CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-11460
7.5 HIGH

The Verowa Connect plugin for WordPress is vulnerable to SQL Injection via the 'search_string' parameter in all versions up to, and including, 3.0.1 due to …

Dec 6, 2024
CVE-2024-11289
8.1 HIGH

The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.5.9 via several functions like penci_archive_more_post_ajax_func, penci_more_post_ajax_func, …

Dec 6, 2024
CVE-2024-10909
6.3 MEDIUM

The The Pojo Forms plugin for WordPress is vulnerable to arbitrary shortcode execution via form_preview_shortcode AJAX action in all versions up to, and including, 1.4.7. …

Dec 6, 2024
CVE-2024-10681
6.3 MEDIUM

The The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to arbitrary shortcode execution in …

Dec 6, 2024
CVE-2024-9872
5.4 MEDIUM

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Dec 6, 2024
CVE-2024-9866
5.4 MEDIUM

The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameters in all versions up to, and …

Dec 6, 2024
CVE-2024-9706
5.3 MEDIUM

The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ucsm_activate_lite_template_lite …

Dec 6, 2024
CVE-2024-9705
4.3 MEDIUM

The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ucsm_update_template_name_lite' …

Dec 6, 2024
CVE-2024-12155
9.8 CRITICAL

The SV100 Companion plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check …

Dec 6, 2024
CVE-2024-12110
4.3 MEDIUM

The Gold Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the activate() and …

Dec 6, 2024
CVE-2024-12060
6.1 MEDIUM

The WP Media Optimizer (.webp) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wpmowebp-css-resources’ and 'wpmowebp-js-resources' parameters in all versions up to, …

Dec 6, 2024
CVE-2024-12028
5.3 MEDIUM

The Friends plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several REST API endpoints in all versions up …

Dec 6, 2024
CVE-2024-12027
4.3 MEDIUM

The Message Filter for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Dec 6, 2024
CVE-2024-12003
6.1 MEDIUM

The WP System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing …

Dec 6, 2024
CVE-2024-11823
6.1 MEDIUM

The Folder Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'foldergallery' shortcode in all versions up to, and including, 1.7.4 …

Dec 6, 2024
CVE-2024-11687
6.1 MEDIUM

The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and …

Dec 6, 2024
CVE-2024-11450
6.4 MEDIUM

The ONLYOFFICE Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'onlyoffice' shortcode in all versions up to, and including, 2.0.0 …

Dec 6, 2024
CVE-2024-11444
4.3 MEDIUM

The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.13.2. This is due …

Dec 6, 2024
CVE-2024-11368
6.1 MEDIUM

The Splash Sync plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in …

Dec 6, 2024
CVE-2024-11352
6.4 MEDIUM

The TwentyTwenty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'twentytwenty' shortcode in all versions up to, and including, 1.0.1 due …

Dec 6, 2024
CVE-2024-11339
6.4 MEDIUM

The Smart PopUp Blaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spb-button' shortcode in all versions up to, and including, …

Dec 6, 2024
CVE-2024-11336
6.1 MEDIUM

The Clickbank WordPress Plugin (Storefront) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7. This is due …

Dec 6, 2024
CVE-2024-11323
8.8 HIGH

The AI Quiz | Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a …

Dec 6, 2024
CVE-2024-11292
5.3 MEDIUM

The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.1 via the WordPress …

Dec 6, 2024
CVE-2024-11276
6.1 MEDIUM

The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all …

Dec 6, 2024
CVE-2024-11204
6.1 MEDIUM

The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in all versions up to, …

Dec 6, 2024
CVE-2024-10879
6.1 MEDIUM

The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without …

Dec 6, 2024
CVE-2024-10849
6.4 MEDIUM

The NewsMash theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all versions up to, and including, 1.0.71 due …

Dec 6, 2024
CVE-2024-10692
4.3 MEDIUM

The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 …

Dec 6, 2024
CVE-2024-10689
4.3 MEDIUM

The XLTab – Accordions and Tabs for Elementor Page Builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, …

Dec 6, 2024
CVE-2024-10320
6.4 MEDIUM

The Cookielay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cookielay shortcode in all versions up to, and including, 1.2.0 due …

Dec 6, 2024
CVE-2024-11178
8.1 HIGH

The Login With OTP plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.4.2. This is due to the plugin …

Dec 6, 2024
CVE-2024-11585
7.5 HIGH

The WP Hide & Security Enhancer plugin for WordPress is vulnerable to arbitrary file contents deletion due to a missing authorization and insufficient file path …

Dec 6, 2024
CVE-2024-11201
6.4 MEDIUM

The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification …

Dec 6, 2024
CVE-2024-10578
8.8 HIGH

The Pubnews theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the pubnews_importer_plugin_action_for_notice() function in all versions …

Dec 6, 2024
CVE-2024-10551
4.8 MEDIUM

The Sticky Social Icons WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Dec 6, 2024
CVE-2024-10480
4.3 MEDIUM

The 3DPrint Lite WordPress plugin before 2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Dec 6, 2024
CVE-2024-11379
6.1 MEDIUM

The Broadcast plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'do_check' parameter in all versions up to, and including, 51.01 due to …

Dec 6, 2024
CVE-2024-9769
4.4 MEDIUM

The Video Gallery – Best WordPress YouTube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, …

Dec 6, 2024
CVE-2024-10836
6.1 MEDIUM

The Flixita theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.0.82 due to …

Dec 6, 2024
CVE-2024-10247
7.2 HIGH

The Video Gallery – Best WordPress YouTube Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the orderby parameter in all versions …

Dec 6, 2024
CVE-2024-49041
4.3 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Dec 6, 2024
CVE-2024-11149
7.9 HIGH

In OpenBSD 7.4 before errata 014, vmm(4) did not restore GDTR limits properly on Intel (VMX) CPUs.

Dec 6, 2024
CVE-2024-6219
3.8 LOW

Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not …

Dec 6, 2024
CVE-2024-6156
3.8 LOW

Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.

Dec 6, 2024
CVE-2024-52798

path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. …

Dec 5, 2024
CVE-2024-38920
9.1 CRITICAL

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggerd …

Dec 5, 2024
CVE-2024-38910
7.5 HIGH

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a use-after-free in the nav2_amcl process. This vulnerability is triggered …

Dec 5, 2024
CVE-2024-37863
9.8 CRITICAL

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_amcl process. This vulnerability is …

Dec 5, 2024
CVE-2024-37862
7.3 HIGH

Buffer Overflow vulnerability in Open Robotic Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allows a local attacker to execute arbitrary code via a crafted …

Dec 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.