

Oct 16, 2024
CVE-2023-7292
4.3 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized notification dismissal due to a missing capability check on the paytium_notice_dismiss …

Oct 16, 2024
CVE-2023-7290
4.3 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the …

Oct 16, 2024
CVE-2023-7289
5.4 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized API key update due to a missing capability check on the …

Oct 16, 2024
CVE-2023-7288
5.4 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_profile_preference …

Oct 16, 2024
CVE-2023-7287
5.4 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized subscription cancellation due to a missing capability check on the pt_cancel_subscription …

Oct 16, 2024
CVE-2023-7286
6.5 MEDIUM

The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.2.2. This makes it …

Oct 16, 2024
CVE-2022-4974
6.3 MEDIUM

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing …

Oct 16, 2024
CVE-2022-4973
4.9 MEDIUM

WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploited by users with access to the WordPress …

Oct 16, 2024
CVE-2022-4971
6.1 MEDIUM

The Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'urls' parameter called via the 'heateor_sss_sharing_count' AJAX action in versions …

Oct 16, 2024
CVE-2021-4451
6.6 MEDIUM

The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and including, 4.3.3. This allows authenticated attackers to perform phar …

Oct 16, 2024
CVE-2021-4446
6.3 MEDIUM

The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and including 4.6.4 due to missing capability checks …

Oct 16, 2024
CVE-2021-4445
6.5 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to Arbitrary Option Updates in versions up to, and including, 4.5.1. This is due to …

Oct 16, 2024
CVE-2020-36835
4.9 MEDIUM

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks …

Oct 16, 2024
CVE-2020-36834
6.3 MEDIUM

The Discount Rules for WooCommerce plugin for WordPress is vulnerable to missing authorization via several AJAX actions in versions up to, and including, 2.0.2 due …

Oct 16, 2024
CVE-2020-36833
6.3 MEDIUM

The Indeed Membership Pro plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various AJAX actions in versions 7.3 - …

Oct 16, 2024
CVE-2020-36831
5.0 MEDIUM

The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple user privilege/security functions provided in …

Oct 16, 2024
CVE-2024-9937
6.1 MEDIUM

The Woo Manage Fraud Orders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, …

Oct 16, 2024
CVE-2024-9888
5.4 MEDIUM

The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's contact form widget redirect URL in all versions …

Oct 16, 2024
CVE-2024-9873
5.4 MEDIUM

The Community by PeepSo – Social Network, Membership, Registration, User Profiles, Premium – Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Oct 16, 2024
CVE-2024-9891
4.3 MEDIUM

The Multiline files upload for contact form 7 plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the …

Oct 16, 2024
CVE-2024-9652
6.1 MEDIUM

The Locatoraid Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST keys in all versions up to, and including, 3.9.47 due …

Oct 16, 2024
CVE-2024-9649
4.3 MEDIUM

The WP ULike – The Ultimate Engagement Toolkit for Websites plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

Oct 16, 2024
CVE-2024-9647
6.1 MEDIUM

The Kama SpamBlock plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST values in all versions up to, and including, 1.8.2 due to …

Oct 16, 2024
CVE-2024-9521
6.4 MEDIUM

The SEO Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post meta in versions up to, and including, 1.9 due to insufficient …

Oct 16, 2024
CVE-2024-9104
5.6 MEDIUM

The UltimateAI plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.8.3. This is due to the improper empty …

Oct 16, 2024
CVE-2024-8787
6.1 MEDIUM

The Smart Online Order for Clover plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate …

Oct 16, 2024
CVE-2024-8541
4.7 MEDIUM

The Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting …

Oct 16, 2024
CVE-2024-49340
4.3 MEDIUM

IBM Watson Studio Local 1.2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a …

Oct 16, 2024
CVE-2024-45085
5.9 MEDIUM

IBM WebSphere Application Server 8.5 is vulnerable to a denial of service, under certain configurations, caused by an unexpected specially crafted request. A remote attacker …

Oct 15, 2024
CVE-2024-9966
5.3 MEDIUM

Inappropriate implementation in Navigations in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium …

Oct 15, 2024
CVE-2024-9964
4.3 MEDIUM

Inappropriate implementation in Payments in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Oct 15, 2024
CVE-2024-9963
4.3 MEDIUM

Insufficient data validation in Downloads in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Oct 15, 2024
CVE-2024-9962
4.3 MEDIUM

Inappropriate implementation in Permissions in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Oct 15, 2024
CVE-2024-9958
4.3 MEDIUM

Inappropriate implementation in PictureInPicture in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Oct 15, 2024
CVE-2024-9594
6.3 MEDIUM

A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process when using …

Oct 15, 2024
CVE-2024-48714
6.5 MEDIUM

In TP-Link TL-WDR7660 v1.0, the guestRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

Oct 15, 2024
CVE-2024-48713
6.5 MEDIUM

In TP-Link TL-WDR7660 1.0, the wacWhitelistJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

Oct 15, 2024
CVE-2024-48712
6.5 MEDIUM

In TP-Link TL-WDR7660 1.0, the rtRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

Oct 15, 2024
CVE-2024-48710
6.5 MEDIUM

In TP-Link TL-WDR7660 1.0, the wlanTimerRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

Oct 15, 2024
CVE-2024-31955
4.9 MEDIUM

An issue was discovered in Samsung eMMC with KLMAG2GE4A and KLM8G1WEMB firmware. Code bypass through Electromagnetic Fault Injection allows an attacker to successfully authenticate and …

Oct 15, 2024
CVE-2024-44337
5.1 MEDIUM

The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to pseudoversion `v0.0.0-20240729232818-a2a9c4f`, which corresponds with commit `a2a9c4f76ef5a5c32108e36f7c47f8d310322252`, there …

Oct 15, 2024
CVE-2024-21286
5.4 MEDIUM

Vulnerability in the PeopleSoft Enterprise ELM Enterprise Learning Management product of Oracle PeopleSoft (component: Enterprise Learning Management). The supported version that is affected is 9.2. …

Oct 15, 2024
CVE-2024-21281
5.3 MEDIUM

Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Infrastructure). The supported version that is affected is 14.7.0.6.0. Difficult to …

Oct 15, 2024
CVE-2024-21273
6.0 MEDIUM

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.22 and prior to 7.1.2. …

Oct 15, 2024
CVE-2024-21264
5.4 MEDIUM

Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Activity Guide Composer). The supported version that is affected is 9.2. …

Oct 15, 2024
CVE-2024-21263
6.1 MEDIUM

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.22 and prior to 7.1.2. …

Oct 15, 2024
CVE-2024-21262
6.5 MEDIUM

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected are 9.0.0 and prior. Easily exploitable vulnerability allows unauthenticated …

Oct 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.