CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-4972
7.5 HIGH

The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in …

Oct 16, 2024
CVE-2022-4971
6.1 MEDIUM

The Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'urls' parameter called via the 'heateor_sss_sharing_count' AJAX action in versions …

Oct 16, 2024
CVE-2021-4451
6.6 MEDIUM

The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and including, 4.3.3. This allows authenticated attackers to perform phar …

Oct 16, 2024
CVE-2021-4450
8.8 HIGH

The Post Grid plugin for WordPress is vulnerable to blind SQL Injection via post metadata in versions up to, and including, 2.1.12 due to insufficient …

Oct 16, 2024
CVE-2021-4449
9.8 CRITICAL

The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'savepng.php' file in versions up to, …

Oct 16, 2024
CVE-2021-4448
7.3 HIGH

The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.0.1 due to insufficient capability checking …

Oct 16, 2024
CVE-2021-4447
8.8 HIGH

The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of …

Oct 16, 2024
CVE-2021-4446
6.3 MEDIUM

The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and including 4.6.4 due to missing capability checks …

Oct 16, 2024
CVE-2021-4445
6.5 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to Arbitrary Option Updates in versions up to, and including, 4.5.1. This is due to …

Oct 16, 2024
CVE-2021-4444
7.3 HIGH

The Product Filter by WooBeWoo plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.4.9 due to missing authorization checks …

Oct 16, 2024
CVE-2021-4443
9.8 CRITICAL

The WordPress Mega Menu plugin for WordPress is vulnerable to Arbitrary File Creation in versions up to, and including, 2.0.6 via the compiler_save AJAX action. …

Oct 16, 2024
CVE-2020-36839
8.3 HIGH

The WP Lead Plus X plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.99. This is due to …

Oct 16, 2024
CVE-2020-36838
7.4 HIGH

The Facebook Chat Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_update_options function in versions up to, …

Oct 16, 2024
CVE-2020-36837
9.9 CRITICAL

The ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability check on the reset_wizard_actions function in versions 1.3.4 …

Oct 16, 2024
CVE-2020-36836
8.0 HIGH

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and including, 0.9.0.2 due to a lack …

Oct 16, 2024
CVE-2020-36835
4.9 MEDIUM

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks …

Oct 16, 2024
CVE-2020-36834
6.3 MEDIUM

The Discount Rules for WooCommerce plugin for WordPress is vulnerable to missing authorization via several AJAX actions in versions up to, and including, 2.0.2 due …

Oct 16, 2024
CVE-2020-36833
6.3 MEDIUM

The Indeed Membership Pro plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various AJAX actions in versions 7.3 - …

Oct 16, 2024
CVE-2020-36832
9.8 CRITICAL

The Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and including, 7.3 to 8.6. This makes it possible for …

Oct 16, 2024
CVE-2020-36831
5.0 MEDIUM

The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple user privilege/security functions provided in …

Oct 16, 2024
CVE-2019-25217
9.8 CRITICAL

The SiteGround Optimizer plugin for WordPress is vulnerable to authorization bypass leading to Remote Code Execution and Local File Inclusion in versions up to, and …

Oct 16, 2024
CVE-2019-25216
7.2 HIGH

The Rich Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the POST body 'update' parameter in versions up to, and including, 1.7.4 …

Oct 16, 2024
CVE-2019-25215
7.3 HIGH

The ARI-Adminer plugin for WordPress is vulnerable to authorization bypass due to a lack of file access controls in nearly every file of the plugin …

Oct 16, 2024
CVE-2019-25214
7.2 HIGH

The ShopWP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST API routes in versions up to, …

Oct 16, 2024
CVE-2019-25213
9.8 CRITICAL

The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation …

Oct 16, 2024
CVE-2018-25105
9.8 CRITICAL

The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions up to, …

Oct 16, 2024
CVE-2017-20192
8.3 HIGH

The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before …

Oct 16, 2024
CVE-2016-15041
7.2 HIGH

The MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mwp_setup_purchase_username’ parameter …

Oct 16, 2024
CVE-2016-15040
9.8 CRITICAL

The Kento Post View Counter plugin for WordPress is vulnerable to SQL Injection via the 'kento_pvc_geo' parameter in versions up to, and including, 2.8 due …

Oct 16, 2024
CVE-2012-10018
8.3 HIGH

The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and including 6.1, 1.0 respectively. This makes …

Oct 16, 2024
CVE-2024-9937
6.1 MEDIUM

The Woo Manage Fraud Orders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, …

Oct 16, 2024
CVE-2024-9888
5.4 MEDIUM

The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's contact form widget redirect URL in all versions …

Oct 16, 2024
CVE-2024-9873
5.4 MEDIUM

The Community by PeepSo – Social Network, Membership, Registration, User Profiles, Premium – Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Oct 16, 2024
CVE-2024-10018
9.8 CRITICAL

Improper permission control in the mobile application (com.transsion.aivoiceassistant) can lead to the launch of any unexported component.

Oct 16, 2024
CVE-2024-9891
4.3 MEDIUM

The Multiline files upload for contact form 7 plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the …

Oct 16, 2024
CVE-2024-9652
6.1 MEDIUM

The Locatoraid Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST keys in all versions up to, and including, 3.9.47 due …

Oct 16, 2024
CVE-2024-9649
4.3 MEDIUM

The WP ULike – The Ultimate Engagement Toolkit for Websites plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

Oct 16, 2024
CVE-2024-9647
6.1 MEDIUM

The Kama SpamBlock plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST values in all versions up to, and including, 1.8.2 due to …

Oct 16, 2024
CVE-2024-9634
9.8 CRITICAL

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.3 …

Oct 16, 2024
CVE-2024-9521
6.4 MEDIUM

The SEO Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post meta in versions up to, and including, 1.9 due to insufficient …

Oct 16, 2024
CVE-2024-9305
8.1 HIGH

The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.4. …

Oct 16, 2024
CVE-2024-9105
9.8 CRITICAL

The UltimateAI plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.8.3. This is due to insufficient verification on the …

Oct 16, 2024
CVE-2024-9104
5.6 MEDIUM

The UltimateAI plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.8.3. This is due to the improper empty …

Oct 16, 2024
CVE-2024-8787
6.1 MEDIUM

The Smart Online Order for Clover plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate …

Oct 16, 2024
CVE-2024-8541
4.7 MEDIUM

The Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting …

Oct 16, 2024
CVE-2024-49340
4.3 MEDIUM

IBM Watson Studio Local 1.2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a …

Oct 16, 2024
CVE-2024-38204
7.5 HIGH

Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network.

Oct 15, 2024
CVE-2024-38190
8.6 HIGH

Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector.

Oct 15, 2024
CVE-2024-38139
8.7 HIGH

Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.

Oct 15, 2024
CVE-2024-45085
5.9 MEDIUM

IBM WebSphere Application Server 8.5 is vulnerable to a denial of service, under certain configurations, caused by an unexpected specially crafted request. A remote attacker …

Oct 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.