CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6729
6.3 MEDIUM

A vulnerability was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of …

Jul 14, 2024
CVE-2024-6728
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been classified as critical. This affects an unknown part of the file typeedit.php. …

Jul 14, 2024
CVE-2024-6465
4.3 MEDIUM

The WP Links Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wplf_ajax_update_screenshots' function in …

Jul 13, 2024
CVE-2024-6574
5.3 MEDIUM

The Laposta plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.12. This is due to the plugin …

Jul 13, 2024
CVE-2024-6070
4.8 MEDIUM

The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jul 13, 2024
CVE-2024-5744
6.8 MEDIUM

The wp-eMember WordPress plugin before 10.6.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site …

Jul 13, 2024
CVE-2024-5713
5.4 MEDIUM

The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.4 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead …

Jul 13, 2024
CVE-2024-5644
5.4 MEDIUM

The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jul 13, 2024
CVE-2024-5627
5.4 MEDIUM

The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some parameters, which could allow users with a role as low as subscriber to …

Jul 13, 2024
CVE-2024-5575
4.7 MEDIUM

The Ditty WordPress plugin before 3.1.43 does not sanitise and escape some of its blocks' settings, which could allow high privilege users such as authors …

Jul 13, 2024
CVE-2024-5442
5.9 MEDIUM

The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.3 does not sanitise and escape some of its settings, which could allow high privilege users …

Jul 13, 2024
CVE-2024-5286
4.8 MEDIUM

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jul 13, 2024
CVE-2024-5284
6.8 MEDIUM

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Jul 13, 2024
CVE-2024-5283
6.1 MEDIUM

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jul 13, 2024
CVE-2024-5282
6.1 MEDIUM

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jul 13, 2024
CVE-2024-5281
6.1 MEDIUM

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jul 13, 2024
CVE-2024-5280
4.7 MEDIUM

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Jul 13, 2024
CVE-2024-5079
6.1 MEDIUM

The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape some of the fields when members register, which allows unauthenticated users to perform Stored …

Jul 13, 2024
CVE-2024-5077
6.8 MEDIUM

The wp-eMember WordPress plugin before 10.6.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Jul 13, 2024
CVE-2024-5075
5.9 MEDIUM

The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jul 13, 2024
CVE-2024-5074
5.4 MEDIUM

The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jul 13, 2024
CVE-2024-5033
5.9 MEDIUM

The SULly WordPress plugin before 4.3.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Jul 13, 2024
CVE-2024-5032
4.7 MEDIUM

The SULly WordPress plugin before 4.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jul 13, 2024
CVE-2024-5028
6.5 MEDIUM

The CM WordPress Search And Replace Plugin WordPress plugin before 1.3.9 does not have CSRF checks in some places, which could allow attackers to make …

Jul 13, 2024
CVE-2024-5002
4.8 MEDIUM

The User Submitted Posts WordPress plugin before 20240516 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jul 13, 2024
CVE-2024-4977
6.8 MEDIUM

The Index WP MySQL For Speed WordPress plugin before 1.4.18 does not sanitise and escape a parameter before outputting it back in the page, leading …

Jul 13, 2024
CVE-2024-4752
5.9 MEDIUM

The EventON WordPress plugin before 2.2.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jul 13, 2024
CVE-2024-4602
5.4 MEDIUM

The Embed Peertube Playlist WordPress plugin before 1.10 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jul 13, 2024
CVE-2024-4272
6.1 MEDIUM

The Support SVG WordPress plugin before 1.1.0 does not sanitize SVG file contents, which enables users with at least the author role to SVG with …

Jul 13, 2024
CVE-2024-4269
6.1 MEDIUM

The SVG Block WordPress plugin before 1.1.20 does not sanitize SVG file contents, which enables users with at least the author role to SVG with …

Jul 13, 2024
CVE-2024-4217
4.7 MEDIUM

The shortcodes-ultimate-pro WordPress plugin before 7.1.5 does not properly escape some of its shortcodes' settings, making it possible for attackers with a Contributor account to …

Jul 13, 2024
CVE-2024-3964
5.9 MEDIUM

The Product Enquiry for WooCommerce WordPress plugin before 3.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jul 13, 2024
CVE-2024-3963
6.5 MEDIUM

The Giveaways and Contests by RafflePress WordPress plugin before 1.12.14 does not sanitise and escape some parameters, which could allow users with a role as …

Jul 13, 2024
CVE-2024-3919
4.6 MEDIUM

The OpenPGP Form Encryption for WordPress plugin before 1.5.1 does not validate and escape some of its shortcode attributes before outputting them back in a …

Jul 13, 2024
CVE-2024-3753
5.9 MEDIUM

The Hostel WordPress plugin before 1.1.5.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jul 13, 2024
CVE-2024-3751
4.8 MEDIUM

The Seriously Simple Podcasting WordPress plugin before 3.3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jul 13, 2024
CVE-2024-3710
6.8 MEDIUM

The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.0 does not validate and escape some of its shortcode attributes before outputting them back …

Jul 13, 2024
CVE-2024-3632
6.8 MEDIUM

The Smart Image Gallery WordPress plugin before 1.0.19 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Jul 13, 2024
CVE-2024-3026
5.4 MEDIUM

The WordPress Button Plugin MaxButtons WordPress plugin before 9.7.8 does not sanitise and escape some parameters, which could allow users with a role as low …

Jul 13, 2024
CVE-2024-2870
6.1 MEDIUM

The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jul 13, 2024
CVE-2023-39329
6.5 MEDIUM

A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial …

Jul 13, 2024
CVE-2023-39327
4.3 MEDIUM

A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the …

Jul 13, 2024
CVE-2024-31947
6.5 MEDIUM

StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows Directory Traversal by authenticated users. Using a crafted path parameter with the Online Help facility can …

Jul 12, 2024
CVE-2024-40690
5.4 MEDIUM

IBM InfoSphere Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus …

Jul 12, 2024
CVE-2024-40547
6.5 MEDIUM

PublicCMS v4.0.202302.e was discovered to contain an arbitrary file content replacement vulnerability via the component /admin/cmsTemplate/replace.

Jul 12, 2024
CVE-2024-38716
6.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Blue Plugins Events Calendar for Google allows PHP Local File Inclusion.This issue …

Jul 12, 2024
CVE-2024-37405
6.5 MEDIUM

Livechat messages can be leaked by combining two NoSQL injections affecting livechat:loginByToken (pre-authentication) and livechat:loadHistory.

Jul 12, 2024
CVE-2024-39916
6.4 MEDIUM

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. There is a security issue with the NFS configuration in /etc/exports generated by the installer that …

Jul 12, 2024
CVE-2024-39909
6.5 MEDIUM

KubeClarity is a tool for detection and management of Software Bill Of Materials (SBOM) and vulnerabilities of container images and filesystems. A time/boolean SQL Injection …

Jul 12, 2024
CVE-2024-38715
6.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ExS ExS Widgets allows PHP Local File Inclusion.This issue affects ExS Widgets: …

Jul 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.