CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8001
5.3 MEDIUM

A vulnerability was found in VIWIS LMS 9.11. It has been classified as critical. Affected is an unknown function of the component Print Handler. The …

Nov 13, 2024
CVE-2024-11028
9.8 CRITICAL

The MultiManager WP – Manage All Your WordPress Sites Easily plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, …

Nov 13, 2024
CVE-2024-9682
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Form Builder widget in all versions up …

Nov 13, 2024
CVE-2024-9668
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, …

Nov 13, 2024
CVE-2024-9059
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps widget in all versions up to, …

Nov 13, 2024
CVE-2024-10877
6.1 MEDIUM

The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without …

Nov 13, 2024
CVE-2024-52268
4.8 MEDIUM

Cross-site scripting vulnerability exists in VK All in One Expansion Unit versions prior to 9.100.1.0. If this vulnerability is exploited, an arbitrary script may be …

Nov 13, 2024
CVE-2024-9409
7.5 HIGH

CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive resulting in communication loss when a large amount of IGMP …

Nov 13, 2024
CVE-2024-8938
8.1 HIGH

CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a potential arbitrary code execution after a successful …

Nov 13, 2024
CVE-2024-8937
6.5 MEDIUM

CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a potential arbitrary code execution after a successful …

Nov 13, 2024
CVE-2024-8936
6.5 MEDIUM

CWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory after a successful Man-In-The-Middle attack followed by sending a …

Nov 13, 2024
CVE-2024-8935
7.5 HIGH

CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss of confidentiality and integrity of controllers when conducting a …

Nov 13, 2024
CVE-2024-21541
7.3 HIGH

Versions of the package dom-iterator before 1.0.1 are vulnerable to Arbitrary Code Execution due to use of the Function constructor without complete input sanitization. Function …

Nov 13, 2024
CVE-2024-21540

Rejected reason: This issue is not a vulnerability because no real attack scenario can happen.

Nov 13, 2024
CVE-2024-11150
9.8 CRITICAL

The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_tmp_uploaded_file() function in …

Nov 13, 2024
CVE-2024-10800
8.8 HIGH

The WordPress User Extra Fields plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the ajax_save_fields() function in all …

Nov 13, 2024
CVE-2024-10575
9.8 CRITICAL

CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connected devices.

Nov 13, 2024
CVE-2024-8933
7.5 HIGH

CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause retrieval of password hash that could lead to …

Nov 13, 2024
CVE-2024-10828
8.1 HIGH

The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.5 via deserialization …

Nov 13, 2024
CVE-2024-10820
9.8 CRITICAL

The WooCommerce Upload Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all …

Nov 13, 2024
CVE-2024-10816
7.5 HIGH

The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.24.01.24 via the js/fallback.php file. This …

Nov 13, 2024
CVE-2024-10802
5.3 MEDIUM

The Hash Elements plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hash_elements_get_posts_title_by_id() function in all …

Nov 13, 2024
CVE-2024-10794
4.3 MEDIUM

The Boostify Header Footer Builder for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.6 via the …

Nov 13, 2024
CVE-2024-10174
7.3 HIGH

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Insecure Direct …

Nov 13, 2024
CVE-2024-11143
4.3 MEDIUM

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.8. This is due …

Nov 13, 2024
CVE-2024-10882
6.1 MEDIUM

The Product Delivery Date for WooCommerce – Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg …

Nov 13, 2024
CVE-2024-10684
6.1 MEDIUM

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dir' parameter in all versions up to, and including, …

Nov 13, 2024
CVE-2024-10593
4.3 MEDIUM

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Cross-Site Request Forgery …

Nov 13, 2024
CVE-2024-10531
5.3 MEDIUM

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_assistant() function …

Nov 13, 2024
CVE-2024-10530
4.3 MEDIUM

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the add_new_assistant() function …

Nov 13, 2024
CVE-2024-10529
5.3 MEDIUM

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_assistant() function …

Nov 13, 2024
CVE-2024-9614
6.1 MEDIUM

The Constant Contact Forms by MailMunch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on …

Nov 13, 2024
CVE-2024-9578
5.3 MEDIUM

The Hide Links plugin for WordPress is vulnerable to unauthorized shortcode execution due to do_shortcode being hooked through the comment_text filter in all versions up …

Nov 13, 2024
CVE-2024-9426
6.4 MEDIUM

The Aqua SVG Sprite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.0.14 …

Nov 13, 2024
CVE-2024-8985
6.4 MEDIUM

The Social Proof (Testimonial) Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's spslider-block shortcode in all versions up to, and …

Nov 13, 2024
CVE-2024-8874
6.1 MEDIUM

The AJAX Login and Registration modal popup + inline form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg …

Nov 13, 2024
CVE-2024-39712
9.1 CRITICAL

Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin …

Nov 13, 2024
CVE-2024-39711
9.1 CRITICAL

Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin …

Nov 13, 2024
CVE-2024-39710
9.1 CRITICAL

Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin …

Nov 13, 2024
CVE-2024-39709
7.8 HIGH

Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1 (Not Applicable to 9.1Rx) …

Nov 13, 2024
CVE-2024-38656
9.1 CRITICAL

Argument injection in Ivanti Connect Secure before version 22.7R2.2 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin …

Nov 13, 2024
CVE-2024-38655
7.2 HIGH

Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.1 and 9.1R18.9 allows a remote authenticated attacker …

Nov 13, 2024
CVE-2024-38654
4.4 MEDIUM

Improper bounds checking in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker with admin privileges to cause a denial of service.

Nov 13, 2024
CVE-2024-38649
7.5 HIGH

An out-of-bounds write in IPsec of Ivanti Connect Secure before version 22.7R2.1(Not Applicable to 9.1Rx) allows a remote unauthenticated attacker to cause a denial of …

Nov 13, 2024
CVE-2024-37400
7.5 HIGH

An out of bounds read in Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to trigger an infinite loop, causing a denial …

Nov 13, 2024
CVE-2024-37398
7.8 HIGH

Insufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.

Nov 13, 2024
CVE-2024-37376
7.2 HIGH

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges …

Nov 13, 2024
CVE-2024-34787
7.8 HIGH

Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code …

Nov 13, 2024
CVE-2024-34784
7.2 HIGH

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges …

Nov 13, 2024
CVE-2024-34782
7.2 HIGH

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges …

Nov 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.