CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-2252
2.7 LOW

The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files.

Jan 16, 2024
CVE-2023-1405
7.5 HIGH

The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is …

Jan 16, 2024
CVE-2023-0824
6.5 MEDIUM

The User registration & user profile WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as …

Jan 16, 2024
CVE-2023-0769
6.1 MEDIUM

The hiWeb Migration Simple WordPress plugin through 2.0.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jan 16, 2024
CVE-2023-0479
6.1 MEDIUM

The Print Invoice & Delivery Notes for WooCommerce WordPress plugin before 4.7.2 is vulnerable to reflected XSS by echoing a GET value in an admin …

Jan 16, 2024
CVE-2023-0389
4.8 MEDIUM

The Calculated Fields Form WordPress plugin before 1.1.151 does not sanitise and escape some of its form settings, which could allow high privilege users such …

Jan 16, 2024
CVE-2023-0376
5.4 MEDIUM

The Qubely WordPress plugin before 1.8.5 does not validate and escape some of its block options before outputting them back in a page/post where the …

Jan 16, 2024
CVE-2023-0224
9.8 CRITICAL

The GiveWP WordPress plugin before 2.24.1 does not properly escape user input before it reaches SQL queries, which could let unauthenticated attackers perform SQL Injection …

Jan 16, 2024
CVE-2023-0094
5.4 MEDIUM

The UpQode Google Maps WordPress plugin through 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post …

Jan 16, 2024
CVE-2023-0079
5.4 MEDIUM

The Customer Reviews for WooCommerce WordPress plugin before 5.17.0 does not validate and escape some of its shortcode attributes before outputting them back in a …

Jan 16, 2024
CVE-2022-3899
8.1 HIGH

The 3dprint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File Manager included with the plugin, allowing …

Jan 16, 2024
CVE-2022-3836
4.8 MEDIUM

The Seed Social WordPress plugin before 2.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jan 16, 2024
CVE-2022-3829
4.8 MEDIUM

The Font Awesome 4 Menus WordPress plugin through 4.7.0 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jan 16, 2024
CVE-2022-3764
7.2 HIGH

The plugin does not filter the "delete_entries" parameter from user requests, leading to an SQL Injection vulnerability.

Jan 16, 2024
CVE-2022-3739
5.4 MEDIUM

The WP Best Quiz WordPress plugin through 1.0 does not sanitize and escape some parameters, which could allow users with a role as low as …

Jan 16, 2024
CVE-2022-3604
7.8 HIGH

The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could lead to CSV injection.

Jan 16, 2024
CVE-2022-3194
5.4 MEDIUM

The Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allow them to run stored XSS attacks against …

Jan 16, 2024
CVE-2022-2413
5.4 MEDIUM

The Slide Anything WordPress plugin before 2.3.47 does not properly sanitize or escape the slide title before outputting it in the admin pages, allowing a …

Jan 16, 2024
CVE-2022-23180
4.3 MEDIUM

The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks, which could allow any authenticated users, such …

Jan 16, 2024
CVE-2022-23179
4.8 MEDIUM

The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.0 does not escape some of its form fields before outputting them in attributes, …

Jan 16, 2024
CVE-2022-1760
4.3 MEDIUM

The Core Control WordPress plugin through 1.2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Jan 16, 2024
CVE-2022-1618
6.1 MEDIUM

The Coru LFMember WordPress plugin through 1.0.2 does not have CSRF check in place when adding a new game, and is lacking sanitisation as well …

Jan 16, 2024
CVE-2022-1617
6.1 MEDIUM

The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as escaping …

Jan 16, 2024
CVE-2022-1609
9.8 CRITICAL

The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API handler, allowing an …

Jan 16, 2024
CVE-2022-1563
5.3 MEDIUM

The WPGraphQL WooCommerce WordPress plugin before 0.12.4 does not prevent unauthenticated attackers from enumerating a shop's coupon codes and values via GraphQL.

