CVE Database

10843+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-48180
9.8 CRITICAL

ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to execute PHP code.

Oct 16, 2024
CVE-2024-9893
9.8 CRITICAL

The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.1.14. This is due to …

Oct 16, 2024
CVE-2024-49260
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Limbcode WordPress Gallery Plugin – Limb Image Gallery limb-gallery allows Code Injection.This issue affects WordPress Gallery …

Oct 16, 2024
CVE-2024-49254
10.0 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in sunjianle ajax-extend ajax-extend allows Code Injection.This issue affects ajax-extend: from n/a through <= 1.0.

Oct 16, 2024
CVE-2024-49242
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Shafiq Digital Lottery digital-lottery allows Upload a Web Shell to a Web Server.This issue affects Digital …

Oct 16, 2024
CVE-2024-49227
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in foter Free Stock Photos Foter free-stock-photos-foter allows Object Injection.This issue affects Free Stock Photos Foter: from n/a through <= …

Oct 16, 2024
CVE-2024-49218
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Al Imran Akash Recently recently-viewed-most-viewed-and-sold-products-for-woocommerce allows Object Injection.This issue affects Recently: from n/a through <= 1.1.

Oct 16, 2024
CVE-2024-49216
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in jclay06 Feed Comments Number feed-comments-number allows Upload a Web Shell to a Web Server.This issue affects …

Oct 16, 2024
CVE-2024-48035
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in takayukii ACF Images Search And Insert acf-images-search-and-insert allows Upload a Web Shell to a Web Server.This …

Oct 16, 2024
CVE-2024-48034
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in fliperrr Creates 3D Flipbook, PDF Flipbook create-flipbook-from-pdf allows Upload a Web Shell to a Web Server.This …

Oct 16, 2024
CVE-2024-48030
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Webextends Telecash Ricaricaweb telecash-ricaricaweb allows Object Injection.This issue affects Telecash Ricaricaweb: from n/a through <= 2.2.

Oct 16, 2024
CVE-2024-48028
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Boyan Raichev IP Loc8 ip-loc8 allows Object Injection.This issue affects IP Loc8: from n/a through <= 1.1.

Oct 16, 2024
CVE-2024-48027
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in xaraartech External featured image from bing external-featured-image-from-bing allows Upload a Web Shell to a Web Server.This …

Oct 16, 2024
CVE-2024-48026
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in GMRobbins Disc Golf Manager disc-golf-manager allows Object Injection.This issue affects Disc Golf Manager: from n/a through <= 1.0.0.

Oct 16, 2024
CVE-2024-47649
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in THATplugin Iconize iconize.This issue affects Iconize: from n/a through <= 1.2.4.

Oct 16, 2024
CVE-2024-49271
9.1 CRITICAL

Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Command Injection.This issue affects Unlimited Elements For …

Oct 16, 2024
CVE-2024-49257
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Denis Azz Anonim Posting azz-anonim-posting allows Upload a Web Shell to a Web Server.This issue affects …

Oct 16, 2024
CVE-2024-49247
9.8 CRITICAL

Authentication Bypass Using an Alternate Path or Channel vulnerability in SK BuddyPress Better Registration better-bp-registration allows Authentication Bypass.This issue affects BuddyPress Better Registration: from n/a …

Oct 16, 2024
CVE-2024-48042
9.1 CRITICAL

Deserialization of Untrusted Data vulnerability in supsystic Contact Form by Supsystic contact-form-by-supsystic allows Command Injection.This issue affects Contact Form by Supsystic: from n/a through <= …

Oct 16, 2024
CVE-2023-32191
9.9 CRITICAL

When RKE provisions a cluster, it stores the cluster state in a configmap called `full-cluster-state` inside the `kube-system` namespace of the cluster itself. The information …

Oct 16, 2024
CVE-2024-45216
9.8 CRITICAL

Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authentication is used, are vulnerable to Authentication …

Oct 16, 2024
CVE-2016-15042
9.8 CRITICAL

The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to …

Oct 16, 2024
CVE-2021-4449
9.8 CRITICAL

The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'savepng.php' file in versions up to, …

