CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-51463
5.4 MEDIUM

IBM i 7.3, 7.4, and 7.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the …

Dec 21, 2024
CVE-2024-12884
7.3 HIGH

A vulnerability was found in Codezips E-Commerce Website 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Dec 21, 2024
CVE-2024-12883
4.3 MEDIUM

A vulnerability was found in code-projects Job Recruitment 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the …

Dec 21, 2024
CVE-2024-12875
4.9 MEDIUM

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and …

Dec 21, 2024
CVE-2024-12591
6.4 MEDIUM

The MagicPost plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wb_share_social shortcode in all versions up to, and including, 1.2.1 due …

Dec 21, 2024
CVE-2024-12558
6.5 MEDIUM

The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check …

Dec 21, 2024
CVE-2024-12408
6.1 MEDIUM

The WP on AWS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST data in all versions up to, and including, 5.2.1 due …

Dec 21, 2024
CVE-2024-11722
5.9 MEDIUM

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.25.1 …

Dec 21, 2024
CVE-2024-11688
6.1 MEDIUM

The LaTeX2HTML plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ver' or 'date' parameter in all versions up to, and including, 2.5.5 …

Dec 21, 2024
CVE-2024-10453
6.4 MEDIUM

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typography Settings …

Dec 21, 2024
CVE-2024-9545
6.4 MEDIUM

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aux_contact_box and aux_gmaps shortcodes in …

Dec 21, 2024
CVE-2024-12588
6.4 MEDIUM

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Staff widget in all versions …

Dec 21, 2024
CVE-2024-11808
6.1 MEDIUM

The Pingmeter Uptime Monitoring plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_wpnonce' parameter in all versions up to, and including, 1.0.3 …

Dec 21, 2024
CVE-2024-10797
4.3 MEDIUM

The Full Screen Menu for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.7 via the Full …

Dec 21, 2024
CVE-2024-12771
8.8 HIGH

The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.43. This …

Dec 21, 2024
CVE-2024-12721
7.2 HIGH

The Custom Product Tabs For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.4 via deserialization …

Dec 21, 2024
CVE-2024-12697
6.4 MEDIUM

The real.Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.1 due to insufficient input sanitization and …

Dec 21, 2024
CVE-2024-12635
6.5 MEDIUM

The WP Docs plugin for WordPress is vulnerable to time-based SQL Injection via the 'dir_id' parameter in all versions up to, and including, 2.2.0 due …

Dec 21, 2024
CVE-2024-12262
6.1 MEDIUM

The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'step' parameter in all versions up to, and including, 5.8001 due …

Dec 21, 2024
CVE-2024-12066
8.8 HIGH

The SMSA Shipping(official) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the smsa_delete_label() function in all versions …

Dec 21, 2024
CVE-2024-11975
6.1 MEDIUM

The Reactflow Visitor Recording and Heatmaps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_wpnonce' parameter in all versions up to, and …

Dec 21, 2024
CVE-2024-11938
6.4 MEDIUM

The One Click Upsell Funnel for WooCommerce – Funnel Builder for WordPress, Create WooCommerce Upsell, Post-Purchase Upsell & Cross Sell Offers that Boost Sales & …

Dec 21, 2024
CVE-2024-11682
6.1 MEDIUM

The G Web Pro Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'q' parameter in all versions up to, and …

Dec 21, 2024
CVE-2024-11287
6.1 MEDIUM

The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in …

Dec 21, 2024
CVE-2024-11196
6.4 MEDIUM

The Multi-column Tag Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mctagmap shortcode in all versions up to, and including, …

Dec 21, 2024
CVE-2024-11977
7.3 HIGH

The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up …

Dec 21, 2024
CVE-2024-11607
6.1 MEDIUM

The GTPayment Donations WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Dec 21, 2024
CVE-2024-12846
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Emlog Pro up to 2.4.1. Affected by this issue is some unknown functionality of …

Dec 21, 2024
CVE-2024-11349
9.8 CRITICAL

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.6. This is due to the plugin not …

Dec 21, 2024
CVE-2023-31280
5.3 MEDIUM

An AirVantage online Warranty Checker tool vulnerability could allow an attacker to perform bulk enumeration of IMEI and Serial Numbers pairs. The AirVantage Warranty Checker …

