CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5213
6.5 MEDIUM

In mintplex-labs/anything-llm versions up to and including 1.5.3, an issue was discovered where the password hash of a user is returned in the response after …

Jun 20, 2024
CVE-2024-6179
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSign CMS: from …

Jun 20, 2024
CVE-2024-6178
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSign CMS: from …

Jun 20, 2024
CVE-2024-6177
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSign …

Jun 20, 2024
CVE-2024-5432
9.8 CRITICAL

The Lifeline Donation plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.6. This is due to insufficient verification on …

Jun 20, 2024
CVE-2024-4742
6.5 MEDIUM

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the order_by …

Jun 20, 2024
CVE-2024-4626
6.4 MEDIUM

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘layout_type’ and 'id' parameters in all versions up to, and …

Jun 20, 2024
CVE-2024-3627
5.4 MEDIUM

The Wheel of Life: Coaching and Assessment Tool for Life Coach plugin for WordPress is vulnerable to unauthorized modification and loss of data due to …

Jun 20, 2024
CVE-2024-3605
10.0 CRITICAL

The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the 'room_type' parameter of the /wphb/v1/rooms/search-rooms REST API endpoint in all versions …

Jun 20, 2024
CVE-2024-3602
4.3 MEDIUM

The Pop ups, Exit intent popups, email popups, banners, bars, countdowns and cart savers – Promolayer plugin for WordPress is vulnerable to unauthorized plugin settings …

Jun 20, 2024
CVE-2024-3597
7.1 HIGH

The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.2.2. This is …

Jun 20, 2024
CVE-2024-3562
8.8 HIGH

The Custom Field Suite plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.6.7 via the Loop custom …

Jun 20, 2024
CVE-2024-3561
8.8 HIGH

The Custom Field Suite plugin for WordPress is vulnerable to SQL Injection via the the 'Term' custom field in all versions up to, and including, …

Jun 20, 2024
CVE-2024-3558
6.4 MEDIUM

The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_title]' parameter versions up to, and including, 2.6.7 due …

Jun 20, 2024
CVE-2024-1168
6.4 MEDIUM

The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's social image URL in all versions up to, …

Jun 20, 2024
CVE-2023-3204
6.5 MEDIUM

The Materialis theme for WordPress is vulnerable to limited arbitrary options updates in versions up to, and including, 1.1.24. This is due to missing authorization …

Jun 20, 2024
CVE-2024-6176

Allocation of Resources Without Limits or Throttling vulnerability in LG Electronics LG SuperSign CMS allows Port Scanning.This issue affects LG SuperSign CMS: from 4.1.3 before …

Jun 20, 2024
CVE-2024-6103
8.8 HIGH

Use after free in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jun 20, 2024
CVE-2024-6102
8.8 HIGH

Out of bounds memory access in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Jun 20, 2024
CVE-2024-6101
8.8 HIGH

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to perform out of bounds memory access via a crafted HTML …

Jun 20, 2024
CVE-2024-6100
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security …

Jun 20, 2024
CVE-2024-5182
9.1 CRITICAL

A path traversal vulnerability exists in mudler/localai version 2.14.0, where an attacker can exploit the `model` parameter during the model deletion process to delete arbitrary …

Jun 20, 2024
CVE-2024-36684
9.8 CRITICAL

In the module "Custom links" (pk_customlinks) <= 2.3 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a sensitive SQL …

Jun 19, 2024
CVE-2024-36680
7.5 HIGH

In the module "Facebook" (pkfacebook) <=1.0.1 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The ajax script facebookConnect.php have a sensitive SQL call …

Jun 19, 2024
CVE-2024-36679
10.0 CRITICAL

In the module "Module Live Chat Pro (All in One Messaging)" (livechatpro) <=8.4.0, a guest can perform PHP Code injection. Due to a predictable token, …

Jun 19, 2024
CVE-2024-36678
9.8 CRITICAL

In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a sensitive SQL …

Jun 19, 2024
CVE-2024-36677
7.5 HIGH

In the module "Login as customer PRO" (loginascustomerpro) <1.2.7 from Weblir for PrestaShop, a guest can access direct link to connect to each customer account …

Jun 19, 2024
CVE-2024-34994
9.8 CRITICAL

In the module "Channable" (channable) up to version 3.2.1 from Channable for PrestaShop, a guest can perform SQL injection via `ChannableFeedModuleFrontController::postProcess()`.

