CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4270
5.4 MEDIUM

The SVGMagic WordPress plugin through 1.1 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious …

Jun 14, 2024
CVE-2024-4005
4.8 MEDIUM

The Social Pixel WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jun 14, 2024
CVE-2024-3993
4.6 MEDIUM

The AZAN Plugin WordPress plugin through 0.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Jun 14, 2024
CVE-2024-3992
4.8 MEDIUM

The Amen WordPress plugin through 3.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jun 14, 2024
CVE-2024-3978
5.4 MEDIUM

The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post …

Jun 14, 2024
CVE-2024-3977
4.8 MEDIUM

The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jun 14, 2024
CVE-2024-3972
4.3 MEDIUM

The Similarity WordPress plugin through 3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Jun 14, 2024
CVE-2024-3971
4.3 MEDIUM

The Similarity WordPress plugin through 3.0 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged …

Jun 14, 2024
CVE-2024-3966
6.1 MEDIUM

The Pray For Me WordPress plugin through 1.0.4 does not sanitise and escape some parameters, which could unauthenticated visitors to perform Cross-Site Scripting attacks that …

Jun 14, 2024
CVE-2024-3965
5.4 MEDIUM

The Pray For Me WordPress plugin through 1.0.4 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Jun 14, 2024
CVE-2024-3754
4.7 MEDIUM

The Alemha watermarker WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jun 14, 2024
CVE-2024-2218
4.6 MEDIUM

The LuckyWP Table of Contents WordPress plugin through 2.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jun 14, 2024
CVE-2024-2122
6.4 MEDIUM

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via album gallery custom URLs in all versions up …

Jun 14, 2024
CVE-2024-23504
5.3 MEDIUM

Missing Authorization vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through 5.0.5.

Jun 14, 2024
CVE-2024-1295
6.5 MEDIUM

The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking …

Jun 14, 2024
CVE-2023-51497
5.4 MEDIUM

Missing Authorization vulnerability in Woo WooCommerce Ship to Multiple Addresses.This issue affects WooCommerce Ship to Multiple Addresses: from n/a through 3.8.9.

Jun 14, 2024
CVE-2023-51496
5.3 MEDIUM

Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.2.7.

Jun 14, 2024
CVE-2023-51495
6.5 MEDIUM

Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.2.7.

Jun 14, 2024
CVE-2023-51377
5.3 MEDIUM

Missing Authorization vulnerability in WPEverest Everest Forms.This issue affects Everest Forms: from n/a through 2.0.3.

Jun 14, 2024
CVE-2024-31160
4.8 MEDIUM

The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can …

Jun 14, 2024
CVE-2024-31159
4.8 MEDIUM

The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can …

Jun 14, 2024
CVE-2024-27180
6.7 MEDIUM

An attacker with admin access can install rogue applications. As for the affected products/models/versions, see the reference URL.

Jun 14, 2024
CVE-2024-27179
4.7 MEDIUM

Admin cookies are written in clear-text in logs. An attacker can retrieve them and bypass the authentication mechanism. As for the affected products/models/versions, see the …

Jun 14, 2024
CVE-2024-27175
4.4 MEDIUM

Remote Command program allows an attacker to read any file using a Local File Inclusion vulnerability. An attacker can read any file on the printer. …

Jun 14, 2024
CVE-2024-27163
6.5 MEDIUM

Toshiba printers will display the password of the admin user in clear-text and additional passwords when sending 2 specific HTTP requests to the internal API. …

Jun 14, 2024
CVE-2024-27162
6.1 MEDIUM

Toshiba printers provide a web interface that will load the JavaScript file. The file contains insecure codes vulnerable to XSS and is loaded inside all …

Jun 14, 2024
CVE-2024-27161
6.2 MEDIUM

all the Toshiba printers have programs containing a hardcoded key used to encrypt files. An attacker can decrypt the encrypted files using the hardcoded key. …

Jun 14, 2024
CVE-2024-27160
6.2 MEDIUM

All the Toshiba printers contain a shell script using the same hardcoded key to encrypt logs. An attacker can decrypt the encrypted files using the …

Jun 14, 2024
CVE-2024-27159
6.2 MEDIUM

All the Toshiba printers contain a shell script using the same hardcoded key to encrypt logs. An attacker can decrypt the encrypted files using the …

