CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-1455
5.9 MEDIUM

A vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External Entity (XXE) exploitation. By nesting multiple layers of …

Mar 26, 2024
CVE-2024-30235
4.3 MEDIUM

Missing Authorization vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.4.0.

Mar 26, 2024
CVE-2024-30234
6.5 MEDIUM

Missing Authorization vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.1.

Mar 26, 2024
CVE-2024-30233
6.5 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.1.

Mar 26, 2024
CVE-2024-2906
6.5 MEDIUM

Missing Authorization vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73.

Mar 26, 2024
CVE-2024-22156
6.5 MEDIUM

Missing Authorization vulnerability in SNP Digital SalesKing.This issue affects SalesKing: from n/a through 1.6.15.

Mar 26, 2024
CVE-2023-52214
4.3 MEDIUM

Missing Authorization vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder.This issue affects Void Contact Form 7 Widget For Elementor Page Builder: …

Mar 26, 2024
CVE-2024-30232
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: …

Mar 26, 2024
CVE-2024-29644
6.1 MEDIUM

Cross Site Scripting vulnerability in dcat-admin v.2.1.3 and before allows a remote attacker to execute arbitrary code via a crafted script to the user login …

Mar 26, 2024
CVE-2024-24799
6.5 MEDIUM

Missing Authorization vulnerability in WooCommerce WooCommerce Box Office.This issue affects WooCommerce Box Office: from n/a through 1.2.2.

Mar 26, 2024
CVE-2024-24719
4.3 MEDIUM

Missing Authorization vulnerability in Uriahs Victor Location Picker at Checkout for WooCommerce.This issue affects Location Picker at Checkout for WooCommerce: from n/a through 1.8.9.

Mar 26, 2024
CVE-2024-24718
4.3 MEDIUM

Missing Authorization vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.6.

Mar 26, 2024
CVE-2024-24711
4.3 MEDIUM

Missing Authorization vulnerability in weDevs WooCommerce Conversion Tracking.This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.11.

Mar 26, 2024
CVE-2024-23520
4.3 MEDIUM

Missing Authorization vulnerability in AccessAlly PopupAlly.This issue affects PopupAlly: from n/a through 2.1.0.

Mar 26, 2024
CVE-2024-2904
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Extend Themes Calliope.This issue affects Calliope: from n/a through 1.0.33.

Mar 26, 2024
CVE-2024-28126
6.1 MEDIUM

Cross-site scripting vulnerability exists in 0ch BBS Script ver.4.00. An arbitrary script may be executed on the web browser of the user accessing the website …

Mar 26, 2024
CVE-2024-28034
5.4 MEDIUM

Cross-site scripting vulnerability exists in Mini Thread Version 3.33βi. An arbitrary script may be executed on the web browser of the user accessing the website …

Mar 26, 2024
CVE-2024-26018
6.1 MEDIUM

Cross-site scripting vulnerability exists in TvRock 0.9t8a. An arbitrary script may be executed on the web browser of the user accessing the website that uses …

Mar 26, 2024
CVE-2024-24805
5.3 MEDIUM

Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator.This issue affects WP Dummy Content Generator: from n/a through 3.1.2.

Mar 26, 2024
CVE-2023-7251
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr User Submitted Posts allows Stored XSS.This issue affects User Submitted Posts: …

Mar 26, 2024
CVE-2023-49838
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in KlbTheme Clotya theme, KlbTheme Cosmetsy theme, KlbTheme Furnob theme, KlbTheme Bacola theme, KlbTheme Partdo theme, KlbTheme Medibazar theme, KlbTheme …

Mar 26, 2024
CVE-2023-32237
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem (Elementor), CodexThemes TheGem (WPBakery) allows Stored XSS.This issue affects TheGem (Elementor): …

Mar 26, 2024
CVE-2023-51416
6.5 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in EnvialoSimple EnvíaloSimple.This issue affects EnvíaloSimple: from n/a through 2.2.

