CVE Database

39204+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-2018
8.8 HIGH

The WP Activity Log Premium plugin for WordPress is vulnerable to SQL Injection via the entry->roles parameter in all versions up to, and including, 4.6.4 …

Apr 9, 2024
CVE-2024-24245
7.8 HIGH

An issue in Canimaan Software LTD ClamXAV v3.1.2 through v3.6.1 and fixed in v.3.6.2 allows a local attacker to escalate privileges via the ClamXAV helper …

Apr 9, 2024
CVE-2024-1991
8.8 HIGH

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to privilege escalation due to a missing capability …

Apr 9, 2024
CVE-2024-1990
8.8 HIGH

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to blind SQL Injection via the ‘id’ parameter …

Apr 9, 2024
CVE-2024-1974
8.8 HIGH

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.6 via …

Apr 9, 2024
CVE-2024-1934
7.5 HIGH

The WP Compress – Image Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wps_local_compress::__construct' …

Apr 9, 2024
CVE-2024-1893
8.8 HIGH

The Easy Property Listings plugin for WordPress is vulnerable to time-based SQL Injection via the ‘property_status’ shortcode attribute in all versions up to, and including, …

Apr 9, 2024
CVE-2024-1852
7.2 HIGH

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in all versions up to, and including, 3.4.9.2 …

Apr 9, 2024
CVE-2024-1812
7.2 HIGH

The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.7 via the 'font_url' parameter. This …

Apr 9, 2024
CVE-2024-1794
7.2 HIGH

The Forminator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. 3gpp file) in all versions up to, and including, …

Apr 9, 2024
CVE-2024-1792
7.5 HIGH

The CMB2 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.10.1 via deserialization of untrusted input from …

Apr 9, 2024
CVE-2024-1774
7.2 HIGH

The Customily Product Personalizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user cookies in all versions up to, and including, 1.23.3 due …

Apr 9, 2024
CVE-2024-1315
8.8 HIGH

The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

Apr 9, 2024
CVE-2024-1308
7.5 HIGH

The WooCommerce Cloak Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'permalink_settings_save' function …

Apr 9, 2024
CVE-2024-0952
7.2 HIGH

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL …

Apr 9, 2024
CVE-2023-7046
7.5 HIGH

The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, SSL Score plugin for WordPress is vulnerable to …

Apr 9, 2024
CVE-2023-6999
8.8 HIGH

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in all versions up to, and …

Apr 9, 2024
CVE-2023-6967
8.8 HIGH

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via shortcode in all versions up to, and including, …

Apr 9, 2024
CVE-2023-6964
8.5 HIGH

The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and …

Apr 9, 2024
CVE-2024-31507
8.6 HIGH

Sourcecodester Online Graduate Tracer System v1.0 is vulnerable to SQL Injection via the "request" parameter in admin/fetch_gendercs.php.

Apr 9, 2024
CVE-2024-31506
7.5 HIGH

Sourcecodester Online Graduate Tracer System v1.0 is vulnerable to SQL Injection via the "id" parameter in admin/admin_cs.php.

Apr 9, 2024
CVE-2024-31457
7.7 HIGH

gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. gin-vue-admin pseudoversion 0.0.0-20240407133540-7bc7c3051067, corresponding …

Apr 9, 2024
CVE-2024-25115
7.0 HIGH

RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 and 2.6.10, specially crafted `CF.LOADCHUNK` commands …

Apr 9, 2024
CVE-2024-22423
8.3 HIGH

yt-dlp is a youtube-dl fork with additional features and fixes. The patch that addressed CVE-2023-40581 attempted to prevent RCE when using `--exec` with `%q` by …

Apr 9, 2024
CVE-2024-29993
8.8 HIGH

Azure CycleCloud Elevation of Privilege Vulnerability

Apr 9, 2024
CVE-2024-29989
8.4 HIGH

Azure Monitor Agent Elevation of Privilege Vulnerability

Apr 9, 2024
CVE-2024-29988
8.8 HIGH KEV

SmartScreen Prompt Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-29985
8.8 HIGH

Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-29984
8.8 HIGH

Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-29983
8.8 HIGH

Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-29982
8.8 HIGH

Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-29905
8.1 HIGH

DIRAC is an interware, meaning a software framework for distributed computing. Prior to version 8.0.41, during the proxy generation process (e.g., when using `dirac-proxy-init`), it …

Apr 9, 2024
CVE-2024-29066
7.2 HIGH

Windows Distributed File System (DFS) Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-29063
7.3 HIGH

Azure AI Search Information Disclosure Vulnerability

Apr 9, 2024
CVE-2024-29062
7.1 HIGH

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-29061
7.8 HIGH

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-29055
7.2 HIGH

Microsoft Defender for IoT Elevation of Privilege Vulnerability

Apr 9, 2024
CVE-2024-29054
7.2 HIGH

Microsoft Defender for IoT Elevation of Privilege Vulnerability

Apr 9, 2024
CVE-2024-29053
8.8 HIGH

Microsoft Defender for IoT Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-29052
7.8 HIGH

Windows Storage Elevation of Privilege Vulnerability

Apr 9, 2024
CVE-2024-29050
8.4 HIGH

Windows Cryptographic Services Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-29048
8.8 HIGH

Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-29047
8.8 HIGH

Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-29046
8.8 HIGH

Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-29045
7.5 HIGH

Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-29044
8.8 HIGH

Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-29043
8.8 HIGH

Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-28945
8.8 HIGH

Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-28944
8.8 HIGH

Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-28943
8.8 HIGH

Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

Apr 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.