CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10877
6.1 MEDIUM

The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without …

Nov 13, 2024
CVE-2024-52268
4.8 MEDIUM

Cross-site scripting vulnerability exists in VK All in One Expansion Unit versions prior to 9.100.1.0. If this vulnerability is exploited, an arbitrary script may be …

Nov 13, 2024
CVE-2024-8937
6.5 MEDIUM

CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a potential arbitrary code execution after a successful …

Nov 13, 2024
CVE-2024-8936
6.5 MEDIUM

CWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory after a successful Man-In-The-Middle attack followed by sending a …

Nov 13, 2024
CVE-2024-10802
5.3 MEDIUM

The Hash Elements plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hash_elements_get_posts_title_by_id() function in all …

Nov 13, 2024
CVE-2024-10794
4.3 MEDIUM

The Boostify Header Footer Builder for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.6 via the …

Nov 13, 2024
CVE-2024-11143
4.3 MEDIUM

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.8. This is due …

Nov 13, 2024
CVE-2024-10882
6.1 MEDIUM

The Product Delivery Date for WooCommerce – Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg …

Nov 13, 2024
CVE-2024-10684
6.1 MEDIUM

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dir' parameter in all versions up to, and including, …

Nov 13, 2024
CVE-2024-10593
4.3 MEDIUM

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Cross-Site Request Forgery …

Nov 13, 2024
CVE-2024-10531
5.3 MEDIUM

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_assistant() function …

Nov 13, 2024
CVE-2024-10530
4.3 MEDIUM

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the add_new_assistant() function …

Nov 13, 2024
CVE-2024-10529
5.3 MEDIUM

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_assistant() function …

Nov 13, 2024
CVE-2024-9614
6.1 MEDIUM

The Constant Contact Forms by MailMunch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on …

Nov 13, 2024
CVE-2024-9578
5.3 MEDIUM

The Hide Links plugin for WordPress is vulnerable to unauthorized shortcode execution due to do_shortcode being hooked through the comment_text filter in all versions up …

Nov 13, 2024
CVE-2024-9426
6.4 MEDIUM

The Aqua SVG Sprite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.0.14 …

Nov 13, 2024
CVE-2024-8985
6.4 MEDIUM

The Social Proof (Testimonial) Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's spslider-block shortcode in all versions up to, and …

Nov 13, 2024
CVE-2024-8874
6.1 MEDIUM

The AJAX Login and Registration modal popup + inline form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg …

Nov 13, 2024
CVE-2024-38654
4.4 MEDIUM

Improper bounds checking in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker with admin privileges to cause a denial of service.

Nov 13, 2024
CVE-2024-29211
4.7 MEDIUM

A race condition in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to modify sensitive configuration files.

Nov 13, 2024
CVE-2024-10887
6.4 MEDIUM

The NiceJob plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes (nicejob-lead, nicejob-review, nicejob-engage, nicejob-badge, nicejob-stories) in all versions …

Nov 13, 2024
CVE-2024-10854
4.3 MEDIUM

The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the buy_one_click_import_options AJAX …

Nov 13, 2024
CVE-2024-10853
4.3 MEDIUM

The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the removeorder AJAX …

Nov 13, 2024
CVE-2024-10852
4.3 MEDIUM

The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the buy_one_click_export_options AJAX …

Nov 13, 2024
CVE-2024-10851
6.1 MEDIUM

The Razorpay Payment Button Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping …

Nov 13, 2024
CVE-2024-10850
6.1 MEDIUM

The Razorpay Payment Button Elementor Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate …

Nov 13, 2024
CVE-2024-10778
4.3 MEDIUM

The BuddyPress Builder for Elementor – BuddyBuilder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.4 via the …

Nov 13, 2024
CVE-2024-10717
6.5 MEDIUM

The Styler for Ninja Forms plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to …

Nov 13, 2024
CVE-2024-10577
6.1 MEDIUM

The 胖鼠采集(Fat Rat Collect) 微信知乎简书腾讯新闻列表分页采集, 还有自动采集、自动发布、自动标签、等多项功能。开源插件 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to missing escaping on a URL in all versions …

Nov 13, 2024
CVE-2024-10038
6.1 MEDIUM

The WP-Strava plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.12.1 due to insufficient …

Nov 13, 2024
CVE-2024-28731
4.3 MEDIUM

Cross Site Request Forgery vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker …

Nov 12, 2024
CVE-2024-28730
5.4 MEDIUM

Cross Site Scripting vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to …

Nov 12, 2024
CVE-2024-28728
6.6 MEDIUM

Cross Site Scripting vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to …

Nov 12, 2024
CVE-2021-27704
6.5 MEDIUM

Appspace 6.2.4 is affected by Incorrect Access Control via the Appspace Web Portal password reset page.

Nov 12, 2024
CVE-2021-27703
5.4 MEDIUM

Sercomm Model Etisalat Model S3- AC2100 is affected by Cross Site Scripting (XSS) via the firmware update page.

Nov 12, 2024
CVE-2021-27701
4.7 MEDIUM

SOCIFI Socifi Guest wifi as SAAS is affected by Cross Site Request Forgery (CSRF) via the Socifi wifi portal. The application does not contain a …

Nov 12, 2024
CVE-2024-48075
5.3 MEDIUM

A Heap buffer overflow in the server-site handshake implementation in Real Time Logic SharkSSL from 09/09/24 and earlier allows a remote attacker to trigger a …

Nov 12, 2024
CVE-2024-49512
5.5 MEDIUM

InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Nov 12, 2024
CVE-2024-49511
5.5 MEDIUM

InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Nov 12, 2024
CVE-2024-49510
5.5 MEDIUM

InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Nov 12, 2024
CVE-2024-11117
4.3 MEDIUM

Inappropriate implementation in FileSystem in Google Chrome prior to 131.0.6778.69 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security …

Nov 12, 2024
CVE-2024-11116
4.3 MEDIUM

Inappropriate implementation in Blink in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Nov 12, 2024
CVE-2024-11111
4.3 MEDIUM

Inappropriate implementation in Autofill in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Nov 12, 2024
CVE-2024-11110
6.5 MEDIUM

Inappropriate implementation in Extensions in Google Chrome prior to 131.0.6778.69 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension. (Chromium security …

Nov 12, 2024
CVE-2024-47440
5.5 MEDIUM

Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Nov 12, 2024
CVE-2024-47439
5.5 MEDIUM

Substance3D - Painter versions 10.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could …

Nov 12, 2024
CVE-2024-47438
5.5 MEDIUM

Substance3D - Painter versions 10.1.0 and earlier are affected by a Write-what-where Condition vulnerability that could lead to a memory leak. This vulnerability allows an …

Nov 12, 2024
CVE-2024-47437
5.5 MEDIUM

Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Nov 12, 2024
CVE-2024-47436
5.5 MEDIUM

Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Nov 12, 2024
CVE-2024-47435
5.5 MEDIUM

Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Nov 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.