CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-28196
6.5 MEDIUM

your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version < 1.9.0 does not prevent other pages from displaying it in an iframe …

Mar 13, 2024
CVE-2024-27953
4.7 MEDIUM

Missing Authorization vulnerability in Cool Plugins Cryptocurrency Widgets – Price Ticker & Coins List.This issue affects Cryptocurrency Widgets – Price Ticker & Coins List: from …

Mar 13, 2024
CVE-2024-20322
5.8 MEDIUM

A vulnerability in the access control list (ACL) processing on Pseudowire interfaces in the ingress direction of Cisco IOS XR Software could allow an unauthenticated, …

Mar 13, 2024
CVE-2024-20319
4.3 MEDIUM

A vulnerability in the UDP forwarding code of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to bypass configured management plane protection policies …

Mar 13, 2024
CVE-2024-20315
5.8 MEDIUM

A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR Software could allow an unauthenticated, …

Mar 13, 2024
CVE-2024-20266
5.3 MEDIUM

A vulnerability in the DHCP version 4 (DHCPv4) server feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to trigger a crash …

Mar 13, 2024
CVE-2024-20262
6.5 MEDIUM

A vulnerability in the Secure Copy Protocol (SCP) and SFTP feature of Cisco IOS XR Software could allow an authenticated, local attacker to create or …

Mar 13, 2024
CVE-2024-0163
5.3 MEDIUM

Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain a TOCTOU race condition vulnerability. A local low privileged attacker could potentially exploit this vulnerability …

Mar 13, 2024
CVE-2024-0162
5.3 MEDIUM

Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit …

Mar 13, 2024
CVE-2024-2293
6.4 MEDIUM

The Site Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user display name in all versions up to, and including, 6.11.4 …

Mar 13, 2024
CVE-2024-2286
6.4 MEDIUM

The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart) plugin for WordPress is vulnerable to Stored …

Mar 13, 2024
CVE-2024-2252
5.4 MEDIUM

The Droit Elementor Addons – Widgets, Blocks, Templates Library For Elementor Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets …

Mar 13, 2024
CVE-2024-2239
6.4 MEDIUM

The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Premium Magic Scroll module in all versions up to, and …

Mar 13, 2024
CVE-2024-2238
6.4 MEDIUM

The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Mouse Cursor module in all versions up to, and …

Mar 13, 2024
CVE-2024-2237
6.4 MEDIUM

The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Global Badge module in all versions up to, and including, …

Mar 13, 2024
CVE-2024-2126
6.4 MEDIUM

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Registration Form widget in all versions up to, and …

Mar 13, 2024
CVE-2024-2106
5.3 MEDIUM

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, …

Mar 13, 2024
CVE-2024-2030
6.4 MEDIUM

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions …

Mar 13, 2024
CVE-2024-2028
6.4 MEDIUM

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Covid-19 Stats Widget in all versions up to, and …

Mar 13, 2024
CVE-2024-2000
6.4 MEDIUM

The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'navigation_dots' parameter of the Multi Scroll Widget in all versions …

Mar 13, 2024
CVE-2024-28683
6.1 MEDIUM

DedeCMS v5.7 was discovered to contain a cross-site scripting (XSS) vulnerability via create file.

Mar 13, 2024
CVE-2024-28682
6.3 MEDIUM

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/sys_cache_up.php.

Mar 13, 2024
CVE-2024-28681
6.1 MEDIUM

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/plus_edit.php.

Mar 13, 2024
CVE-2024-28680
6.1 MEDIUM

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/diy_add.php.

Mar 13, 2024
CVE-2024-28679
6.1 MEDIUM

DedeCMS v5.7 was discovered to contain a cross-site scripting (XSS) vulnerability via Photo Collection.

Mar 13, 2024
CVE-2024-28678
6.3 MEDIUM

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article_description_main.php

Mar 13, 2024
CVE-2024-28677
6.1 MEDIUM

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/article_keywords_main.php.

Mar 13, 2024
CVE-2024-28676
6.1 MEDIUM

DedeCMS v5.7 was discovered to contain a cross-site scripting (XSS) vulnerability via /dede/article_edit.php.

Mar 13, 2024
CVE-2024-28672
5.4 MEDIUM

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/media_edit.php.

Mar 13, 2024
CVE-2024-28670
6.1 MEDIUM

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/freelist_main.php.

Mar 13, 2024
CVE-2024-28669
5.4 MEDIUM

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/freelist_edit.php.

Mar 13, 2024
CVE-2024-25101
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yonifre Maspik – Spam Blacklist allows Stored XSS.This issue affects Maspik – Spam …

Mar 13, 2024
CVE-2024-25099
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David de Boer Paytium: Mollie payment forms & donations allows Stored XSS.This issue …

Mar 13, 2024
CVE-2024-25097
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeNcode LLC TNC PDF viewer allows Stored XSS.This issue affects TNC PDF viewer: …

Mar 13, 2024
CVE-2024-23672
6.3 MEDIUM

Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource …

Mar 13, 2024
CVE-2024-1997
6.4 MEDIUM

The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premium_fbchat_app_id' parameter of the Messenger Chat Widget in all versions …

Mar 13, 2024
CVE-2024-1996
6.4 MEDIUM

The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's IHover widget link in all versions up to, and …

Mar 13, 2024
CVE-2024-1985
4.7 MEDIUM

The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Display Name' parameter in all versions up to, and including, 4.4.2 …

Mar 13, 2024
CVE-2024-1894
6.4 MEDIUM

The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'burst_total_pageviews_count' custom meta field in all …

Mar 13, 2024
CVE-2024-1854
6.4 MEDIUM

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blockId parameter in …

Mar 13, 2024
CVE-2024-1843
4.3 MEDIUM

The Auto Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the aalAddLink function in …

Mar 13, 2024
CVE-2024-1806
6.4 MEDIUM

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site …

Mar 13, 2024
CVE-2024-1763
6.5 MEDIUM

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Mar 13, 2024
CVE-2024-1723
6.4 MEDIUM

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 1.58.7 due …

Mar 13, 2024
CVE-2024-1691
6.1 MEDIUM

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file …

Mar 13, 2024
CVE-2024-1690
4.3 MEDIUM

The TeraWallet – Best WooCommerce Wallet System With Cashback Rewards, Partial Payment, Wallet Refunds plugin for WordPress is vulnerable to unauthorized access of data due …

Mar 13, 2024
CVE-2024-1684
6.4 MEDIUM

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the contact …

Mar 13, 2024
CVE-2024-1680
6.4 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Settings URL of the Banner, Team Members, and …

Mar 13, 2024
CVE-2024-1668
6.5 MEDIUM

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 7.11.5 …

Mar 13, 2024
CVE-2024-1642
4.3 MEDIUM

The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

Mar 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.