CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-49265
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SPBooking.com Booking.com Banner Creator bookingcom-banner-creator.This issue affects Booking.com Banner Creator: from n/a through …

Oct 16, 2024
CVE-2024-29155
4.3 MEDIUM

On Microchip RN4870 devices, when more than one consecutive PairReqNoInputNoOutput request is received, the device becomes incapable of completing the pairing process. A third party …

Oct 16, 2024
CVE-2024-49267
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nayon46 Unlimited Addon For Elementor unlimited-addon-for-elementor allows Stored XSS.This issue affects Unlimited Addon …

Oct 16, 2024
CVE-2024-49266
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thimo Grauerholz WP-Spreadplugin wp-spreadplugin allows Cross-Site Scripting (XSS).This issue affects WP-Spreadplugin: from n/a …

Oct 16, 2024
CVE-2024-48744
6.1 MEDIUM

A Reflected Cross Site Scripting (XSS) vulnerability was found in /trms/listed- teachers.php in PHPGurukul Teachers Record Management System v2.1, which allows remote attackers to execute …

Oct 16, 2024
CVE-2024-47139
6.8 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the Administrator role to …

Oct 16, 2024
CVE-2024-49270
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Smart Blocks smart-blocks allows Stored XSS.This issue affects Smart Blocks: from n/a …

Oct 16, 2024
CVE-2024-49258
6.5 MEDIUM

Path Traversal: '.../...//' vulnerability in Limbcode WordPress Gallery Plugin – Limb Image Gallery limb-gallery.This issue affects WordPress Gallery Plugin – Limb Image Gallery: from n/a …

Oct 16, 2024
CVE-2024-49252
5.3 MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in VaultDweller Leyka leyka.This issue affects Leyka: from n/a through <= 3.31.6.

Oct 16, 2024
CVE-2024-22034
5.5 MEDIUM

Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc …

Oct 16, 2024
CVE-2024-22033
6.3 MEDIUM

The OBS service obs-service-download_url was vulnerable to a command injection vulnerability. The attacker could provide a configuration to the service that allowed to execute command …

Oct 16, 2024
CVE-2024-22032
6.5 MEDIUM

A vulnerability has been identified in which an RKE1 cluster keeps constantly reconciling when secrets encryption configuration is enabled. When reconciling, the Kube API secret …

Oct 16, 2024
CVE-2023-32189
5.9 MEDIUM

Insecure handling of ssh keys used to bootstrap clients allows local attackers to potentially gain access to the keys

Oct 16, 2024
CVE-2024-10024
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Pharmacy Management System 1.0. This issue affects some unknown processing of the file …

Oct 16, 2024
CVE-2024-10023
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Pharmacy Management System 1.0. This vulnerability affects unknown code of the file /php/add_new_medicine.php. The manipulation of …

Oct 16, 2024
CVE-2023-32196
6.6 MEDIUM

A vulnerability has been identified whereby privilege escalation checks are not properly enforced for RoleTemplateobjects when external=true, which in specific scenarios can lead to privilege …

Oct 16, 2024
CVE-2020-36841
5.3 MEDIUM

The WooCommerce Smart Coupons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the woocommerce_coupon_admin_init function in versions up …

Oct 16, 2024
CVE-2024-10022
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. This affects an unknown part of the file /php/manage_supplier.php?action=search. The manipulation …

Oct 16, 2024
CVE-2024-10021
6.3 MEDIUM

A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Oct 16, 2024
CVE-2024-8921
6.4 MEDIUM

The Zita Elementor Site Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Oct 16, 2024
CVE-2024-9444
6.4 MEDIUM

The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Oct 16, 2024
CVE-2024-9540
4.3 MEDIUM

The Sina Extension for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.7 via the render …

Oct 16, 2024
CVE-2024-45714
4.8 MEDIUM

Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a variable with a payload.

Oct 16, 2024
CVE-2024-45462
6.3 MEDIUM

The logout operation in the CloudStack web interface does not expire the user session completely which is valid until expiry by time or restart of …

Oct 16, 2024
CVE-2024-45461
5.7 MEDIUM

The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources, and is disabled by default. In environments …

Oct 16, 2024
CVE-2023-7296
6.4 MEDIUM

The BigBlueButton plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the moderator code and viewer code fields in versions up to, and …

Oct 16, 2024
CVE-2023-7295
6.1 MEDIUM

The Video Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.21 due to …

Oct 16, 2024
CVE-2017-20194
5.3 MEDIUM

The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. …

Oct 16, 2024
CVE-2017-20193
4.7 MEDIUM

The Product Vendors is vulnerable to Reflected Cross-Site Scripting via the 'vendor_description' parameter in versions up to, and including, 2.0.35 due to insufficient input sanitization …

Oct 16, 2024
CVE-2024-9582
6.4 MEDIUM

The Accordion Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ attribute of an accordion slider in all versions up to, …

Oct 16, 2024
CVE-2023-7293
4.3 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the …

Oct 16, 2024
CVE-2023-7292
4.3 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized notification dismissal due to a missing capability check on the paytium_notice_dismiss …

Oct 16, 2024
CVE-2023-7290
4.3 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the …

Oct 16, 2024
CVE-2023-7289
5.4 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized API key update due to a missing capability check on the …

Oct 16, 2024
CVE-2023-7288
5.4 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_profile_preference …

Oct 16, 2024
CVE-2023-7287
5.4 MEDIUM

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized subscription cancellation due to a missing capability check on the pt_cancel_subscription …

Oct 16, 2024
CVE-2023-7286
6.5 MEDIUM

The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.2.2. This makes it …

Oct 16, 2024
CVE-2022-4974
6.3 MEDIUM

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing …

Oct 16, 2024
CVE-2022-4973
4.9 MEDIUM

WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploited by users with access to the WordPress …

Oct 16, 2024
CVE-2022-4971
6.1 MEDIUM

The Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'urls' parameter called via the 'heateor_sss_sharing_count' AJAX action in versions …

Oct 16, 2024
CVE-2021-4451
6.6 MEDIUM

The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and including, 4.3.3. This allows authenticated attackers to perform phar …

Oct 16, 2024
CVE-2021-4446
6.3 MEDIUM

The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and including 4.6.4 due to missing capability checks …

Oct 16, 2024
CVE-2021-4445
6.5 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to Arbitrary Option Updates in versions up to, and including, 4.5.1. This is due to …

Oct 16, 2024
CVE-2020-36835
4.9 MEDIUM

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks …

Oct 16, 2024
CVE-2020-36834
6.3 MEDIUM

The Discount Rules for WooCommerce plugin for WordPress is vulnerable to missing authorization via several AJAX actions in versions up to, and including, 2.0.2 due …

Oct 16, 2024
CVE-2020-36833
6.3 MEDIUM

The Indeed Membership Pro plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various AJAX actions in versions 7.3 - …

Oct 16, 2024
CVE-2020-36831
5.0 MEDIUM

The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple user privilege/security functions provided in …

Oct 16, 2024
CVE-2024-9937
6.1 MEDIUM

The Woo Manage Fraud Orders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, …

Oct 16, 2024
CVE-2024-9888
5.4 MEDIUM

The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's contact form widget redirect URL in all versions …

Oct 16, 2024
CVE-2024-9873
5.4 MEDIUM

The Community by PeepSo – Social Network, Membership, Registration, User Profiles, Premium – Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Oct 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.