cvekit
LIVE

Trending CVEs

last 7d
  • Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

    5.9
    1.00
    almost 5 years ago
  • The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

    3.4
    1.00
    almost 12 years ago
  • CVE-2017-7921CRITICALKEV

    An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 161125, DS-2CD4x2xFWD Series V5.2.0 build 140721 to V5.4.0 Build 160414, DS-2CD4xx5 Series V5.2.0 build 140721 to V5.4.0 Build 160421, DS-2DFx Series V5.2.0 build 140805 to V5.4.5 Build 160928, and DS-2CD63xx Series V5.0.9 build 140305 to V5.3.5 Build 160106 devices. The improper authentication vulnerability occurs when an application does not adequately or correctly authenticate users. This may allow a malicious user to escalate his or her privileges on the system and gain access to sensitive information.

    9.8
    1.00
    over 9 years ago
  • Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

    8.8
    1.00
    about 1 year ago
  • CVE-2025-53770CRITICALKEV

    Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.

    9.8
    1.00
    about 1 year ago
  • Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1.

    5.3
    1.00
    about 5 years ago
  • CVE-2024-23897CRITICALKEV

    Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.

    9.8
    1.00
    over 2 years ago
  • CVE-2024-3400CRITICALKEV

    A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.

    10.0
    1.00
    over 2 years ago
  • CVE-2024-3273CRITICALKEV

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument system leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259284. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

    9.8
    1.00
    over 2 years ago
  • A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

    8.2
    1.00
    over 2 years ago
  • CVE-2023-35082CRITICALKEV

    An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.

    9.8
    1.00
    about 3 years ago
  • CVE-2024-21887CRITICALKEV

    A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

    9.1
    1.00
    over 2 years ago
  • CVE-2023-1671CRITICALKEV

    A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.

    9.8
    1.00
    over 3 years ago
  • CVE-2023-22518CRITICALKEV

    All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to - but not limited to - full loss of confidentiality, integrity and availability.  Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.

    9.8
    1.00
    almost 3 years ago
  • Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

    7.5
    1.00
    almost 3 years ago
  • The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

    7.5
    1.00
    almost 3 years ago
  • Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This permitted an unauthenticated user to use the unauthenticated Openfire Setup Environment in an already configured Openfire environment to access restricted pages in the Openfire Admin Console reserved for administrative users. This vulnerability affects all versions of Openfire that have been released since April 2015, starting with version 3.10.0. The problem has been patched in Openfire release 4.7.5 and 4.6.8, and further improvements will be included in the yet-to-be released first version on the 4.8 branch (which is expected to be version 4.8.0). Users are advised to upgrade. If an Openfire upgrade isn’t available for a specific release, or isn’t quickly actionable, users may see the linked github advisory (GHSA-gw42-f939-fhvm) for mitigation advice.

    7.5
    1.00
    over 3 years ago
  • CVE-2023-35078CRITICALKEV

    An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

    9.8
    1.00
    about 3 years ago
  • TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.

    8.8
    1.00
    over 3 years ago
  • CVE-2023-27350CRITICALKEV

    This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987.

    9.8
    1.00
    over 3 years ago
  • Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.

    7.2
    1.00
    over 3 years ago
  • CVE-2022-44877CRITICALKEV

    login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.

    9.8
    1.00
    over 3 years ago
  • CVE-2022-26134CRITICALKEV

    In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.

    9.8
    1.00
    over 4 years ago
  • The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

    7.5
    1.00
    over 12 years ago
  • CVE-2022-29464CRITICALKEV

    Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.

    9.8
    1.00
    over 4 years ago
  • CVE-2022-22954CRITICALKEV

    VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

    9.8
    1.00
    over 4 years ago
  • CVE-2013-2251CRITICALKEV

    Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

    9.8
    1.00
    about 13 years ago
  • CVE-2012-1823CRITICALKEV

    sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.

    9.8
    1.00
    over 14 years ago
  • CVE-2019-16920CRITICALKEV

    Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.

    9.8
    1.00
    almost 7 years ago
  • CVE-2017-9841CRITICALKEV

    Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.

