| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-2018 | Hig | 0.57 | 8.8 | 0.01 | Apr 9, 2024 | The WP Activity Log Premium plugin for WordPress is vulnerable to SQL Injection via the entry->roles parameter in all versions up to, and including, 4.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. … | ||
| CVE-2024-24245 | Hig | 0.51 | 7.8 | 0.00 | Apr 9, 2024 | An issue in Canimaan Software LTD ClamXAV v3.1.2 through v3.6.1 and fixed in v.3.6.2 allows a local attacker to escalate privileges via the ClamXAV helper tool component. | ||
| CVE-2024-1991 | Hig | 0.50 | 8.8 | 0.01 | Apr 9, 2024 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the update_users_role() function in all versions up to, and including, 5.3.0.0. This… | ||
| CVE-2024-1990 | Hig | 0.50 | 8.8 | 0.01 | Apr 9, 2024 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to blind SQL Injection via the ‘id’ parameter of the RM_Form shortcode in all versions up to, and including, 5.3.1.0 due to insufficient… | ||
| CVE-2024-1974 | Hig | 0.50 | 8.8 | 0.01 | Apr 9, 2024 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.6 via the render function. This makes it possible for authenticated attackers, with contributor access or higher, to read the… | ||
| CVE-2024-1934 | Hig | 0.49 | 7.5 | 0.01 | Apr 9, 2024 | The WP Compress – Image Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wps_local_compress::__construct' function in all versions up to, and including, 6.11.10. This makes it possible for… | ||
| CVE-2024-1893 | Hig | 0.57 | 8.8 | 0.01 | Apr 9, 2024 | The Easy Property Listings plugin for WordPress is vulnerable to time-based SQL Injection via the ‘property_status’ shortcode attribute in all versions up to, and including, 3.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation… | ||
| CVE-2024-1852 | Hig | 0.47 | 7.2 | 0.01 | Apr 9, 2024 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in all versions up to, and including, 3.4.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | ||
| CVE-2024-1812 | Hig | 0.40 | 7.2 | 0.01 | Apr 9, 2024 | The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.7 via the 'font_url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web… | ||
| CVE-2024-1794 | Hig | 0.47 | 7.2 | 0.01 | Apr 9, 2024 | The Forminator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. 3gpp file) in all versions up to, and including, 1.29.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | ||
| CVE-2024-1792 | Hig | 0.42 | 7.5 | 0.01 | Apr 9, 2024 | The CMB2 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.10.1 via deserialization of untrusted input from the text_datetime_timestamp_timezone field. This makes it possible for authenticated attackers, with contributor access or… | ||
| CVE-2024-1774 | Hig | 0.47 | 7.2 | 0.00 | Apr 9, 2024 | The Customily Product Personalizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user cookies in all versions up to, and including, 1.23.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | ||
| CVE-2024-1315 | Hig | 0.57 | 8.8 | 0.00 | Apr 9, 2024 | The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.4. This is due to missing or incorrect nonce validation on the 'rtcl_update_user_account' function.… | ||
| CVE-2024-1308 | Hig | 0.49 | 7.5 | 0.01 | Apr 9, 2024 | The WooCommerce Cloak Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'permalink_settings_save' function in all versions up to, and including, 1.0.33. This makes it possible for unauthenticated… | ||
| CVE-2024-0952 | Hig | 0.40 | 7.2 | 0.01 | Apr 9, 2024 | The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all versions up to, and including, 1.12.9 due to insufficient escaping on the user supplied… | ||
| CVE-2023-7046 | Hig | 0.49 | 7.5 | 0.00 | Apr 9, 2024 | The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, SSL Score plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.0 via exposed Private key files. This makes it possible for… | ||
| CVE-2023-6999 | Hig | 0.57 | 8.8 | 0.01 | Apr 9, 2024 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This makes it possible for authenticated attackers, with… | ||
| CVE-2023-6967 | Hig | 0.57 | 8.8 | 0.01 | Apr 9, 2024 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2) due to insufficient escaping on the user supplied parameter and lack… | ||
| CVE-2023-6964 | Hig | 0.55 | 8.5 | 0.00 | Apr 9, 2024 | The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.26 via the 'kadence_import_get_new_connection_data' AJAX action. This makes it possible for authenticated… | ||
