CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-1815
6.4 MEDIUM

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Gallery block in all versions up …

May 23, 2024
CVE-2024-1814
6.4 MEDIUM

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial block in all versions up to, …

May 23, 2024
CVE-2023-7045
5.4 MEDIUM

A CSRF vulnerability exists within GitLab CE/EE from versions 13.11 before 16.10.6, from 16.11 before 16.11.3, from 17.0 before 17.0.1. By leveraging this vulnerability, an …

May 23, 2024
CVE-2023-6502
4.3 MEDIUM

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions before 16.10.6, version 16.11 before 16.11.3, and 17.0 before 17.0.1. …

May 23, 2024
CVE-2024-5165
6.5 MEDIUM

In Eclipse Ditto versions 3.0.0 to 3.5.5, the user input of several input fields of the Eclipse Ditto Explorer User Interface https://eclipse.dev/ditto/user-interface.html was not properly …

May 23, 2024
CVE-2024-4779
8.8 HIGH

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to SQL Injection via the ‘data[post_ids][0]’ parameter in all versions up …

May 23, 2024
CVE-2024-2861
6.4 MEDIUM

The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ProfilePress User Panel widget in all versions up to, and including, 4.15.8 …

May 23, 2024
CVE-2024-5264
5.9 MEDIUM

Network Transfer with AES KHT in Thales Luna EFT 2.1 and above allows a user with administrative console access to access backups taken via offline …

May 23, 2024
CVE-2024-35223
5.3 MEDIUM

Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. Dapr sends the app token of the invoker app instead of …

May 23, 2024
CVE-2024-35186
8.8 HIGH

gitoxide is a pure Rust implementation of Git. During checkout, `gix-worktree-state` does not verify that paths point to locations in the working tree. A specially …

May 23, 2024
CVE-2024-32969
2.7 LOW

vantage6 is an open-source infrastructure for privacy preserving analysis. Collaboration administrators can add extra organizations to their collaboration that can extend their influence. For example, …

May 23, 2024
CVE-2024-30280
7.8 HIGH

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read …

May 23, 2024
CVE-2024-30279
7.8 HIGH

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

May 23, 2024
CVE-2024-4706
6.4 MEDIUM

The WordPress + Microsoft Office 365 / Azure AD | LOGIN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pintra' shortcode …

May 23, 2024
CVE-2024-5241
4.7 MEDIUM

A vulnerability was found in Huashi Private Cloud CDN Live Streaming Acceleration Server up to 20240520. It has been classified as critical. Affected is an …

May 23, 2024
CVE-2024-5240
6.3 MEDIUM

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. This issue affects some unknown processing of the file …

May 23, 2024
CVE-2024-4835
8.0 HIGH

A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can …

May 23, 2024
CVE-2024-4043
6.4 MEDIUM

The WP Ultimate Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpupg-text' shortcode in all versions up to, and …

May 23, 2024
CVE-2024-3648
6.4 MEDIUM

The ShareThis Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sharethis-inline-button' shortcode in all versions up to, and including, …

May 23, 2024
CVE-2024-36013
6.8 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect() Extend a critical section to prevent chan from early …

May 23, 2024
CVE-2024-36012
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: msft: fix slab-use-after-free in msft_do_close() Tying the msft->data lifetime to hdev by freeing it …

May 23, 2024
CVE-2024-36011
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HCI: Fix potential null-ptr-deref Fix potential null-ptr-deref in hci_le_big_sync_established_evt().

May 23, 2024
CVE-2024-2874
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions before 16.10.6, version 16.11 before 16.11.3, and 17.0 before 17.0.1. A runner registered with …

May 23, 2024
CVE-2024-2038
7.5 HIGH

The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, …

May 23, 2024
CVE-2024-5239
6.3 MEDIUM

A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file …

May 23, 2024
CVE-2024-5238
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file …

May 23, 2024
CVE-2024-5237
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Campcodes Complete Web-Based School Management System 1.0. Affected by this issue is some unknown …

May 23, 2024
CVE-2024-5177
6.4 MEDIUM

The Hash Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' parameter within multiple widgets in all versions up to, and …

May 23, 2024
CVE-2024-4399
9.1 CRITICAL

The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack

May 23, 2024
CVE-2024-4388
7.5 HIGH

This does not validate a path generated with user input when downloading files, allowing unauthenticated user to download arbitrary files from the server

May 23, 2024
CVE-2024-4347
7.2 HIGH

The WP Fastest Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.6 via the specificDeleteCache function. This …

May 23, 2024
CVE-2024-3920
3.5 LOW

The Flattr WordPress plugin through 1.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 23, 2024
CVE-2024-3918
4.8 MEDIUM

The Pet Manager WordPress plugin through 1.4 does not sanitise and escape some of its Pet settings, which could allow high privilege users such as …

May 23, 2024
CVE-2024-3917
6.1 MEDIUM

The Pet Manager WordPress plugin through 1.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

May 23, 2024
CVE-2024-3711
4.3 MEDIUM

The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized plugin setting update due to a missing capability check on the functions action_request_disable, …

May 23, 2024
CVE-2024-3626
4.3 MEDIUM

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access of data …

May 23, 2024
CVE-2024-3594
8.7 HIGH

The IDonate WordPress plugin through 1.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 23, 2024
CVE-2024-2220
3.5 LOW

The Button contact VR WordPress plugin through 4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 23, 2024
CVE-2024-5236
6.3 MEDIUM

A vulnerability classified as critical was found in Campcodes Complete Web-Based School Management System 1.0. Affected by this vulnerability is an unknown functionality of the …

May 23, 2024
CVE-2024-5235
6.3 MEDIUM

A vulnerability classified as critical has been found in Campcodes Complete Web-Based School Management System 1.0. Affected is an unknown function of the file /view/teacher_salary_invoice.php. …

May 23, 2024
CVE-2024-5234
6.3 MEDIUM

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as critical. This issue affects some unknown processing of …

May 23, 2024
CVE-2024-5233
6.3 MEDIUM

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the …

May 23, 2024
CVE-2024-4662
8.8 HIGH

The Oxygen Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.8.2 via post metadata. This is …

May 23, 2024
CVE-2023-6325
5.3 MEDIUM

The RomethemeForm For Elementor plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the export_entries, …

May 23, 2024
CVE-2024-5232
6.3 MEDIUM

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as critical. This affects an unknown part of the …

May 23, 2024
CVE-2024-4431
6.4 MEDIUM

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and …

May 23, 2024
CVE-2024-5231
6.3 MEDIUM

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of …

May 23, 2024
CVE-2024-4895
4.7 MEDIUM

The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the CSV import …

May 23, 2024
CVE-2024-5230
5.3 MEDIUM

A vulnerability has been found in EnvaySoft FleetCart up to 4.1.1 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation …

May 23, 2024
CVE-2024-4978
8.4 HIGH KEV

Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor …

May 23, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.