CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-11282
5.3 MEDIUM

The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.10 …

Jan 7, 2025
CVE-2024-9702
6.4 MEDIUM

The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'socialrocket-floating' shortcode in all versions up …

Jan 7, 2025
CVE-2024-9697
5.3 MEDIUM

The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Jan 7, 2025
CVE-2024-9638
4.8 MEDIUM

The Category Posts Widget WordPress plugin before 4.9.18 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jan 7, 2025
CVE-2024-8857
4.8 MEDIUM

The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jan 7, 2025
CVE-2024-8855
9.8 CRITICAL

The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing editors and …

Jan 7, 2025
CVE-2024-7696
6.3 MEDIUM

Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for an authenticated malicious client to tamper with …

Jan 7, 2025
CVE-2024-12849
7.5 HIGH

The Error Log Viewer By WP Guru plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.0.1.3 via …

Jan 7, 2025
CVE-2024-12633
7.1 HIGH

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page parameter …

Jan 7, 2025
CVE-2024-12535
8.6 HIGH

The Host PHP Info plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function …

Jan 7, 2025
CVE-2024-12471
8.8 HIGH

The Post Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator plugin for WordPress is vulnerable to arbitrary files uploads due …

Jan 7, 2025
CVE-2024-12464
6.4 MEDIUM

The Chatroll Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'chatroll' shortcode in all versions up to, and including, …

Jan 7, 2025
CVE-2024-12440
6.4 MEDIUM

The Candifly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'candifly' shortcode in all versions up to, and including, 1.0.6 due …

Jan 7, 2025
CVE-2024-12439
6.4 MEDIUM

The Marketplace Items plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'marketplace' shortcode in all versions up to, and including, 1.5.5 …

Jan 7, 2025
CVE-2024-12438
6.1 MEDIUM

The WooCommerce Digital Content Delivery (incl. DRM) – FlickRocket plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'start_date’ and 'end_date' parameters in …

Jan 7, 2025
CVE-2024-12384
6.1 MEDIUM

The Binary MLM Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page’ parameter in all versions up to, and including, 2.0 …

Jan 7, 2025
CVE-2024-12383
6.1 MEDIUM

The Binary MLM Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0. This is due to …

Jan 7, 2025
CVE-2024-12261
6.1 MEDIUM

The SmartEmailing.cz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'se-lists-updated' parameter in all versions up to, and including, 2.2.0 due to …

Jan 7, 2025
CVE-2024-12073
6.4 MEDIUM

The Meteor Slides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slide_url_value' parameter in all versions up to, and including, 1.5.7 due …

Jan 7, 2025
CVE-2024-11887
6.4 MEDIUM

The Geo Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'geotargetlygeocontent' shortcode in all versions up to, and including, 6.0 …

Jan 7, 2025
CVE-2024-11756
6.4 MEDIUM

The SweepWidget Contests, Giveaways, Photo Contests, Competitions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sweepwidget' shortcode in all versions up …

Jan 7, 2025
CVE-2024-11749
6.4 MEDIUM

The App Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'appizy' shortcode in all versions up to, and including, 2.3.2 …

Jan 7, 2025
CVE-2024-11606
5.3 MEDIUM

The Tabs Shortcode WordPress plugin through 2.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Jan 7, 2025
CVE-2024-11369
6.1 MEDIUM

The Store credit / Gift cards for woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'coupon', 'start_date', and 'end_date' parameters in …

Jan 7, 2025
CVE-2024-10562
2.7 LOW

The Form Maker by 10Web WordPress plugin before 1.15.31 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jan 7, 2025
CVE-2024-10536
4.3 MEDIUM

The FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor plugin for WordPress is vulnerable to unauthorized access of …

Jan 7, 2025
CVE-2024-10102
2.7 LOW

The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could …

Jan 7, 2025
CVE-2024-9208
6.1 MEDIUM

The Enable Accessibility plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the …

Jan 7, 2025
CVE-2024-12470
9.8 CRITICAL

The School Management System – SakolaWP plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.8. This is due …

Jan 7, 2025
CVE-2024-12462
6.4 MEDIUM

The YOGO Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yogo-calendar' shortcode in all versions up to, and including, 1.6.2 …

Jan 7, 2025
CVE-2024-12457
6.4 MEDIUM

The Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Jan 7, 2025
CVE-2024-12453
6.4 MEDIUM

The Uptodown APK Download Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'utd-widget' shortcode in all versions up to, and …

Jan 7, 2025
CVE-2024-12445
6.4 MEDIUM

The RightMessage WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rm_area' shortcode in all versions up to, and including, 0.9.7 …

Jan 7, 2025
CVE-2024-12435
6.1 MEDIUM

The Compare Products for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s_feature’ parameter in all versions up to, and including, …

Jan 7, 2025
CVE-2024-12332
6.5 MEDIUM

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and including, …

Jan 7, 2025
CVE-2024-12327
4.3 MEDIUM

The LazyLoad Background Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pblzbg_save_settings() function in …

Jan 7, 2025
CVE-2024-12324
6.1 MEDIUM

The Unilevel MLM Plan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all versions up to, and including, 1.1.0 …

Jan 7, 2025
CVE-2024-12322
8.8 HIGH

The ThePerfectWedding.nl Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8. This is due to missing …

Jan 7, 2025
CVE-2024-12313
8.1 HIGH

The Compare Products for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.1 via deserialization of …

Jan 7, 2025
CVE-2024-12291
6.1 MEDIUM

The ViewMedica 9 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.17. This is due to missing …

Jan 7, 2025
CVE-2024-12290
6.1 MEDIUM

The Infility Global plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘set_type’ parameter in all versions up to, and including, 2.9.8 due …

Jan 7, 2025
CVE-2024-12288
6.1 MEDIUM

The Simple add pages or posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.0. This is …

Jan 7, 2025
CVE-2024-12264
9.8 CRITICAL

The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.8.3. This is due to /wp-json/payu/v1/generate-user-token …

Jan 7, 2025
CVE-2024-12256
6.1 MEDIUM

The Simple Video Management System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'analytics_video' parameter in all versions up to, and including, …

Jan 7, 2025
CVE-2024-12252
9.8 CRITICAL

The SEO LAT Auto Post plugin for WordPress is vulnerable to file overwrite due to a missing capability check on the remote_update AJAX action in …

Jan 7, 2025
CVE-2024-12214
6.1 MEDIUM

The WooCommerce HSS Extension for Streaming Video plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘videolink’ parameter in all versions up to, …

Jan 7, 2025
CVE-2024-12207
4.4 MEDIUM

The Toggles Shortcode and Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, …

Jan 7, 2025
CVE-2024-12176
5.3 MEDIUM

The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'wl_config_plugin' …

Jan 7, 2025
CVE-2024-12170
5.4 MEDIUM

The ViewMedica 9 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.15. This is due to missing …

Jan 7, 2025
CVE-2024-12159
5.3 MEDIUM

The Optimize Your Campaigns – Google Shopping – Google Ads – Google Adwords plugin for WordPress is vulnerable to Information Exposure in all versions up …

Jan 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.