CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6735
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file setgeneral.php. …

Jul 15, 2024
CVE-2024-6734
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been classified as critical. This affects an unknown part of the file templateadd.php. …

Jul 15, 2024
CVE-2024-6733
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jul 14, 2024
CVE-2024-6732
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Student Study Center Desk Management System 1.0. This vulnerability affects unknown code of the file /sscdms/classes/Users.php?f=save. …

Jul 14, 2024
CVE-2024-6731
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Student Study Center Desk Management System 1.0. This affects an unknown part of the file …

Jul 14, 2024
CVE-2024-39734
4.3 MEDIUM

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able …

Jul 14, 2024
CVE-2024-39733
5.5 MEDIUM

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 stores user credentials in plain clear text which can be read by a local user. IBM …

Jul 14, 2024
CVE-2024-39732
4.1 MEDIUM

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 temporarily stores data from different environments that could be obtained by a malicious user. IBM X-Force …

Jul 14, 2024
CVE-2023-52885
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix UAF in svc_tcp_listen_data_ready() After the listener svc_sock is freed, and before invoking svc_tcp_accept() …

Jul 14, 2024
CVE-2024-6730
6.3 MEDIUM

A vulnerability was found in Nanjing Xingyuantu Technology SparkShop up to 1.1.6. It has been rated as critical. This issue affects some unknown processing of …

Jul 14, 2024
CVE-2024-6729
6.3 MEDIUM

A vulnerability was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of …

Jul 14, 2024
CVE-2024-6728
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been classified as critical. This affects an unknown part of the file typeedit.php. …

Jul 14, 2024
CVE-2024-6465
4.3 MEDIUM

The WP Links Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wplf_ajax_update_screenshots' function in …

Jul 13, 2024
CVE-2024-6574
5.3 MEDIUM

The Laposta plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.12. This is due to the plugin …

Jul 13, 2024
CVE-2024-6070
4.8 MEDIUM

The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jul 13, 2024
CVE-2024-5744
6.8 MEDIUM

The wp-eMember WordPress plugin before 10.6.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site …

Jul 13, 2024
CVE-2024-5715
7.1 HIGH

The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jul 13, 2024
CVE-2024-5713
5.4 MEDIUM

The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.4 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead …

Jul 13, 2024
CVE-2024-5644
5.4 MEDIUM

The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jul 13, 2024
CVE-2024-5627
5.4 MEDIUM

The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some parameters, which could allow users with a role as low as subscriber to …

Jul 13, 2024
CVE-2024-5575
4.7 MEDIUM

The Ditty WordPress plugin before 3.1.43 does not sanitise and escape some of its blocks' settings, which could allow high privilege users such as authors …

Jul 13, 2024
CVE-2024-5472
7.1 HIGH

The WP QuickLaTeX WordPress plugin before 3.8.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jul 13, 2024
CVE-2024-5450
9.1 CRITICAL

The Bug Library WordPress plugin before 2.1.1 does not check the file type on user-submitted bug reports, allowing an unauthenticated user to upload PHP files

Jul 13, 2024
CVE-2024-5442
5.9 MEDIUM

The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.3 does not sanitise and escape some of its settings, which could allow high privilege users …

Jul 13, 2024
CVE-2024-5287
7.1 HIGH

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged …

Jul 13, 2024
CVE-2024-5286
4.8 MEDIUM

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jul 13, 2024
CVE-2024-5284
6.8 MEDIUM

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Jul 13, 2024
CVE-2024-5283
6.1 MEDIUM

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jul 13, 2024
CVE-2024-5282
6.1 MEDIUM

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jul 13, 2024
CVE-2024-5281
6.1 MEDIUM

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jul 13, 2024
CVE-2024-5280
4.7 MEDIUM

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Jul 13, 2024
CVE-2024-5167
8.1 HIGH

The CM Email Registration Blacklist and Whitelist WordPress plugin before 1.4.9 does not have CSRF check when adding or deleting an item from the blacklist …

Jul 13, 2024
CVE-2024-5151
7.1 HIGH

The SULly WordPress plugin before 4.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jul 13, 2024
CVE-2024-5080
8.8 HIGH

The wp-eMember WordPress plugin before 10.6.6 does not validate files to be uploaded, which could allow admins to upload arbitrary files such as PHP on …

Jul 13, 2024
CVE-2024-5079
6.1 MEDIUM

The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape some of the fields when members register, which allows unauthenticated users to perform Stored …

Jul 13, 2024
CVE-2024-5077
6.8 MEDIUM

The wp-eMember WordPress plugin before 10.6.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Jul 13, 2024
CVE-2024-5076
8.8 HIGH

The wp-eMember WordPress plugin before 10.6.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted …

Jul 13, 2024
CVE-2024-5075
5.9 MEDIUM

The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jul 13, 2024
CVE-2024-5074
5.4 MEDIUM

The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jul 13, 2024
CVE-2024-5034
8.8 HIGH

The SULly WordPress plugin before 4.3.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted …

Jul 13, 2024
CVE-2024-5033
5.9 MEDIUM

The SULly WordPress plugin before 4.3.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Jul 13, 2024
CVE-2024-5032
4.7 MEDIUM

The SULly WordPress plugin before 4.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jul 13, 2024
CVE-2024-5028
6.5 MEDIUM

The CM WordPress Search And Replace Plugin WordPress plugin before 1.3.9 does not have CSRF checks in some places, which could allow attackers to make …

Jul 13, 2024
CVE-2024-5002
4.8 MEDIUM

The User Submitted Posts WordPress plugin before 20240516 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jul 13, 2024
CVE-2024-4977
6.8 MEDIUM

The Index WP MySQL For Speed WordPress plugin before 1.4.18 does not sanitise and escape a parameter before outputting it back in the page, leading …

Jul 13, 2024
CVE-2024-4752
5.9 MEDIUM

The EventON WordPress plugin before 2.2.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jul 13, 2024
CVE-2024-4602
5.4 MEDIUM

The Embed Peertube Playlist WordPress plugin before 1.10 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jul 13, 2024
CVE-2024-4272
6.1 MEDIUM

The Support SVG WordPress plugin before 1.1.0 does not sanitize SVG file contents, which enables users with at least the author role to SVG with …

Jul 13, 2024
CVE-2024-4269
6.1 MEDIUM

The SVG Block WordPress plugin before 1.1.20 does not sanitize SVG file contents, which enables users with at least the author role to SVG with …

Jul 13, 2024
CVE-2024-4217
4.7 MEDIUM

The shortcodes-ultimate-pro WordPress plugin before 7.1.5 does not properly escape some of its shortcodes' settings, making it possible for attackers with a Contributor account to …

Jul 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.