CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-11631
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /expedit.php. The …

Nov 23, 2024
CVE-2024-11231
6.4 MEDIUM

The 우커머스 네이버페이 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mnp_purchase shortcode in all versions up to, and including, 3.3.7 …

Nov 23, 2024
CVE-2024-11229
6.4 MEDIUM

The 코드엠샵 소셜톡 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's add_plus_friends and add_plus_talk shortcodes in all versions up to, and …

Nov 23, 2024
CVE-2024-11228
6.4 MEDIUM

The 워드프레스 결제 심플페이 – 우커머스 결제 플러그인 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's pafw_instant_payment shortcode in all versions …

Nov 23, 2024
CVE-2024-11034
7.3 HIGH

The The Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form Popup – Product Quotation plugin for WordPress …

Nov 23, 2024
CVE-2024-11227
6.4 MEDIUM

The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's memberlite_accordion shortcode in all versions up to, and including, 1.3.9 …

Nov 23, 2024
CVE-2024-11199
6.4 MEDIUM

The Rescue Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rescue_progressbar shortcode in all versions up to, and including, 2.9 …

Nov 23, 2024
CVE-2024-10519
6.1 MEDIUM

The Wishlist for WooCommerce: Multi Wishlists Per Customer PRO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wtab' parameter in versions 3.0.8 …

Nov 23, 2024
CVE-2024-9942
9.8 CRITICAL

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the MJ_gmgt_user_avatar_image_upload() …

Nov 23, 2024
CVE-2024-9941
8.8 HIGH

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the MJ_gmgt_add_staff_member() function …

Nov 23, 2024
CVE-2024-9660
8.8 HIGH

The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj_smgt_load_documets_new() and …

Nov 23, 2024
CVE-2024-9659
9.8 CRITICAL

The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj_smgt_user_avatar_image_upload() function …

Nov 23, 2024
CVE-2024-9511
9.8 CRITICAL

The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to PHP Object …

Nov 23, 2024
CVE-2024-10803
7.5 HIGH

The MP3 Sticky Player plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.0 via the content/downloader.php file. This …

Nov 23, 2024
CVE-2024-9635
6.1 MEDIUM

The Checkout with Cash App on WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_wp_http_referer' parameter in several files in all …

Nov 23, 2024
CVE-2024-11446
6.1 MEDIUM

The Chessgame Shizzle plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'cs_nonce' parameter in all versions up to, and including, 1.3.0 due …

Nov 23, 2024
CVE-2024-11330
6.1 MEDIUM

The Custom CSS, JS & PHP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate …

Nov 23, 2024
CVE-2024-11265
4.3 MEDIUM

The Increase Maximum Upload File Size | Increase Execution Time plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and …

Nov 23, 2024
CVE-2024-11188
6.1 MEDIUM

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to POST-Based Reflected Cross-Site …

Nov 23, 2024
CVE-2024-11426
6.4 MEDIUM

The AutoListicle: Automatically Update Numbered List Articles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'auto-list-number' shortcode in all versions up …

Nov 23, 2024
CVE-2024-11408
6.4 MEDIUM

The Slotti Ajanvaraus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slotti' shortcode in all versions up to, and including, 1.3.0 …

Nov 23, 2024
CVE-2024-11387
6.4 MEDIUM

The Easy Liveblogs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'elb_liveblog' shortcode in all versions up to, and including, 2.3.5 …

Nov 23, 2024
CVE-2024-11361
6.1 MEDIUM

The PDF Invoices & Packing Slips Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without …

Nov 23, 2024
CVE-2024-11332
6.4 MEDIUM

The HIPAA Compliant Forms with Drag’n’Drop HIPAA Form Builder. Sign HIPAA documents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hipaatizer' …

Nov 23, 2024
CVE-2024-10880
6.1 MEDIUM

The JobBoardWP – Job Board Listings and Submissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg …

Nov 23, 2024
CVE-2024-10873
8.8 HIGH

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via the …

Nov 23, 2024
CVE-2024-10606
4.3 MEDIUM

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized modification of data due to a …

Nov 23, 2024
CVE-2024-9223
4.3 MEDIUM

The WPDash Notes plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wp_ajax_post_it_list_comment' function in all …

Nov 23, 2024
CVE-2024-11463
6.1 MEDIUM

The DeBounce Email Validator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'from', 'to', and 'key' parameters in all versions up to, …

Nov 23, 2024
CVE-2024-11415
8.8 HIGH

The WP-Orphanage Extended plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing …

Nov 23, 2024
CVE-2024-11362
6.1 MEDIUM

The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use …

Nov 23, 2024
CVE-2024-10961
9.8 CRITICAL

The Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.9.0. This is due to insufficient verification …

Nov 23, 2024
CVE-2024-10886
6.4 MEDIUM

The Tribute Testimonials – WordPress Testimonial Grid/Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tribute_testimonials_slider' shortcode in all versions up …

Nov 23, 2024
CVE-2024-10874
6.4 MEDIUM

The Quotes llama plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'quotes-llama' shortcode in all versions up to, and including, 3.0.0 …

Nov 23, 2024
CVE-2024-10869
6.1 MEDIUM

The WordPress Brute Force Protection – Stop Brute Force Attacks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg …

Nov 23, 2024
CVE-2024-10868
4.3 MEDIUM

The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.1.9 …

Nov 23, 2024
CVE-2024-10813
5.3 MEDIUM

The Product Table for WooCommerce by CodeAstrology (wooproducttable.com) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1 …

Nov 23, 2024
CVE-2024-10537
4.3 MEDIUM

The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability …

Nov 23, 2024
CVE-2024-10216
4.3 MEDIUM

The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Nov 23, 2024
CVE-2024-10116
6.4 MEDIUM

The Twitter Follow Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'username' parameter in all versions up to, and including, 0.2 …

Nov 23, 2024
CVE-2024-41761
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server …

Nov 23, 2024
CVE-2024-11586
4.0 MEDIUM

Ubuntu's implementation of pulseaudio can be crashed by a malicious program if a bluetooth headset is connected.

Nov 23, 2024
CVE-2024-0138
9.8 CRITICAL

NVIDIA Base Command Manager contains a missing authentication vulnerability in the CMDaemon component. A successful exploit of this vulnerability might lead to code execution, denial …

Nov 23, 2024
CVE-2024-0122
7.6 HIGH

NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an attacker may cause an unauthorized action. A successful exploit of this vulnerability …

Nov 23, 2024
CVE-2024-52034
10.0 CRITICAL

An OS Command Injection vulnerability exists within myPRO Manager. A parameter within a command can be exploited by an unauthenticated remote attacker to inject arbitrary …

Nov 22, 2024
CVE-2024-50054
7.5 HIGH

The back-end does not sufficiently verify the user-controlled filename parameter which makes it possible for an attacker to perform a path traversal attack and retrieve …

Nov 22, 2024
CVE-2024-47407
10.0 CRITICAL

A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote attacker to inject arbitrary …

Nov 22, 2024
CVE-2024-47138
9.8 CRITICAL

The administrative interface listens by default on all interfaces on a TCP port and does not require authentication when being accessed.

Nov 22, 2024
CVE-2024-45369
8.1 HIGH

The web application uses a weak authentication mechanism to verify that a request is coming from an authenticated and authorized resource.

Nov 22, 2024
CVE-2024-9767
7.8 HIGH

IrfanView SID File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User …

Nov 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.