Mar 26, 2024
CVE-2024-2889
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister Lite for Amazon wp-lister-for-amazon.This issue affects WP-Lister Lite for Amazon: …

Mar 26, 2024
CVE-2024-2888
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor …

Mar 26, 2024
CVE-2024-2303
6.4 MEDIUM

The Easy Textillate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'textillate' shortcode in all versions up to, and including, 2.01 …

Mar 26, 2024
CVE-2024-2170
6.4 MEDIUM

The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the child page index widget in all versions …

Mar 26, 2024
CVE-2024-1745
4.3 MEDIUM

The Testimonial Slider WordPress plugin before 2.3.7 does not properly ensure that a user has the necessary capabilities to edit certain sensitive Testimonial Slider WordPress …

Mar 26, 2024
CVE-2023-7232
5.3 MEDIUM

The Backup and Restore WordPress WordPress plugin through 1.45 does not protect some log files containing sensitive information such as site configuration etc, allowing unauthenticated …

Mar 26, 2024
CVE-2024-29195
6.0 MEDIUM

The azure-c-shared-utility is a C library for AMQP/MQTT communication to Azure Cloud Services. This library may be used by the Azure IoT C SDK for …

Mar 26, 2024
CVE-2024-2732
5.4 MEDIUM

The Themify Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'themify_post_slider shortcode in all versions up to, and including, 2.0.8 …

Mar 26, 2024
CVE-2024-21914
5.3 MEDIUM

A vulnerability exists in the affected product that allows a malicious user to restart the Rockwell Automation PanelView™ Plus 7 terminal remotely without security protections. …

Mar 25, 2024
CVE-2024-29179
4.8 MEDIUM

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. An attacker with admin privileges can upload an …

Mar 25, 2024
CVE-2024-29041
6.1 MEDIUM

Express.js minimalist web framework for node. Versions of Express.js prior to 4.19.0 and all pre-release alpha and beta versions of 5.0 are affected by an …

Mar 25, 2024
CVE-2024-29025
5.3 MEDIUM

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to …

Mar 25, 2024
CVE-2024-28246
5.5 MEDIUM

KaTeX is a JavaScript library for TeX math rendering on the web. Code that uses KaTeX's `trust` option, specifically that provides a function to blacklist …

Mar 25, 2024
CVE-2024-28245
6.3 MEDIUM

KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\includegraphics` …

Mar 25, 2024
CVE-2024-28244
6.5 MEDIUM

KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\def` …

Mar 25, 2024
CVE-2024-28243
6.5 MEDIUM

KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\edef` …

Mar 25, 2024
CVE-2024-28108
4.7 MEDIUM

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Due to insufficient validation on the `contentLink` parameter, …

Mar 25, 2024
CVE-2024-28106
4.3 MEDIUM

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. By manipulating the news parameter in a POST …

Mar 25, 2024
CVE-2024-27300
5.5 MEDIUM

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The `email` field in phpMyFAQ's user control panel …

Mar 25, 2024
CVE-2023-48296
4.3 MEDIUM

OroPlatform is a PHP Business Application Platform (BAP). Navigation history, most viewed and favorite navigation items are returned to storefront user in JSON navigation response …

Mar 25, 2024
CVE-2023-45824
4.3 MEDIUM

OroPlatform is a PHP Business Application Platform (BAP). A logged in user can access page state data of pinned pages of other users by pageId …

Mar 25, 2024
CVE-2024-30203
5.5 MEDIUM

In Emacs before 29.3, Gnus treats inline MIME contents as trusted.

Mar 25, 2024
CVE-2024-28183
6.1 MEDIUM

ESP-IDF is the development framework for Espressif SoCs supported on Windows, Linux and macOS. A Time-of-Check to Time-of-Use (TOCTOU) vulnerability was discovered in the implementation …

Mar 25, 2024
CVE-2024-25175
6.1 MEDIUM

An issue in Kickdler before v1.107.0 allows attackers to provide an XSS payload via a HTTP response splitting attack.

Mar 25, 2024
CVE-2024-28435
5.4 MEDIUM

The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload.

Mar 25, 2024
CVE-2023-27608
6.5 MEDIUM

Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce.This issue affects Points and Rewards for WooCommerce: from n/a through 1.5.0.

Mar 25, 2024
CVE-2023-25039
4.3 MEDIUM

Missing Authorization vulnerability in CodePeople Google Maps CP.This issue affects Google Maps CP: from n/a through 1.0.43.

Mar 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.