CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-6266
7.5 HIGH

The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the BMI_BACKUP case of …

Jan 11, 2024
CVE-2023-6220
8.1 HIGH

The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'piotnetforms_ajax_form_builder' function in versions up …

Jan 11, 2024
CVE-2023-5691
4.4 MEDIUM

The Chatbot for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version 2.3.9 due to insufficient input sanitization and …

Jan 11, 2024
CVE-2023-5504
8.7 HIGH

The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the Log File Folder. This allows authenticated …

Jan 11, 2024
CVE-2023-52032
9.8 CRITICAL

TOTOlink EX1200T V4.1.2cu.5232_B20210713 was discovered to contain a remote command execution (RCE) vulnerability via the "main" function.

Jan 11, 2024
CVE-2023-52031
9.8 CRITICAL

TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the UploadFirmwareFile function.

Jan 11, 2024
CVE-2023-52030
9.8 CRITICAL

TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setOpModeCfg function.

Jan 11, 2024
CVE-2023-52029
9.8 CRITICAL

TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setDiagnosisCfg function.

Jan 11, 2024
CVE-2023-52028
9.8 CRITICAL

TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setTracerouteCfg function.

Jan 11, 2024
CVE-2023-52027
9.8 CRITICAL

TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the NTPSyncWithHost function.

Jan 11, 2024
CVE-2023-4962
6.4 MEDIUM

The Video PopUp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'video_popup' shortcode in versions up to, and including, 1.1.3 due to insufficient …

Jan 11, 2024
CVE-2023-4960
6.4 MEDIUM

The WCFM Marketplace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wcfm_stores' shortcode in versions up to, and including, 3.6.2 due to insufficient …

Jan 11, 2024
CVE-2023-4372
6.4 MEDIUM

The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'esi' shortcode in versions up to, and including, 5.6 due to …

Jan 11, 2024
CVE-2023-4248
5.4 MEDIUM

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incorrect …

Jan 11, 2024
CVE-2023-4247
5.4 MEDIUM

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incorrect …

Jan 11, 2024
CVE-2023-4246
4.3 MEDIUM

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incorrect …

Jan 11, 2024
CVE-2024-0252
8.8 HIGH

ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication …

Jan 11, 2024
CVE-2023-37644
5.5 MEDIUM

SWFTools 0.9.2 772e55a allows attackers to trigger a large memory-allocation attempt via a crafted document, as demonstrated by pdf2swf. This occurs in png_read_chunk in lib/png.c.

Jan 11, 2024
CVE-2023-6883
4.3 MEDIUM

The Easy Social Feed plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in …

Jan 11, 2024
CVE-2023-6699
9.1 CRITICAL

The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.10.33 via the …

Jan 11, 2024
CVE-2023-6520
4.3 MEDIUM

The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.0. …

Jan 11, 2024
CVE-2023-6506
4.3 MEDIUM

The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Jan 11, 2024
CVE-2023-6446
4.4 MEDIUM

The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.40 due …

Jan 11, 2024
CVE-2023-6223
4.3 MEDIUM

The LearnPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.5.7 via the /wp-json/lp/v1/profile/course-tab REST API …

Jan 11, 2024
CVE-2024-21669
9.9 CRITICAL

Hyperledger Aries Cloud Agent Python (ACA-Py) is a foundation for building decentralized identity applications and services running in non-mobile environments. When verifying W3C Format Verifiable …

Jan 11, 2024
CVE-2024-21637
7.6 HIGH

Authentik is an open-source Identity Provider. Authentik is a vulnerable to a reflected Cross-Site Scripting vulnerability via JavaScript-URIs in OpenID Connect flows with `response_mode=form_post`. This …

Jan 11, 2024
CVE-2023-6630
4.3 MEDIUM

The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Jan 11, 2024
CVE-2023-5448
8.8 HIGH

The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.9. This is due …

Jan 11, 2024
CVE-2024-22195
5.4 MEDIUM

Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject arbitrary HTML …

Jan 11, 2024
CVE-2024-22194
2.2 LOW

cdo-local-uuid project provides a specialized UUID-generating function that can, on user request, cause a program to generate deterministic UUIDs. An information leakage vulnerability is present …

Jan 11, 2024
CVE-2023-52274
6.1 MEDIUM

member/index/register.html in YzmCMS 6.5 through 7.0 allows XSS via the Referer HTTP header.

Jan 11, 2024
CVE-2023-51073
8.1 HIGH

An issue in Buffalo LS210D v.1.78-0.03 allows a remote attacker to execute arbitrary code via the Firmware Update Script at /etc/init.d/update_notifications.sh.

Jan 11, 2024
CVE-2023-45171
6.2 MEDIUM

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the kernel to cause a denial of …

Jan 11, 2024
CVE-2023-45169
6.2 MEDIUM

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the pmsvcs kernel extension to cause a …

Jan 11, 2024
CVE-2023-38267
6.2 MEDIUM

IBM Security Access Manager Appliance (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user …

Jan 11, 2024
CVE-2023-31003
8.4 HIGH

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user …

Jan 11, 2024
CVE-2023-31001
5.1 MEDIUM

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) temporarily stores sensitive information in …

Jan 11, 2024
CVE-2022-40361
6.1 MEDIUM

Cross Site Scripting Vulnerability in Elite CRM v1.2.11 allows attacker to execute arbitrary code via the language parameter to the /ngs/login endpoint.

Jan 11, 2024
CVE-2024-22190
7.8 HIGH

GitPython is a python library used to interact with Git repositories. There is an incomplete fix for CVE-2023-40590. On Windows, GitPython uses an untrusted search …

Jan 11, 2024
CVE-2023-45175
6.2 MEDIUM

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a …

Jan 11, 2024
CVE-2023-45173
6.2 MEDIUM

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the NFS kernel extension to cause a …

Jan 11, 2024
CVE-2024-21667
6.5 MEDIUM

pimcore/customer-data-framework is the Customer Management Framework for management of customer data within Pimcore. An authenticated and unauthorized user can access the GDPR data extraction feature …

Jan 11, 2024
CVE-2024-21666
6.5 MEDIUM

The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management, segmentation, personalization and marketing automation. An authenticated and unauthorized user can access …

Jan 11, 2024
CVE-2024-21665
4.3 MEDIUM

ecommerce-framework-bundle is the Pimcore Ecommerce Framework Bundle. An authenticated and unauthorized user can access the back-office orders list and be able to query over the …

Jan 11, 2024
CVE-2024-21833
8.8 HIGH

Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product to execute arbitrary OS commands. The affected device, with the initial configuration, …

Jan 11, 2024
CVE-2024-21821
8.0 HIGH

Multiple TP-LINK products allow a network-adjacent authenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands.

Jan 11, 2024
CVE-2024-21773
8.8 HIGH

Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands on …

Jan 11, 2024
CVE-2022-45794
8.6 HIGH

An attacker with network access to the affected PLC (CJ-series and CS-series PLCs, all versions) may use a network protocol to read and write files …

Jan 10, 2024
CVE-2024-21638
9.1 CRITICAL

Azure IPAM (IP Address Management) is a lightweight solution developed on top of the Azure platform designed to help Azure customers manage their IP Address …

Jan 10, 2024
CVE-2024-0333
5.3 MEDIUM

Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.216 allowed an attacker in a privileged network position to install a malicious extension via …

Jan 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.