Oct 16, 2024
CVE-2021-4443
9.8 CRITICAL

The WordPress Mega Menu plugin for WordPress is vulnerable to Arbitrary File Creation in versions up to, and including, 2.0.6 via the compiler_save AJAX action. …

Oct 16, 2024
CVE-2020-36837
9.9 CRITICAL

The ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability check on the reset_wizard_actions function in versions 1.3.4 …

Oct 16, 2024
CVE-2020-36832
9.8 CRITICAL

The Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and including, 7.3 to 8.6. This makes it possible for …

Oct 16, 2024
CVE-2019-25217
9.8 CRITICAL

The SiteGround Optimizer plugin for WordPress is vulnerable to authorization bypass leading to Remote Code Execution and Local File Inclusion in versions up to, and …

Oct 16, 2024
CVE-2019-25213
9.8 CRITICAL

The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation …

Oct 16, 2024
CVE-2018-25105
9.8 CRITICAL

The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions up to, …

Oct 16, 2024
CVE-2016-15040
9.8 CRITICAL

The Kento Post View Counter plugin for WordPress is vulnerable to SQL Injection via the 'kento_pvc_geo' parameter in versions up to, and including, 2.8 due …

Oct 16, 2024
CVE-2024-10018
9.8 CRITICAL

Improper permission control in the mobile application (com.transsion.aivoiceassistant) can lead to the launch of any unexported component.

Oct 16, 2024
CVE-2024-9634
9.8 CRITICAL

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.3 …

Oct 16, 2024
CVE-2024-9105
9.8 CRITICAL

The UltimateAI plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.8.3. This is due to insufficient verification on the …

Oct 16, 2024
CVE-2024-10004
9.1 CRITICAL

Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result …

Oct 15, 2024
CVE-2024-9486
9.8 CRITICAL

A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine …

Oct 15, 2024
CVE-2024-48782
9.8 CRITICAL

File Upload vulnerability in DYCMS Open-Source Version v2.0.9.41 allows a remote attacker to execute arbitrary code via the application only detecting the extension of image …

Oct 15, 2024
CVE-2024-48781
9.8 CRITICAL

An issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary code via a specially constructed so file/opt/EdrawProj-2/plugins/imageformat.

Oct 15, 2024
CVE-2024-48779
9.8 CRITICAL

An issue in Wanxing Technology's Yitu project Management Software 3.2.2 allows a remote attacker to execute arbitrary code via the platformpluginpath parameter to specify that …

Oct 15, 2024
CVE-2024-48411
9.8 CRITICAL

itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload to the val-email parameter in forget_password.php.

Oct 15, 2024
CVE-2024-49195
9.8 CRITICAL

Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair

Oct 15, 2024
CVE-2024-21216
9.8 CRITICAL

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability …

Oct 15, 2024
CVE-2024-21172
9.0 CRITICAL

Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected are 5.6.19.19, 5.6.25.8 and 5.6.26.4. …

Oct 15, 2024
CVE-2024-48914
9.1 CRITICAL

Vendure is an open-source headless commerce platform. Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's asset server plugin allows an attacker to craft …

Oct 15, 2024
CVE-2024-48283
9.8 CRITICAL

Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-result.php via the searchkey parameter.

Oct 15, 2024
CVE-2024-49388
9.1 CRITICAL

Sensitive information manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.

Oct 15, 2024
CVE-2024-45275
9.8 CRITICAL

The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.

Oct 15, 2024
CVE-2024-45274
9.8 CRITICAL

An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.

Oct 15, 2024
CVE-2024-47945
9.8 CRITICAL

The devices are vulnerable to session hijacking due to insufficient entropy in its session ID generation algorithm. The session IDs are predictable, with only 32,768 …

Oct 15, 2024
CVE-2024-9985
10.0 CRITICAL

Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privileges can upload a webshell and use it …

Oct 15, 2024
CVE-2024-9984
9.8 CRITICAL

Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user's session …

Oct 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.