CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-36287
3.8 LOW

Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC restrictions on macOS.

Jun 14, 2024
CVE-2024-25142
5.5 MEDIUM

Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow. Airflow did not return "Cache-Control" header for dynamic content, which in case of …

Jun 14, 2024
CVE-2024-5995
8.8 HIGH

The notification emails sent by Soar Cloud HR Portal contain a link with a embedded session. The expiration of the session is not properly configured, …

Jun 14, 2024
CVE-2024-5961

Improper neutralization of input during web page generation vulnerability in 2ClickPortal software allows reflected cross-site scripting (XSS). An attacker might trick somebody into using a …

Jun 14, 2024
CVE-2024-5577
9.8 CRITICAL

The Where I Was, Where I Will Be plugin for WordPress is vulnerable to Remote File Inclusion in version <= 1.1.1 via the WIW_HEADER parameter …

Jun 14, 2024
CVE-2024-5465
5.9 MEDIUM

Function vulnerabilities in the Calendar module Impact: Successful exploitation of this vulnerability will affect availability.

Jun 14, 2024
CVE-2024-5464
4.0 MEDIUM

Vulnerability of insufficient permission verification in the NearLink module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jun 14, 2024
CVE-2024-36503
7.3 HIGH

Memory management vulnerability in the Gralloc module Impact: Successful exploitation of this vulnerability will affect availability.

Jun 14, 2024
CVE-2024-36502
7.9 HIGH

Out-of-bounds read vulnerability in the audio module Impact: Successful exploitation of this vulnerability will affect availability.

Jun 14, 2024
CVE-2024-36501
5.6 MEDIUM

Memory management vulnerability in the boottime module Impact: Successful exploitation of this vulnerability can affect integrity.

Jun 14, 2024
CVE-2024-36500
7.8 HIGH

Privilege escalation vulnerability in the AMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jun 14, 2024
CVE-2024-36499
6.8 MEDIUM

Vulnerability of unauthorized screenshot capturing in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jun 14, 2024
CVE-2024-5994
6.4 MEDIUM

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom JS option in versions up to, …

Jun 14, 2024
CVE-2024-31163
7.2 HIGH

ASUS Download Master has a buffer overflow vulnerability. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability to execute arbitrary system commands on …

Jun 14, 2024
CVE-2024-31162
7.2 HIGH

The specific function parameter of ASUS Download Master does not properly filter user input. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability …

Jun 14, 2024
CVE-2024-5551
7.5 HIGH

The WP STAGING Pro WordPress Backup Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.6.0. This …

Jun 14, 2024
CVE-2024-5155
6.1 MEDIUM

The Inquiry cart WordPress plugin through 3.4.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Jun 14, 2024
CVE-2024-4751
4.3 MEDIUM

The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Jun 14, 2024
CVE-2024-4480
6.1 MEDIUM

The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its email settings, which could allow attackers to …

Jun 14, 2024
CVE-2024-4404
8.5 HIGH

The ElementsKit PRO plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.6.2 via the 'render_raw' function. This can …

Jun 14, 2024
CVE-2024-4271
4.6 MEDIUM

The SVGator WordPress plugin through 1.2.6 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious …

Jun 14, 2024
CVE-2024-4270
5.4 MEDIUM

The SVGMagic WordPress plugin through 1.1 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious …

Jun 14, 2024
CVE-2024-4005
4.8 MEDIUM

The Social Pixel WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jun 14, 2024
CVE-2024-3993
4.6 MEDIUM

The AZAN Plugin WordPress plugin through 0.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Jun 14, 2024
CVE-2024-3992
4.8 MEDIUM

The Amen WordPress plugin through 3.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jun 14, 2024
CVE-2024-3978
5.4 MEDIUM

The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post …

Jun 14, 2024
CVE-2024-3977
4.8 MEDIUM

The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jun 14, 2024
CVE-2024-3972
4.3 MEDIUM

The Similarity WordPress plugin through 3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Jun 14, 2024
CVE-2024-3971
4.3 MEDIUM

The Similarity WordPress plugin through 3.0 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged …

Jun 14, 2024
CVE-2024-3966
6.1 MEDIUM

The Pray For Me WordPress plugin through 1.0.4 does not sanitise and escape some parameters, which could unauthenticated visitors to perform Cross-Site Scripting attacks that …

Jun 14, 2024
CVE-2024-3965
5.4 MEDIUM

The Pray For Me WordPress plugin through 1.0.4 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Jun 14, 2024
CVE-2024-3754
4.7 MEDIUM

The Alemha watermarker WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jun 14, 2024
CVE-2024-2218
4.6 MEDIUM

The LuckyWP Table of Contents WordPress plugin through 2.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jun 14, 2024
CVE-2024-2122
6.4 MEDIUM

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via album gallery custom URLs in all versions up …

Jun 14, 2024
CVE-2024-23504
5.3 MEDIUM

Missing Authorization vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through 5.0.5.

Jun 14, 2024
CVE-2024-1295
6.5 MEDIUM

The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking …

Jun 14, 2024
CVE-2023-51497
5.4 MEDIUM

Missing Authorization vulnerability in Woo WooCommerce Ship to Multiple Addresses.This issue affects WooCommerce Ship to Multiple Addresses: from n/a through 3.8.9.

Jun 14, 2024
CVE-2023-51496
5.3 MEDIUM

Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.2.7.

Jun 14, 2024
CVE-2023-51495
6.5 MEDIUM

Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.2.7.

Jun 14, 2024
CVE-2023-51377
5.3 MEDIUM

Missing Authorization vulnerability in WPEverest Everest Forms.This issue affects Everest Forms: from n/a through 2.0.3.

Jun 14, 2024
CVE-2024-4936
9.8 CRITICAL

The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via the abspath parameter. This makes …

Jun 14, 2024
CVE-2024-3498
7.8 HIGH

Attackers can then execute malicious files by enabling certain services of the printer via the web configuration page and elevate its privileges to root. As …

Jun 14, 2024
CVE-2024-3497
8.8 HIGH

Path traversal vulnerability in the web server of the Toshiba printer enables attacker to overwrite orginal files or add new ones to the printer. As …

Jun 14, 2024
CVE-2024-3496
8.8 HIGH

Attackers can bypass the web login authentication process to gain access to the printer's system information and upload malicious drivers to the printer. As for …

Jun 14, 2024
CVE-2024-1094
7.3 HIGH

The Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling plugin for WordPress is vulnerable to unauthorized modification of data due to …

Jun 14, 2024
CVE-2024-5469
3.1 LOW

DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 and 16.11.0 prior to 16.11.3 allows an attacker to crash KAS …

Jun 14, 2024
CVE-2024-31161
7.2 HIGH

The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrative privilege can exploit this vulnerability to upload any …

Jun 14, 2024
CVE-2024-31160
4.8 MEDIUM

The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can …

Jun 14, 2024
CVE-2024-31159
4.8 MEDIUM

The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can …

Jun 14, 2024
CVE-2024-27180
6.7 MEDIUM

An attacker with admin access can install rogue applications. As for the affected products/models/versions, see the reference URL.

Jun 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.