CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-36270
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: tproxy: bail out if IP has been disabled on the device syzbot reports: general …

Jun 21, 2024
CVE-2024-36244
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/sched: taprio: extend minimum interval restriction to entire cycle too It is possible for syzbot …

Jun 21, 2024
CVE-2024-33621
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipvlan: Dont Use skb->sk in ipvlan_process_v{4,6}_outbound Raw packet from PF_PACKET socket ontop of an IPv6-backed …

Jun 21, 2024
CVE-2024-33619
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: efi: libstub: only free priv.runtime_map when allocated priv.runtime_map is only allocated when efi_novamap is not …

Jun 21, 2024
CVE-2024-31076
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: genirq/cpuhotplug, x86/vector: Prevent vector leak during CPU offline The absence of IRQD_MOVE_PCNTXT prevents immediate effectiveness …

Jun 21, 2024
CVE-2023-52884
4.4 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Input: cyapa - add missing input core locking to suspend/resume functions Grab input->mutex during suspend/resume …

Jun 21, 2024
CVE-2024-6027
9.8 CRITICAL

The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to time-based SQL Injection via the ‘conditions’ parameter in all versions up to, and …

Jun 21, 2024
CVE-2024-31890
7.8 HIGH

IBM i 7.3, 7.4, and 7.5 product IBM TCP/IP Connectivity Utilities for i contains a local privilege escalation vulnerability. A malicious actor with command line …

Jun 21, 2024
CVE-2024-5859
6.1 MEDIUM

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘d’ parameter in all …

Jun 21, 2024
CVE-2024-6225
4.4 MEDIUM

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up …

Jun 21, 2024
CVE-2024-5945
6.4 MEDIUM

The WP SVG Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘type’ parameter in all versions up to, and including, 4.3 …

Jun 21, 2024
CVE-2024-2003
7.3 HIGH

Local privilege escalation vulnerability allowed an attacker to misuse ESET's file operations during a restore operation from quarantine.

Jun 21, 2024
CVE-2024-5639
4.3 MEDIUM

The User Profile Picture plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.1 via the 'rest_api_change_profile_image' …

Jun 21, 2024
CVE-2024-5191
6.4 MEDIUM

The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mime_types’ parameter in all …

Jun 21, 2024
CVE-2024-38874
5.4 MEDIUM

An issue was discovered in the events2 (aka Events 2) extension before 8.3.8 and 9.x before 9.0.6 for TYPO3. Missing access checks in the management …

Jun 21, 2024
CVE-2024-38873
5.3 MEDIUM

An issue was discovered in the friendlycaptcha_official (aka Integration of Friendly Captcha) extension before 0.1.4 for TYPO3. The extension fails to check the requirement of …

Jun 21, 2024
CVE-2024-5448
5.4 MEDIUM

The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode WordPress plugin through 1.7 does not validate and escape some of its shortcode attributes …

Jun 21, 2024
CVE-2024-5447
4.8 MEDIUM

The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode WordPress plugin through 1.7 does not sanitise and escape some of its settings, which …

Jun 21, 2024
CVE-2024-4970
4.8 MEDIUM

The Widget Bundle WordPress plugin through 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jun 21, 2024
CVE-2024-4969
4.3 MEDIUM

The Widget Bundle WordPress plugin through 2.0.0 does not have CSRF checks when logging Widgets, which could allow attackers to make logged in admin enable/disable …

Jun 21, 2024
CVE-2024-4755
4.8 MEDIUM

The Google CSE WordPress plugin through 1.0.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jun 21, 2024
CVE-2024-4616
6.1 MEDIUM

The Widget Bundle WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jun 21, 2024
CVE-2024-4477
5.4 MEDIUM

The WP Logs Book WordPress plugin through 1.0.1 does not sanitise and escape some of its log data before outputting them back in an admin …

Jun 21, 2024
CVE-2024-4475
4.3 MEDIUM

The WP Logs Book WordPress plugin through 1.0.1 does not have CSRF check when clearing logs, which could allow attackers to make a logged in …

Jun 21, 2024
CVE-2024-4474
4.3 MEDIUM

The WP Logs Book WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Jun 21, 2024
CVE-2024-4384
4.8 MEDIUM

The CSSable Countdown WordPress plugin through 1.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jun 21, 2024
CVE-2024-4382
6.5 MEDIUM

The CB (legacy) WordPress plugin through 0.9.4.18 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins …

Jun 21, 2024
CVE-2024-4381
4.8 MEDIUM

The CB (legacy) WordPress plugin through 0.9.4.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jun 21, 2024
CVE-2024-4377
5.4 MEDIUM

The DOP Shortcodes WordPress plugin through 1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Jun 21, 2024
CVE-2021-47621
7.5 HIGH

ClassGraph before 4.8.112 was not resistant to XML eXternal Entity (XXE) attacks.

Jun 21, 2024
CVE-2024-5756
9.8 CRITICAL

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via …

Jun 21, 2024
CVE-2024-5455
8.8 HIGH

The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.5.4 via …

Jun 21, 2024
CVE-2024-3961
5.3 MEDIUM

The ConvertKit – Email Newsletter, Email Marketing, Subscribers and Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Jun 21, 2024
CVE-2024-6218
7.3 HIGH

A vulnerability, which was classified as critical, has been found in itsourcecode Vehicle Management System 1.0. Affected by this issue is some unknown functionality of …

Jun 21, 2024
CVE-2024-6217
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Food Ordering Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jun 21, 2024
CVE-2024-6216
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Food Ordering Management System 1.0. Affected is an unknown function of the file add-users.php. The …

Jun 21, 2024
CVE-2024-6215
6.3 MEDIUM

A vulnerability was found in SourceCodester Food Ordering Management System up to 1.0. It has been rated as critical. This issue affects some unknown processing …

Jun 21, 2024
CVE-2024-5503
8.8 HIGH

The WP Blog Post Layouts plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.3. This makes it …

Jun 21, 2024
CVE-2024-5344
6.1 MEDIUM

The The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘forgoturl’ attribute within the plugin's WP …

Jun 21, 2024
CVE-2024-3610
5.3 MEDIUM

The WP Child Theme Generator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wctg_easy_child_theme() function …

Jun 21, 2024
CVE-2024-1955
4.3 MEDIUM

The Hide Dashboard Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'warning_notices_settings' function in …

Jun 21, 2024
CVE-2024-1639
6.5 MEDIUM

The License Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the showLicenseKey() and …

Jun 21, 2024
CVE-2023-3352
4.3 MEDIUM

The Smush plugin for WordPress is vulnerable to unauthorized deletion of the resmush list due to a missing capability check on the delete_resmush_list() function. This …

Jun 21, 2024
CVE-2024-6214
6.3 MEDIUM

A vulnerability was found in SourceCodester Food Ordering Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Jun 21, 2024
CVE-2024-6213
7.3 HIGH

A vulnerability was found in SourceCodester Food Ordering Management System up to 1.0. It has been classified as critical. This affects an unknown part of …

Jun 21, 2024
CVE-2024-6212
3.5 LOW

A vulnerability was found in SourceCodester Simple Student Attendance System 1.0 and classified as problematic. Affected by this issue is the function get_student of the …

Jun 21, 2024
CVE-2020-35162

Rejected reason: CVE ID was once reserved, but never used.

Jun 21, 2024
CVE-2020-35161

Rejected reason: CVE ID was once reserved, but never used.

Jun 21, 2024
CVE-2020-35160

Rejected reason: CVE ID was once reserved, but never used.

Jun 21, 2024
CVE-2020-35159

Rejected reason: CVE ID was once reserved, but never used.

Jun 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.