CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-44151
5.4 MEDIUM

Missing Authorization vulnerability in Brainstorm Force Pre-Publish Checklist.This issue affects Pre-Publish Checklist: from n/a through 1.1.1.

Jun 19, 2024
CVE-2023-44148
5.4 MEDIUM

Missing Authorization vulnerability in Brainstorm Force Astra Bulk Edit.This issue affects Astra Bulk Edit: from n/a through 1.2.7.

Jun 19, 2024
CVE-2024-35765
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wpsoul Greenshift – animation and page builder blocks allows Stored XSS.This …

Jun 19, 2024
CVE-2023-48761
6.3 MEDIUM

Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.

Jun 19, 2024
CVE-2023-47788
4.3 MEDIUM

Missing Authorization vulnerability in Automattic Jetpack.This issue affects Jetpack: from n/a before 12.7.

Jun 19, 2024
CVE-2024-5676
6.8 MEDIUM

The Paradox IP150 Internet Module in version 1.40.00 is vulnerable to Cross-Site Request Forgery (CSRF) attacks due to a lack of countermeasures and the use …

Jun 19, 2024
CVE-2023-50900
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.9.10.

Jun 19, 2024
CVE-2024-4632
6.4 MEDIUM

The WooCommerce Checkout & Funnel Builder by CartFlows – Create High Converting Stores For WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jun 19, 2024
CVE-2024-0383
6.4 MEDIUM

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [wprm-recipe-instructions] and [wprm-recipe-ingredients] shortcodes in all versions up to, …

Jun 19, 2024
CVE-2023-6495
4.4 MEDIUM

The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to …

Jun 19, 2024
CVE-2024-0789
5.3 MEDIUM

The WP Maintenance plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 6.1.9.2 due to insufficient IP address …

Jun 19, 2024
CVE-2024-3894
6.4 MEDIUM

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an Image Title in all versions …

Jun 19, 2024
CVE-2024-37881
5.3 MEDIUM

SiteGuard WP Plugin provides a functionality to customize the path to the login page wp-login.php and implements a measure to avoid redirection from other URLs. …

Jun 19, 2024
CVE-2024-37387
4.0 MEDIUM

Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, files in the PC where the product …

Jun 19, 2024
CVE-2024-36252
6.3 MEDIUM

Improper restriction of communication channel to intended endpoints issue exists in Ricoh Streamline NX PC Client ver.3.6.x and earlier. If this vulnerability is exploited, arbitrary …

Jun 19, 2024
CVE-2024-1407
5.4 MEDIUM

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up …

Jun 19, 2024
CVE-2024-5208
6.5 MEDIUM

An uncontrolled resource consumption vulnerability exists in the `upload-link` endpoint of mintplex-labs/anything-llm. This vulnerability allows attackers to cause a denial of service (DOS) by shutting …

Jun 19, 2024
CVE-2023-6692
6.4 MEDIUM

The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's tab anchor metabox in all versions …

Jun 19, 2024
CVE-2024-35298
4.3 MEDIUM

Improper authorization in handler for custom URL scheme issue in 'ZOZOTOWN' App for Android versions prior to 7.39.6 allows an attacker to lead a user …

Jun 19, 2024
CVE-2024-5768
6.4 MEDIUM

The MIMO Woocommerce Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'mimo_update_provider' function …

Jun 19, 2024
CVE-2024-5649
5.4 MEDIUM

The Universal Slider plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.5 via deserialization of untrusted input …

Jun 19, 2024
CVE-2024-4873
4.3 MEDIUM

The Replace Image plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.10 via the image replacement …

Jun 19, 2024
CVE-2024-4787
5.8 MEDIUM

The Cost Calculator Builder PRO for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 3.1.75. This is due to …

Jun 19, 2024
CVE-2024-4663
6.4 MEDIUM

The OSM Map Widget for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in all versions up to, and …

Jun 19, 2024
CVE-2024-4623
6.4 MEDIUM

The Blogmentor – Blog Layouts for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pagination_style’ parameter in all versions up to, …

