CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-13224
6.1 MEDIUM

The SlideDeck 1 Lite Content Slider WordPress plugin through 1.4.8 does not sanitise and escape a parameter before outputting it back in the page, leading …

Jan 31, 2025
CVE-2024-13223
6.1 MEDIUM

The Tabulate WordPress plugin through 2.10.3 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site …

Jan 31, 2025
CVE-2024-13222
6.1 MEDIUM

The User Messages WordPress plugin through 1.2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jan 31, 2025
CVE-2024-13221
6.1 MEDIUM

The Fantastic ElasticSearch WordPress plugin through 4.1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jan 31, 2025
CVE-2024-13220
6.1 MEDIUM

The WordPress Google Map Professional (Map In Your Language) WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in …

Jan 31, 2025
CVE-2024-13219
6.1 MEDIUM

The Privacy Policy Genius WordPress plugin through 2.0.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jan 31, 2025
CVE-2024-13218
6.1 MEDIUM

The Fast Tube WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jan 31, 2025
CVE-2024-13216
4.3 MEDIUM

The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and …

Jan 31, 2025
CVE-2024-13112
6.1 MEDIUM

The WP MediaTagger WordPress plugin through 4.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jan 31, 2025
CVE-2024-13101
5.4 MEDIUM

The WP MediaTagger WordPress plugin through 4.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Jan 31, 2025
CVE-2024-13100
6.1 MEDIUM

The OPSI Israel Domestic Shipments WordPress plugin through 2.6.3 does not sanitise and escape a parameter before outputting it back in the page, leading to …

Jan 31, 2025
CVE-2024-12872
4.8 MEDIUM

The Zalomení WordPress plugin through 1.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jan 31, 2025
CVE-2024-12772
5.4 MEDIUM

The Ninja Tables WordPress plugin before 5.0.17 does not sanitize and escape a parameter before outputting it back in the page when importing a CSV, …

Jan 31, 2025
CVE-2024-12275
6.1 MEDIUM

The Canvasflow for WordPress plugin through 1.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jan 31, 2025
CVE-2024-11886
6.4 MEDIUM

The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vCitaMeetingScheduler ' shortcode in …

Jan 31, 2025
CVE-2025-0507
6.4 MEDIUM

The Ticketmeo – Sell Tickets – Event Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up …

Jan 31, 2025
CVE-2025-0493
9.8 CRITICAL

The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Limited Local File Inclusion in all versions up to, and …

Jan 31, 2025
CVE-2024-10867
5.4 MEDIUM

The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads …

Jan 31, 2025
CVE-2025-0470
6.1 MEDIUM

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the title parameter …

Jan 31, 2025
CVE-2024-47900
7.8 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to access OOB kernel memory.

Jan 31, 2025
CVE-2024-47899
7.8 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions.

Jan 31, 2025
CVE-2024-47898
7.8 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions.

Jan 31, 2025
CVE-2024-47891
7.8 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions.

Jan 31, 2025
CVE-2024-13463
6.4 MEDIUM

The SeatReg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'seatreg' shortcode in all versions up to, and including, 1.56.0 due …

Jan 31, 2025
CVE-2024-46974
7.8 HIGH

Software installed and run as a non-privileged user may conduct improper read/write operations on imported/exported DMA buffers.

Jan 31, 2025
CVE-2024-13767
8.1 HIGH

The Live2DWebCanvas plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ClearFiles() function in all versions up …

Jan 31, 2025
CVE-2024-13399
6.4 MEDIUM

The Gosign – Posts Slider Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'posts-slider-block' block in all versions up to, and …

Jan 31, 2025
CVE-2024-13397
6.4 MEDIUM

The WPRadio – WordPress Radio Streaming Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpradio_player' shortcode in all versions up …

Jan 31, 2025
CVE-2024-13396
6.4 MEDIUM

The Frictionless plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'frictionless_form' shortcode[s] in all versions up to, and including, 0.0.23 due …

Jan 31, 2025
CVE-2023-0092
4.9 MEDIUM

An authenticated user who has read access to the juju controller model, may construct a remote request to download an arbitrary file from the controller's …

Jan 31, 2025
CVE-2022-1736
9.8 CRITICAL

Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.

Jan 31, 2025
CVE-2020-11936
3.1 LOW

gdbus setgid privilege escalation

Jan 31, 2025
CVE-2024-23929
7.3 HIGH

This vulnerability allows network-adjacent attackers to create arbitrary files on affected installations of Pioneer DMH-WT7600NEX devices. Although authentication is required to exploit this vulnerability, the …

Jan 31, 2025
CVE-2024-23921
8.8 HIGH

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this …

Jan 31, 2025
CVE-2024-23920
8.8 HIGH

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this …

Jan 31, 2025
CVE-2022-28653
7.5 HIGH

Users can consume unlimited disk space in /var/crash

Jan 31, 2025
CVE-2025-24336
3.3 LOW

SXF Common Library handles input data improperly. If a product using the library reads a crafted file, the product may be crashed.

Jan 31, 2025
CVE-2024-24731
7.5 HIGH

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. …

Jan 31, 2025
CVE-2024-23973
8.8 HIGH

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. …

Jan 31, 2025
CVE-2024-23971
8.8 HIGH

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this …

Jan 31, 2025
CVE-2024-23970
6.5 MEDIUM

This vulnerability allows network-adjacent attackers to compromise transport security on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this …

Jan 31, 2025
CVE-2024-23969
8.8 HIGH

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this …

Jan 31, 2025
CVE-2024-23968
8.8 HIGH

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this …

Jan 31, 2025
CVE-2024-23963
8.0 HIGH

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. An attacker must first obtain the ability to pair …

Jan 31, 2025
CVE-2024-23962
5.3 MEDIUM

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The …

Jan 31, 2025
CVE-2024-23937
4.3 MEDIUM

This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. …

Jan 31, 2025
CVE-2024-23930
4.3 MEDIUM

This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Pioneer DMH-WT7600NEX devices. Authentication is not required to exploit this vulnerability. …

Jan 31, 2025
CVE-2024-23928
6.5 MEDIUM

This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of Pioneer DMH-WT7600NEX devices. Authentication is not required to exploit …

Jan 31, 2025
CVE-2024-1211
6.4 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting …

Jan 31, 2025
CVE-2023-6195
2.6 LOW

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.5 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting …

Jan 31, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.