CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10410
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. Affected by this vulnerability is the function upload of the file …

Oct 27, 2024
CVE-2024-10409
6.3 MEDIUM

A vulnerability was found in code-projects Blood Bank Management 1.0 and classified as critical. This issue affects some unknown processing of the file /file/accept.php. The …

Oct 27, 2024
CVE-2024-10408
6.3 MEDIUM

A vulnerability has been found in code-projects Blood Bank Management up to 1.0 and classified as critical. This vulnerability affects unknown code of the file …

Oct 27, 2024
CVE-2024-10407
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Petrol Pump Management Software 1.0. This affects an unknown part of the file /admin/edit_customer.php. …

Oct 27, 2024
CVE-2024-10406
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0. Affected by this issue is some unknown functionality …

Oct 26, 2024
CVE-2020-26311
7.5 HIGH

Useragent is a user agent parser for Node.js. All versions as of time of publication contain one or more regular expressions that are vulnerable to …

Oct 26, 2024
CVE-2020-26310

Validate.js provides a declarative way of validating javascript objects. All versions as of 30 November 2020 contain one or more regular expressions that are vulnerable …

Oct 26, 2024
CVE-2020-26309

Validate.js provides a declarative way of validating javascript objects. Versions 0.11.3 and prior contain one or more regular expressions that are vulnerable to Regular Expression …

Oct 26, 2024
CVE-2020-26308
7.5 HIGH

Validate.js provides a declarative way of validating javascript objects. Versions 0.13.1 and prior contain one or more regular expressions that are vulnerable to Regular Expression …

Oct 26, 2024
CVE-2020-26307

HTML2Markdown is a Javascript implementation for converting HTML to Markdown text. All available versions contain one or more regular expressions that are vulnerable to Regular …

Oct 26, 2024
CVE-2020-26306

Knwl.js is a Javascript library that parses through text for dates, times, phone numbers, emails, places, and more. Versions 1.0.2 and prior contain one or …

Oct 26, 2024
CVE-2020-26305
7.5 HIGH

CommonRegexJS is a CommonRegex port for JavaScript. All available versions contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service …

Oct 26, 2024
CVE-2020-26304
7.5 HIGH

Foundation is a front-end framework. Versions 6.3.3 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). …

Oct 26, 2024
CVE-2020-26303
7.5 HIGH

insane is a whitelist-oriented HTML sanitizer. Versions 2.6.2 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service …

Oct 26, 2024
CVE-2024-9501
9.8 CRITICAL

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.0.7. This …

Oct 26, 2024
CVE-2024-10402
7.5 HIGH

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability …

Oct 26, 2024
CVE-2024-10117
6.4 MEDIUM

The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcf_donate shortcode in all versions up to, and including, 2.1.11 …

Oct 26, 2024
CVE-2024-9772
7.3 HIGH

The The Uix Shortcodes – Compatible with Gutenberg plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.9.9. …

Oct 26, 2024
CVE-2024-9116
6.4 MEDIUM

The Monkee-Boy Essentials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1 due …

Oct 26, 2024
CVE-2024-10357
4.3 MEDIUM

The Clever Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.1 via the getTemplateContent …

Oct 26, 2024
CVE-2024-9967
6.4 MEDIUM

The WP show more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's show_more shortcode in all versions up to, and including, …

Oct 26, 2024
CVE-2024-9853
6.4 MEDIUM

The ID-SK Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.7.2 due …

Oct 26, 2024
CVE-2024-9642
6.4 MEDIUM

The Editor Custom Color Palette plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Oct 26, 2024
CVE-2024-9637
8.8 HIGH

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.10. …

Oct 26, 2024
CVE-2024-8392
7.2 HIGH

The WordPress Post Grid Layouts with Pagination – Sogrid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, …

Oct 26, 2024
CVE-2024-0128
7.1 HIGH

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager that allows a user of the guest OS to access global resources. A successful …

Oct 26, 2024
CVE-2024-0127
7.8 HIGH

NVIDIA vGPU software contains a vulnerability in the GPU kernel driver of the vGPU Manager for all supported hypervisors, where a user of the guest …

Oct 26, 2024
CVE-2024-10092
4.3 MEDIUM

The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handle_api_key_actions function in all …

Oct 26, 2024
CVE-2024-0126
8.2 HIGH

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which could allow a privileged attacker to escalate permissions. A successful exploit of this …

Oct 26, 2024
CVE-2024-0121
7.8 HIGH

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A …

Oct 26, 2024
CVE-2024-0120
7.8 HIGH

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A …

Oct 26, 2024
CVE-2024-0119
7.8 HIGH

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A …

Oct 26, 2024
CVE-2024-0118
7.8 HIGH

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A …

Oct 26, 2024
CVE-2024-0117
7.8 HIGH

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A …

Oct 26, 2024
CVE-2024-9456
6.4 MEDIUM

The WP Awesome Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.4.0 …

Oct 26, 2024
CVE-2024-8870
6.1 MEDIUM

The Forms for Mailchimp by Optin Cat – Grow Your MailChimp List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use …

Oct 26, 2024
CVE-2024-9933
9.8 CRITICAL

The WatchTowerHQ plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.10.1. This is due to the 'watchtower_ota_token' default value …

Oct 26, 2024
CVE-2024-9932
9.8 CRITICAL

The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in versions …

Oct 26, 2024
CVE-2024-9931
9.8 CRITICAL

The Wux Blog Editor plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.0. This is due to missing validation …

Oct 26, 2024
CVE-2024-9930
9.8 CRITICAL

The Extensions by HocWP Team plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.2.3.2. This is due to missing …

Oct 26, 2024
CVE-2024-9890
8.8 HIGH

The User Toolkit plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.3. This is due to an improper capability …

Oct 26, 2024
CVE-2024-9626
4.3 MEDIUM

The Editorial Assistant by Sovrn plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_zemanta_set_featured_image' function …

Oct 26, 2024
CVE-2024-9613
6.1 MEDIUM

The FormFacade – WordPress plugin for Google Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'userId' and 'publishId' parameters in all …

Oct 26, 2024
CVE-2024-9475
4.9 MEDIUM

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to generic SQL Injection via the order_by parameter in all …

Oct 26, 2024
CVE-2024-9462
5.5 MEDIUM

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Stored Cross-Site Scripting via poll settings in all versions …

Oct 26, 2024
CVE-2024-9454
6.4 MEDIUM

The PriPre plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.4.11 due to …

Oct 26, 2024
CVE-2024-10091
6.4 MEDIUM

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Comparison Widget in all versions up to, and including, …

Oct 26, 2024
CVE-2024-47821
9.1 CRITICAL

pyLoad is a free and open-source Download Manager. The folder `/.pyload/scripts` has scripts which are run when certain actions are completed, for e.g. a download …

Oct 25, 2024
CVE-2024-48239
4.8 MEDIUM

An issue was discovered in WTCMS 1.0. In the plupload method in \AssetController.class.php, the app parameters aren't processed, resulting in Cross Site Scripting (XSS).

Oct 25, 2024
CVE-2024-48238
4.7 MEDIUM

WTCMS 1.0 is vulnerable to SQL Injection in the edit_post method of /Admin\Controller\NavControl.class.php via the parentid parameter.

Oct 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.