| CVE-2024-31507 | Hig | 0.56 | 8.6 | 0.00 | Apr 9, 2024 | Sourcecodester Online Graduate Tracer System v1.0 is vulnerable to SQL Injection via the "request" parameter in admin/fetch_gendercs.php. | ||
| CVE-2024-31506 | Hig | 0.49 | 7.5 | 0.01 | Apr 9, 2024 | Sourcecodester Online Graduate Tracer System v1.0 is vulnerable to SQL Injection via the "id" parameter in admin/admin_cs.php. | ||
| CVE-2024-31457 | Hig | 0.43 | 7.7 | 0.01 | Apr 9, 2024 | gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. gin-vue-admin pseudoversion 0.0.0-20240407133540-7bc7c3051067, corresponding to version 2.6.1, has a code injection vulnerability in the backend. In the… | ||
| CVE-2024-25115 | Hig | 0.39 | 7.0 | 0.00 | Apr 9, 2024 | RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 and 2.6.10, specially crafted `CF.LOADCHUNK` commands may be used by authenticated users to perform heap overflow, which may lead to remote code execution. The… | ||
| CVE-2024-22423 | Hig | 0.47 | 8.3 | 0.01 | Apr 9, 2024 | yt-dlp is a youtube-dl fork with additional features and fixes. The patch that addressed CVE-2023-40581 attempted to prevent RCE when using `--exec` with `%q` by replacing double quotes with two double quotes. However, this escaping is not sufficient, and still allows expansion… | ||
| CVE-2024-29993 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Azure CycleCloud Elevation of Privilege Vulnerability | ||
| CVE-2024-29989 | Hig | 0.55 | 8.4 | 0.01 | Apr 9, 2024 | Azure Monitor Agent Elevation of Privilege Vulnerability | ||
| CVE-2024-29988 | Hig | 0.73 | 8.8 | 0.45 | KEV | Apr 9, 2024 | SmartScreen Prompt Security Feature Bypass Vulnerability | |
| CVE-2024-29985 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-29984 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-29983 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-29982 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-29905 | Hig | 0.46 | 8.1 | 0.00 | Apr 9, 2024 | DIRAC is an interware, meaning a software framework for distributed computing. Prior to version 8.0.41, during the proxy generation process (e.g., when using `dirac-proxy-init`), it is possible for unauthorized users on the same machine to gain read access to the proxy. This… | ||
| CVE-2024-29066 | Hig | 0.47 | 7.2 | 0.01 | Apr 9, 2024 | Windows Distributed File System (DFS) Remote Code Execution Vulnerability | ||
| CVE-2024-29063 | Hig | 0.48 | 7.3 | 0.01 | Apr 9, 2024 | Azure AI Search Information Disclosure Vulnerability | ||
| CVE-2024-29062 | Hig | 0.46 | 7.1 | 0.01 | Apr 9, 2024 | Secure Boot Security Feature Bypass Vulnerability | ||
| CVE-2024-29061 | Hig | 0.51 | 7.8 | 0.01 | Apr 9, 2024 | Secure Boot Security Feature Bypass Vulnerability | ||
| CVE-2024-29055 | Hig | 0.47 | 7.2 | 0.02 | Apr 9, 2024 | Microsoft Defender for IoT Elevation of Privilege Vulnerability | ||
| CVE-2024-29054 | Hig | 0.47 | 7.2 | 0.02 | Apr 9, 2024 | Microsoft Defender for IoT Elevation of Privilege Vulnerability | ||
| CVE-2024-29053 | Hig | 0.57 | 8.8 | 0.03 | Apr 9, 2024 | Microsoft Defender for IoT Remote Code Execution Vulnerability | ||
| CVE-2024-29052 | Hig | 0.51 | 7.8 | 0.01 | Apr 9, 2024 | Windows Storage Elevation of Privilege Vulnerability | ||
| CVE-2024-29050 | Hig | 0.55 | 8.4 | 0.01 | Apr 9, 2024 | Windows Cryptographic Services Remote Code Execution Vulnerability | ||
| CVE-2024-29048 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-29047 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-29046 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-29045 | Hig | 0.49 | 7.5 | 0.02 | Apr 9, 2024 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-29044 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-29043 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-28945 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-28944 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-28943 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability |
- risk 0.57cvss 8.8epss 0.01
The WP Activity Log Premium plugin for WordPress is vulnerable to SQL Injection via the entry->roles parameter in all versions up to, and including, 4.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. …
- risk 0.51cvss 7.8epss 0.00
An issue in Canimaan Software LTD ClamXAV v3.1.2 through v3.6.1 and fixed in v.3.6.2 allows a local attacker to escalate privileges via the ClamXAV helper tool component.
