CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9224
6.5 MEDIUM

The Hello World plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 2.1.1 via the hello_world_lyric() function. This …

Oct 1, 2024
CVE-2024-9220
6.1 MEDIUM

The LH Copy Media File plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …

Oct 1, 2024
CVE-2024-9209
6.1 MEDIUM

The WP Search Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Oct 1, 2024
CVE-2024-9018
8.8 HIGH

The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘key’ parameter in all versions up …

Oct 1, 2024
CVE-2024-8799
6.1 MEDIUM

The Custom Banners plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in …

Oct 1, 2024
CVE-2024-8793
6.1 MEDIUM

The Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to …

Oct 1, 2024
CVE-2024-8786
6.1 MEDIUM

The Auto Featured Image from Title plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on …

Oct 1, 2024
CVE-2024-8430
5.3 MEDIUM

The Spice Starter Sites plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the spice_starter_sites_importer_creater function in …

Oct 1, 2024
CVE-2024-8324
6.4 MEDIUM

The XO Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘get_slider’ function in all versions up to, and including, 3.8.6 due …

Oct 1, 2024
CVE-2024-8288
6.4 MEDIUM

The Guten Post Layout – An Advanced Post Grid Collection for WordPress Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ …

Oct 1, 2024
CVE-2024-9304
6.4 MEDIUM

The LocateAndFilter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.14 due to …

Oct 1, 2024
CVE-2024-9274
6.4 MEDIUM

The Elastik Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.27.4 …

Oct 1, 2024
CVE-2024-9272
6.4 MEDIUM

The R Animated Icon Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Oct 1, 2024
CVE-2024-9269
6.4 MEDIUM

The Relogo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.4.2 due to …

Oct 1, 2024
CVE-2024-9267
6.1 MEDIUM

The Easy WordPress Subscribe – Optin Hound plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping …

Oct 1, 2024
CVE-2024-9145

Wiz Code Visual Studio Code extension in versions 1.0.0 up to 1.5.3 and Wiz (legacy) Visual Studio Code extension in versions 0.13.0 up to 0.17.8 …

Oct 1, 2024
CVE-2024-9119
6.4 MEDIUM

The SVG Complete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.2 due …

Oct 1, 2024
CVE-2024-9108
9.8 CRITICAL

The Wechat Social login plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'convert_remoteimage_to_local' function in versions …

Oct 1, 2024
CVE-2024-9106
9.8 CRITICAL

The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.3.0. This is due to insufficient verification …

Oct 1, 2024
CVE-2024-8990
6.4 MEDIUM

The Geo Mashup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's geo_mashup_visible_posts_list shortcode in all versions up to, and including, 1.13.13 …

Oct 1, 2024
CVE-2024-8989
6.4 MEDIUM

The Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's …

Oct 1, 2024
CVE-2024-8728
6.1 MEDIUM

The Easy Load More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Oct 1, 2024
CVE-2024-8727
6.1 MEDIUM

The DK PDF plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in …

Oct 1, 2024
CVE-2024-8720
6.4 MEDIUM

The RumbleTalk Live Group Chat – HTML5 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rumbletalk-admin-button' shortcode in all versions up …

Oct 1, 2024
CVE-2024-8718
6.1 MEDIUM

The Gravity Forms Toolbar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 1.7.0 …

Oct 1, 2024
CVE-2024-8675
4.3 MEDIUM

The Soumettre.fr plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the soumettre_disconnect_gateway function in all versions …

Oct 1, 2024
CVE-2024-8632
6.5 MEDIUM

The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized access and modification of data due to a …

Oct 1, 2024
CVE-2024-8548
8.1 HIGH

The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a …

Oct 1, 2024
CVE-2024-7869
7.2 HIGH

The 123.chat - Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.1 due to insufficient …

Oct 1, 2024
CVE-2024-7434
8.8 HIGH

The UltraPress theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.2 via deserialization of untrusted input. This …

Oct 1, 2024
CVE-2024-7433
8.8 HIGH

The Empowerment theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.2 via deserialization of untrusted input. This …

Oct 1, 2024
CVE-2024-7432
8.8 HIGH

The Unseen Blog theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 via deserialization of untrusted input. …

Oct 1, 2024
CVE-2024-8107
6.4 MEDIUM

The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7.18 due …

Oct 1, 2024
CVE-2024-8421

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.

Oct 1, 2024
CVE-2024-21531
5.3 MEDIUM

All versions of the package git-shallow-clone are vulnerable to Command injection due to missing sanitization or mitigation flags in the process variable of the gitShallowClone …

Oct 1, 2024
CVE-2024-21489
8.2 HIGH

Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to missing check if the attribute resolves to …

Oct 1, 2024
CVE-2024-0116
4.9 MEDIUM

NVIDIA Triton Inference Server contains a vulnerability where a user may cause an out-of-bounds read issue by releasing a shared memory region while it is …

Oct 1, 2024
CVE-2024-47295
8.1 HIGH

Insecure initial password configuration issue in SEIKO EPSON Web Config allows a remote unauthenticated attacker to set an arbitrary password and operate the device with …

Oct 1, 2024
CVE-2024-9360
7.3 HIGH

A vulnerability was found in code-projects Restaurant Reservation System 1.0. It has been classified as critical. This affects an unknown part of the file /updatebal.php. …

Oct 1, 2024
CVE-2024-8981
7.1 HIGH

The Broken Link Checker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg in /app/admin-notices/features/class-view.php without appropriate escaping on …

Oct 1, 2024
CVE-2024-9359
7.3 HIGH

A vulnerability was found in code-projects Restaurant Reservation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Oct 1, 2024
CVE-2024-9358
5.3 MEDIUM

A vulnerability has been found in ThingsBoard up to 3.7.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component …

Oct 1, 2024
CVE-2024-47560
7.8 HIGH

RevoWorks Cloud Client 3.0.91 and earlier contains an incorrect authorization vulnerability. If this vulnerability is exploited, unintended processes may be executed in the sandbox environment. …

Oct 1, 2024
CVE-2024-47396
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moveaddons Move Addons for Elementor move-addons allows Stored XSS.This issue affects Move Addons …

Oct 1, 2024
CVE-2024-9194
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Linux and Microsoft Windows Octopus Server on Windows, Linux allows SQL …

Sep 30, 2024
CVE-2024-45073
4.8 MEDIUM

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in …

Sep 30, 2024
CVE-2024-7675
7.8 HIGH

A maliciously crafted DWF file, when parsed in w3dtk.dll through Autodesk Navisworks, can force a Use-After-Free. A malicious actor can leverage this vulnerability to cause …

Sep 30, 2024
CVE-2024-7674
7.8 HIGH

A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, can force a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability …

Sep 30, 2024
CVE-2024-7673
7.8 HIGH

A maliciously crafted DWFX file, when parsed in w3dtk.dll through Autodesk Navisworks, can force a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability …

Sep 30, 2024
CVE-2024-7672
7.8 HIGH

A maliciously crafted DWF file, when parsed in dwfcore.dll through Autodesk Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this …

Sep 30, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.