CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-12605
4.3 MEDIUM

The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is …

Jan 9, 2025
CVE-2024-12542
8.6 HIGH

The linkID plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function in all …

Jan 9, 2025
CVE-2024-12515
6.4 MEDIUM

The Muslim Prayer Time-Salah/Iqamah plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Masjid ID parameter in all versions up to, and including, …

Jan 9, 2025
CVE-2024-12514
6.4 MEDIUM

The 3DVieweronline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '3Dvo-model' shortcode in all versions up to, and including, 2.2.2 due …

Jan 9, 2025
CVE-2024-12496
6.4 MEDIUM

The Linear plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linear_block_buy_commissions' shortcode in all versions up to, and including, 2.7.12 due …

Jan 9, 2025
CVE-2024-12493
6.4 MEDIUM

The Files Download Delay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fddwrap' shortcode in all versions up to, and including, …

Jan 9, 2025
CVE-2024-12491
6.4 MEDIUM

The SimplyRETS Real Estate IDX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sr_search_form' shortcode in all versions up to, and …

Jan 9, 2025
CVE-2024-12394
6.1 MEDIUM

The Action Network plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.4.4 due …

Jan 9, 2025
CVE-2024-12330
7.5 HIGH

The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in all …

Jan 9, 2025
CVE-2024-12285
6.1 MEDIUM

The SEMA API plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘catid’ parameter in all versions up to, and including, 5.27 due …

Jan 9, 2025
CVE-2024-12249
4.3 MEDIUM

The GS Insever Portfolio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_settings() function in …

Jan 9, 2025
CVE-2024-12222
6.1 MEDIUM

The Deliver via Shipos for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dvsfw_bulk_label_url’ parameter in all versions up to, and …

Jan 9, 2025
CVE-2024-12218
6.1 MEDIUM

The Woocommerce check pincode/zipcode for shipping plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.4. This is …

Jan 9, 2025
CVE-2024-12206
4.3 MEDIUM

The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.8. This …

Jan 9, 2025
CVE-2024-12122
6.1 MEDIUM

The ResAds plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions up to, and including, 2.0.6 due to insufficient …

Jan 9, 2025
CVE-2024-12067
6.5 MEDIUM

The WP Travel – Ultimate Travel Booking System, Tour Management Engine plugin for WordPress is vulnerable to SQL Injection via the 'booking_itinerary' parameter of the …

Jan 9, 2025
CVE-2024-11929
6.4 MEDIUM

The Responsive FlipBook Plugin Wordpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the rfbwp_save_settings() functionin all versions up to, and including, 2.5.0 …

Jan 9, 2025
CVE-2024-11907
6.4 MEDIUM

The Skyword API Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skyword_iframe' shortcode in all versions up to, and including, …

Jan 9, 2025
CVE-2024-11815
6.1 MEDIUM

The Pósturinn\'s Shipping with WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the printed_marked and nonprinted_marked parameters in all versions up to, …

Jan 9, 2025
CVE-2024-11686
6.1 MEDIUM

The WhatsApp 🚀 click to chat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'manycontacts_code' parameter in all versions up to, and …

Jan 9, 2025
CVE-2024-11642
9.8 CRITICAL

The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder plugin for WordPress …

Jan 9, 2025
CVE-2024-11328
6.1 MEDIUM

The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping …

Jan 9, 2025
CVE-2025-0348
3.5 LOW

A vulnerability was found in CampCodes DepEd Equipment Inventory System 1.0. It has been rated as problematic. This issue affects some unknown processing of the …

Jan 9, 2025
CVE-2025-0347
7.3 HIGH

A vulnerability was found in code-projects Admission Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file index.php …

Jan 9, 2025
CVE-2025-0346
4.7 MEDIUM

A vulnerability was found in code-projects Content Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/publishnews.php …

Jan 9, 2025
CVE-2025-0345
6.3 MEDIUM

A vulnerability was found in leiyuxi cy-fast 1.0 and classified as critical. Affected by this issue is the function listData of the file /sys/menu/listData. The …

Jan 9, 2025
CVE-2024-13153
6.4 MEDIUM

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.5.135 …

Jan 9, 2025
CVE-2024-12802
9.1 CRITICAL

SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal Name) and SAM (Security Account …

Jan 9, 2025
CVE-2025-0344
6.3 MEDIUM

A vulnerability has been found in leiyuxi cy-fast 1.0 and classified as critical. Affected by this vulnerability is the function listData of the file /commpara/listData. …

Jan 9, 2025
CVE-2025-0342
3.5 LOW

A vulnerability, which was classified as problematic, was found in CampCodes Computer Laboratory Management System 1.0. This affects an unknown part of the file /class/edit/edit. …

Jan 9, 2025
CVE-2025-0341
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in CampCodes Computer Laboratory Management System 1.0. Affected by this issue is some unknown functionality …

Jan 9, 2025
CVE-2024-43663
9.8 CRITICAL

There are many buffer overflow vulnerabilities present in several CGI binaries of the charging station.This issue affects Iocharger firmware for AC model chargers beforeversion 24120701. …

Jan 9, 2025
CVE-2024-43662

The <redacted>.exe or <redacted>.exe CGI binary can be used to upload arbitrary files to /tmp/upload/ or /tmp/ respectively as any user, although the user interface …

Jan 9, 2025
CVE-2024-43661
9.8 CRITICAL

The <redacted>.so library, which is used by <redacted>, is vulnerable to a buffer overflow in the code that handles the deletion of certificates. This buffer …

Jan 9, 2025
CVE-2024-43660
7.5 HIGH

The CGI script <redacted>.sh can be used to download any file on the filesystem. This issue affects Iocharger firmware for AC model chargers beforeversion 24120701. …

Jan 9, 2025
CVE-2024-43659
7.2 HIGH

After gaining access to the firmware of a charging station, a file at <redacted> can be accessed to obtain default credentials that are the same …

Jan 9, 2025
CVE-2024-43658

Patch traversal, External Control of File Name or Path vulnerability in Iocharger Home allows deletion of arbitrary files This issue affects Iocharger firmware for AC …

Jan 9, 2025
CVE-2024-43657
8.8 HIGH

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue affects Iocharger firmware for AC …

Jan 9, 2025
CVE-2024-43656
8.8 HIGH

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue affects Iocharger firmware for AC …

Jan 9, 2025
CVE-2024-43655

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue affects Iocharger firmware for AC …

Jan 9, 2025
CVE-2024-43654
8.8 HIGH

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware for AC models allows OS Command Injection as root This …

Jan 9, 2025
CVE-2024-43653
8.8 HIGH

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue affects Iocharger firmware for AC …

Jan 9, 2025
CVE-2024-43652
8.8 HIGH

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue affects Iocharger firmware for AC …

Jan 9, 2025
CVE-2024-43651

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue affects Iocharger firmware for AC …

Jan 9, 2025
CVE-2024-43650

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware for AC models allows OS Command Injection as root This …

Jan 9, 2025
CVE-2024-43649
8.8 HIGH

Authenticated command injection in the filename of a <redacted>.exe request leads to remote code execution as the root user. This issue affects Iocharger firmware for …

Jan 9, 2025
CVE-2024-43648
8.8 HIGH

Command injection in the <redacted> parameter of a <redacted>.exe request leads to remote code execution as the root user. This issue affects Iocharger firmware for …

Jan 9, 2025
CVE-2024-40765
9.8 CRITICAL

An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially …

Jan 9, 2025
CVE-2024-12806
4.9 MEDIUM

A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file.

Jan 9, 2025
CVE-2024-12805
7.2 HIGH

A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.

Jan 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.