- risk 0.50cvss 8.8epss 0.01
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the update_users_role() function in all versions up to, and including, 5.3.0.0. This…
- risk 0.50cvss 8.8epss 0.01
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to blind SQL Injection via the ‘id’ parameter of the RM_Form shortcode in all versions up to, and including, 5.3.1.0 due to insufficient…
- risk 0.50cvss 8.8epss 0.01
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.6 via the render function. This makes it possible for authenticated attackers, with contributor access or higher, to read the…
- risk 0.49cvss 7.5epss 0.01
The WP Compress – Image Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wps_local_compress::__construct' function in all versions up to, and including, 6.11.10. This makes it possible for…
- risk 0.57cvss 8.8epss 0.01
The Easy Property Listings plugin for WordPress is vulnerable to time-based SQL Injection via the ‘property_status’ shortcode attribute in all versions up to, and including, 3.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
- risk 0.47cvss 7.2epss 0.01
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in all versions up to, and including, 3.4.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
- risk 0.40cvss 7.2epss 0.01
The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.7 via the 'font_url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web…
- risk 0.47cvss 7.2epss 0.01
The Forminator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. 3gpp file) in all versions up to, and including, 1.29.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
- risk 0.42cvss 7.5epss 0.01
The CMB2 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.10.1 via deserialization of untrusted input from the text_datetime_timestamp_timezone field. This makes it possible for authenticated attackers, with contributor access or…
- risk 0.47cvss 7.2epss 0.00
The Customily Product Personalizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user cookies in all versions up to, and including, 1.23.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
- risk 0.57cvss 8.8epss 0.00
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.4. This is due to missing or incorrect nonce validation on the 'rtcl_update_user_account' function.…
- risk 0.49cvss 7.5epss 0.01
The WooCommerce Cloak Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'permalink_settings_save' function in all versions up to, and including, 1.0.33. This makes it possible for unauthenticated…
- risk 0.40cvss 7.2epss 0.01
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all versions up to, and including, 1.12.9 due to insufficient escaping on the user supplied…
- risk 0.49cvss 7.5epss 0.00
The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, SSL Score plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.0 via exposed Private key files. This makes it possible for…
- risk 0.57cvss 8.8epss 0.01
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This makes it possible for authenticated attackers, with…
- risk 0.57cvss 8.8epss 0.01
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2) due to insufficient escaping on the user supplied parameter and lack…
- risk 0.55cvss 8.5epss 0.00
The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.26 via the 'kadence_import_get_new_connection_data' AJAX action. This makes it possible for authenticated…
- risk 0.56cvss 8.6epss 0.00
Sourcecodester Online Graduate Tracer System v1.0 is vulnerable to SQL Injection via the "request" parameter in admin/fetch_gendercs.php.
- risk 0.49cvss 7.5epss 0.01
Sourcecodester Online Graduate Tracer System v1.0 is vulnerable to SQL Injection via the "id" parameter in admin/admin_cs.php.
- risk 0.43cvss 7.7epss 0.01
gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. gin-vue-admin pseudoversion 0.0.0-20240407133540-7bc7c3051067, corresponding to version 2.6.1, has a code injection vulnerability in the backend. In the…
- risk 0.39cvss 7.0epss 0.00
RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 and 2.6.10, specially crafted `CF.LOADCHUNK` commands may be used by authenticated users to perform heap overflow, which may lead to remote code execution. The…
- risk 0.47cvss 8.3epss 0.01
yt-dlp is a youtube-dl fork with additional features and fixes. The patch that addressed CVE-2023-40581 attempted to prevent RCE when using `--exec` with `%q` by replacing double quotes with two double quotes. However, this escaping is not sufficient, and still allows expansion…
- risk 0.57cvss 8.8epss 0.02
Azure CycleCloud Elevation of Privilege Vulnerability
- risk 0.55cvss 8.4epss 0.01
Azure Monitor Agent Elevation of Privilege Vulnerability
- risk 0.73cvss 8.8epss 0.45
SmartScreen Prompt Security Feature Bypass Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.46cvss 8.1epss 0.00
DIRAC is an interware, meaning a software framework for distributed computing. Prior to version 8.0.41, during the proxy generation process (e.g., when using `dirac-proxy-init`), it is possible for unauthorized users on the same machine to gain read access to the proxy. This…
- risk 0.47cvss 7.2epss 0.01
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
- risk 0.48cvss 7.3epss 0.01
Azure AI Search Information Disclosure Vulnerability
- risk 0.46cvss 7.1epss 0.01
Secure Boot Security Feature Bypass Vulnerability
- risk 0.51cvss 7.8epss 0.01
Secure Boot Security Feature Bypass Vulnerability
- risk 0.47cvss 7.2epss 0.02
Microsoft Defender for IoT Elevation of Privilege Vulnerability
- risk 0.47cvss 7.2epss 0.02
Microsoft Defender for IoT Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.03
Microsoft Defender for IoT Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Storage Elevation of Privilege Vulnerability
- risk 0.55cvss 8.4epss 0.01
Windows Cryptographic Services Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.02
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability