CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-7046
7.5 HIGH

The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, SSL Score plugin for WordPress is vulnerable to …

Apr 9, 2024
CVE-2023-6999
8.8 HIGH

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in all versions up to, and …

Apr 9, 2024
CVE-2023-6993
6.4 MEDIUM

The Custom post types, Custom Fields & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode and custom post meta …

Apr 9, 2024
CVE-2023-6967
8.8 HIGH

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via shortcode in all versions up to, and including, …

Apr 9, 2024
CVE-2023-6965
4.3 MEDIUM

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0.10 (with …

Apr 9, 2024
CVE-2023-6964
8.5 HIGH

The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and …

Apr 9, 2024
CVE-2023-6799
5.9 MEDIUM

The WP Reset – Most Advanced WordPress Reset Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, …

Apr 9, 2024
CVE-2023-6777
5.3 MEDIUM

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 9.0.34 …

Apr 9, 2024
CVE-2023-6695
6.5 MEDIUM

The Beaver Themer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the 'wpbb' shortcode. This …

Apr 9, 2024
CVE-2023-6694
6.4 MEDIUM

The Beaver Themer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.4.9 due …

Apr 9, 2024
CVE-2023-6486
6.4 MEDIUM

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS metabox in all versions up to …

Apr 9, 2024
CVE-2022-4965
6.1 MEDIUM

The Invitation Code Content Restriction Plugin from CreativeMinds plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘target_id’ parameter in all versions up …

Apr 9, 2024
CVE-2024-31507
8.6 HIGH

Sourcecodester Online Graduate Tracer System v1.0 is vulnerable to SQL Injection via the "request" parameter in admin/fetch_gendercs.php.

Apr 9, 2024
CVE-2024-31506
7.5 HIGH

Sourcecodester Online Graduate Tracer System v1.0 is vulnerable to SQL Injection via the "id" parameter in admin/admin_cs.php.

Apr 9, 2024
CVE-2024-31457
7.7 HIGH

gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. gin-vue-admin pseudoversion 0.0.0-20240407133540-7bc7c3051067, corresponding …

Apr 9, 2024
CVE-2024-31454
6.5 MEDIUM

PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.2.0, the absence of restrictions on the endpoint, which is designed for uploading …

Apr 9, 2024
CVE-2024-31453
6.5 MEDIUM

PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.2.0, the absence of restrictions on the endpoint, which allows users to create …

Apr 9, 2024
CVE-2024-30704

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Apr 9, 2024
CVE-2024-30703

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Apr 9, 2024
CVE-2024-30702

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Apr 9, 2024
CVE-2024-27247
5.5 MEDIUM

Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a privileged user to conduct an escalation of …

Apr 9, 2024
CVE-2024-27242
4.1 MEDIUM

Cross site scripting in Zoom Desktop Client for Linux before version 5.17.10 may allow an authenticated user to conduct a denial of service via network …

Apr 9, 2024
CVE-2024-25116
5.5 MEDIUM

RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 and 2.6.10, authenticated users can use …

Apr 9, 2024
CVE-2024-25115
7.0 HIGH

RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 and 2.6.10, specially crafted `CF.LOADCHUNK` commands …

Apr 9, 2024
CVE-2024-24694
5.9 MEDIUM

Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an authenticated user to conduct an escalation of …

Apr 9, 2024
CVE-2024-24576
10.0 CRITICAL

Rust is a programming language. The Rust Security Response WG was notified that the Rust standard library prior to version 1.77.2 did not properly escape …

Apr 9, 2024
CVE-2024-22423
8.3 HIGH

yt-dlp is a youtube-dl fork with additional features and fixes. The patch that addressed CVE-2023-40581 attempted to prevent RCE when using `--exec` with `%q` by …

Apr 9, 2024
CVE-2024-31867
6.5 MEDIUM

Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties to LDAP search filter. This issue affects …

Apr 9, 2024
CVE-2024-31455
4.3 MEDIUM

Minder by Stacklok is an open source software supply chain security platform. A refactoring in commit `5c381cf` added the ability to get GitHub repositories registered …

Apr 9, 2024
CVE-2024-30262
5.9 MEDIUM

Contao is an open source content management system. Prior to version 4.13.40, when a frontend member changes their password in the personal data or the …

Apr 9, 2024
CVE-2024-29993
8.8 HIGH

Azure CycleCloud Elevation of Privilege Vulnerability

Apr 9, 2024
CVE-2024-29992
5.5 MEDIUM

Azure Identity Library for .NET Information Disclosure Vulnerability

Apr 9, 2024
CVE-2024-29990
9.0 CRITICAL

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

Apr 9, 2024
CVE-2024-29989
8.4 HIGH

Azure Monitor Agent Elevation of Privilege Vulnerability

Apr 9, 2024
CVE-2024-29988
8.8 HIGH KEV

SmartScreen Prompt Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-29985
8.8 HIGH

Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-29984
8.8 HIGH

Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-29983
8.8 HIGH

Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-29982
8.8 HIGH

Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-29905
8.1 HIGH

DIRAC is an interware, meaning a software framework for distributed computing. Prior to version 8.0.41, during the proxy generation process (e.g., when using `dirac-proxy-init`), it …

Apr 9, 2024
CVE-2024-29066
7.2 HIGH

Windows Distributed File System (DFS) Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-29064
6.2 MEDIUM

Windows Hyper-V Denial of Service Vulnerability

Apr 9, 2024
CVE-2024-29063
7.3 HIGH

Azure AI Search Information Disclosure Vulnerability

Apr 9, 2024
CVE-2024-29062
7.1 HIGH

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-29061
7.8 HIGH

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-29056
4.3 MEDIUM

Windows Authentication Elevation of Privilege Vulnerability

Apr 9, 2024
CVE-2024-29055
7.2 HIGH

Microsoft Defender for IoT Elevation of Privilege Vulnerability

Apr 9, 2024
CVE-2024-29054
7.2 HIGH

Microsoft Defender for IoT Elevation of Privilege Vulnerability

Apr 9, 2024
CVE-2024-29053
8.8 HIGH

Microsoft Defender for IoT Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-29052
7.8 HIGH

Windows Storage Elevation of Privilege Vulnerability

Apr 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.