CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-52196
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phil Ewels CPT Bootstrap Carousel allows Reflected XSS.This issue affects CPT Bootstrap Carousel: …

Jan 8, 2024
CVE-2023-52142
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cool Plugins Events Shortcodes For The Events Calendar.This issue affects Events …

Jan 8, 2024
CVE-2023-51508
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jordy Meow Database Cleaner: Clean, Optimize & Repair.This issue affects Database Cleaner: Clean, Optimize & …

Jan 8, 2024
CVE-2023-51490
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPMU DEV Defender Security – Malware Scanner, Login Security & Firewall.This issue affects Defender Security …

Jan 8, 2024
CVE-2023-51408
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StudioWombat WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce.This issue …

Jan 8, 2024
CVE-2023-51406
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team FastDup – Fastest WordPress Migration & Duplicator.This issue affects FastDup – Fastest WordPress …

Jan 8, 2024
CVE-2023-49961
7.5 HIGH

WALLIX Bastion 7.x, 8.x, 9.x and 10.x and WALLIX Access Manager 3.x and 4.x have Incorrect Access Control which can lead to sensitive data exposure.

Jan 8, 2024
CVE-2023-27739
6.1 MEDIUM

easyXDM 2.5 allows XSS via the xdm_e parameter.

Jan 8, 2024
CVE-2022-45354
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.

Jan 8, 2024
CVE-2023-52271
6.5 MEDIUM

The wsftprm.sys kernel driver 2.0.0.0 in Topaz Antifraud allows low-privileged attackers to kill any (Protected Process Light) process via an IOCTL (which will be named …

Jan 8, 2024
CVE-2023-52216
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Yevhen Kotelnytskyi JS & CSS Script Optimizer.This issue affects JS & CSS Script Optimizer: from n/a through 0.3.3.

Jan 8, 2024
CVE-2023-52213
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VideoWhisper Rate Star Review – AJAX Reviews for Content, with Star Ratings allows …

Jan 8, 2024
CVE-2023-52206
7.7 HIGH

Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder.This issue affects Page Builder: Live Composer: from n/a through 1.5.25.

Jan 8, 2024
CVE-2023-52205
9.1 CRITICAL

Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 SoundCloud Player with Playlist Free.This issue affects HTML5 SoundCloud Player with Playlist Free: from n/a through …

Jan 8, 2024
CVE-2023-52204
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Javik Randomize.This issue affects Randomize: from n/a through 1.4.3.

Jan 8, 2024
CVE-2023-52203
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bastian Germann cformsII allows Stored XSS.This issue affects cformsII: from n/a …

Jan 8, 2024
CVE-2023-52200
9.6 CRITICAL

Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup.This …

Jan 8, 2024
CVE-2023-51246
5.4 MEDIUM

A Cross Site Scripting (XSS) vulnerability in GetSimple CMS 3.3.16 exists when using Source Code Mode as a backend user to add articles via the …

Jan 8, 2024
CVE-2023-50982
9.0 CRITICAL

Stud.IP 5.x through 5.3.3 allows XSS with resultant upload of executable files, because upload_action and edit_action in Admin_SmileysController do not check the file extension. This …

Jan 8, 2024
CVE-2023-47890
8.8 HIGH

pyLoad 0.5.0 is vulnerable to Unrestricted File Upload.

Jan 8, 2024
CVE-2023-6845
8.8 HIGH

The CommentTweets WordPress plugin through 0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted …

Jan 8, 2024
CVE-2023-6750
7.5 HIGH

The Clone WordPress plugin before 2.4.3 uses buffer files to store in-progress backup informations, which is stored at a publicly accessible, statically defined file path.

Jan 8, 2024
CVE-2023-6631
7.8 HIGH

PowerSYSTEM Center versions 2020 Update 16 and prior contain a vulnerability that may allow an authorized local user to insert arbitrary code into the unquoted …

Jan 8, 2024
CVE-2023-6627
6.1 MEDIUM

The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.28 does not properly protect most of its REST API routes, which attackers can …

Jan 8, 2024
CVE-2023-6555
6.1 MEDIUM

The Email Subscription Popup WordPress plugin before 1.2.20 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jan 8, 2024
CVE-2023-6532
8.8 HIGH

The WP Blogs' Planetarium WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Jan 8, 2024
CVE-2023-6529
6.1 MEDIUM

The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, …

Jan 8, 2024
CVE-2023-6528
8.8 HIGH

The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially …

Jan 8, 2024
CVE-2023-6505
7.5 HIGH

The Migrate WordPress Website & Backups WordPress plugin before 1.9.3 does not prevent directory listing in sensitive directories containing export files.

