CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4218
6.5 MEDIUM

The AffiEasy plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.6. This is due to plugin improperly …

May 30, 2024
CVE-2024-3947
4.3 MEDIUM

The WP To Do plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.0. This is due to …

May 30, 2024
CVE-2024-3946
4.4 MEDIUM

The WP To Do plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.3.0 due …

May 30, 2024
CVE-2024-3945
4.3 MEDIUM

The WP To Do plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.0. This is due to …

May 30, 2024
CVE-2024-3943
4.3 MEDIUM

The WP To Do plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.0. This is due to …

May 30, 2024
CVE-2024-3277
5.0 MEDIUM

The Yumpu ePaper publishing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handler function in …

May 30, 2024
CVE-2024-5223
6.4 MEDIUM

The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file uploading …

May 30, 2024
CVE-2024-3269
5.4 MEDIUM

The Download Monitor plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on the dlm_uninstall_plugin function in all …

May 30, 2024
CVE-2024-3190
5.4 MEDIUM

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's text field widget in …

May 30, 2024
CVE-2024-3063
6.4 MEDIUM

The WPB Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the output of 'tags' added to widgets in all versions up …

May 30, 2024
CVE-2024-2253
6.4 MEDIUM

The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via URL values the plugin's carousel widgets in all versions up …

May 30, 2024
CVE-2024-3726
6.4 MEDIUM

The Login Logout Register Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'llrmloginlogout' shortcode in all versions up to, and …

May 30, 2024
CVE-2024-35221
4.3 MEDIUM

Rubygems.org is the Ruby community's gem hosting service. A Gem publisher can cause a Remote DoS when publishing a Gem. This is due to how …

May 29, 2024
CVE-2024-35512
5.3 MEDIUM

hmq v1.5.5 is vulnerable to Denial of Service (DoS) due to a Null Pointer Exception. A remote attacker can trigger a broker crash by sending …

May 29, 2024
CVE-2024-35284
5.4 MEDIUM

A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a reflected cross-site scripting …

May 29, 2024
CVE-2024-35283
6.1 MEDIUM

A vulnerability in the Ignite component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a stored cross-site scripting (XSS) …

May 29, 2024
CVE-2024-35200
5.3 MEDIUM

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate.

May 29, 2024
CVE-2024-34161
5.3 MEDIUM

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of …

May 29, 2024
CVE-2024-32760
6.5 MEDIUM

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate …

May 29, 2024
CVE-2024-31079
4.8 MEDIUM

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or …

May 29, 2024
CVE-2023-46297
5.1 MEDIUM

An issue was discovered on Mercusys MW325R EU V3 MW325R(EU)_V3_1.11.0 221019 devices. A WAN attacker can make the admin interface unreachable/invisible via an unauthenticated HTTP …

May 29, 2024
CVE-2024-36378
5.9 MEDIUM

In JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokens

May 29, 2024
CVE-2024-36377
6.5 MEDIUM

In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions

May 29, 2024
CVE-2024-36376
6.5 MEDIUM

In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissions

May 29, 2024
CVE-2024-36375
5.3 MEDIUM

In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed

May 29, 2024
CVE-2024-36374
4.6 MEDIUM

In JetBrains TeamCity before 2024.03.2 stored XSS via build step settings was possible

May 29, 2024
CVE-2024-36373
4.6 MEDIUM

In JetBrains TeamCity before 2024.03.2 several stored XSS in untrusted builds settings were possible

May 29, 2024
CVE-2024-36372
4.6 MEDIUM

In JetBrains TeamCity before 2023.05.6 reflected XSS on the subscriptions page was possible

May 29, 2024
CVE-2024-36371
4.6 MEDIUM

In JetBrains TeamCity before 2023.05.6, 2023.11.5 stored XSS in Commit status publisher was possible

May 29, 2024
CVE-2024-36370
4.6 MEDIUM

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via OAuth connection settings was possible

May 29, 2024
CVE-2024-36369
4.6 MEDIUM

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was possible

May 29, 2024
CVE-2024-36368
4.6 MEDIUM

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 reflected XSS via OAuth provider configuration was possible

May 29, 2024
CVE-2024-36367
4.6 MEDIUM

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party reports was possible

May 29, 2024
CVE-2024-36366
5.4 MEDIUM

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grouping and filtering operations

May 29, 2024
CVE-2024-36365
6.8 MEDIUM

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent

May 29, 2024
CVE-2024-36364
6.5 MEDIUM

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisher build features was possible

May 29, 2024
CVE-2024-36363
4.6 MEDIUM

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 several Stored XSS in code inspection reports were possible

May 29, 2024
CVE-2024-36362
6.5 MEDIUM

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible

May 29, 2024
CVE-2024-25975
6.5 MEDIUM

The application implements an up- and downvote function which alters a value within a JSON file. The POST parameters are not filtered properly and therefore …

May 29, 2024
CVE-2024-5039
6.4 MEDIUM

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up …

May 29, 2024
CVE-2024-25976
6.1 MEDIUM

When LDAP authentication is activated in the configuration it is possible to obtain reflected XSS execution by creating a custom URL that the victim only …

May 29, 2024
CVE-2024-27313
6.3 MEDIUM

Zoho ManageEngine PAM360 is vulnerable to Stored XSS vulnerability. This vulnerability is applicable only in the version 6610.

May 29, 2024
CVE-2023-52881
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tcp: do not accept ACK of bytes we never sent This patch is based on …

May 29, 2024
CVE-2024-5086
6.4 MEDIUM

The Essential Addons for Elementor PRO – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

May 29, 2024
CVE-2024-36014
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/arm/malidp: fix a possible null pointer dereference In malidp_mw_connector_reset, new memory is allocated with kzalloc, …

May 29, 2024
CVE-2024-4419
4.4 MEDIUM

The Fetch JFT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.3 due to …

May 29, 2024
CVE-2024-3937
4.8 MEDIUM

The Playlist for Youtube WordPress plugin through 1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 29, 2024
CVE-2024-3921
4.8 MEDIUM

The Gianism WordPress plugin through 5.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 29, 2024
CVE-2024-0434
5.3 MEDIUM

The WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

May 29, 2024
CVE-2024-36112
6.3 MEDIUM

Nautobot is a Network Source of Truth and Network Automation Platform. A user with permissions to view Dynamic Group records (`extras.view_dynamicgroup` permission) can use the …

May 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.