CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-11380
6.4 MEDIUM

The Mini Program API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'qvideo' shortcode in all versions up to, and including, …

Dec 7, 2024
CVE-2024-12270
7.5 HIGH

The Beautiful taxonomy filters plugin for WordPress is vulnerable to SQL Injection via the 'selects[0][term]' parameter in all versions up to, and including, 2.4.3 due …

Dec 7, 2024
CVE-2024-12253
5.4 MEDIUM

The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on …

Dec 7, 2024
CVE-2024-12128
6.1 MEDIUM

The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘monthly_sales_current_year’ parameter in all …

Dec 7, 2024
CVE-2024-11374
6.1 MEDIUM

The TWChat – Send or receive messages from users plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without …

Dec 7, 2024
CVE-2024-11367
6.1 MEDIUM

The Smoove connector for Elementor forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on …

Dec 7, 2024
CVE-2024-11010
7.2 HIGH

The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, …

Dec 7, 2024
CVE-2024-53143
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: fsnotify: Fix ordering of iput() and watched_objects decrement Ensure the superblock is kept alive until …

Dec 7, 2024
CVE-2024-11183
4.8 MEDIUM

The Simple Side Tab WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Dec 7, 2024
CVE-2024-8679
6.8 MEDIUM

The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via the ‘value' parameter of the owt_lib_handler AJAX …

Dec 7, 2024
CVE-2024-7894
5.3 MEDIUM

The If Menu plugin for WordPress is vulnerable to unauthorized modification of the plugin's license key due to a missing capability check on the 'actions' …

Dec 7, 2024
CVE-2024-12257
6.1 MEDIUM

The CardGate Payments for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, …

Dec 7, 2024
CVE-2024-12167
6.1 MEDIUM

The Shortcodes Blocks Creator Ultimate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_wpnonce' parameter in all versions up to, and including, …

Dec 7, 2024
CVE-2024-12166
6.1 MEDIUM

The Shortcodes Blocks Creator Ultimate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, …

Dec 7, 2024
CVE-2024-12165
6.1 MEDIUM

The Mollie for Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and …

Dec 7, 2024
CVE-2024-12115
4.3 MEDIUM

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

Dec 7, 2024
CVE-2024-12026
4.3 MEDIUM

The Message Filter for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Dec 7, 2024
CVE-2024-11943
6.1 MEDIUM

The 워드프레스 결제 심플페이 – 우커머스 결제 플러그인 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg() function without …

Dec 7, 2024
CVE-2024-11904
6.4 MEDIUM

The 코드엠샵 소셜톡 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'msntt_add_plus_talk' shortcode in all versions up to, and including, 1.2.0 …

Dec 7, 2024
CVE-2024-11451
6.4 MEDIUM

The Zooom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zooom' shortcode in all versions up to, and including, 1.1.0 due …

Dec 7, 2024
CVE-2024-11436
6.1 MEDIUM

The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! plugin for WordPress is vulnerable to Reflected Cross-Site …

Dec 7, 2024
CVE-2024-11353
4.3 MEDIUM

The SMS for Lead Capture Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_message() …

Dec 7, 2024
CVE-2024-11329
6.1 MEDIUM

The Comfino Payment Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on …

Dec 7, 2024
CVE-2024-10046
6.1 MEDIUM

The افزونه پیامک ووکامرس Persian WooCommerce SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping …

Dec 7, 2024
CVE-2024-54138
6.1 MEDIUM

NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While …

Dec 6, 2024
CVE-2024-44856
7.5 HIGH

Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_smac_planner().

Dec 6, 2024
CVE-2024-44855
7.5 HIGH

Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_navfn_planner().

Dec 6, 2024
CVE-2024-44854
7.5 HIGH

Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component smoothPlan().

Dec 6, 2024
CVE-2024-44853
7.5 HIGH

Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component computeControl().

Dec 6, 2024
CVE-2024-44852
9.8 CRITICAL

Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a segmentation violation via the component theta_star::ThetaStar::isUnsafeToPlan().

Dec 6, 2024
CVE-2024-41650
9.8 CRITICAL

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to …

Dec 6, 2024
CVE-2024-41649
9.8 CRITICAL

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to …

Dec 6, 2024
CVE-2024-41648
9.8 CRITICAL

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to …

Dec 6, 2024
CVE-2024-41647
9.8 CRITICAL

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to …

Dec 6, 2024
CVE-2024-41646
9.8 CRITICAL

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to …

Dec 6, 2024
CVE-2024-41645
9.8 CRITICAL

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to …

Dec 6, 2024
CVE-2024-41644
9.8 CRITICAL

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via the dyn_param_handler_ component.

Dec 6, 2024
CVE-2024-38927
9.8 CRITICAL

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered …

Dec 6, 2024
CVE-2024-38926
9.8 CRITICAL

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered …

Dec 6, 2024
CVE-2024-38925
9.8 CRITICAL

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered …

Dec 6, 2024
CVE-2024-38924
9.8 CRITICAL

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered …

Dec 6, 2024
CVE-2024-38923
9.8 CRITICAL

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered …

Dec 6, 2024
CVE-2024-38922
9.8 CRITICAL

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a heap overflow in the nav2_amcl process. This vulnerability is …

Dec 6, 2024
CVE-2024-38921
9.8 CRITICAL

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered …

Dec 6, 2024
CVE-2024-7875

Tungsten Automation (Kofax) TotalAgility in versions all through 7.9.0.25.0.954 is vulnerable to a Reflected XSS attacks through mfpScreenResolutionWidth parameter manipulation in a form sent to …

Dec 6, 2024
CVE-2024-7874

Tungsten Automation (Kofax) TotalAgility in versions all through 7.9.0.25.0.954 is vulnerable to a Reflected XSS attacks through mfpConnectionId parameter manipulation in a form sent to …

Dec 6, 2024
CVE-2024-12326
6.1 MEDIUM

Jirafeau normally prevents browser preview for SVG files due to the possibility that manipulated SVG files could be exploited for cross site scripting. This was …

Dec 6, 2024
CVE-2024-0139
4.4 MEDIUM

NVIDIA Base Command Manager and Bright Cluster Manager for Linux contain an insecure temporary file vulnerability. A successful exploit of this vulnerability might lead to …

Dec 6, 2024
CVE-2024-0130
8.8 HIGH

NVIDIA UFM Enterprise, UFM Appliance, and UFM CyberAI contain a vulnerability where an attacker can cause an improper authentication issue by sending a malformed request …

Dec 6, 2024
CVE-2024-52324
9.8 CRITICAL

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x uses an inherently dangerous function which could allow an attacker to send a malicious …

Dec 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.