Jan 8, 2024
CVE-2023-6383
7.5 HIGH

The Debug Log Manager WordPress plugin before 2.3.0 contains a Directory listing vulnerability was discovered, which allows you to download the debug log without authorization …

Jan 8, 2024
CVE-2023-6161
6.1 MEDIUM

The WP Crowdfunding WordPress plugin before 2.1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jan 8, 2024
CVE-2023-6141
5.4 MEDIUM

The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with …

Jan 8, 2024
CVE-2023-6140
8.8 HIGH

The Essential Real Estate WordPress plugin before 4.4.0 does not prevent users with limited privileges on the site, like subscribers, from momentarily uploading malicious PHP …

Jan 8, 2024
CVE-2023-6139
6.5 MEDIUM

The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with …

Jan 8, 2024
CVE-2023-6042
7.5 HIGH

Any unauthenticated user may send e-mail from the site with any title or content to the admin

Jan 8, 2024
CVE-2023-5957
7.2 HIGH

The Ni Purchase Order(PO) For WooCommerce WordPress plugin through 1.2.1 does not validate logo and signature image files uploaded in the settings, allowing high privileged …

Jan 8, 2024
CVE-2023-5911
4.8 MEDIUM

The WP Custom Cursors | WordPress Cursor Plugin WordPress plugin through 3.2 does not sanitise and escape some of its settings, which could allow high …

Jan 8, 2024
CVE-2023-5235
8.8 HIGH

The Ovic Responsive WPBakery WordPress plugin before 1.2.9 does not limit which options can be updated via some of its AJAX actions, which may allow …

Jan 8, 2024
CVE-2023-52222
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 8.2.2.

Jan 8, 2024
CVE-2023-52208
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Constant Contact Constant Contact Forms.This issue affects Constant Contact Forms: from n/a through 2.4.2.

Jan 8, 2024
CVE-2023-52207
9.1 CRITICAL

Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Playlist Free.This issue affects HTML5 MP3 Player with Playlist Free: from n/a through …

Jan 8, 2024
CVE-2023-52190
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Swings Coupon Referral Program.This issue affects Coupon Referral Program: from n/a through 1.7.2.

Jan 8, 2024
CVE-2023-1032
4.7 MEDIUM

The Linux kernel io_uring IORING_OP_SOCKET operation contained a double free in function __sys_socket_file() in file net/socket.c. This issue was introduced in da214a475f8bd1d3e9e7a19ddfeb4d1617551bab and fixed in …

Jan 8, 2024
CVE-2021-3600
7.8 HIGH

It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and …

Jan 8, 2024
CVE-2018-25095
9.8 CRITICAL

The Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script …

Jan 8, 2024
CVE-2023-52225
10.0 CRITICAL

Deserialization of Untrusted Data vulnerability in Tagbox Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics.This issue affects Tagbox – UGC Galleries, Social …

Jan 8, 2024
CVE-2023-52219
9.9 CRITICAL

Deserialization of Untrusted Data vulnerability in Gecka Gecka Terms Thumbnails.This issue affects Gecka Terms Thumbnails: from n/a through 1.1.

Jan 8, 2024
CVE-2023-52218
10.0 CRITICAL

Deserialization of Untrusted Data vulnerability in Anton Bond Woocommerce Tranzila Payment Gateway.This issue affects Woocommerce Tranzila Payment Gateway: from n/a through 1.0.8.

Jan 8, 2024
CVE-2023-52215
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UkrSolution Simple Inventory Management – just scan barcode to manage products …

Jan 8, 2024
CVE-2022-3328
7.8 HIGH

Race condition in snap-confine's must_mkdir_and_open_with_perms()

Jan 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.