CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-45967
4.7 MEDIUM

Pagekit 1.0.18 is vulnerable to Cross Site Scripting (XSS) in index.php/admin/site/widget.

Oct 1, 2024
CVE-2024-44610
5.6 MEDIUM

PCAN-Ethernet Gateway FD before 1.3.0 and PCAN-Ethernet Gateway before 2.11.0 are vulnerable to Command injection via shell metacharacters in a Software Update to processing.php.

Oct 1, 2024
CVE-2024-25658
6.5 MEDIUM

Cleartext storage of passwords in Infinera TNMS (Transcend Network Management System) Server 19.10.3 allows attackers (with access to the database or exported configuration files) to …

Oct 1, 2024
CVE-2021-37577
6.8 MEDIUM

Bluetooth LE and BR/EDR Secure Connections pairing and Secure Simple Pairing using the Passkey entry protocol in Bluetooth Core Specifications 2.1 through 5.3 may permit …

Oct 1, 2024
CVE-2024-44744
5.7 MEDIUM

An issue in Malwarebytes Premium Security v5.0.0.883 allows attackers to execute arbitrary code via placing crafted binaries into unspecified directories. NOTE: Malwarebytes argues that this …

Oct 1, 2024
CVE-2023-7273
6.8 MEDIUM

Cross site request forgery in Kiteworks OwnCloud allows an unauthenticated attacker to forge requests. If a request has no Authorization header, it is created with …

Oct 1, 2024
CVE-2024-9405
5.3 MEDIUM

An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting version 4.7.18. An unauthenticated attacker could …

Oct 1, 2024
CVE-2024-9118
6.4 MEDIUM

The QS Dark Mode Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Oct 1, 2024
CVE-2024-9060
6.4 MEDIUM

The AVIF & SVG Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in version 1.1.0 due to insufficient input …

Oct 1, 2024
CVE-2023-3441
6.6 MEDIUM

An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4. The product did not sufficiently warn about security implications …

Oct 1, 2024
CVE-2024-9241
6.1 MEDIUM

The PDF Image Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Oct 1, 2024
CVE-2024-9228
6.1 MEDIUM

The Loggedin – Limit Active Logins plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on …

Oct 1, 2024
CVE-2024-9224
6.5 MEDIUM

The Hello World plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 2.1.1 via the hello_world_lyric() function. This …

Oct 1, 2024
CVE-2024-9220
6.1 MEDIUM

The LH Copy Media File plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …

Oct 1, 2024
CVE-2024-9209
6.1 MEDIUM

The WP Search Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Oct 1, 2024
CVE-2024-8799
6.1 MEDIUM

The Custom Banners plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in …

Oct 1, 2024
CVE-2024-8793
6.1 MEDIUM

The Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to …

Oct 1, 2024
CVE-2024-8786
6.1 MEDIUM

The Auto Featured Image from Title plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on …

Oct 1, 2024
CVE-2024-8430
5.3 MEDIUM

The Spice Starter Sites plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the spice_starter_sites_importer_creater function in …

Oct 1, 2024
CVE-2024-8324
6.4 MEDIUM

The XO Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘get_slider’ function in all versions up to, and including, 3.8.6 due …

Oct 1, 2024
CVE-2024-8288
6.4 MEDIUM

The Guten Post Layout – An Advanced Post Grid Collection for WordPress Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ …

Oct 1, 2024
CVE-2024-9304
6.4 MEDIUM

The LocateAndFilter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.14 due to …

Oct 1, 2024
CVE-2024-9274
6.4 MEDIUM

The Elastik Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.27.4 …

Oct 1, 2024
CVE-2024-9272
6.4 MEDIUM

The R Animated Icon Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Oct 1, 2024
CVE-2024-9269
6.4 MEDIUM

The Relogo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.4.2 due to …

Oct 1, 2024
CVE-2024-9267
6.1 MEDIUM

The Easy WordPress Subscribe – Optin Hound plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping …

Oct 1, 2024
CVE-2024-9119
6.4 MEDIUM

The SVG Complete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.2 due …

Oct 1, 2024
CVE-2024-8990
6.4 MEDIUM

The Geo Mashup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's geo_mashup_visible_posts_list shortcode in all versions up to, and including, 1.13.13 …

Oct 1, 2024
CVE-2024-8989
6.4 MEDIUM

The Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's …

Oct 1, 2024
CVE-2024-8728
6.1 MEDIUM

The Easy Load More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Oct 1, 2024
CVE-2024-8727
6.1 MEDIUM

The DK PDF plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in …

Oct 1, 2024
CVE-2024-8720
6.4 MEDIUM

The RumbleTalk Live Group Chat – HTML5 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rumbletalk-admin-button' shortcode in all versions up …

Oct 1, 2024
CVE-2024-8718
6.1 MEDIUM

The Gravity Forms Toolbar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 1.7.0 …

Oct 1, 2024
CVE-2024-8675
4.3 MEDIUM

The Soumettre.fr plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the soumettre_disconnect_gateway function in all versions …

Oct 1, 2024
CVE-2024-8632
6.5 MEDIUM

The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized access and modification of data due to a …

Oct 1, 2024
CVE-2024-8107
6.4 MEDIUM

The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7.18 due …

Oct 1, 2024
CVE-2024-21531
5.3 MEDIUM

All versions of the package git-shallow-clone are vulnerable to Command injection due to missing sanitization or mitigation flags in the process variable of the gitShallowClone …

Oct 1, 2024
CVE-2024-0116
4.9 MEDIUM

NVIDIA Triton Inference Server contains a vulnerability where a user may cause an out-of-bounds read issue by releasing a shared memory region while it is …

Oct 1, 2024
CVE-2024-9358
5.3 MEDIUM

A vulnerability has been found in ThingsBoard up to 3.7.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component …

Oct 1, 2024
CVE-2024-47396
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moveaddons Move Addons for Elementor move-addons allows Stored XSS.This issue affects Move Addons …

Oct 1, 2024
CVE-2024-45073
4.8 MEDIUM

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in …

Sep 30, 2024
CVE-2024-28807
6.5 MEDIUM

An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @CT desktop management application allows guest …

Sep 30, 2024
CVE-2024-28810
6.6 MEDIUM

An issue was discovered in Infinera hiT 7300 5.60.50. Sensitive information inside diagnostic files (exported by the @CT application) allows an attacker to achieve loss …

Sep 30, 2024
CVE-2024-46635
5.9 MEDIUM

An issue in the API endpoint /AccountMaster/GetCurrentUserInfo of INROAD before v202402060 allows attackers to access sensitive information via a crafted payload to the UserNameOrPhoneNumber parameter.

Sep 30, 2024
CVE-2024-35495
4.3 MEDIUM

An Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Build 220930 Rel.143947 allows attackers to observe device …

Sep 30, 2024
CVE-2024-47536
5.4 MEDIUM

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. A user with the editmyprivateinfo right or who can otherwise change their …

Sep 30, 2024
CVE-2024-46548
6.3 MEDIUM

TP-Link Tapo P125M and Kasa KP125M v1.0.3 was discovered to improperly validate certificates, allowing attackers to eavesdrop on communications and access sensitive information via a …

Sep 30, 2024
CVE-2024-46540
6.3 MEDIUM

A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attackers to use remote file downloads and self-extract fucntions …

Sep 30, 2024
CVE-2024-45993
6.5 MEDIUM

Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb.

Sep 30, 2024
CVE-2024-47532
6.5 MEDIUM

RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to protected (and potentially sensible) information indirectly via …

Sep 30, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.