CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-37437
5.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor.This issue affects Elementor Website Builder: from n/a through …

Jul 9, 2024
CVE-2024-37430
5.3 MEDIUM

Authentication Bypass by Spoofing vulnerability in patreon Patreon WordPress patreon-connect.This issue affects Patreon WordPress: from n/a through <= 1.9.0.

Jul 9, 2024
CVE-2024-37410
4.9 MEDIUM

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in IdeaBox Creations PowerPack Lite for Beaver Builder powerpack-addon-for-beaver-builder.This issue …

Jul 9, 2024
CVE-2023-3290
5.0 MEDIUM

A BOLA vulnerability in POST /customers allows a low privileged user to create a low privileged user (customer) in the system. This results in unauthorized …

Jul 9, 2024
CVE-2024-37266
4.9 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Tutor LMS allows Path Traversal.This issue affects Tutor LMS: from n/a …

Jul 9, 2024
CVE-2024-6168
4.3 MEDIUM

The Just Custom Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.2. This is due to …

Jul 9, 2024
CVE-2024-6167
4.3 MEDIUM

The Just Custom Fields plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several AJAX functions in …

Jul 9, 2024
CVE-2024-5993
5.4 MEDIUM

The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_session' function in …

Jul 9, 2024
CVE-2024-5992
6.5 MEDIUM

The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_chatbot_token' and 'update_chatbot_position' …

Jul 9, 2024
CVE-2024-5937
6.4 MEDIUM

The Simple Alert Boxes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Alert shortcode in all versions up to, and including, …

Jul 9, 2024
CVE-2024-5856
4.3 MEDIUM

The Comment Images Reloaded plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the cir_delete_image AJAX action …

Jul 9, 2024
CVE-2024-5810
5.3 MEDIUM

The WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.1. …

Jul 9, 2024
CVE-2024-5704
4.3 MEDIUM

The XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Jul 9, 2024
CVE-2024-5669
6.4 MEDIUM

The XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Jul 9, 2024
CVE-2024-5648
5.4 MEDIUM

The LearnDash LMS – Reports plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions (i.e. …

Jul 9, 2024
CVE-2024-5600
5.4 MEDIUM

The SCSS Happy Compiler – Compile SCSS to CSS & Automatic Enqueue plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing …

Jul 9, 2024
CVE-2024-5457
6.4 MEDIUM

The Panda Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.4.0 due …

Jul 9, 2024
CVE-2024-4868
6.4 MEDIUM

The Extensions for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's EE Events and EE Flipbox widgets in all versions …

Jul 9, 2024
CVE-2024-4102
5.4 MEDIUM

The Pricing Table plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all …

Jul 9, 2024
CVE-2024-4100
5.3 MEDIUM

The Pricing Table plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.1. This is due to missing …

Jul 9, 2024
CVE-2024-3608
5.3 MEDIUM

The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the product_designer_ajax_delete_attach_id() function in all …

Jul 9, 2024
CVE-2024-3603
6.4 MEDIUM

The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'osm_map' shortcode in all versions up to, and including, …

Jul 9, 2024
CVE-2024-3563
6.4 MEDIUM

The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sharing block in all versions up to, and including, 3.1.3 …

Jul 9, 2024
CVE-2024-3228
5.3 MEDIUM

The Social Sharing Plugin – Kiwi plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.1.7 via the 'kiwi-nw-pinterest' …

Jul 9, 2024
CVE-2024-37502
5.4 MEDIUM

Deserialization of Untrusted Data vulnerability in wpweb WooCommerce Social Login woo-social-login.This issue affects WooCommerce Social Login: from n/a through <= 2.6.3.

Jul 9, 2024
CVE-2024-5881
6.4 MEDIUM

The Webico Slider Flatsome Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wbc_image shortcode in all versions up to, and …

Jul 9, 2024
CVE-2024-37923
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in cliengo Cliengo – Chatbot cliengo allows Cross Site Request Forgery.This issue affects Cliengo – Chatbot: from n/a through <= …

Jul 9, 2024
CVE-2024-22062
6.3 MEDIUM

There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permissions to administrator permissions by modifying the configuration.

Jul 9, 2024
CVE-2024-6334
6.1 MEDIUM

The Easy Table of Contents WordPress plugin before 2.0.67.1 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jul 9, 2024
CVE-2024-5802
4.8 MEDIUM

The URL Shortener by Myhop WordPress plugin through 1.0.17 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jul 9, 2024
CVE-2024-3410
4.3 MEDIUM

The DN Footer Contacts WordPress plugin before 1.6.3 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jul 9, 2024
CVE-2024-6171
5.3 MEDIUM

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, …

Jul 9, 2024
CVE-2024-6170
6.4 MEDIUM

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘email’ parameter in all versions …

Jul 9, 2024
CVE-2024-6169
6.4 MEDIUM

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ parameter in all versions …

Jul 9, 2024
CVE-2024-4667
6.4 MEDIUM

The Blog, Posts and Category Filter for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post and Category Filter widget in …

Jul 9, 2024
CVE-2024-39600
5.0 MEDIUM

Under certain conditions, the memory of SAP GUI for Windows contains the password used to log on to an SAP system, which might allow an …

Jul 9, 2024
CVE-2024-39599
4.7 MEDIUM

Due to a Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP Platform, a developer can bypass the configured malware scanner API …

Jul 9, 2024
CVE-2024-39596
4.3 MEDIUM

Due to missing authorization checks, SAP Enable Now allows an author to escalate privileges to access information which should otherwise be restricted. On successful exploitation, …

Jul 9, 2024
CVE-2024-39595
5.4 MEDIUM

SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user-controlled inputs, resulting in Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability allows …

Jul 9, 2024
CVE-2024-39594
6.1 MEDIUM

SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user controlled inputs, resulting in Reflected Cross-Site Scripting (XSS) vulnerability. After successful …

Jul 9, 2024
CVE-2024-37180
4.1 MEDIUM

Under certain conditions SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to access remote-enabled function module with no further authorization which …

Jul 9, 2024
CVE-2024-37175
4.3 MEDIUM

SAP CRM WebClient does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to access …

Jul 9, 2024
CVE-2024-37172
5.4 MEDIUM

SAP S/4HANA Finance (Advanced Payment Management) does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. As a result, it …

Jul 9, 2024
CVE-2024-37171
5.0 MEDIUM

SAP Transportation Management (Collaboration Portal) allows an attacker with non-administrative privileges to send a crafted request from a vulnerable web application. This will trigger the …

Jul 9, 2024
CVE-2024-34689
5.0 MEDIUM

WebFlow Services of SAP Business Workflow allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On …

Jul 9, 2024
CVE-2024-39598
5.0 MEDIUM

SAP CRM (WebClient UI Framework) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful …

Jul 9, 2024
CVE-2024-39593
6.9 MEDIUM

SAP Landscape Management allows an authenticated user to read confidential data disclosed by the REST Provider Definition response. Successful exploitation can cause high impact on …

Jul 9, 2024
CVE-2024-37174
6.1 MEDIUM

Custom CSS support option in SAP CRM WebClient UI does not sufficiently encode user-controlled inputs resulting in Cross-Site Scripting vulnerability. On successful exploitation an attacker …

Jul 9, 2024
CVE-2024-37173
6.1 MEDIUM

Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script. When a …

Jul 9, 2024
CVE-2024-34685
6.1 MEDIUM

Due to weak encoding of user-controlled input in SAP NetWeaver Knowledge Management XMLEditor which allows malicious scripts can be executed in the application, potentially leading …

Jul 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.