CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-13795
4.3 MEDIUM

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.27. This …

Feb 18, 2025
CVE-2024-13704
7.2 HIGH

The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'st_user_title' parameter in all versions up to, and including, 4.0.1 due …

Feb 18, 2025
CVE-2024-13575
6.4 MEDIUM

The Web Stories Enhancer – Level Up Your Web Stories plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'web_stories_enhancer' shortcode in …

Feb 18, 2025
CVE-2024-13465
6.4 MEDIUM

The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Table Of Content" Block, specifically in the "markerView" …

Feb 18, 2025
CVE-2024-11895
6.4 MEDIUM

The Online Payments – Get Paid with PayPal, Square & Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in …

Feb 18, 2025
CVE-2024-11376
6.1 MEDIUM

The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting …

Feb 18, 2025
CVE-2024-57964
7.3 HIGH

Insecure Loading of Dynamic Link Libraries have been discovered in HVAC Energy Saving Program, which could allow local attackers to potentially disclose information or execute …

Feb 18, 2025
CVE-2024-57963
7.3 HIGH

Insecure Loading of Dynamic Link Libraries have been discovered in USB-CONVERTERCABLE DRIVER, which could allow local attackers to potentially disclose information or execute arbitray code …

Feb 18, 2025
CVE-2024-13523
6.1 MEDIUM

The MemorialDay plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing or …

Feb 18, 2025
CVE-2024-45320
6.5 MEDIUM

Out-of-bounds write vulnerability exists in DocuPrint CP225w 01.22.01 and earlier, DocuPrint CP228w 01.22.01 and earlier, DocuPrint CM225fw 01.10.01 and earlier, and DocuPrint CM228fw 01.10.01 and …

Feb 18, 2025
CVE-2024-13556
8.1 HIGH

The Affiliate Links: WordPress Plugin for Link Cloaking and Link Management plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, …

Feb 18, 2025
CVE-2024-13438
4.3 MEDIUM

The SpeedSize Image & Video AI-Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.1. This is …

Feb 18, 2025
CVE-2024-13315
8.8 HIGH

The Shopwarden – Automated WooCommerce monitoring & testing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.11. …

Feb 18, 2025
CVE-2025-0805
6.4 MEDIUM

The Mortgage Calculator / Loan Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mlcalc' shortcode in all versions up to, …

Feb 18, 2025
CVE-2025-0796
4.3 MEDIUM

The Mortgage Lead Capture System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.2.11. This is due …

Feb 18, 2025
CVE-2024-13852
8.8 HIGH

The Option Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing nonce validation on the plugin_page() …

Feb 18, 2025
CVE-2024-13848
5.5 MEDIUM

The Reaction Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.6 due to …

Feb 18, 2025
CVE-2024-13725
9.8 CRITICAL

The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.1 via the service …

Feb 18, 2025
CVE-2024-13687
4.3 MEDIUM

The Team Builder – Meet the Team plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Feb 18, 2025
CVE-2024-13684
8.1 HIGH

The Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. This is due to missing or …

Feb 18, 2025
CVE-2024-13677
8.8 HIGH

The GetBookingsWP – Appointments Booking Calendar Plugin For WordPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, …

Feb 18, 2025
CVE-2024-13622
7.5 HIGH

The File Uploads Addon for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1 via the …

Feb 18, 2025
CVE-2024-13609
5.9 MEDIUM

The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions …

Feb 18, 2025
CVE-2024-13595
6.5 MEDIUM

The Simple Signup Form plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'ssf' shortcode in all versions up to, …

Feb 18, 2025
CVE-2024-13588
6.4 MEDIUM

The Simplebooklet PDF Viewer and Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'simplebooklet' shortcode in all versions up to, …

Feb 18, 2025
CVE-2024-13587
6.4 MEDIUM

The Zigaform – Price Calculator & Cost Estimation Form Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zgfm_fvar' shortcode …

Feb 18, 2025
CVE-2024-13582
6.4 MEDIUM

The Simple Pricing Tables For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wdo_simple_pricing_table_free' shortcode in …

Feb 18, 2025
CVE-2024-13581
6.4 MEDIUM

The Simple Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'simple_chart' shortcode in all versions up to, and including, 1.0 …

Feb 18, 2025
CVE-2024-13579
6.4 MEDIUM

The WP-Asambleas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'polls_popup' shortcode in all versions up to, and including, 2.85.0 due …

Feb 18, 2025
CVE-2024-13578
6.4 MEDIUM

The WP-BibTeX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'WpBibTeX' shortcode in all versions up to, and including, 3.0.1 due …

Feb 18, 2025
CVE-2024-13577
6.4 MEDIUM

The CATS Job Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catsone' shortcode in all versions up to, and including, …

Feb 18, 2025
CVE-2024-13576
6.4 MEDIUM

The Gumlet Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gumlet' shortcode in all versions up to, and including, 1.0.3 …

Feb 18, 2025
CVE-2024-13573
6.4 MEDIUM

The Zigaform – Form Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zgfm_rfvar' shortcode in all versions up to, …

Feb 18, 2025
CVE-2024-13565
6.4 MEDIUM

The Simple Map No Api plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions up to, and including, …

Feb 18, 2025
CVE-2024-13555
5.3 MEDIUM

The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions …

Feb 18, 2025
CVE-2024-13540
5.3 MEDIUM

The WooODT Lite – Delivery & pickup date time location for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up …

Feb 18, 2025
CVE-2024-13538
5.3 MEDIUM

The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.0. This is …

Feb 18, 2025
CVE-2024-13535
5.3 MEDIUM

The Actionwear products sync plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.3.2. This is due the …

Feb 18, 2025
CVE-2024-13522
6.1 MEDIUM

The magayo Lottery Results plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.12. This is due to …

Feb 18, 2025
CVE-2024-13501
6.4 MEDIUM

The WP-FormAssembly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'formassembly' shortcode in all versions up to, and including, 2.0.11 due …

Feb 18, 2025
CVE-2024-13464
6.4 MEDIUM

The Library Bookshelves plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bookshelf' shortcode in all versions up to, and including, 5.10 …

Feb 18, 2025
CVE-2024-12813
6.4 MEDIUM

The Open Hours – Easy Opening Hours plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'open-hours-current-status' shortcode in all versions up …

Feb 18, 2025
CVE-2024-12525
6.4 MEDIUM

The Easy MLS Listings Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasap-featured-listings' shortcode in all versions up to, and …

Feb 18, 2025
CVE-2024-12314
7.2 HIGH

The Rapid Cache plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 1.2.3. This is due to plugin storing …

Feb 18, 2025
CVE-2025-1390
6.1 MEDIUM

The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as …

Feb 18, 2025
CVE-2024-13740
4.3 MEDIUM

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Feb 18, 2025
CVE-2024-13741
5.4 MEDIUM

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, …

Feb 18, 2025
CVE-2025-25224
7.5 HIGH

The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a missing authentication vulnerability in dloader.php. If this vulnerability …

Feb 18, 2025
CVE-2025-25223
5.3 MEDIUM

The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a path traversal vulnerability in dloader.php. If this vulnerability …

Feb 18, 2025
CVE-2025-25222
9.8 CRITICAL

The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in retrieve.php. If this vulnerability …

Feb 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.