CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-12436
4.3 MEDIUM

The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF checks in some places, which could allow attackers to make logged in users …

Jan 27, 2025
CVE-2024-12280
4.3 MEDIUM

The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF check in place when deleting its logs, which could allow attackers to make …

Jan 27, 2025
CVE-2024-28771
4.8 MEDIUM

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers …

Jan 27, 2025
CVE-2024-28770
4.8 MEDIUM

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers …

Jan 27, 2025
CVE-2023-46187
5.4 MEDIUM

IBM InfoSphere Master Data Management 11.6, 12.0, and 14.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in …

Jan 27, 2025
CVE-2025-0722
4.7 MEDIUM

A vulnerability classified as critical was found in needyamin image_gallery 1.0. This vulnerability affects unknown code of the file /admin/gallery.php of the component Cover Image …

Jan 27, 2025
CVE-2025-0721
4.3 MEDIUM

A vulnerability classified as problematic has been found in needyamin image_gallery 1.0. This affects the function image_gallery of the file /view.php. The manipulation of the …

Jan 27, 2025
CVE-2017-20196
6.3 MEDIUM

A vulnerability was found in Itechscripts School Management Software 2.75. It has been classified as critical. This affects an unknown part of the file /notice-edit.php. …

Jan 26, 2025
CVE-2023-50946
6.5 MEDIUM

IBM Common Licensing 9.0 could allow an authenticated user to modify a configuration file that they should not have access to due to a broken …

Jan 26, 2025
CVE-2023-50945
6.2 MEDIUM

IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user.

Jan 26, 2025
CVE-2023-38009
4.2 MEDIUM

IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the middle techniques due to the lack of certificate pinning.

Jan 26, 2025
CVE-2024-31906
6.2 MEDIUM

IBM Automation Decision Services 23.0.2 allows web pages to be stored locally which can be read by another user on the system.

Jan 26, 2025
CVE-2024-13505
5.5 MEDIUM

The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ays_sections[5][questions][8][title]’ parameter in all versions up to, and including, 5.1.3.3 due …

Jan 26, 2025
CVE-2024-12334
6.1 MEDIUM

The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via any parameter in all versions up …

Jan 26, 2025
CVE-2024-11090
5.3 MEDIUM

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.13 via the …

Jan 26, 2025
CVE-2024-10705
5.4 MEDIUM

The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.5 via …

Jan 26, 2025
CVE-2024-10636
6.1 MEDIUM

The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘content’ parameter in all versions up to, …

Jan 26, 2025
CVE-2024-35150
5.3 MEDIUM

IBM Maximo Application Suite 8.10.12, 8.11.0, 9.0.1, and 9.1.0 - Monitor Component does not neutralize output that is written to logs, which could allow an …

Jan 25, 2025
CVE-2024-35148
6.3 MEDIUM

IBM Maximo Application Suite 8.10.10, 8.11.7, and 9.0 - Monitor Component is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, …

Jan 25, 2025
CVE-2024-35145
6.1 MEDIUM

IBM Maximo Application Suite 9.0.0 - Monitor Component is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in …

Jan 25, 2025
CVE-2024-35144
5.3 MEDIUM

IBM Maximo Application Suite 8.10, 8.11, and 9.0 - Monitor Component stores source code on the web server that could aid in further attacks against …

Jan 25, 2025
CVE-2024-35134
5.3 MEDIUM

IBM Analytics Content Hub 2.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. …

Jan 25, 2025
CVE-2024-35114
5.3 MEDIUM

IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to enumerate usernames due to an observable discrepancy between login attempts.

Jan 25, 2025
CVE-2024-35113
4.3 MEDIUM

IBM Control Center 6.2.1 and 6.3.1 could allow an authenticated user to obtain sensitive information exposed through a directory listing.

Jan 25, 2025
CVE-2024-35112
5.4 MEDIUM

IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the …

Jan 25, 2025
CVE-2024-35111
4.3 MEDIUM

IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the …

Jan 25, 2025
CVE-2023-38716
5.3 MEDIUM

IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0 could disclose sensitive information about the system that could aid in …

Jan 25, 2025
CVE-2023-38714
5.3 MEDIUM

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information about the …

Jan 25, 2025
CVE-2023-38713
5.3 MEDIUM

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information about the …

Jan 25, 2025
CVE-2023-38271
4.3 MEDIUM

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could allow an authenticated user to …

Jan 25, 2025
CVE-2023-38013
5.3 MEDIUM

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information in HTTP …

Jan 25, 2025
CVE-2023-38012
5.3 MEDIUM

IBM Cloud Pak System 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0 could allow a remote attacker to traverse directories on the system. …

Jan 25, 2025
CVE-2025-0350
6.4 MEDIUM

The Divi Carousel Maker – Image, Logo, Testimonial, Post Carousel & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image …

Jan 25, 2025
CVE-2024-13449
4.3 MEDIUM

The Boom Fest plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'bf_admin_action' function in all …

Jan 25, 2025
CVE-2024-13599
6.4 MEDIUM

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.2.7.5 due to …

Jan 25, 2025
CVE-2024-13586
6.4 MEDIUM

The Masy Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'justified-gallery' shortcode in all versions up to, and including, 1.7 …

Jan 25, 2025
CVE-2024-13551
6.4 MEDIUM

The ABC Notation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'abcjs' shortcode in all versions up to, and including, 6.1.3 …

Jan 25, 2025
CVE-2024-13550
6.5 MEDIUM

The ABC Notation plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.1.3 via the 'file' attribute of the …

Jan 25, 2025
CVE-2024-13548
6.4 MEDIUM

The Power Ups for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'magic-button' shortcode in all versions up to, and …

Jan 25, 2025
CVE-2024-13467
6.1 MEDIUM

The WP Contact Form7 Email Spam Blocker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post' parameter in all versions up to, …

Jan 25, 2025
CVE-2024-13458
6.4 MEDIUM

The WordPress SEO Friendly Accordion FAQ with AI assisted content generation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'noticefaq' shortcode …

Jan 25, 2025
CVE-2024-13441
6.4 MEDIUM

The Bilingual Linker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bl_otherlang_link_1 parameter in all versions up to, and including, 2.4 due …

Jan 25, 2025
CVE-2024-13370
6.5 MEDIUM

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a …

Jan 25, 2025
CVE-2024-13368
4.3 MEDIUM

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a …

Jan 25, 2025
CVE-2024-12885
6.5 MEDIUM

The Connections Business Directory plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation when deleting a connections image directory …

Jan 25, 2025
CVE-2024-12826
4.3 MEDIUM

The GoHero Store Customizer for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wooh_action_settings_save_frontend() …

Jan 25, 2025
CVE-2024-12817
6.4 MEDIUM

The Etsy Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'product_link' shortcode in all versions up to, and including, 1.4.2 …

Jan 25, 2025
CVE-2024-12816
6.4 MEDIUM

The NOTICE BOARD BY TOWKIR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'notice-board' shortcode in all versions up to, and …

Jan 25, 2025
CVE-2024-12529
6.4 MEDIUM

The brodos.net Onlineshop Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'BrodosCategory' shortcode in all versions up to, and including, …

Jan 25, 2025
CVE-2024-12512
6.4 MEDIUM

The Ask Me Anything (Anonymously) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'askmeanythingpeople' shortcode in all versions up to, and …

Jan 25, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.