CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4107
6.4 MEDIUM

The Elementor Website Builder – More than Just a Page Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters …

May 14, 2024
CVE-2024-4104
6.1 MEDIUM

The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dbp_id' parameter in all versions up …

May 14, 2024
CVE-2024-4103
4.3 MEDIUM

The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.0. …

May 14, 2024
CVE-2024-4082
4.3 MEDIUM

The Joli FAQ SEO – WordPress FAQ Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.2. …

May 14, 2024
CVE-2024-4068
7.5 HIGH

The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In …

May 14, 2024
CVE-2024-4067
5.3 MEDIUM

The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the …

May 14, 2024
CVE-2024-4046
6.4 MEDIUM

Cracking vulnerability in the OS security module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-4044
7.8 HIGH

A deserialization of untrusted data vulnerability exists in common code used by FlexLogger and InstrumentStudio that may result in remote code execution. Successful exploitation requires …

May 14, 2024
CVE-2024-4041
6.1 MEDIUM

The Yoast SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 22.5 due to insufficient …

May 14, 2024
CVE-2024-4039
6.5 MEDIUM

The The Orders Tracking for WooCommerce plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.10. …

May 14, 2024
CVE-2024-4038
6.5 MEDIUM

The The Back In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all …

May 14, 2024
CVE-2024-3990
6.4 MEDIUM

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Tooltip & Popover Widget in all …

May 14, 2024
CVE-2024-3989
6.4 MEDIUM

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Gallery Justify Widget in all …

May 14, 2024
CVE-2024-3974
6.4 MEDIUM

The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_name’ parameter in versions up to, and including, 12.4.0 due to insufficient …

May 14, 2024
CVE-2024-3956
5.4 MEDIUM

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pod Form widget in all versions …

May 14, 2024
CVE-2024-3954
8.8 HIGH

The Ditty plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.1.38 via deserialization of untrusted input when adding a …

May 14, 2024
CVE-2024-3952
6.4 MEDIUM

The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Ad widget in all versions …

May 14, 2024
CVE-2024-3941
4.7 MEDIUM

The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

May 14, 2024
CVE-2024-3940
8.8 HIGH

The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

May 14, 2024
CVE-2024-3923
6.4 MEDIUM

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link_target parameter in all versions up to, …

May 14, 2024
CVE-2024-3916
6.4 MEDIUM

The Swift Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, …

May 14, 2024
CVE-2024-3915
5.3 MEDIUM

The Swift Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sf_edit_directory_item() function in all …

May 14, 2024
CVE-2024-3903
7.1 HIGH

The Add Custom CSS and JS WordPress plugin through 1.20 does not have CSRF check in some places, and is missing sanitisation as well as …

May 14, 2024
CVE-2024-3831
6.4 MEDIUM

The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Heading widget in all versions …

May 14, 2024
CVE-2024-3828
8.8 HIGH

The Spectra Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.5. This is due to the plugin …

May 14, 2024
CVE-2024-3809
8.8 HIGH

The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.9 via the 'slideshow_type' …

May 14, 2024
CVE-2024-3808
8.8 HIGH

The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.0 via the 'porto_portfolios' …

May 14, 2024
CVE-2024-3807
8.8 HIGH

The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via 'porto_page_header_shortcode_type', 'slideshow_type' and 'post_layout' post …

May 14, 2024
CVE-2024-3806
9.8 CRITICAL

The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via the 'porto_ajax_posts' function. This makes …

May 14, 2024
CVE-2024-3796
4.8 MEDIUM

Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/BackupSchedule, description field. Exploitation of this vulnerability could allow a remote user …

May 14, 2024
CVE-2024-3795
4.8 MEDIUM

Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/BackupTemplate, name / description fields. Exploitation of this vulnerability could allow a …

May 14, 2024
CVE-2024-3794
4.8 MEDIUM

Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/AdvancedSystem, description field, all parameters. Exploitation of this vulnerability could allow a …

May 14, 2024
CVE-2024-3793
4.8 MEDIUM

Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/CloudAccounts, account name / user password / server fields, all parameters. Exploitation …

May 14, 2024
CVE-2024-3792
4.8 MEDIUM

Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/DeviceReplication, execution range field, all parameters. Exploitation of this vulnerability could allow …

May 14, 2024
CVE-2024-3791
4.8 MEDIUM

Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/SystemConfiguration, name / free memory limit fields , type / password parameters. …

May 14, 2024
CVE-2024-3790
4.8 MEDIUM

Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/SystemUsers, login / description fields, passwd1/ passwd2 parameters. Exploitation of this vulnerability …

May 14, 2024
CVE-2024-3789
6.5 MEDIUM

Uncontrolled resource consumption vulnerability in White Bear Solutions WBSAirback, version 21.02.04. This vulnerability could allow an attacker to send multiple command injection payloads to influence …

May 14, 2024
CVE-2024-3788
6.6 MEDIUM

Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through License (/admin/CDPUsers). Exploitation of this vulnerability could allow a remote user to …

May 14, 2024
CVE-2024-3787
6.6 MEDIUM

Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 disks (/admin/DeviceS3). Exploitation of this vulnerability could allow a remote user …

May 14, 2024
CVE-2024-3727
8.3 HIGH

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing …

May 14, 2024
CVE-2024-3722
5.4 MEDIUM

The Swift Performance Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ajax_handler() function in all versions …

May 14, 2024
CVE-2024-3680
6.4 MEDIUM

The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Animation Title widget's img tag …

May 14, 2024
CVE-2024-3595
6.4 MEDIUM

The Pure Chat – Live Chat Plugin & More! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the purechatwid and purechatwname parameter in …

May 14, 2024
CVE-2024-3590
6.1 MEDIUM

The LetterPress WordPress plugin through 1.2.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted …

May 14, 2024
CVE-2024-3582
4.8 MEDIUM

The UnGallery WordPress plugin through 2.2.4 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

May 14, 2024
CVE-2024-3547
6.1 MEDIUM

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'google_connect_error' parameter in all versions …

May 14, 2024
CVE-2024-3462
5.4 MEDIUM

Ant Media Server Community Edition in a default configuration is vulnerable to an improper HTTP header based authorization, leading to a possible use of non-administrative …

May 14, 2024
CVE-2024-3461
6.2 MEDIUM

KioWare for Windows (versions all through 8.35) allows to brute force the PIN number, which protects the application from being closed, as there are no …

May 14, 2024
CVE-2024-3460
7.4 HIGH

In KioWare for Windows (versions all through 8.34) it is possible to exit this software and use other already opened applications utilizing a short time …

May 14, 2024
CVE-2024-3459
8.4 HIGH

KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened in an external …

May 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.