    9.8
    1.00
    about 9 years ago

Newest CVEs

by publish date
  • The Real3D Flipbook Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lightboxtext' shortcode attribute (and other unsanitized attributes handled by on_shortcode()) in versions up to, and including, 5.1.1. This is due to insufficient input sanitization and output escaping in the on_shortcode() and print_global_options() functions: shortcode attribute values are copied verbatim into $this->flipbook_options and then emitted via wp_json_encode() inside a <script type="application/json"> block without the JSON_HEX_TAG flag, allowing a literal </script> byte sequence in the attribute value to break out of the JSON script context. Because WordPress's shortcode_parse_atts() applies stripcslashes() to attribute values, an attacker can encode the breakout tag as \x3c/script\x3e\x3cscript\x3e…\x3c/script\x3e, which survives the wp_kses_post save-time filter applied to Contributor content (the escape bytes are safe text characters, not HTML tags) and is decoded to real angle brackets at render time. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user (typically an Editor or Administrator previewing/moderating the pending post) accesses an injected page.

    6.4
    about 1 hour ago
  • The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data' Dynamic Content Tag in all versions up to, and including, 4.14.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    6.1
    about 1 hour ago
  • The Ibtana – Ecommerce Product Addons plugin for WordPress is vulnerable to unauthorized post meta modification due to a missing capability check on the 'iepa_use_gt_editor' AJAX action in all versions up to, and including, 0.4.7.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update or delete arbitrary post meta entries via the 'iepa_builder' meta key.

    5.3
    about 1 hour ago
  • The Custom Field Template plugin for WordPress is vulnerable to generic SQL Injection via the 'post_ID' parameter in all versions up to, and including, 2.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The capability check via current_user_can('edit_post', $id) is bypassable because WordPress internally casts $id to an integer for the permission evaluation while the full unsanitized string is preserved and passed to the SQL sink, and a valid nonce — which is also required — can be legitimately obtained by any Contributor-level user from the post edit screen.

    6.5
    about 1 hour ago
  • The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media field filter values in versions up to, and including, 4.5.13 This is due to insufficient input sanitization of nested array values in the user_meta_save() function and unsafe output of filter CSS values in the render() function without proper escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    6.4
    about 1 hour ago
  • The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 7.0.02. This is due to the plugin not properly validating user input. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into clicking on a specially crafted link. Exploitation requires tricking a logged-in user into clicking a crafted logout URL; the victim is fully logged out via wp_logout() before the malicious redirect is issued, making the logout irreversible as part of the attack chain.

    4.7
    about 1 hour ago
  • The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.17.2 This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes.

    8.1
    about 1 hour ago
  • The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fb-config' Setting in all versions up to, and including, 2.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. On multisite installations where administrators do not hold the unfiltered_html capability, this vulnerability can be leveraged to target the network super administrator.

    4.4
    about 1 hour ago
  • The GoPay for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'log_table_filter' parameter in all versions up to, and including, 1.0.36 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with shop manager-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    4.9
    about 1 hour ago
  • The Create plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, and including, 2.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerable advanced-filter SQL branch is only entered when at least one of the following parameters is present in the request: linked_posts, created_after, created_before, missing_fields, post_id, a comma-separated type value, or exclude_type.

    6.5
    about 1 hour ago
  • The Wow Elements Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.11.2. This is due to the plugin passing user-controlled input from the 'Changelog File' setting directly to the wp_remote_get function without adequate validation or sanitization of the URL. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

    6.5
    about 1 hour ago
  • The WP Composer – The Easiest Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pbwp_raw_shortcode' shortcode in all versions up to, and including, 1.0.5. This is due to the shortcode handler decoding Base64-encoded content and outputting it directly without any sanitization or escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The Base64 encoding allows the payload to bypass WordPress's KSES content filtering at save time, since the encoded string contains no harmful HTML characters.

    6.4
    about 1 hour ago
  • The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1. This is due to missing authorization checks on the twiz_ajax_callback AJAX action's 'savesection' handler combined with the use of eval() to execute user-supplied 'custom logic' code on the frontend. The AJAX handler at twiz-ajax.php verifies a nonce but performs no current_user_can() capability check for the ACTION_SAVE_SECTION case. Furthermore, the nonce is exposed to any authenticated user through the directly-accessible twiz-ajax.js.php file which loads WordPress and outputs the nonce. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary PHP code via the twiz_custom_logic POST parameter when saving a section with output choice 'twiz_logic_output'.

