CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5589
6.3 MEDIUM

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. This affects an unknown part of the file …

Jun 3, 2024
CVE-2024-5588
6.3 MEDIUM

A vulnerability was found in itsourcecode Learning Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jun 2, 2024
CVE-2024-36392
6.1 MEDIUM

MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Jun 2, 2024
CVE-2024-5587
5.3 MEDIUM

A vulnerability was found in Casdoor up to 1.335.0. It has been classified as problematic. Affected is an unknown function of the file /conf/app.conf of …

Jun 2, 2024
CVE-2024-4344
4.3 MEDIUM

The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, …

Jun 2, 2024
CVE-2024-35647
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Global Notification Bar allows Stored XSS.This issue affects Global Notification Bar: …

Jun 2, 2024
CVE-2024-35646
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Erez Hadas-Sonnenschein Smartarget Message Bar smartarget-message-bar.This issue affects Smartarget Message Bar: from n/a …

Jun 2, 2024
CVE-2024-35645
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar Random Banner random-banner allows DOM-Based XSS.This issue affects Random …

Jun 2, 2024
CVE-2024-35636
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Uploadcare Uploadcare File Uploader and Adaptive Delivery (beta) uploadcare.This issue affects Uploadcare File Uploader and Adaptive Delivery (beta): from …

Jun 1, 2024
CVE-2024-2295
6.4 MEDIUM

The Contact Form Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [xyz-cfm-form] shortcode in all versions up to, and including, …

Jun 1, 2024
CVE-2024-2506
6.4 MEDIUM

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS functionality …

Jun 1, 2024
CVE-2024-1324
5.3 MEDIUM

The QQWorld Auto Save Images plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the save_remote_images_get_auto_saved_results() function …

Jun 1, 2024
CVE-2024-5501
6.4 MEDIUM

The Supreme Modules Lite – Divi Theme, Extra Theme and Divi Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_one_id’ parameter …

Jun 1, 2024
CVE-2024-4342
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image hotspot, image accordion, off canvas, woogrid, …

Jun 1, 2024
CVE-2024-4087
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Back to Top widget in all versions …

Jun 1, 2024
CVE-2023-6382
6.4 MEDIUM

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_slide' shortcode in all versions up …

Jun 1, 2024
CVE-2024-3565
6.4 MEDIUM

The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'content_block' shortcode in all versions up to, …

Jun 1, 2024
CVE-2024-4711
6.4 MEDIUM

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ajax_load_more shortcode in versions up to, …

Jun 1, 2024
CVE-2024-2933
6.4 MEDIUM

The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Social Profiles widget in all versions up …

Jun 1, 2024
CVE-2024-34006
4.3 MEDIUM

The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered.

May 31, 2024
CVE-2024-34005
6.5 MEDIUM

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore database …

May 31, 2024
CVE-2024-34004
6.5 MEDIUM

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore wiki …

May 31, 2024
CVE-2024-34003
5.9 MEDIUM

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore workshop …

May 31, 2024
CVE-2024-34002
6.5 MEDIUM

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore feedback …

May 31, 2024
CVE-2024-36845
4.3 MEDIUM

An invalid pointer in the modbus_receive() function of libmodbus v3.1.6 allows attackers to cause a Denial of Service (DoS) via a crafted message sent to …

May 31, 2024
CVE-2024-34000
4.3 MEDIUM

ID numbers displayed in the lesson overview report required additional sanitizing to prevent a stored XSS risk.

May 31, 2024
CVE-2024-33998
5.4 MEDIUM

Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features.

May 31, 2024
CVE-2024-33997
6.1 MEDIUM

Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation.

May 31, 2024
CVE-2024-33996
6.2 MEDIUM

Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not …

May 31, 2024
CVE-2024-22060
4.9 MEDIUM

An unrestricted file upload vulnerability in web component of Ivanti Neurons for ITSM allows a remote, authenticated, high privileged user to write arbitrary files into …

May 31, 2024
CVE-2021-44534
6.5 MEDIUM

Insufficient user input filtering leads to arbitrary file read by non-authenticated attacker, which results in sensitive information disclosure.

May 31, 2024
CVE-2022-25038
6.1 MEDIUM

wanEditor v4.7.11 was discovered to contain a cross-site scripting (XSS) vulnerability via the video upload function.

May 31, 2024
CVE-2022-25037
5.4 MEDIUM

An issue in wanEditor v4.7.11 and fixed in v.4.7.12 and v.5 was discovered to contain a cross-site scripting (XSS) vulnerability via the image upload function.

May 31, 2024
CVE-2023-7073
6.4 MEDIUM

The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.7 via …

May 31, 2024
CVE-2024-31908
6.4 MEDIUM

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web …

May 31, 2024
CVE-2024-31907
5.4 MEDIUM

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

May 31, 2024
CVE-2024-31889
5.4 MEDIUM

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

May 31, 2024
CVE-2024-22338
4.0 MEDIUM

IBM Security Verify Access OIDC Provider 22.09 through 23.03 could disclose sensitive information to a local user due to hazardous input validation. IBM X-Force ID: …

May 31, 2024
CVE-2024-5347
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'arrow' attribute within the plugin's Post Navigation widget in …

May 31, 2024
CVE-2024-5041
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ha-ia-content-button’ parameter in all versions up to, and including, …

May 31, 2024
CVE-2024-4160
6.4 MEDIUM

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' shortcode in all versions up to, and including, 3.2.90 …

May 31, 2024
CVE-2024-5524
5.3 MEDIUM

Information exposure vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows unregistered users to access all internal links of the application without providing any credentials.

May 31, 2024
CVE-2024-5427
6.4 MEDIUM

The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's …

May 31, 2024
CVE-2024-4379
5.4 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Global Tooltip widget in all versions up to, …

May 31, 2024
CVE-2024-4376
6.4 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fancy Text widget in all versions up to, …

May 31, 2024
CVE-2024-4205
4.3 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_template_content() function …

May 31, 2024
CVE-2024-23847
5.9 MEDIUM

Incorrect default permissions issue exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a …

May 31, 2024
CVE-2024-5418
6.4 MEDIUM

The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slitems' attribute within the plugin's De Product Tab & Slide …

May 31, 2024
CVE-2024-1298
6.0 MEDIUM

EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A …

May 30, 2024
CVE-2024-35189
6.5 MEDIUM

Fides is an open-source privacy engineering platform. The Fides webserver has a number of endpoints that retrieve `ConnectionConfiguration` records and their associated `secrets` which _can_ …

May 30, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.