Jun 19, 2024
CVE-2024-4541
4.3 MEDIUM

The Custom Product List Table plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due …

Jun 19, 2024
CVE-2024-4450
6.3 MEDIUM

The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the …

Jun 19, 2024
CVE-2024-3984
6.4 MEDIUM

The EmbedSocial – Social Media Feeds, Reviews and Galleries plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'embedsocial_reviews' shortcode in all …

Jun 19, 2024
CVE-2024-5970
6.4 MEDIUM

The MaxGalleria plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's maxgallery_thumb shortcode in all versions up to, and including, 6.4.4 due …

Jun 18, 2024
CVE-2024-6128
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in spa-cartcms 1.9.0.6. This issue affects some unknown processing of the file /checkout of the …

Jun 18, 2024
CVE-2024-38277
5.4 MEDIUM

A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between …

Jun 18, 2024
CVE-2024-38274
6.1 MEDIUM

Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt.

Jun 18, 2024
CVE-2024-38273
5.4 MEDIUM

Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.

Jun 18, 2024
CVE-2024-36977
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: Wait unconditionally after issuing EndXfer command Currently all controller IP/revisions except DWC3_usb3 >= …

Jun 18, 2024
CVE-2024-36976
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Revert "media: v4l2-ctrls: show all owned controls in log_status" This reverts commit 9801b5b28c6929139d6fceeee8d739cc67bb2739. This patch …

Jun 18, 2024
CVE-2024-36975
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Do not use WARN when encode fails When asn1_encode_sequence() fails, WARN is not …

Jun 18, 2024
CVE-2024-37791
6.0 MEDIUM

DuxCMS3 v3.1.3 was discovered to contain a SQL injection vulnerability via the keyword parameter at /article/Content/index?class_id.

Jun 18, 2024
CVE-2024-38351
5.4 MEDIUM

Pocketbase is an open source web backend written in go. In affected versions a malicious user may be able to compromise other user accounts. In …

Jun 18, 2024
CVE-2024-37904
5.7 MEDIUM

Minder is an open source Software Supply Chain Security Platform. Minder's Git provider is vulnerable to a denial of service from a maliciously configured GitHub …

Jun 18, 2024
CVE-2024-37803
5.4 MEDIUM

Multiple stored cross-site scripting (XSS) vulnerabilities in CodeProjects Health Care hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a …

Jun 18, 2024
CVE-2024-37800
6.1 MEDIUM

CodeProjects Restaurant Reservation System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Date parameter at index.php.

Jun 18, 2024
CVE-2024-37799
5.4 MEDIUM

CodeProjects Restaurant Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the reserv_id parameter at view_reservations.php.

Jun 18, 2024
CVE-2024-21685
6.5 MEDIUM

This High severity Information Disclosure vulnerability was introduced in versions 9.4.0, 9.12.0, and 9.15.0 of Jira Core Data Center. This Information Disclosure vulnerability, with a …

Jun 18, 2024
CVE-2024-6109
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jun 18, 2024
CVE-2024-38506
6.3 MEDIUM

In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows

Jun 18, 2024
CVE-2024-38505
5.3 MEDIUM

In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site

Jun 18, 2024
CVE-2024-38504
4.3 MEDIUM

In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles

Jun 18, 2024
CVE-2024-6108
4.3 MEDIUM

A vulnerability was found in Genexis Tilgin Home Gateway 322_AS0500-03_05_13_05. It has been classified as problematic. Affected is an unknown function of the file /vood/cgi-bin/vood_view.cgi?act=index&lang=EN# …

Jun 18, 2024
CVE-2024-5953
5.7 MEDIUM

A denial of service vulnerability was found in the 389-ds-base LDAP server. This issue may allow an authenticated user to cause a server denial of …

Jun 18, 2024
CVE-2024-5533
6.4 MEDIUM

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.25.1 due to insufficient input sanitization and …

Jun 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.