CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-32193
8.3 HIGH

A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in Norman's public API endpoint can be exploited. This can lead to an attacker …

Oct 16, 2024
CVE-2023-32192
8.3 HIGH

A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in the API Server's public API endpoint can be exploited, allowing an attacker to …

Oct 16, 2024
CVE-2023-32191
9.9 CRITICAL

When RKE provisions a cluster, it stores the cluster state in a configmap called `full-cluster-state` inside the `kube-system` namespace of the cluster itself. The information …

Oct 16, 2024
CVE-2020-36841
5.3 MEDIUM

The WooCommerce Smart Coupons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the woocommerce_coupon_admin_init function in versions up …

Oct 16, 2024
CVE-2024-8040
7.7 HIGH

An authorization bypass through user-controlled key vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an authenticated attacker to access some unauthorized data.

Oct 16, 2024
CVE-2024-6380
8.7 HIGH

A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary …

Oct 16, 2024
CVE-2024-10022
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. This affects an unknown part of the file /php/manage_supplier.php?action=search. The manipulation …

Oct 16, 2024
CVE-2024-10021
6.3 MEDIUM

A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Oct 16, 2024
CVE-2023-32190
7.8 HIGH

mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.

Oct 16, 2024
CVE-2024-8921
6.4 MEDIUM

The Zita Elementor Site Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Oct 16, 2024
CVE-2024-9444
6.4 MEDIUM

The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Oct 16, 2024
CVE-2024-9858
7.8 HIGH

There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windows installs. A local "m2cuser" was greated …

Oct 16, 2024
CVE-2023-32188

A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to …

Oct 16, 2024
CVE-2023-22650
8.8 HIGH

A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from the configured authentication provider (AP). …

Oct 16, 2024
CVE-2024-9540
4.3 MEDIUM

The Sina Extension for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.7 via the render …

Oct 16, 2024
CVE-2024-9061
7.3 HIGH

The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary shortcode execution via the wp_ajax_nopriv_shortcode_Api_Add AJAX …

Oct 16, 2024
CVE-2024-45715
7.1 HIGH

The SolarWinds Platform was susceptible to a Cross-Site Scripting vulnerability when performing an edit function to existing elements.

Oct 16, 2024
CVE-2024-45714
4.8 MEDIUM

Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a variable with a payload.

Oct 16, 2024
CVE-2024-45711
7.5 HIGH

SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible depending on privileges given to the authenticated user. This issue …

Oct 16, 2024
CVE-2024-45710
7.8 HIGH

SolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This requires a low privilege account and local access to the …

Oct 16, 2024
CVE-2024-45693
8.0 HIGH

Users logged into the Apache CloudStack's web interface can be tricked to submit malicious CSRF requests due to missing validation of the origin of the …

Oct 16, 2024
CVE-2024-45462
6.3 MEDIUM

The logout operation in the CloudStack web interface does not expire the user session completely which is valid until expiry by time or restart of …

Oct 16, 2024
CVE-2024-45461
5.7 MEDIUM

The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources, and is disabled by default. In environments …

Oct 16, 2024
CVE-2024-45219
8.5 HIGH

Account users in Apache CloudStack by default are allowed to upload and register templates for deploying instances and volumes for attaching them as data disks …

Oct 16, 2024
CVE-2024-45217
8.1 HIGH

Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore command, which copy a configSet from the backup …

Oct 16, 2024
CVE-2024-45216
9.8 CRITICAL

Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authentication is used, are vulnerable to Authentication …

Oct 16, 2024
CVE-2023-7296
6.4 MEDIUM

The BigBlueButton plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the moderator code and viewer code fields in versions up to, and …

Oct 16, 2024
CVE-2023-7295
6.1 MEDIUM

The Video Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.21 due to …

Oct 16, 2024
CVE-2023-22649
8.4 HIGH

A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. [Rancher Audit Logging](https://ranchermanager.docs.rancher.com/how-to-guides/advanced-user-guides/enable-api-audit-log) is an opt-in feature, only …

Oct 16, 2024
CVE-2021-4452
7.1 HIGH

The Google Language Translator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions up to, and including, 6.0.9 due to …

Oct 16, 2024
CVE-2020-36842
8.8 HIGH

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvivid_upload_import_files and …

Oct 16, 2024
CVE-2020-36840
7.3 HIGH

The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_route_url() function …

Oct 16, 2024
CVE-2017-20194
5.3 MEDIUM

The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. …

Oct 16, 2024
CVE-2017-20193
4.7 MEDIUM

The Product Vendors is vulnerable to Reflected Cross-Site Scripting via the 'vendor_description' parameter in versions up to, and including, 2.0.35 due to insufficient input sanitization …

Oct 16, 2024
CVE-2016-15042
9.8 CRITICAL

The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to …

Oct 16, 2024
CVE-2024-9582
6.4 MEDIUM

The Accordion Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ attribute of an accordion slider in all versions up to, …

Oct 16, 2024
CVE-2024-8918
7.4 HIGH

The File Manager Pro plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 8.3.9. This is due …

Oct 16, 2024
CVE-2024-8746
7.5 HIGH

The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing file type validation via the 'mk_file_folder_manager_shortcode' …

Oct 16, 2024
CVE-2024-8507
8.8 HIGH

The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.3.9. This is due to …

Oct 16, 2024
CVE-2023-7294
7.1 HIGH

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the create_mollie_profile …

Oct 16, 2024
CVE-2023-7293
4.3 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the …

Oct 16, 2024
CVE-2023-7292
4.3 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized notification dismissal due to a missing capability check on the paytium_notice_dismiss …

Oct 16, 2024
CVE-2023-7291
7.1 HIGH

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Oct 16, 2024
CVE-2023-7290
4.3 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the …

Oct 16, 2024
CVE-2023-7289
5.4 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized API key update due to a missing capability check on the …

Oct 16, 2024
CVE-2023-7288
5.4 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_profile_preference …

Oct 16, 2024
CVE-2023-7287
5.4 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized subscription cancellation due to a missing capability check on the pt_cancel_subscription …

Oct 16, 2024
CVE-2023-7286
6.5 MEDIUM

The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.2.2. This makes it …

Oct 16, 2024
CVE-2022-4974
6.3 MEDIUM

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing …

Oct 16, 2024
CVE-2022-4973
4.9 MEDIUM

WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploited by users with access to the WordPress …

Oct 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.