CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-47845
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Lim Kai Yang Grab & Save.This issue affects Grab & Save: from n/a through 1.0.4.

Jun 12, 2024
CVE-2023-47828
4.3 MEDIUM

Missing Authorization vulnerability in Mandrill wpMandrill.This issue affects wpMandrill: from n/a through 1.33.

Jun 12, 2024
CVE-2023-44234
4.3 MEDIUM

Missing Authorization vulnerability in Bastianon Massimo WP GPX Map.This issue affects WP GPX Map: from n/a through 1.7.08.

Jun 12, 2024
CVE-2023-41240
5.3 MEDIUM

Missing Authorization vulnerability in Vark Pricing Deals for WooCommerce.This issue affects Pricing Deals for WooCommerce: from n/a through 2.0.3.2.

Jun 12, 2024
CVE-2023-40672
5.4 MEDIUM

Missing Authorization vulnerability in Hardik Chavada Sticky Social Media Icons.This issue affects Sticky Social Media Icons: from n/a through 2.1.

Jun 12, 2024
CVE-2023-40603
5.3 MEDIUM

Missing Authorization vulnerability in Gangesh Matta Simple Org Chart.This issue affects Simple Org Chart: from n/a through 2.3.4.

Jun 12, 2024
CVE-2023-40209
6.5 MEDIUM

Missing Authorization vulnerability in Himalaya Saxena Highcompress Image Compressor.This issue affects Highcompress Image Compressor: from n/a through 6.0.0.

Jun 12, 2024
CVE-2023-38395
5.4 MEDIUM

Missing Authorization vulnerability in Afzal Multani WP Clone Menu.This issue affects WP Clone Menu: from n/a through 1.0.1.

Jun 12, 2024
CVE-2023-25030
4.3 MEDIUM

Missing Authorization vulnerability in Buy Me a Coffee.This issue affects Buy Me a Coffee: from n/a through 3.7.

Jun 12, 2024
CVE-2024-5742
6.7 MEDIUM

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a …

Jun 12, 2024
CVE-2024-5468
6.5 MEDIUM

The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to unauthorized site option deletion due to a missing validation and capability checks …

Jun 12, 2024
CVE-2024-5266
6.4 MEDIUM

The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpdm_user_dashboard, wpdm_package, wpdm_packages, wpdm_search_result, and wpdm_tag shortcodes in all versions up …

Jun 12, 2024
CVE-2024-5203

Rejected reason: After careful review of CVE-2024-5203, it has been determined that the issue is not exploitable in real-world scenarios. Moreover, the exploit assumes that …

Jun 12, 2024
CVE-2024-5154
8.1 HIGH

A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This …

Jun 12, 2024
CVE-2024-3183
8.1 HIGH

A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for …

Jun 12, 2024
CVE-2023-52177
5.4 MEDIUM

Missing Authorization vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.3.

Jun 12, 2024
CVE-2023-52117
4.3 MEDIUM

Missing Authorization vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid: from n/a through 5.6.6.

Jun 12, 2024
CVE-2023-51680
4.3 MEDIUM

Missing Authorization vulnerability in TechnoVama Quotes for WooCommerce.This issue affects Quotes for WooCommerce: from n/a through 2.0.1.

Jun 12, 2024
CVE-2023-51679
5.4 MEDIUM

Missing Authorization vulnerability in BulkGate BulkGate SMS Plugin for WooCommerce.This issue affects BulkGate SMS Plugin for WooCommerce: from n/a through 3.0.2.

Jun 12, 2024
CVE-2023-51671
5.4 MEDIUM

Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.

Jun 12, 2024
CVE-2023-51670
4.3 MEDIUM

Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.

Jun 12, 2024
CVE-2023-51537
5.3 MEDIUM

Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.5.

Jun 12, 2024
CVE-2023-51526
4.3 MEDIUM

Missing Authorization vulnerability in Brett Shumaker Simple Staff List.This issue affects Simple Staff List: from n/a through 2.2.4.

Jun 12, 2024
CVE-2024-5873

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 12, 2024
CVE-2024-5783

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 12, 2024
CVE-2024-5782

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 12, 2024
CVE-2024-5781

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 12, 2024
CVE-2024-5780

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 12, 2024
CVE-2024-5779

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 12, 2024
CVE-2024-5778

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 12, 2024
CVE-2024-5777

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 12, 2024
CVE-2024-5776

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 12, 2024
CVE-2024-3925
6.4 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jun 12, 2024
CVE-2024-2698
8.8 HIGH

A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition for granting the "forwardable" flag …

Jun 12, 2024
CVE-2024-5739
6.1 MEDIUM

The in-app browser of LINE client for iOS versions below 14.9.0 contains a Universal XSS (UXSS) vulnerability. This vulnerability allows for cross-site scripting (XSS) where …

Jun 12, 2024
CVE-2024-28970
4.7 MEDIUM

Dell Client BIOS contains an Out-of-bounds Write vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to platform denial …

Jun 12, 2024
CVE-2024-0160
6.8 MEDIUM

Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by bypassing BIOS authorization …

Jun 12, 2024
CVE-2024-5892
6.4 MEDIUM

The Divi Torque Lite – Divi Theme and Extra Theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘support_unfiltered_files_upload’ function in all …

Jun 12, 2024
CVE-2024-4924
6.1 MEDIUM

The Social Sharing Plugin WordPress plugin before 3.3.63 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jun 12, 2024
CVE-2024-36454
5.3 MEDIUM

Use of uninitialized resource issue exists in IPCOM EX2 Series (V01L0x Series) V01L07NF0201 and earlier, and IPCOM VE2 Series V01L07NF0201 and earlier. If this vulnerability …

Jun 12, 2024
CVE-2024-0427
6.3 MEDIUM

The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.4.1 does not properly escape user-controlled input when it is reflected in some of …

Jun 12, 2024
CVE-2024-3559
6.4 MEDIUM

The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_content]' parameter versions up to, and including, 2.6.7 due …

Jun 12, 2024
CVE-2024-5553
4.4 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via several parameters in all versions up to, and including, …

Jun 12, 2024
CVE-2024-4564
6.4 MEDIUM

The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Jun 12, 2024
CVE-2024-36856
7.5 HIGH

RMQTT Broker 0.4.0 is vulnerable to Denial of Service (DoS) due to improper session resource management. An attacker can exhaust system memory and crash the …

Jun 12, 2024
CVE-2024-5543
8.1 HIGH

The Slideshow Gallery LITE plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all versions up to, and including, 1.8.1 …

Jun 12, 2024
CVE-2024-4892
6.4 MEDIUM

The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ parameter in versions up to, and including, 12.4.1 due to insufficient …

Jun 12, 2024
CVE-2024-4315
9.1 CRITICAL

parisneo/lollms version 9.5 is vulnerable to Local File Inclusion (LFI) attacks due to insufficient path sanitization. The `sanitize_path_from_endpoint` function fails to properly sanitize Windows-style paths …

Jun 12, 2024
CVE-2024-36103
6.8 MEDIUM

OS command injection vulnerability in WRC-X5400GS-B v1.0.10 and earlier, and WRC-X5400GSA-B v1.0.10 and earlier allows a network-adjacent attacker with an administrative privilege to execute arbitrary …

Jun 12, 2024
CVE-2024-35225
9.6 CRITICAL

Jupyter Server Proxy allows users to run arbitrary external processes alongside their notebook server and provide authenticated web access to them. Versions of 3.x prior …

Jun 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.