CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-45231
6.5 MEDIUM

EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to …

Jan 16, 2024
CVE-2023-45229
6.5 MEDIUM

EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can …

Jan 16, 2024
CVE-2023-3771
6.1 MEDIUM

The T1 WordPress theme through 19.0 is vulnerable to unauthenticated open redirect with which any attacker and redirect users to arbitrary websites.

Jan 16, 2024
CVE-2023-3647
4.8 MEDIUM

The IURNY by INDIGITALL WordPress plugin before 3.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jan 16, 2024
CVE-2023-3372
5.4 MEDIUM

The Lana Shortcodes WordPress plugin before 1.2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Jan 16, 2024
CVE-2023-3178
4.3 MEDIUM

The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could allow attackers to make logged …

Jan 16, 2024
CVE-2023-37522
5.6 MEDIUM

HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower has missing or insecure tags that could allow an attacker to execute a malicious …

Jan 16, 2024
CVE-2023-0824
6.5 MEDIUM

The User registration & user profile WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as …

Jan 16, 2024
CVE-2023-0769
6.1 MEDIUM

The hiWeb Migration Simple WordPress plugin through 2.0.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jan 16, 2024
CVE-2023-0479
6.1 MEDIUM

The Print Invoice & Delivery Notes for WooCommerce WordPress plugin before 4.7.2 is vulnerable to reflected XSS by echoing a GET value in an admin …

Jan 16, 2024
CVE-2023-0389
4.8 MEDIUM

The Calculated Fields Form WordPress plugin before 1.1.151 does not sanitise and escape some of its form settings, which could allow high privilege users such …

Jan 16, 2024
CVE-2023-0376
5.4 MEDIUM

The Qubely WordPress plugin before 1.8.5 does not validate and escape some of its block options before outputting them back in a page/post where the …

Jan 16, 2024
CVE-2023-0094
5.4 MEDIUM

The UpQode Google Maps WordPress plugin through 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post …

Jan 16, 2024
CVE-2023-0079
5.4 MEDIUM

The Customer Reviews for WooCommerce WordPress plugin before 5.17.0 does not validate and escape some of its shortcode attributes before outputting them back in a …

Jan 16, 2024
CVE-2022-3836
4.8 MEDIUM

The Seed Social WordPress plugin before 2.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jan 16, 2024
CVE-2022-3829
4.8 MEDIUM

The Font Awesome 4 Menus WordPress plugin through 4.7.0 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jan 16, 2024
CVE-2022-3739
5.4 MEDIUM

The WP Best Quiz WordPress plugin through 1.0 does not sanitize and escape some parameters, which could allow users with a role as low as …

Jan 16, 2024
CVE-2022-3194
5.4 MEDIUM

The Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allow them to run stored XSS attacks against …

Jan 16, 2024
CVE-2022-2413
5.4 MEDIUM

The Slide Anything WordPress plugin before 2.3.47 does not properly sanitize or escape the slide title before outputting it in the admin pages, allowing a …

Jan 16, 2024
CVE-2022-23180
4.3 MEDIUM

The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks, which could allow any authenticated users, such …

Jan 16, 2024
CVE-2022-23179
4.8 MEDIUM

The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.0 does not escape some of its form fields before outputting them in attributes, …

Jan 16, 2024
CVE-2022-1760
4.3 MEDIUM

The Core Control WordPress plugin through 1.2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Jan 16, 2024
CVE-2022-1618
6.1 MEDIUM

The Coru LFMember WordPress plugin through 1.0.2 does not have CSRF check in place when adding a new game, and is lacking sanitisation as well …

Jan 16, 2024
CVE-2022-1617
6.1 MEDIUM

The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as escaping …

Jan 16, 2024
CVE-2022-1563
5.3 MEDIUM

The WPGraphQL WooCommerce WordPress plugin before 0.12.4 does not prevent unauthenticated attackers from enumerating a shop's coupon codes and values via GraphQL.

