CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5965
6.4 MEDIUM

The Mosaic theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter within the theme's Button shortcode in all versions up to, …

Jun 22, 2024
CVE-2024-5791
7.2 HIGH

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp_id' parameter in all …

Jun 22, 2024
CVE-2024-5346
6.4 MEDIUM

The Flatsome theme for WordPress is vulnerable to Stored Cross-Site Scripting via the UX Countdown, Video Button, UX Video, UX Slider, UX Sidebar, and UX …

Jun 22, 2024
CVE-2024-4313
6.4 MEDIUM

The Table Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, …

Jun 22, 2024
CVE-2024-2484
6.4 MEDIUM

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Services and Post Type Grid widgets in all versions …

Jun 22, 2024
CVE-2024-6120
6.5 MEDIUM

The Sparkle Demo Importer plugin for WordPress is vulnerable to unauthorized database reset and demo data import due to a missing capability check on the …

Jun 22, 2024
CVE-2024-37694

Rejected reason: This submission has been rejected by the CNA of record. Authentication is user configurable as described in our documentation. https://enterprise.arcgis.com/en/server/latest/administer/windows/configuring-arcgis-server-security.htm

Jun 21, 2024
CVE-2024-37654
6.1 MEDIUM

An issue in BAS-IP AV-01D, AV-01MD, AV-01MFD, AV-01ED, AV-01KD, AV-01BD, AV-01KBD, AV-02D, AV-02IDE, AV-02IDR, AV-02IPD, AV-02FDE, AV-02FDR, AV-03D, AV-03BD, AV-04AFD, AV-04ASD, AV-04FD, AV-04SD, AV-05FD, AV-05SD, …

Jun 21, 2024
CVE-2024-36532
10.0 CRITICAL

Insecure permissions in kruise v1.6.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Jun 21, 2024
CVE-2024-34989
9.8 CRITICAL

In the module RSI PDF/HTML catalog evolution (prestapdf) <= 7.0.0 from RSI for PrestaShop, a guest can perform SQL injection via `PrestaPDFProductListModuleFrontController::queryDb().'

Jun 21, 2024
CVE-2024-34452
6.1 MEDIUM

CMSimple_XH 1.7.6 allows XSS by uploading a crafted SVG document.

Jun 21, 2024
CVE-2022-42974
4.8 MEDIUM

In Kostal PIKO 1.5-1 MP plus HMI OEM p 1.0.1, the web application for the Solar Panel is vulnerable to a Stored Cross-Site Scripting (XSS) …

Jun 21, 2024
CVE-2014-5470
9.8 CRITICAL

Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for part of the input data passed to an eval …

Jun 21, 2024
CVE-2012-6664
9.1 CRITICAL

Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remote attackers to read or write arbitrary files via …

Jun 21, 2024
CVE-2023-45673
8.9 HIGH

Joplin is a free, open source note taking and to-do application. A remote code execution (RCE) vulnerability in affected versions allows clicking on a link …

Jun 21, 2024
CVE-2023-39517
8.2 HIGH

Joplin is a free, open source note taking and to-do application. A Cross site scripting (XSS) vulnerability in affected versions allows clicking on an untrusted …

Jun 21, 2024
CVE-2023-38506
8.2 HIGH

Joplin is a free, open source note taking and to-do application. A Cross-site Scripting (XSS) vulnerability allows pasting untrusted data into the rich text editor …

Jun 21, 2024
CVE-2023-37898
8.2 HIGH

Joplin is a free, open source note taking and to-do application. A Cross-site Scripting (XSS) vulnerability allows an untrusted note opened in safe mode to …

Jun 21, 2024
CVE-2020-27352
9.3 CRITICAL

When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will …

Jun 21, 2024
CVE-2024-6241
6.3 MEDIUM

A vulnerability was found in Pear Admin Boot up to 2.0.2 and classified as critical. This issue affects the function getDictItems of the file /system/dictData/getDictItems/. …

Jun 21, 2024
CVE-2024-37675
5.4 MEDIUM

Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the parameter "sectionContent" related to …

Jun 21, 2024
CVE-2024-37673
5.4 MEDIUM

Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the filename parameter.

Jun 21, 2024
CVE-2024-37672
5.4 MEDIUM

Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the idactivity parameter.

Jun 21, 2024
CVE-2024-37671
5.4 MEDIUM

Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the page parameter.

