CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5654
6.5 MEDIUM

The CF7 Google Sheets Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'execute_post_data_cg7_free' function …

Jun 8, 2024
CVE-2024-4468
4.3 MEDIUM

The Salon booking system plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions …

Jun 8, 2024
CVE-2024-5638
6.1 MEDIUM

The Formula theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in the 'ti_customizer_notify_dismiss_recommended_plugins' AJAX action in all versions up to, …

Jun 8, 2024
CVE-2024-5613
6.1 MEDIUM

The Formula theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in the 'quality_customizer_notify_dismiss_action' AJAX action in all versions up to, …

Jun 8, 2024
CVE-2024-5087
6.3 MEDIUM

The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Jun 8, 2024
CVE-2024-4661
4.3 MEDIUM

The WP Reset plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_ajax function in all …

Jun 8, 2024
CVE-2024-5770
4.2 MEDIUM

The WP Force SSL & HTTPS SSL Redirect plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Jun 8, 2024
CVE-2024-5663
6.4 MEDIUM

The Cards for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Cards widget in all versions up to, and …

Jun 8, 2024
CVE-2024-37163
6.4 MEDIUM

SkyScrape is a GUI Dashboard for AWS Infrastructure and Managing Resources and Usage Costs. SkyScrape's API requests are currently unsecured HTTP requests, leading to potential …

Jun 7, 2024
CVE-2024-31958
6.8 MEDIUM

An issue was discovered in Samsung Mobile Processor EExynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the validation of native handles, which …

Jun 7, 2024
CVE-2024-37162
4.0 MEDIUM

zsa is a library for building typesafe server actions in Next.js. All users are impacted. The zsa application transfers the parse error stack from the …

Jun 7, 2024
CVE-2024-36788
4.8 MEDIUM

Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 does not properly set the HTTPOnly flag for cookies. This allows attackers to possibly intercept and access sensitive communications between the …

Jun 7, 2024
CVE-2024-36773
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

Jun 7, 2024
CVE-2024-37160
4.8 MEDIUM

Formwork is a flat file-based Content Management System (CMS). An attackers (requires administrator privilege) to execute arbitrary web scripts by modifying site options via /panel/options/site. …

Jun 7, 2024
CVE-2024-31878
5.3 MEDIUM

IBM i 7.2, 7.3, 7.4, and 7.5 Service Tools Server (SST) is vulnerable to SST user enumeration by a remote attacker. This vulnerability can be …

Jun 7, 2024
CVE-2024-5438
4.3 MEDIUM

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and …

Jun 7, 2024
CVE-2024-5382
6.5 MEDIUM

The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to …

Jun 7, 2024
CVE-2024-5734
6.3 MEDIUM

A vulnerability classified as critical has been found in itsourcecode Online Discussion Forum 1.0. Affected is an unknown function of the file /members/poster.php. The manipulation …

Jun 7, 2024
CVE-2024-5645
6.4 MEDIUM

The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_css_id’ parameter within the Button widget in all versions up to, …

Jun 7, 2024
CVE-2024-5481
6.8 MEDIUM

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.8.23 …

Jun 7, 2024
CVE-2024-5426
6.4 MEDIUM

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘svg’ parameter in all versions …

Jun 7, 2024
CVE-2023-5424
4.7 MEDIUM

The WS Form LITE plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.9.217. This allows unauthenticated attackers to embed …

Jun 7, 2024
CVE-2024-4703
6.4 MEDIUM

The One Page Express Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's one_page_express_contact_form shortcode in all versions up to, and …

Jun 7, 2024
CVE-2024-4489
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_upload_mimes’ function in versions up to, and including, …

Jun 7, 2024
CVE-2024-4488
6.4 MEDIUM

The Royal Elementor Addons and Templates for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘inline_list’ parameter in versions up to, and including, 1.3.976 …

Jun 7, 2024
CVE-2024-4451
6.4 MEDIUM

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_video_player shortcode in all versions up to, and including, …

Jun 7, 2024
CVE-2024-5003
5.4 MEDIUM

The WP Stacker WordPress plugin through 1.8.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Jun 7, 2024
CVE-2024-4756
5.4 MEDIUM

The WP Backpack WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jun 7, 2024
CVE-2024-4621
4.8 MEDIUM

The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 does not sanitise and escape some of its settings, which could allow high …

Jun 7, 2024
CVE-2024-4354
6.4 MEDIUM

The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.3 …

Jun 7, 2024
CVE-2024-4042
6.4 MEDIUM

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Jun 7, 2024
CVE-2024-3288
5.4 MEDIUM

The Logo Slider WordPress plugin before 4.0.0 does not validate and escape some of its Slider Settings before outputting them back in attributes, which could …

Jun 7, 2024
CVE-2023-6491
4.3 MEDIUM

The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the wpmtst_save_view_sticky function in all …

Jun 7, 2024
CVE-2024-5640
6.4 MEDIUM

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jun 7, 2024
CVE-2024-5612
6.4 MEDIUM

The Essential Addons for Elementor Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eael_lightbox_open_btn_icon’ parameter within the Lightbox & Modal widget …

Jun 7, 2024
CVE-2024-5425
6.4 MEDIUM

The WP jQuery Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ attribute in all versions up to, and including, 1.5.4 …

Jun 7, 2024
CVE-2024-37384
6.1 MEDIUM

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.

Jun 7, 2024
CVE-2024-37383
6.1 MEDIUM KEV

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

Jun 7, 2024
CVE-2024-36082
6.5 MEDIUM

SQL injection vulnerability in Music Store - WordPress eCommerce versions prior to 1.1.14 allows a remote authenticated attacker with an administrative privilege to execute arbitrary …

Jun 7, 2024
CVE-2024-1988
6.4 MEDIUM

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Jun 7, 2024
CVE-2024-5607
5.4 MEDIUM

The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Jun 7, 2024
CVE-2024-3987
5.4 MEDIUM

The WP Mobile Menu – The Mobile-Friendly Responsive Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt text in all versions …

Jun 7, 2024
CVE-2024-1768
6.4 MEDIUM

The Clever Fox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's info box block in all versions up to, and including, …

Jun 7, 2024
CVE-2024-1689
4.3 MEDIUM

The WooCommerce Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the woocommerce_tool_toggle_module() function in all …

Jun 7, 2024
CVE-2023-6876
5.4 MEDIUM

The Clever Fox – One Click Website Importer by Nayra Themes plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Jun 7, 2024
CVE-2022-4968
6.5 MEDIUM

netplan leaks the private key of wireguard to local users. Versions after 1.0 are not affected.

Jun 7, 2024
CVE-2024-4013
5.6 MEDIUM

A bug exists in the API, mesh_node_power_off(), which fails to copy the contents of the Replay Protection List (RPL) from RAM to NVM before powering …

Jun 6, 2024
CVE-2024-36775
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

Jun 6, 2024
CVE-2024-22525
5.5 MEDIUM

dnspod-sr 0dfbd37 contains a SEGV.

Jun 6, 2024
CVE-2024-22524
5.5 MEDIUM

dnspod-sr 0dfbd37 is vulnerable to buffer overflow.

Jun 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.