CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0681
5.3 MEDIUM

The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.3.4. …

Mar 13, 2024
CVE-2024-0631
5.3 MEDIUM

The Duitku Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the check_duitku_response function in …

Mar 13, 2024
CVE-2024-0614
4.4 MEDIUM

The Events Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.4.6.4 due to …

Mar 13, 2024
CVE-2024-0592
5.4 MEDIUM

The Related Posts for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due …

Mar 13, 2024
CVE-2024-0591
6.1 MEDIUM

The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'A' parameter …

Mar 13, 2024
CVE-2024-0449
4.4 MEDIUM

The ArtiBot Free Chat Bot for WordPress WebSites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, …

Mar 13, 2024
CVE-2024-0447
5.0 MEDIUM

The ArtiBot Free Chat Bot for WordPress WebSites plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Mar 13, 2024
CVE-2024-0385
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxAddCategory function in all versions …

Mar 13, 2024
CVE-2024-0377
5.3 MEDIUM

The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Mar 13, 2024
CVE-2024-0369
4.3 MEDIUM

The Bulk Edit Post Titles plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bulkUpdatePostTitles function …

Mar 13, 2024
CVE-2024-0326
6.4 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Link Wrapper functionality in all versions up to, …

Mar 13, 2024
CVE-2023-7015
6.1 MEDIUM

The File Manager Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tb' parameter in all versions up to, and including, 8.3.4 …

Mar 13, 2024
CVE-2023-6969
4.3 MEDIUM

The User Shortcodes Plus plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.2 via the user_meta …

Mar 13, 2024
CVE-2023-6957
4.9 MEDIUM

The Fluent Forms plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, …

Mar 13, 2024
CVE-2023-6954
6.4 MEDIUM

The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.2.85 …

Mar 13, 2024
CVE-2023-6880
6.4 MEDIUM

The Visual Composer Website Builder, Landing Page Builder, Custom Theme Builder, Maintenance Mode & Coming Soon Pages plugin for WordPress is vulnerable to Stored Cross-Site …

Mar 13, 2024
CVE-2023-6809
6.4 MEDIUM

The Custom fields shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cf shortcode in all versions up to, and including, …

Mar 13, 2024
CVE-2023-6785
5.3 MEDIUM

The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, …

Mar 13, 2024
CVE-2024-25154
5.3 MEDIUM

Improper URL validation leads to path traversal in FileCatalyst Direct 3.8.8 and earlier allowing an encoded payload to cause the web server to return files …

Mar 13, 2024
CVE-2024-26629
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix RELEASE_LOCKOWNER The test on so_count in nfsd4_release_lockowner() is nonsense and harmful. Revert to …

Mar 13, 2024
CVE-2024-1508
6.4 MEDIUM

The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'settings['title_tags']' attribute of the Mercury widget in …

Mar 13, 2024
CVE-2024-1507
6.4 MEDIUM

The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tags' attribute of the Rubix widget in …

Mar 13, 2024
CVE-2023-52608
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Check mailbox/SMT channel for consistency On reception of a completion interrupt the shared …

Mar 13, 2024
CVE-2024-28668
6.1 MEDIUM

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/mychannel_add.php

Mar 13, 2024
CVE-2024-28667
6.1 MEDIUM

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/templets_one_edit.php

Mar 13, 2024
CVE-2024-28666
5.5 MEDIUM

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/media_add.php

Mar 13, 2024
CVE-2024-28430
6.1 MEDIUM

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_edit.php.

Mar 13, 2024
CVE-2024-28429
5.5 MEDIUM

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/archives_do.php

Mar 13, 2024
CVE-2024-2416
6.5 MEDIUM

Cross-Site Request Forgery vulnerability in Movistar's 4G router affecting version ES_WLD71-T1_v2.0.201820. This vulnerability allows an attacker to force an end user to execute unwanted actions …

Mar 13, 2024
CVE-2023-43043
5.1 MEDIUM

IBM Maximo Application Suite - Maximo Mobile for EAM 8.10 and 8.11 could disclose sensitive information to a local user. IBM X-Force ID: 266875.

Mar 13, 2024
CVE-2023-38723
6.4 MEDIUM

IBM Maximo Application Suite 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …

Mar 13, 2024
CVE-2023-28517
5.4 MEDIUM

IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …

Mar 13, 2024
CVE-2018-25090
5.4 MEDIUM

An unauthenticated remote attacker can use an XSS attack due to improper neutralization of input during web page generation. User interaction is required. This leads …

Mar 13, 2024
CVE-2024-28623
6.1 MEDIUM

RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section.

Mar 13, 2024
CVE-2024-27440
4.8 MEDIUM

The Toyoko Inn official App for iOS versions prior to 1.13.0 and Toyoko Inn official App for Android versions prior 1.3.14 don't properly verify server …

Mar 13, 2024
CVE-2024-2412
5.3 MEDIUM

The disabling function of the user registration page for Heimavista Rpage and Epage is not properly implemented, allowing remote attackers to complete user registration on …

Mar 13, 2024
CVE-2015-10130
5.3 MEDIUM

The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or …

Mar 13, 2024
CVE-2024-1582
6.4 MEDIUM

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpgmza' shortcode in all versions …

Mar 13, 2024
CVE-2023-4839
4.4 MEDIUM

The WP Go Maps for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 9.0.32 due to insufficient …

Mar 13, 2024
CVE-2024-1421
6.4 MEDIUM

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘border_type’ attribute of the Post Carousel …

Mar 12, 2024
CVE-2024-1397
6.4 MEDIUM

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up …

Mar 12, 2024
CVE-2024-2107
5.8 MEDIUM

The Blossom Spa theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.3 via generated source. This makes …

Mar 12, 2024
CVE-2023-43279
6.5 MEDIUM

Null Pointer Dereference in mask_cidr6 component at cidr.c in Tcpreplay 4.4.4 allows attackers to crash the application via crafted tcprewrite command.

Mar 12, 2024
CVE-2024-2406
5.4 MEDIUM

A vulnerability, which was classified as critical, was found in Gacjie Server up to 1.0. This affects the function index of the file /app/admin/controller/Upload.php. The …

Mar 12, 2024
CVE-2024-28239
5.4 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. The authentication API has a `redirect` parameter that can be exploited as …

Mar 12, 2024
CVE-2024-27305
5.3 MEDIUM

aiosmtpd is a reimplementation of the Python stdlib smtpd.py based on asyncio. aiosmtpd is vulnerable to inbound SMTP smuggling. SMTP smuggling is a novel vulnerability …

Mar 12, 2024
CVE-2024-24097
5.4 MEDIUM

Cross Site Scripting (XSS) vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via the News Feed.

Mar 12, 2024
CVE-2023-43292
6.1 MEDIUM

Cross Site Scripting vulnerability in My Food Recipe Using PHP with Source Code v.1.0 allows a local attacker to execute arbitrary code via a crafted …

Mar 12, 2024
CVE-2023-42308
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Manage Fastrack Subjects in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via the "Subject Name" …

Mar 12, 2024
CVE-2023-42307
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via "Subject Name" and "Subject Code" section.

Mar 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.