Jun 21, 2024
CVE-2024-35537
7.5 HIGH

TVS Motor Company Limited TVS Connect Android v4.6.0 and IOS v5.0.0 was discovered to insecurely handle the RSA key pair, allowing attackers to possibly access …

Jun 21, 2024
CVE-2024-37790

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not …

Jun 21, 2024
CVE-2024-35781
6.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in YAHMAN Word Balloon allows PHP Local File Inclusion.This issue affects Word Balloon: …

Jun 21, 2024
CVE-2024-35778
6.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in John West Slideshow SE PHP Local File Inclusion.This issue affects Slideshow SE: …

Jun 21, 2024
CVE-2024-35767
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Bogdan Bendziukov Squeeze allows Code Injection.This issue affects Squeeze: from n/a through 1.4.

Jun 21, 2024
CVE-2023-38389
9.8 CRITICAL

Incorrect Authorization vulnerability in Artbees JupiterX Core allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JupiterX Core: from n/a through 3.3.8.

Jun 21, 2024
CVE-2022-44593
3.7 LOW

Use of Less Trusted Source vulnerability in SolidWP Solid Security allows HTTP DoS.This issue affects Solid Security: from n/a through 9.3.1.

Jun 21, 2024
CVE-2022-44587
5.3 MEDIUM

Insertion of Sensitive Information into Log File vulnerability in WP 2FA allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP 2FA: from n/a …

Jun 21, 2024
CVE-2022-38055
4.3 MEDIUM

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpForo Forum allows Content Spoofing.This issue affects wpForo Forum: …

Jun 21, 2024
CVE-2023-45197
9.8 CRITICAL

The file upload plugin in Adminer and AdminerEvo allows an attacker to upload a file with a table name of “..” to the root of …

Jun 21, 2024
CVE-2024-6240
7.7 HIGH

Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate …

Jun 21, 2024
CVE-2024-6239
7.5 HIGH

A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, …

Jun 21, 2024
CVE-2024-37230
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Book Landing Page.This issue affects Book Landing Page: from n/a through 1.2.3.

Jun 21, 2024
CVE-2024-37227
4.3 MEDIUM

Cross Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.7.

Jun 21, 2024
CVE-2024-37212
8.3 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Ali2Woo Ali2Woo Lite.This issue affects Ali2Woo Lite: from n/a through 3.3.5.

Jun 21, 2024
CVE-2024-37198
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in blazethemes Digital Newspaper.This issue affects Digital Newspaper: from n/a through 1.1.5.

Jun 21, 2024
CVE-2024-37118
5.4 MEDIUM

Cross Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Automator Pro.This issue affects Uncanny Automator Pro: from n/a through 5.3.

Jun 21, 2024
CVE-2023-51375
4.3 MEDIUM

Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.8.3.

Jun 21, 2024
CVE-2022-45803
6.5 MEDIUM

Missing Authorization vulnerability in Nikolay Strikhar WordPress Form Builder Plugin – Gutenberg Forms.This issue affects WordPress Form Builder Plugin – Gutenberg Forms: from n/a through …

Jun 21, 2024
CVE-2022-43453
8.8 HIGH

Missing Authorization vulnerability in Bill Minozzi WP Tools.This issue affects WP Tools: from n/a through 3.41.

Jun 21, 2024
CVE-2024-5059
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A WP Life Event Management Tickets Booking.This issue affects Event Management Tickets Booking: from n/a …

Jun 21, 2024
CVE-2024-35776
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exeebit phpinfo() WP.This issue affects phpinfo() WP: from n/a through 5.0.

Jun 21, 2024
CVE-2024-35772
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in presscustomizr Hueman.This issue affects Hueman: from n/a through 3.7.24.

Jun 21, 2024
CVE-2024-35771
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in presscustomizr Customizr.This issue affects Customizr: from n/a through 4.4.21.

Jun 21, 2024
CVE-2024-35770
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Dave Kiss Vimeography: Vimeo Video Gallery WordPress Plugin.This issue affects Vimeography: Vimeo Video Gallery WordPress Plugin: from n/a through …

Jun 21, 2024
CVE-2024-35768
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiveComposer Page Builder: Live Composer live-composer-page-builder allows DOM-Based XSS.This issue affects Page Builder: …

Jun 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.