Jan 16, 2024
CVE-2022-1538
7.2 HIGH

Theme Demo Import WordPress plugin before 1.1.1 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as …

Jan 16, 2024
CVE-2022-0775
4.3 MEDIUM

The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as subscriber to …

Jan 16, 2024
CVE-2022-0402
6.1 MEDIUM

The Super Forms - Drag & Drop Form Builder WordPress plugin before 6.0.4 does not escape the bob_czy_panstwa_sprawa_zostala_rozwiazana parameter before outputting it back in an …

Jan 16, 2024
CVE-2021-4227
5.3 MEDIUM

The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing attackers to inject an iFrame in …

Jan 16, 2024
CVE-2021-25117
4.8 MEDIUM

The WP-PostRatings WordPress plugin before 1.86.1 does not sanitise the postratings_image parameter from its options page (wp-admin/admin.php?page=wp-postratings/postratings-options.php). Even though the page is only accessible to …

Jan 16, 2024
CVE-2021-24870
6.1 MEDIUM

The WP Fastest Cache WordPress plugin before 0.9.5 is lacking a CSRF check in its wpfc_save_cdn_integration AJAX action, and does not sanitise and escape some …

Jan 16, 2024
CVE-2021-24869
8.8 HIGH

The WP Fastest Cache WordPress plugin before 0.9.5 does not escape user input in the set_urls_with_terms method before using it in a SQL statement, leading …

Jan 16, 2024
CVE-2021-24567
5.4 MEDIUM

The Simple Post WordPress plugin through 1.1 does not sanitize user input when an authenticated user Text value, then it does not escape these values …

Jan 16, 2024
CVE-2021-24566
8.8 HIGH

The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortcode.

Jan 16, 2024
CVE-2021-24559
5.4 MEDIUM

The Qyrr WordPress plugin before 0.7 does not escape the data-uri of the QR Code when outputting it in a src attribute, allowing for Cross-Site …

Jan 16, 2024
CVE-2021-24433
5.4 MEDIUM

The simple sort&search WordPress plugin through 0.0.3 does not make sure that the indexurl parameter of the shortcodes "category_sims", "order_sims", "orderby_sims", "period_sims", and "tag_sims" use …

Jan 16, 2024
CVE-2021-24432
6.1 MEDIUM

The Advanced AJAX Product Filters WordPress plugin does not sanitise the 'term_id' POST parameter before outputting it in the page, leading to reflected Cross-Site Scripting …

Jan 16, 2024
CVE-2021-24151
7.2 HIGH

The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated (admin+) blind SQL injection issue via …

Jan 16, 2024
CVE-2024-0582
7.8 HIGH

A memory leak flaw was found in the Linux kernel’s io_uring functionality in how a user registers a buffer ring with IORING_REGISTER_PBUF_RING, mmap() it, and …

Jan 16, 2024
CVE-2024-0575
8.8 HIGH

A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been classified as critical. This affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation …

Jan 16, 2024
CVE-2024-0574
8.8 HIGH

A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130 and classified as critical. Affected by this issue is the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The …

Jan 16, 2024
CVE-2024-0573
8.8 HIGH

A vulnerability has been found in Totolink LR1200GB 9.1.0u.6619_B20230130 and classified as critical. Affected by this vulnerability is the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. …

Jan 16, 2024
CVE-2023-6395
6.7 MEDIUM

The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling the execution of arbitrary code with root user privileges. This …

Jan 16, 2024
CVE-2021-4432
5.3 MEDIUM

A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as problematic. This affects an unknown part of the component USER Command …

Jan 16, 2024
CVE-2024-0584

Rejected reason: Do not use this CVE as it is duplicate of CVE-2023-6932

Jan 16, 2024
CVE-2024-0581
4.0 MEDIUM

An Uncontrolled Resource Consumption vulnerability has been found on Sandsprite Scdbg.exe, affecting version 1.0. This vulnerability allows an attacker to send a specially crafted shellcode …

Jan 16, 2024
CVE-2024-0572
8.8 HIGH

A vulnerability, which was classified as critical, was found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected is the function setOpModeCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Jan 16, 2024
CVE-2024-0571
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. This issue affects the function setSmsCfg of the file /cgi-bin/cstecgi.cgi. The …

Jan 16, 2024
CVE-2024-0570
7.3 HIGH

A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6265. This vulnerability affects unknown code of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. …

Jan 16, 2024
CVE-2024-0567
7.5 HIGH

A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a …

Jan 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.