Jun 14, 2024
CVE-2024-27157
6.8 MEDIUM

The sessions are stored in clear-text logs. An attacker can retrieve authentication sessions. A remote attacker can retrieve the credentials and bypass the authentication mechanism. …

Jun 14, 2024
CVE-2024-27156
6.8 MEDIUM

The session cookies, used for authentication, are stored in clear-text logs. An attacker can retrieve authentication sessions. A remote attacker can retrieve the credentials and …

Jun 14, 2024
CVE-2024-0892
4.3 MEDIUM

The Schema App Structured Data plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due …

Jun 14, 2024
CVE-2023-6492
4.3 MEDIUM

The Simple Sitemap – Create a Responsive HTML Sitemap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Jun 14, 2024
CVE-2024-27154
6.2 MEDIUM

Passwords are stored in clear-text logs. An attacker can retrieve passwords. As for the affected products/models/versions, see the reference URL.

Jun 14, 2024
CVE-2024-27146
6.7 MEDIUM

The Toshiba printers do not implement privileges separation. As for the affected products/models/versions, see the reference URL.

Jun 14, 2024
CVE-2024-27142
5.9 MEDIUM

Toshiba printers use XML communication for the API endpoint provided by the printer. For the endpoint, XML parsing library is used and it is vulnerable …

Jun 14, 2024
CVE-2024-27141
5.9 MEDIUM

Toshiba printers use XML communication for the API endpoint provided by the printer. For the endpoint, XML parsing library is used and it is vulnerable …

Jun 14, 2024
CVE-2024-5985
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Best Online News Portal 1.0. This affects an unknown part of the file /admin/index.php. The …

Jun 14, 2024
CVE-2024-5981
6.3 MEDIUM

A vulnerability was found in itsourcecode Online House Rental System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Jun 14, 2024
CVE-2023-51523
4.3 MEDIUM

Missing Authorization vulnerability in WriterSystem WooCommerce Easy Duplicate Product.This issue affects WooCommerce Easy Duplicate Product: from n/a through 0.3.0.7.

Jun 14, 2024
CVE-2023-51516
5.4 MEDIUM

Missing Authorization vulnerability in Business Directory Team Business Directory Plugin.This issue affects Business Directory Plugin: from n/a through 6.3.9.

Jun 14, 2024
CVE-2023-51507
5.3 MEDIUM

Missing Authorization vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.16.

Jun 14, 2024
CVE-2023-37394
5.3 MEDIUM

Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator.This issue affects WP Dummy Content Generator: from n/a through 2.3.0.

Jun 14, 2024
CVE-2023-36695
5.4 MEDIUM

Missing Authorization vulnerability in Maxime Schoeni Sublanguage.This issue affects Sublanguage: from n/a through 2.9.

Jun 14, 2024
CVE-2023-36694
6.3 MEDIUM

Missing Authorization vulnerability in Bryan Lee Kingkong Board.This issue affects Kingkong Board: from n/a through 2.1.0.2.

Jun 14, 2024
CVE-2023-36504
6.5 MEDIUM

Missing Authorization vulnerability in BBS e-Theme BBS e-Popup.This issue affects BBS e-Popup: from n/a through 2.4.5.

Jun 14, 2024
CVE-2023-35045
4.3 MEDIUM

Missing Authorization vulnerability in Fat Rat Fat Rat Collect.This issue affects Fat Rat Collect: from n/a through 2.6.7.

Jun 14, 2024
CVE-2023-35040
5.3 MEDIUM

Missing Authorization vulnerability in SendPress SendPress Newsletters.This issue affects SendPress Newsletters: from n/a through 1.23.11.6.

Jun 14, 2024
CVE-2023-29174
6.5 MEDIUM

Missing Authorization vulnerability in NervyThemes SKU Label Changer For WooCommerce.This issue affects SKU Label Changer For WooCommerce: from n/a through 3.0.

Jun 14, 2024
CVE-2024-33253
5.4 MEDIUM

Cross-site scripting (XSS) vulnerability in GUnet OpenEclass E-learning Platform version 3.15 and before allows a authenticated privileged attacker to execute arbitrary code via the title …

Jun 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.