CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-46600
4.7 MEDIUM

dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/doAdminAction.php?act=delCate&id=31

Sep 25, 2024
CVE-2024-46485
6.3 MEDIUM

dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=addCate

Sep 25, 2024
CVE-2024-43990
5.3 MEDIUM

Insertion of Sensitive Information into Log File vulnerability in StylemixThemes Masterstudy LMS Starter.This issue affects Masterstudy LMS Starter: from n/a through 1.1.8.

Sep 25, 2024
CVE-2024-43237
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Steve Burge WordPress Tag Cloud Plugin – Tag Groups tag-groups.This issue affects WordPress Tag Cloud …

Sep 25, 2024
CVE-2024-6512
6.5 MEDIUM

Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows authenticated users with permissions to approve their own requests, …

Sep 25, 2024
CVE-2024-45613
6.1 MEDIUM

CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prior to version 43.1.1, a Cross-Site Scripting (XSS) vulnerability is present in the …

Sep 25, 2024
CVE-2024-8546
6.4 MEDIUM

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video widget in all versions up to, and including, …

Sep 25, 2024
CVE-2024-8858
6.4 MEDIUM

The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘piechart_settings’ parameter in all versions up to, and including, …

Sep 25, 2024
CVE-2024-9169
5.5 MEDIUM

The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all versions up to, and including, 6.4.1 due …

Sep 25, 2024
CVE-2024-47303
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh Addons for Elementor addons-for-elementor allows Cross-Site Scripting (XSS).This issue affects Livemesh …

Sep 25, 2024
CVE-2024-40761
5.3 MEDIUM

Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. Using the MD5 value of a user's email to access Gravatar …

Sep 25, 2024
CVE-2024-23454
6.2 MEDIUM

Apache Hadoop’s RunJar.run() does not set permissions for temporary directory by default. If sensitive data will be present in this file, all the other local …

Sep 25, 2024
CVE-2024-8910
4.3 MEDIUM

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.5 …

Sep 25, 2024
CVE-2024-8678
5.3 MEDIUM

The Revolut Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wc/v3/revolut REST …

Sep 25, 2024
CVE-2024-3866
4.7 MEDIUM

The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Referer' header in all versions up to, and …

Sep 25, 2024
CVE-2024-8658
5.3 MEDIUM

The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification …

Sep 25, 2024
CVE-2024-7892
4.3 MEDIUM

The adstxt Plugin WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Sep 25, 2024
CVE-2024-7878
4.8 MEDIUM

The WP ULike WordPress plugin before 4.7.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Sep 25, 2024
CVE-2024-6845
5.3 MEDIUM

The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users to retrieve the …

Sep 25, 2024
CVE-2024-8668
6.4 MEDIUM

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored …

Sep 25, 2024
CVE-2024-8516
4.3 MEDIUM

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.1 via the render() function. …

Sep 25, 2024
CVE-2024-8515
6.4 MEDIUM

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets like 'TF E Slider Widget', 'TF Video Widget', …

Sep 25, 2024
CVE-2024-9073
6.4 MEDIUM

The GutenGeek Free Gutenberg Blocks for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, …

Sep 25, 2024
CVE-2024-9069
6.4 MEDIUM

The Graphicsly – The ultimate graphics plugin for WordPress website builder ( Gutenberg, Elementor, Beaver Builder, WPBakery ) plugin for WordPress is vulnerable to Stored …

Sep 25, 2024
CVE-2024-9068
6.4 MEDIUM

The OneElements – Best Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and …

Sep 25, 2024
CVE-2024-9028
6.4 MEDIUM

The WP GPX Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sgpx' shortcode in all versions up to, and including, …

Sep 25, 2024
CVE-2024-9027
6.4 MEDIUM

The WPZOOM Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcode in all versions up to, and including, 1.0.5 …

Sep 25, 2024
CVE-2024-9024
6.4 MEDIUM

The Material Design Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mdi-icon shortcode in all versions up to, and including, …

Sep 25, 2024
CVE-2024-8741
6.1 MEDIUM

The Beam me up Scotty – Back to Top Button plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg …

Sep 25, 2024
CVE-2024-8713
6.1 MEDIUM

The Kodex Posts likes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Sep 25, 2024
CVE-2024-8549
6.1 MEDIUM

The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping …

Sep 25, 2024
CVE-2024-8483
4.3 MEDIUM

The MAS Static Content plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.8 via the static_content() function. This …

Sep 25, 2024
CVE-2024-8476
4.3 MEDIUM

The Easy PayPal Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to …

Sep 25, 2024
CVE-2024-8434
4.3 MEDIUM

The Easy Mega Menu Plugin for WordPress – ThemeHunk plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several …

Sep 25, 2024
CVE-2024-7491
5.3 MEDIUM

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Sep 25, 2024
CVE-2024-7426
5.3 MEDIUM

The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, …

Sep 25, 2024
CVE-2024-7386
4.3 MEDIUM

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.1. …

Sep 25, 2024
CVE-2024-6590
6.3 MEDIUM

The Spreadsheet Integration – Automate Google Sheets With WordPress, WooCommerce & Most Popular Form Plugins. Also, Display Google sheet as a Table. plugin for WordPress …

Sep 25, 2024
CVE-2024-9141
5.4 MEDIUM

Cross-Site Scripting (XSS) vulnerability in the Oct8ne system. This flaw could allow an attacker to embed harmful JavaScript code into the body of a chat …

Sep 25, 2024
CVE-2024-8942
6.3 MEDIUM

Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input validation, affecting the “id_form_msg_title” parameter, among others. …

Sep 25, 2024
CVE-2024-8919
6.4 MEDIUM

The Confetti Fall Animation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'confetti-fall-animation' shortcode in all versions up to, and including, …

Sep 25, 2024
CVE-2024-8917
6.4 MEDIUM

The AnWP Football Leagues plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.16.7 …

Sep 25, 2024
CVE-2024-8801
4.3 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.2 via the Content …

Sep 25, 2024
CVE-2024-8437
4.3 MEDIUM

The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions …

Sep 25, 2024
CVE-2024-8291
4.8 MEDIUM

Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in Image Editor Background Color. A rogue admin could add malicious …

Sep 25, 2024
CVE-2024-8267
6.4 MEDIUM

The Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Sep 25, 2024
CVE-2024-8103
6.4 MEDIUM

The WP Category Dropdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' parameter in all versions up to, and including, 1.8 …

Sep 25, 2024
CVE-2024-7398
5.4 MEDIUM

Concrete CMS versions 9 through 9.3.3 and versions below 8.5.19 are vulnerable to stored XSS in the calendar event addition feature because the calendar event …

Sep 25, 2024
CVE-2024-47048
5.4 MEDIUM

Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier allows stored XSS in the description and release notes of the marketplace and private apps.

Sep 25, 2024
CVE-2024-46934
6.1 MEDIUM

Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to DOM-based Cross-site Scripting (XSS). Attackers may be able to abuse the UpdateOTRAck method …

Sep 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.