Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2022-37346

    EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files. Exploiting this vulnerability allows a remote unauthenticated attacker to upload arbitrary files other than image f... Read more

    Affected Products : product_image_bulk_upload
    • EPSS Score: %1.22
    • Published: Sep. 27, 2022
    • Modified: May. 21, 2025
  • 9.8

    CRITICAL
    CVE-2022-30004

    Sourcecodester Online Market Place Site v1.0 suffers from an unauthenticated blind SQL Injection Vulnerability allowing remote attackers to dump the SQL database via time-based SQL injection..... Read more

    Affected Products : online_market_place_site
    • EPSS Score: %0.72
    • Published: Sep. 26, 2022
    • Modified: May. 21, 2025
  • 8.8

    HIGH
    CVE-2022-2998

    Use after free in Browser Creation in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who had convinced a user to engage in a specific UI interaction to potentially exploit heap corruption via a crafted HTML page.... Read more

    Affected Products : chrome
    • EPSS Score: %25.26
    • Published: Sep. 26, 2022
    • Modified: May. 21, 2025
  • 6.5

    MEDIUM
    CVE-2021-41437

    An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to craft a specific URL that if an authenticated victim visits it, the URL will give access to the cloud storage of the attacker.... Read more

    Affected Products : rt-ax88u_firmware rt-ax88u
    • EPSS Score: %0.97
    • Published: Sep. 26, 2022
    • Modified: May. 21, 2025
  • 6.8

    MEDIUM
    CVE-2025-25927

    A Cross-Site Request Forgery (CSRF) in Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted GET request.... Read more

    Affected Products : openmrs
    • Published: Mar. 11, 2025
    • Modified: May. 21, 2025
    • Vuln Type: Cross-Site Request Forgery
  • 6.1

    MEDIUM
    CVE-2024-6334

    The Easy Table of Contents WordPress plugin before 2.0.67.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.... Read more

    Affected Products : easy_table_of_contents
    • Published: Jul. 09, 2024
    • Modified: May. 21, 2025
  • 9.8

    CRITICAL
    CVE-2024-5488

    The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticated attackers to unserialize malicious gadget chains, compromising the site i... Read more

    Affected Products : seopress
    • Published: Jul. 09, 2024
    • Modified: May. 21, 2025
  • 4.3

    MEDIUM
    CVE-2024-3410

    The DN Footer Contacts WordPress plugin before 1.6.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallo... Read more

    Affected Products : footer_contacts_bar
    • Published: Jul. 09, 2024
    • Modified: May. 21, 2025
  • 6.1

    MEDIUM
    CVE-2024-4057

    The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.37 does not validate and escape some of its block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and... Read more

    Affected Products : gutenberg_blocks_with_ai
    • Published: Jun. 04, 2024
    • Modified: May. 21, 2025
  • 5.4

    MEDIUM
    CVE-2024-2470

    The Simple Ajax Chat WordPress plugin before 20240412 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disal... Read more

    Affected Products : simple_ajax_chat
    • Published: Jun. 04, 2024
    • Modified: May. 21, 2025
  • 5.4

    MEDIUM
    CVE-2024-0757

    The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file extensions are allowed to be imported on the server, allowing the uploading of malicious code within zip files... Read more

    • Published: Jun. 04, 2024
    • Modified: May. 21, 2025
  • 7.5

    HIGH
    CVE-2024-4469

    The WP STAGING WordPress Backup Plugin WordPress plugin before 3.5.0 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may be a problem in multisite configurations.... Read more

    Affected Products : wp_staging
    • Published: May. 31, 2024
    • Modified: May. 21, 2025
  • 4.8

    MEDIUM
    CVE-2024-3937

    The Playlist for Youtube WordPress plugin through 1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disal... Read more

    Affected Products : playlist_for_youtube
    • Published: May. 29, 2024
    • Modified: May. 21, 2025
  • 4.8

    MEDIUM
    CVE-2024-3921

    The Gianism WordPress plugin through 5.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for e... Read more

    Affected Products : gianism
    • Published: May. 29, 2024
    • Modified: May. 21, 2025
  • 9.1

    CRITICAL
    CVE-2024-3050

    The Site Reviews WordPress plugin before 7.0.0 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass IP-based blocking... Read more

    Affected Products : site_reviews
    • Published: May. 29, 2024
    • Modified: May. 21, 2025
  • 5.4

    MEDIUM
    CVE-2024-3939

    The Ditty WordPress plugin before 3.1.36 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for ex... Read more

    Affected Products : ditty
    • Published: May. 27, 2024
    • Modified: May. 21, 2025
  • 3.5

    LOW
    CVE-2024-3920

    The Flattr WordPress plugin through 1.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for ex... Read more

    Affected Products : flattr
    • Published: May. 23, 2024
    • Modified: May. 21, 2025
  • 4.8

    MEDIUM
    CVE-2024-3918

    The Pet Manager WordPress plugin through 1.4 does not sanitise and escape some of its Pet settings, which could allow high privilege users such as Contributor to perform Stored Cross-Site Scripting attacks.... Read more

    Affected Products : pet_manager
    • Published: May. 23, 2024
    • Modified: May. 21, 2025
  • 6.1

    MEDIUM
    CVE-2024-3917

    The Pet Manager WordPress plugin through 1.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more

    Affected Products : pet_manager
    • Published: May. 23, 2024
    • Modified: May. 21, 2025
  • 8.7

    HIGH
    CVE-2024-3594

    The IDonate WordPress plugin through 1.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for ... Read more

    Affected Products : idonate
    • Published: May. 23, 2024
    • Modified: May. 21, 2025
Showing 20 of 292761 Results