CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-36684
7.1 HIGH

Missing Authorization vulnerability in Brainstorm Force Convert Pro.This issue affects Convert Pro: from n/a through 1.7.5.

Jun 19, 2024
CVE-2023-39998
8.2 HIGH

Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 27.1.1.

Jun 19, 2024
CVE-2023-38386
7.6 HIGH

Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.

Jun 19, 2024
CVE-2023-37870
8.1 HIGH

Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.1.9.

Jun 19, 2024
CVE-2023-35049
7.5 HIGH

Missing Authorization vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.4.0.

Jun 19, 2024
CVE-2023-47770
7.6 HIGH

Missing Authorization vulnerability in Muffin Group Betheme.This issue affects Betheme: from n/a through 27.1.1.

Jun 19, 2024
CVE-2023-46148
8.8 HIGH

Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.

Jun 19, 2024
CVE-2023-46146
8.3 HIGH

Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.

Jun 19, 2024
CVE-2023-45658
7.6 HIGH

Missing Authorization vulnerability in POSIMYTH Nexter.This issue affects Nexter: from n/a through 2.0.3.

Jun 19, 2024
CVE-2023-40608
8.2 HIGH

Missing Authorization vulnerability in Paid Memberships Pro Paid Memberships Pro CCBill Gateway.This issue affects Paid Memberships Pro CCBill Gateway: from n/a through 0.3.

Jun 19, 2024
CVE-2023-40004
7.3 HIGH

Missing Authorization vulnerability in ServMask All-in-One WP Migration Box Extension, ServMask All-in-One WP Migration OneDrive Extension, ServMask All-in-One WP Migration Dropbox Extension, ServMask All-in-One WP …

Jun 19, 2024
CVE-2024-35780
8.5 HIGH

Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.42.

Jun 19, 2024
CVE-2023-48760
8.2 HIGH

Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.

Jun 19, 2024
CVE-2023-48759
7.5 HIGH

Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.

Jun 19, 2024
CVE-2023-47783
8.3 HIGH

Missing Authorization vulnerability in Thrive Themes Thrive Theme Builder.This issue affects Thrive Theme Builder: from n/a before 3.24.0.

Jun 19, 2024
CVE-2023-47771
8.3 HIGH

Missing Authorization vulnerability in ThemePunch OHG Essential Grid.This issue affects Essential Grid: from n/a through 3.0.18.

Jun 19, 2024
CVE-2024-36978
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: sched: sch_multiq: fix possible OOB write in multiq_tune() q->bands will be assigned to qopt->bands …

Jun 19, 2024
CVE-2024-6132
8.8 HIGH

The Pexels: Free Stock Photos plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'pexels_fsp_images_options_validate' function in …

Jun 19, 2024
CVE-2024-5574
7.5 HIGH

The WP Magazine Modules Lite plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.2 via the 'blockLayout' …

Jun 19, 2024
CVE-2024-5343
8.8 HIGH

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Jun 19, 2024
CVE-2024-5724
8.8 HIGH

The Photo Video Gallery Master plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5.3 via deserialization of …

Jun 19, 2024
CVE-2024-2381
8.8 HIGH

The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_save_image function …

Jun 19, 2024
CVE-2024-6125
8.1 HIGH

The Login with phone number plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 1.7.34. This is due to …

Jun 19, 2024
CVE-2024-6146
8.8 HIGH

Actiontec WCB6200Q uh_get_postdata_withupload Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Actiontec WCB6200Q …

Jun 19, 2024
CVE-2024-6145
8.8 HIGH

Actiontec WCB6200Q Cookie Format String Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Actiontec WCB6200Q routers. …

Jun 19, 2024
CVE-2024-6144
8.8 HIGH

Actiontec WCB6200Q Multipart Boundary Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Actiontec …

Jun 19, 2024
CVE-2024-6143
8.8 HIGH

Actiontec WCB6200Q uh_tcp_recv_header Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Actiontec WCB6200Q routers. …

Jun 19, 2024
CVE-2024-6142
8.8 HIGH

Actiontec WCB6200Q uh_tcp_recv_content Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Actiontec WCB6200Q routers. …

Jun 19, 2024
CVE-2024-38276
8.8 HIGH

Incorrect CSRF token checks resulted in multiple CSRF risks.

