CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-24701
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Native Grid LLC A no-code page builder for beautiful performance-based content.This issue affects A no-code page builder for beautiful …

Feb 29, 2024
CVE-2024-24155
6.5 MEDIUM

Bento4 v1.5.1-628 contains a Memory leak on AP4_Movie::AP4_Movie, parsing tracks and added into m_Tracks list, but mp42aac cannot correctly delete when we got an no …

Feb 29, 2024
CVE-2024-24150
6.5 MEDIUM

A memory leak issue discovered in parseSWF_TEXTRECORD in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.

Feb 29, 2024
CVE-2024-24149
6.5 MEDIUM

A memory leak issue discovered in parseSWF_GLYPHENTRY in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.

Feb 29, 2024
CVE-2024-24147
6.5 MEDIUM

A memory leak issue discovered in parseSWF_FILLSTYLEARRAY in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF file.

Feb 29, 2024
CVE-2024-24146
6.5 MEDIUM

A memory leak issue discovered in parseSWF_DEFINEBUTTON in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF file.

Feb 29, 2024
CVE-2024-23946
5.3 MEDIUM

Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

Feb 29, 2024
CVE-2024-23519
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in M&S Consulting Email Before Download.This issue affects Email Before Download: from n/a through 6.9.7.

Feb 29, 2024
CVE-2024-22936
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in Parents & Student Portal in Genesis School Management Systems in Genesis AIMS Student Information Systems v.3053 allows remote attackers to …

Feb 29, 2024
CVE-2024-22251
5.9 MEDIUM

VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). A malicious actor with local administrative privileges on …

Feb 29, 2024
CVE-2024-21726
6.5 MEDIUM

Inadequate content filtering leads to XSS vulnerabilities in various components.

Feb 29, 2024
CVE-2024-21725
6.1 MEDIUM

Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components.

Feb 29, 2024
CVE-2024-21724
6.1 MEDIUM

Inadequate input validation for media selection fields lead to XSS vulnerabilities in various extensions.

Feb 29, 2024
CVE-2024-21723
4.3 MEDIUM

Inadequate parsing of URLs could result into an open redirect.

Feb 29, 2024
CVE-2024-21722
6.3 MEDIUM

The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified.

Feb 29, 2024
CVE-2024-20344
5.3 MEDIUM

A vulnerability in system resource management in Cisco UCS 6400 and 6500 Series Fabric Interconnects that are in Intersight Managed Mode (IMM) could allow an …

Feb 29, 2024
CVE-2024-20294
6.6 MEDIUM

A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to …

Feb 29, 2024
CVE-2024-20291
5.8 MEDIUM

A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000 Series Switches in standalone NX-OS mode …

Feb 29, 2024
CVE-2024-1970
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in SourceCodester Online Learning System V2 1.0. Affected is an unknown function of the file /index.php. …

Feb 29, 2024
CVE-2024-1928
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Web-Based Student Clearance System 1.0. Affected by this issue is some unknown functionality …

Feb 29, 2024
CVE-2024-1927
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Web-Based Student Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Feb 29, 2024
CVE-2024-1586
6.4 MEDIUM

The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom schema in all versions …

Feb 29, 2024
CVE-2024-1570
6.4 MEDIUM

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site …

Feb 29, 2024
CVE-2024-1519
6.5 MEDIUM

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site …

Feb 29, 2024
CVE-2024-1496
6.4 MEDIUM

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the fifu_input_url parameter in all versions up to, and …

Feb 29, 2024
CVE-2024-1492
5.3 MEDIUM

The WPify Woo Czech plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the maybe_send_to_packeta function in …

Feb 29, 2024
CVE-2024-1475
5.3 MEDIUM

The Coming Soon Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.5 via the REST …

Feb 29, 2024
CVE-2024-1472
5.3 MEDIUM

The WP Maintenance plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.1.6 via the REST API. This makes …

Feb 29, 2024
CVE-2024-1448
6.4 MEDIUM

The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up …

Feb 29, 2024
CVE-2024-1447
6.4 MEDIUM

The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aThemes Slider button element in all versions up to, and …

Feb 29, 2024
CVE-2024-1445
6.4 MEDIUM

The Page scroll to id plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, …

Feb 29, 2024
CVE-2024-1425
6.4 MEDIUM

The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable …

Feb 29, 2024
CVE-2024-1411
6.4 MEDIUM

The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the settings of the Twitter Buttons Widget in all versions …

Feb 29, 2024
CVE-2024-1408
6.4 MEDIUM

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site …

Feb 29, 2024
CVE-2024-1390
4.3 MEDIUM

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a …

Feb 29, 2024
CVE-2024-1389
5.3 MEDIUM

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a …

Feb 29, 2024
CVE-2024-1349
6.4 MEDIUM

The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable …

Feb 29, 2024
CVE-2024-1340
5.4 MEDIUM

The Login Lockdown – Protect Login Form plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the …

Feb 29, 2024
CVE-2024-1339
4.3 MEDIUM

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is …

Feb 29, 2024
CVE-2024-1338
4.3 MEDIUM

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is …

Feb 29, 2024
CVE-2024-1337
4.3 MEDIUM

The SKT Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'saveSktbuilderPageData' function in …

Feb 29, 2024
CVE-2024-1336
4.3 MEDIUM

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is …

Feb 29, 2024
CVE-2024-1335
4.3 MEDIUM

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is …

Feb 29, 2024
CVE-2024-1334
4.3 MEDIUM

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is …

Feb 29, 2024
CVE-2024-1322
5.3 MEDIUM

The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Feb 29, 2024
CVE-2024-1318
6.5 MEDIUM

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized modification of …

Feb 29, 2024
CVE-2024-1294
5.3 MEDIUM

The Sunshine Photo Cart: Free Client Galleries for Photographers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, …

Feb 29, 2024
CVE-2024-1288
4.3 MEDIUM

The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Feb 29, 2024
CVE-2024-1282
6.4 MEDIUM

The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all …

Feb 29, 2024
CVE-2024-1277
6.4 MEDIUM

The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom fields in all versions up to, and including, 2.2.4 due to …

Feb 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.