Jun 19, 2024
CVE-2024-34990
10.0 CRITICAL

In the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop, a customer can upload .php …

Jun 19, 2024
CVE-2024-33836
9.8 CRITICAL

In the module "JA Marketplace" (jamarketplace) up to version 9.0.1 from JA Module for PrestaShop, a guest can upload files with extensions .php. In version …

Jun 19, 2024
CVE-2024-38358
2.9 LOW

Wasmer is a web assembly (wasm) Runtime supporting WASIX, WASI and Emscripten. If the preopened directory has a symlink pointing outside, WASI programs can traverse …

Jun 19, 2024
CVE-2024-38357
6.1 MEDIUM

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content parsing code. This allowed specially crafted noscript …

Jun 19, 2024
CVE-2024-38356
6.1 MEDIUM

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content extraction code. When using the `noneditable_regexp` option, …

Jun 19, 2024
CVE-2024-38355
7.3 HIGH

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus …

Jun 19, 2024
CVE-2024-34993
6.3 MEDIUM

In the module "Bulk Export products to Google Merchant-Google Shopping" (bagoogleshopping) up to version 1.0.26 from Buy Addons for PrestaShop, a guest can perform SQL …

Jun 19, 2024
CVE-2024-38352

Rejected reason: CVE was assigned in error.

Jun 19, 2024
CVE-2024-36117
8.6 HIGH

Reposilite is an open source, lightweight and easy-to-use repository manager for Maven based artifacts in JVM ecosystem. Reposilite v3.5.10 is affected by an Arbitrary File …

Jun 19, 2024
CVE-2024-36116
7.5 HIGH

Reposilite is an open source, lightweight and easy-to-use repository manager for Maven based artifacts in JVM ecosystem. Reposilite provides support for JavaDocs files, which are …

Jun 19, 2024
CVE-2024-36115
7.1 HIGH

Reposilite is an open source, lightweight and easy-to-use repository manager for Maven based artifacts in JVM ecosystem. As a Maven repository manager, Reposilite provides the …

Jun 19, 2024
CVE-2024-32030
8.1 HIGH

Kafka UI is an Open-Source Web UI for Apache Kafka Management. Kafka UI API allows users to connect to different Kafka brokers by specifying their …

Jun 19, 2024
CVE-2024-34444
7.1 HIGH

Missing Authorization vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a before 6.7.0.

Jun 19, 2024
CVE-2024-34443
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemePunch OHG Slider Revolution allows Stored XSS.This issue affects Slider Revolution: …

Jun 19, 2024
CVE-2024-22263
8.8 HIGH

Spring Cloud Data Flow is a microservices-based Streaming and Batch data processing in Cloud Foundry and Kubernetes. The Skipper server has the ability to receive …

Jun 19, 2024
CVE-2023-39312
9.1 CRITICAL

Missing Authorization vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.

Jun 19, 2024
CVE-2023-38394
5.4 MEDIUM

Missing Authorization vulnerability in Artbees JupiterX Core.This issue affects JupiterX Core: from 3.0.0 through 3.3.0.

Jun 19, 2024
CVE-2023-38393
7.6 HIGH

Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.

Jun 19, 2024
CVE-2023-36516
7.6 HIGH

Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3.

Jun 19, 2024
CVE-2023-36515
7.3 HIGH

Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3.

Jun 19, 2024
CVE-2023-25697
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in GamiPress.This issue affects GamiPress: from n/a through 2.5.6.

Jun 19, 2024
CVE-2022-45832
6.5 MEDIUM

Missing Authorization vulnerability in Hennessey Digital Attorney.This issue affects Attorney: from n/a through 3.

Jun 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.