Jun 18, 2024
CVE-2024-38275
7.5 HIGH

The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to …

Jun 18, 2024
CVE-2024-37821
8.8 HIGH

An arbitrary file upload vulnerability in the Upload Template function of Dolibarr ERP CRM up to v19.0.1 allows attackers to execute arbitrary code via uploading …

Jun 18, 2024
CVE-2024-36974
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/sched: taprio: always validate TCA_TAPRIO_ATTR_PRIOMAP If one TCA_TAPRIO_ATTR_PRIOMAP attribute has been provided, taprio_parse_mqprio_opt() must validate …

Jun 18, 2024
CVE-2024-22002
7.8 HIGH

CORSAIR iCUE 5.9.105 with iCUE Murals on Windows allows unprivileged users to insert DLL files in the cuepkg-1.2.6 subdirectory of the installation directory.

Jun 18, 2024
CVE-2022-23829
8.2 HIGH

A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native System Management Mode …

Jun 18, 2024
CVE-2024-38348
8.8 HIGH

CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Staff Info module via the searvalu parameter.

Jun 18, 2024
CVE-2024-38347
8.8 HIGH

CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Room Information module via the id parameter.

Jun 18, 2024
CVE-2024-37802
8.8 HIGH

CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Patient Info module via the searvalu parameter.

Jun 18, 2024
CVE-2024-5275
7.8 HIGH

A hard-coded password in the FileCatalyst TransferAgent can be found which can be used to unlock the keystore from which contents may be read out, …

Jun 18, 2024
CVE-2024-6116
7.3 HIGH

A vulnerability, which was classified as critical, has been found in itsourcecode Simple Online Hotel Reservation System 1.0. Affected by this issue is some unknown …

Jun 18, 2024
CVE-2023-47726
7.1 HIGH

IBM QRadar Suite Software 1.10.12.0 through 1.10.21.0 and IBM Cloud Pak for Security 1.10.12.0 through 1.10.21.0 could allow an authenticated user to execute certain arbitrary …

Jun 18, 2024
CVE-2024-6115
7.3 HIGH

A vulnerability classified as critical was found in itsourcecode Simple Online Hotel Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the …

Jun 18, 2024
CVE-2024-6114
7.3 HIGH

A vulnerability classified as critical has been found in itsourcecode Monbela Tourist Inn Online Reservation System up to 1.0. Affected is an unknown function of …

Jun 18, 2024
CVE-2024-6112
7.3 HIGH

A vulnerability classified as critical was found in itsourcecode Pool of Bethesda Online Reservation System 1.0. This vulnerability affects unknown code of the file index.php. …

Jun 18, 2024
CVE-2024-6111
7.3 HIGH

A vulnerability classified as critical has been found in itsourcecode Pool of Bethesda Online Reservation System 1.0. This affects an unknown part of the file …

Jun 18, 2024
CVE-2024-6110
7.3 HIGH

A vulnerability was found in itsourcecode Magbanua Beach Resort Online Reservation System up to 1.0. It has been rated as critical. Affected by this issue …

Jun 18, 2024
CVE-2024-37081
7.8 HIGH

The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues …

Jun 18, 2024
CVE-2024-33620
8.6 HIGH

Absolute path traversal vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, the file contents including sensitive information …

Jun 18, 2024
CVE-2023-5527
7.4 HIGH

The Business Directory Plugin plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.4.3 via the class-csv-exporter.php file. This allows …

Jun 18, 2024
CVE-2024-6084
7.3 HIGH

A vulnerability has been found in itsourcecode Pool of Bethesda Online Reservation System up to 1.0 and classified as critical. Affected by this vulnerability is …

Jun 18, 2024
CVE-2024-6080
7.8 HIGH

A vulnerability classified as critical was found in Intelbras InControl 2.21.56. This vulnerability affects unknown code of the component incontrolWebcam Service. The manipulation leads to …

Jun 17, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.