    8.8
    about 1 hour ago
  • The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the full customer dataset from the ea_customers table, including personally identifiable information such as names, email addresses, mobile numbers, dates of birth, and physical addresses.

    6.5
    about 1 hour ago
  • The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'host' parameter in all versions up to, and including, 4.7.42 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The vulnerability is only exploitable when in the system_requirements stage.

    6.1
    about 1 hour ago
  • The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.23. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the whitelabel settings password to an attacker-controlled value, enabling them to unlock whitelabel-protected admin settings tabs including whitelabel, general, and advanced configuration.

    4.3
    about 1 hour ago
  • The WP Optimizer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to and including 2.5.0. This is due to an unsafe subquery-detection branch in the Query::parse_key_compare_field() method that, when the user-supplied value matches the regex ^[(\s]*SELECT\s+, wraps the value in parentheses and embeds it directly into the SQL string without any escaping or quoting. While the normal LIKE code path correctly uses esc_sql($wpdb->esc_like(...)) and wraps the value in single quotes, this branch completely bypasses those protections. Because the attack payload (SELECT ...) contains no single quotes, WordPress's wp_magic_quotes() provides no protection. This makes it possible for authenticated attackers with administrator-level access to inject arbitrary SQL subqueries — including time-based blind payloads — that can be used to extract sensitive information from the database.

    4.9
    about 1 hour ago
  • The Create plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions up to, and including, 2.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The REST endpoint permission callback defaults to the publish_posts capability, meaning any Author-level user or above can reach the vulnerable code path without any additional preconditions.

    6.5
    about 1 hour ago
  • The AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via save_ams_license_key AJAX Handler in all versions up to, and including, 3.15.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The save_ams_license_key AJAX handler performs no capability check and no nonce verification, meaning any authenticated user with Subscriber-level access or above can invoke it to store the malicious payload.

    6.4
    about 1 hour ago
  • The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callback in all versions up to, and including, 4.2.6 due to the use of an AND (&&) operator instead of an OR (||) operator. This makes it possible for authenticated attackers, with Subscriber-level access and above, to bypass authorization checks and create arbitrary posts.

    4.3
    about 1 hour ago
  • The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8. This is due to the publicly accessible `woocommerce_api_wt_stripe` webhook endpoint (`EH_Stripe_Webhook_Handler::handle()`) wrapping the only call to `\Stripe\Webhook::constructEvent()` inside an `if (!empty($endpoint_secret))` guard that is never entered on default installations — because the `eh_stripe_webhook_secret` option is empty after a fresh plugin install — causing the raw, attacker-controlled POST body to be decoded and processed as a fully trusted Stripe event without any signature verification, authentication, or authorization. This makes it possible for unauthenticated attackers to send forged Stripe webhook events to manipulate WooCommerce order statuses, including marking unpaid orders as paid or completed via `payment_complete()`, forcing legitimate orders into a failed state, fabricating dispute notifications, and injecting forged refund events. This vulnerability is only exploitable when the Stripe webhook signing secret has not been configured by an administrator; once a valid signing secret is saved, `\Stripe\Webhook::constructEvent()` is enforced and forged requests are rejected.

    5.3
    about 1 hour ago
  • The VW Writer Blog theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'vw_writer_blog_reset_all_settings' function in all versions up to, and including, 1.3.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset all theme customizer settings to their defaults.

    4.3
    about 1 hour ago
  • The Bread plugin for WordPress is vulnerable to information exposure in versions up to and including 2.9.12. This is due to the lack of authentication and authorization checks on the settings export functionality (download_settings function) which is registered on the plugins_loaded hook and explicitly allows execution on non-admin (public) pages. The function exports all plugin configuration settings including the protection_password field, which is stored in plaintext. This makes it possible for unauthenticated attackers to retrieve the PDF protection password by accessing the /?export-meeting-list=1 endpoint.

    5.3
    about 1 hour ago
  • The Metasync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_instant_indexing_settings() function in versions up to, and including, 2.6.23. This function is registered on the admin_init hook and only checks for the presence of $_POST['submit'] before writing attacker-supplied $_POST['metasync_post_types'] into the site-wide 'metasync_options_instant_indexing' option via update_option(); no current_user_can()/current_user_has_plugin_access() check and no nonce verification are performed. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the site's Google Instant Indexing post-type configuration, controlling which post types are auto-submitted to Google's Instant Indexing service.