Dec 21, 2024
CVE-2023-31279
8.1 HIGH

The AirVantage platform is vulnerable to an unauthorized attacker registering previously unregistered devices on the AirVantage platform when the owner has not disabled the AirVantage …

Dec 21, 2024
CVE-2024-11811
6.1 MEDIUM

The Feedify – Web Push Notifications plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'platform', 'phone', 'email', and 'store_url' parameters. in all …

Dec 20, 2024
CVE-2024-12845
3.5 LOW

A vulnerability classified as problematic was found in Emlog Pro up to 2.4.1. Affected by this vulnerability is an unknown functionality in the library /include/lib/common.php. …

Dec 20, 2024
CVE-2021-40959
6.1 MEDIUM

A reflected cross-site scripting vulnerability in MONITORAPP Application Insight Web Application Firewall (AIWAF) <= 4.1.6 and <=5.0 was identified on the subpage `/process_management/process_status.xhr.php`. This vulnerability …

Dec 20, 2024
CVE-2020-13712
7.8 HIGH

A command injection is possible through the user interface, allowing arbitrary command execution as the root user. oMG2000 running MGOS 3.15.1 or earlier is affected. …

Dec 20, 2024
CVE-2024-56359
8.1 HIGH

grist-core is a spreadsheet hosting server. A user visiting a malicious document and clicking on a link in a HyperLink cell using a control modifier …

Dec 20, 2024
CVE-2024-56358
8.1 HIGH

grist-core is a spreadsheet hosting server. A user visiting a malicious document and previewing an attachment could have their account compromised, because JavaScript in an …

Dec 20, 2024
CVE-2024-56357
8.1 HIGH

grist-core is a spreadsheet hosting server. A user visiting a malicious document or submitting a malicious form could have their account compromised, because it was …

Dec 20, 2024
CVE-2024-56335
7.6 HIGH

vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected versions an attacker is capable of updating or deleting …

Dec 20, 2024
CVE-2024-56334
7.8 HIGH

systeminformation is a System and OS information library for node.js. In affected versions SSIDs are not sanitized when before they are passed as a parameter …

Dec 20, 2024
CVE-2024-55509
9.8 CRITICAL

SQL injection vulnerability in CodeAstro Complaint Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via the id parameter of …

Dec 20, 2024
CVE-2024-40875

There is a cross-site scripting vulnerability in the management console of Absolute Secure Access prior to version 13.52. Attackers with system administrator permissions can interfere …

Dec 20, 2024
CVE-2024-12844
4.3 MEDIUM

A vulnerability classified as problematic has been found in Emlog Pro up to 2.4.1. Affected is an unknown function of the file /admin/store.php. The manipulation …

Dec 20, 2024
CVE-2024-12843
4.3 MEDIUM

A vulnerability was found in Emlog Pro up to 2.4.1. It has been rated as problematic. This issue affects some unknown processing of the file …

Dec 20, 2024
CVE-2024-56333

Onyxia is a web app that aims at being the glue between multiple open source backend technologies to provide a state of art working environment …

Dec 20, 2024
CVE-2024-56331
6.8 MEDIUM

Uptime Kuma is an open source, self-hosted monitoring tool. An **Improper URL Handling Vulnerability** allows an attacker to access sensitive local files on the server …

Dec 20, 2024
CVE-2024-56330

Stardust is a platform for streaming isolated desktop containers. With this exploit, inter container communication (ICC) is not disabled. This would allow users within a …

Dec 20, 2024
CVE-2024-56329

Socialstream is a third-party package for Laravel Jetstream. It replaces the published authentication and profile scaffolding provided by Laravel Jetstream, with scaffolding that has support …

Dec 20, 2024
CVE-2024-55341
4.7 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Piranha CMS 11.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by …

Dec 20, 2024
CVE-2024-12867

Server-Side Request Forgery in URL Mapper in Arctic Security's Arctic Hub versions 3.0.1764-5.6.1877 allows an unauthenticated remote attacker to exfiltrate and modify configurations and data.

Dec 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.