Jan 16, 2024
CVE-2022-0775
4.3 MEDIUM

The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as subscriber to …

Jan 16, 2024
CVE-2022-0402
6.1 MEDIUM

The Super Forms - Drag & Drop Form Builder WordPress plugin before 6.0.4 does not escape the bob_czy_panstwa_sprawa_zostala_rozwiazana parameter before outputting it back in an …

Jan 16, 2024
CVE-2021-4227
5.3 MEDIUM

The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing attackers to inject an iFrame in …

Jan 16, 2024
CVE-2021-25117
4.8 MEDIUM

The WP-PostRatings WordPress plugin before 1.86.1 does not sanitise the postratings_image parameter from its options page (wp-admin/admin.php?page=wp-postratings/postratings-options.php). Even though the page is only accessible to …

Jan 16, 2024
CVE-2021-24870
6.1 MEDIUM

The WP Fastest Cache WordPress plugin before 0.9.5 is lacking a CSRF check in its wpfc_save_cdn_integration AJAX action, and does not sanitise and escape some …

Jan 16, 2024
CVE-2021-24567
5.4 MEDIUM

The Simple Post WordPress plugin through 1.1 does not sanitize user input when an authenticated user Text value, then it does not escape these values …

Jan 16, 2024
CVE-2021-24559
5.4 MEDIUM

The Qyrr WordPress plugin before 0.7 does not escape the data-uri of the QR Code when outputting it in a src attribute, allowing for Cross-Site …

Jan 16, 2024
CVE-2021-24433
5.4 MEDIUM

The simple sort&search WordPress plugin through 0.0.3 does not make sure that the indexurl parameter of the shortcodes "category_sims", "order_sims", "orderby_sims", "period_sims", and "tag_sims" use …

Jan 16, 2024
CVE-2021-24432
6.1 MEDIUM

The Advanced AJAX Product Filters WordPress plugin does not sanitise the 'term_id' POST parameter before outputting it in the page, leading to reflected Cross-Site Scripting …

Jan 16, 2024
CVE-2023-6395
6.7 MEDIUM

The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling the execution of arbitrary code with root user privileges. This …

Jan 16, 2024
CVE-2021-4432
5.3 MEDIUM

A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as problematic. This affects an unknown part of the component USER Command …

Jan 16, 2024
CVE-2024-0581
4.0 MEDIUM

An Uncontrolled Resource Consumption vulnerability has been found on Sandsprite Scdbg.exe, affecting version 1.0. This vulnerability allows an attacker to send a specially crafted shellcode …

Jan 16, 2024
CVE-2024-0232
4.7 MEDIUM

A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim …

Jan 16, 2024
CVE-2024-0569
4.3 MEDIUM

A vulnerability classified as problematic has been found in Totolink T8 4.1.5cu.833_20220905. This affects the function getSysStatusCfg of the file /cgi-bin/cstecgi.cgi of the component Setting …

Jan 16, 2024
CVE-2024-0555
4.6 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability has been found on WIC1200, affecting version 1.1. An authenticated user could lead another user into executing unwanted actions …

Jan 16, 2024
CVE-2024-0554
5.5 MEDIUM

A Cross-site scripting (XSS) vulnerability has been found on WIC1200, affecting version 1.1. An authenticated user could store a malicious javascript payload in the device …

Jan 16, 2024
CVE-2023-52106
4.4 MEDIUM

Vulnerability of permission verification for APIs in the DownloadProviderMain module. Impact: Successful exploitation of this vulnerability will affect integrity and availability.

Jan 16, 2024
CVE-2023-52112
5.3 MEDIUM

Unauthorized file access vulnerability in the wallpaper service module. Successful exploitation of this vulnerability may cause features to perform abnormally.

Jan 16, 2024
CVE-2011-10005
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in EasyFTP 1.7.0.2. Affected is an unknown function of the component MKD Command Handler. The manipulation …

Jan 16, 2024
CVE-2023-6457
6.6 MEDIUM

Incorrect Default Permissions vulnerability in Hitachi Tuning Manager on Windows (Hitachi Tuning Manager server component) allows local users to read and write specific files.This issue …

Jan 16, 2024
CVE-2023-49107
5.3 MEDIUM

Generation of Error Message Containing Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent modules).This issue affects Hitachi Device Manager: before …

Jan 16, 2024
CVE-2023-49106
4.6 MEDIUM

Missing Password Field Masking vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent component).This issue affects Hitachi Device Manager: before 8.8.5-04.

Jan 16, 2024
CVE-2023-48104
6.1 MEDIUM

Alinto SOGo before 5.9.1 is vulnerable to HTML Injection.

Jan 16, 2024
CVE-2023-47459
6.5 MEDIUM

An issue in Knovos Discovery v.22.67.0 allows a remote attacker to obtain sensitive information via the /DiscoveryReview/Service/CaseManagement.svc/GetProductSiteName component.

Jan 16, 2024
CVE-2023-41619
6.1 MEDIUM

Emlog Pro v2.1.14 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/article.php?action=write.

Jan 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.