CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8505
6.4 MEDIUM

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_label’ parameter in all versions up …

Oct 2, 2024
CVE-2024-8282
6.4 MEDIUM

The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ attribute within the 'wp:ive/ive-productscarousel' Gutenberg block in …

Oct 2, 2024
CVE-2024-9378
6.1 MEDIUM

The YML for Yandex Market plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, …

Oct 2, 2024
CVE-2024-9344
6.1 MEDIUM

The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is vulnerable to Reflected …

Oct 2, 2024
CVE-2024-9218
6.1 MEDIUM

The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to Reflected …

Oct 2, 2024
CVE-2024-9225
6.1 MEDIUM

The SEOPress – On-site SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping …

Oct 2, 2024
CVE-2024-9222
6.1 MEDIUM

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use …

Oct 2, 2024
CVE-2024-9210
6.1 MEDIUM

The MC4WP: Mailchimp Top Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …

Oct 2, 2024
CVE-2024-9172
6.4 MEDIUM

The Demo Importer Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0.1 …

Oct 2, 2024
CVE-2024-8967
6.4 MEDIUM

The PWA — easy way to Progressive Web App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions …

Oct 2, 2024
CVE-2024-8800
6.1 MEDIUM

The RabbitLoader – Website Speed Optimization for improving Core Web Vital metrics with Cache, Image Optimization, and more plugin for WordPress is vulnerable to Reflected …

Oct 2, 2024
CVE-2024-8254
5.4 MEDIUM

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in …

Oct 2, 2024
CVE-2024-9174
5.4 MEDIUM

Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UI

Oct 2, 2024
CVE-2024-21530
4.5 MEDIUM

Versions of the package cocoon before 0.4.0 are vulnerable to Reusing a Nonce, Key Pair in Encryption when the encrypt, wrap, and dump functions are …

Oct 2, 2024
CVE-2024-9407
4.7 MEDIUM

A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not properly validate the input passed to this option, …

Oct 1, 2024
CVE-2024-47528
4.8 MEDIUM

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Stored Cross-Site Scripting (XSS) can be achieved by uploading a new Background for a Custom Map. Users …

Oct 1, 2024
CVE-2024-46082
5.4 MEDIUM

Scriptcase v.9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in nm_cor.php via the form and field parameters.

Oct 1, 2024
CVE-2024-9355
6.5 MEDIUM

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed …

Oct 1, 2024
CVE-2024-9341
5.4 MEDIUM

A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper …

Oct 1, 2024
CVE-2024-46083
5.4 MEDIUM

Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads using the messages feature, which allows the …

Oct 1, 2024
CVE-2024-46081
5.4 MEDIUM

Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads in the To-Do List. The assigned user …

Oct 1, 2024
CVE-2024-46079
6.1 MEDIUM

Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in proj_new.php via the Descricao parameter.

Oct 1, 2024
CVE-2024-31835
4.8 MEDIUM

Cross Site Scripting vulnerability in flatpress CMS Flatpress v1.3 allows a remote attacker to execute arbitrary code via a crafted payload to the file name …

Oct 1, 2024
CVE-2024-9398
5.3 MEDIUM

By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler …

Oct 1, 2024
CVE-2024-9397
6.1 MEDIUM

A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This …

Oct 1, 2024
CVE-2024-9395
5.3 MEDIUM

A specially crafted filename containing a large number of spaces could obscure the file's extension when displayed in the download dialog. *This bug only affects …

Oct 1, 2024
CVE-2024-9391
6.5 MEDIUM

A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing …

Oct 1, 2024
CVE-2024-47071
6.8 MEDIUM

OSS Endpoint Manager is an endpoint manager module for FreePBX. OSS Endpoint Manager module activation can allow authenticated web users unauthorized access to read system …

Oct 1, 2024
CVE-2024-45967
4.7 MEDIUM

Pagekit 1.0.18 is vulnerable to Cross Site Scripting (XSS) in index.php/admin/site/widget.

Oct 1, 2024
CVE-2024-44610
5.6 MEDIUM

PCAN-Ethernet Gateway FD before 1.3.0 and PCAN-Ethernet Gateway before 2.11.0 are vulnerable to Command injection via shell metacharacters in a Software Update to processing.php.

Oct 1, 2024
CVE-2024-25658
6.5 MEDIUM

Cleartext storage of passwords in Infinera TNMS (Transcend Network Management System) Server 19.10.3 allows attackers (with access to the database or exported configuration files) to …

Oct 1, 2024
CVE-2021-37577
6.8 MEDIUM

Bluetooth LE and BR/EDR Secure Connections pairing and Secure Simple Pairing using the Passkey entry protocol in Bluetooth Core Specifications 2.1 through 5.3 may permit …

Oct 1, 2024
CVE-2024-44744
5.7 MEDIUM

An issue in Malwarebytes Premium Security v5.0.0.883 allows attackers to execute arbitrary code via placing crafted binaries into unspecified directories. NOTE: Malwarebytes argues that this …

Oct 1, 2024
CVE-2023-7273
6.8 MEDIUM

Cross site request forgery in Kiteworks OwnCloud allows an unauthenticated attacker to forge requests. If a request has no Authorization header, it is created with …

Oct 1, 2024
CVE-2024-9405
5.3 MEDIUM

An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting version 4.7.18. An unauthenticated attacker could …

Oct 1, 2024
CVE-2024-9118
6.4 MEDIUM

The QS Dark Mode Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Oct 1, 2024
CVE-2024-9060
6.4 MEDIUM

The AVIF & SVG Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in version 1.1.0 due to insufficient input …

Oct 1, 2024
CVE-2023-3441
6.6 MEDIUM

An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4. The product did not sufficiently warn about security implications …

Oct 1, 2024
CVE-2024-9241
6.1 MEDIUM

The PDF Image Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Oct 1, 2024
CVE-2024-9228
6.1 MEDIUM

The Loggedin – Limit Active Logins plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on …

Oct 1, 2024
CVE-2024-9224
6.5 MEDIUM

The Hello World plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 2.1.1 via the hello_world_lyric() function. This …

Oct 1, 2024
CVE-2024-9220
6.1 MEDIUM

The LH Copy Media File plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the …

Oct 1, 2024
CVE-2024-9209
6.1 MEDIUM

The WP Search Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Oct 1, 2024
CVE-2024-8799
6.1 MEDIUM

The Custom Banners plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in …

Oct 1, 2024
CVE-2024-8793
6.1 MEDIUM

The Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to …

Oct 1, 2024
CVE-2024-8786
6.1 MEDIUM

The Auto Featured Image from Title plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on …

Oct 1, 2024
CVE-2024-8430
5.3 MEDIUM

The Spice Starter Sites plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the spice_starter_sites_importer_creater function in …

Oct 1, 2024
CVE-2024-8324
6.4 MEDIUM

The XO Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘get_slider’ function in all versions up to, and including, 3.8.6 due …

Oct 1, 2024
CVE-2024-8288
6.4 MEDIUM

The Guten Post Layout – An Advanced Post Grid Collection for WordPress Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ …

Oct 1, 2024
CVE-2024-9304
6.4 MEDIUM

The LocateAndFilter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.14 due to …

Oct 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.