    4.3
    about 1 hour ago
  • The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.11. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve invoice numbers, formatted invoice numbers, and creation timestamps for arbitrary WooCommerce orders by supplying any OrderNumber and InvoiceId values with a garbage nonce.

    4.3
    about 1 hour ago
  • The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple Choice 'Other' Value in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected script executes in the context of the WordPress admin results view, making administrators the primary target when reviewing submitted form entries.

    7.2
    about 1 hour ago
  • The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' parameter in all versions up to, and including, 3.7.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    6.1
    about 1 hour ago
  • The Flex Import plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0. This is due to the license_activate_fleximp() and license_deactivate_fleximp() functions, hooked to the wp_ajax_license_activate_fleximp and wp_ajax_license_deactivate_fleximp AJAX actions, lacking both a capability check (current_user_can()) and nonce verification (the client-side script sends a 'wpnonce' value but the handlers never validate it). This makes it possible for authenticated attackers, with subscriber-level access and above, to activate an arbitrary/fraudulent license key (persisting it via update_option('fleximp_is_premium') and toggling validation, suspension, and bundle status options) or deactivate the site's legitimate license (deleting the stored key and setting fleximp_validation_status to false), thereby disrupting the plugin's premium functionality.

    4.3
    about 1 hour ago
  • The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated users to reach administrator-oriented endpoints and trigger a persistent state change.

    about 3 hours ago
  • The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the authenticity of its PIX payment webhook before updating an order's status, allowing unauthenticated attackers to mark a pending order as paid without paying.

    about 3 hours ago

CVSS Score Histogram

256.3k scored
12
36
1.5k
4.4k
21.6k
47.5k
42.5k
67.0k
35.5k
36.2k
0123456789+
lowCVSS base scorehigh

Severity

all tracked
256.2k
total
  • MEDIUM43.5%
  • HIGH40.0%
  • CRITICAL14.1%
  • LOW2.3%
  • NONE0.0%

Top Weaknesses

30 · CWE

Top Vendors

50 · by CVE
  • 1
    microsoft1090p
    26.9k
  • 2
    linux18p
    19.4k
  • 3
    google239p
    16.6k
  • 4
    apple198p
    15.4k
  • 5
    oracle1109p
    12.7k
  • 6
    debian112p
    10.2k
  • 7
    ibm1618p
    8.8k
  • 8
    adobe183p
    7.7k
  • 9
    cisco6285p
    6.7k
  • 10
    redhat541p
    6.2k
  • 11
    fedoraproject20p
    5.4k
  • 12
    canonical60p
    4.3k
  • 13
    mozilla44p
    3.8k
  • 14
    apache392p
    3.4k
  • 15
    opensuse50p
    3.3k
  • 16
    qualcomm3633p
    2.5k
  • 17
    hp17236p
    2.5k
  • 18
    netapp373p
    2.5k
  • 19
    huawei1956p
    2.3k
  • 20
    siemens4191p
    2.2k
  • 21
    tenda218p
    1.8k
  • 22
    jenkins696p
    1.8k
  • 23
    intel9744p
    1.8k
  • 24
    dell3734p
    1.8k
  • 25
    dlink934p
    1.8k
  • 26
    sun200p
    1.7k
  • 27
    samsung2873p
    1.7k
  • 28
    sap430p
    1.6k
  • 29
    gitlab10p
    1.5k
  • 30
    netgear1136p
    1.3k
  • 31
    gnu122p
    1.2k
  • 32
    suse121p
    1.2k
  • 33
    fortinet255p
    1.1k
  • 34
    juniper440p
    1.1k
  • 35
    totolink159p
    1.1k
  • 36
    vmware198p
    1.1k
  • 37
    mediatek598p
    1.1k
  • 38
    phpgurukul87p
    1.1k
  • 39
    f5282p
    1.0k
  • 40
    joomla149p
    986
  • 41
    nvidia360p
    876
  • 42
    drupal142p
    864
  • 43
    imagemagick3p
    812
  • 44
    foxitsoftware24p
    797
  • 45
    schneider-electric1763p
    780
  • 46
    php25p
    780
  • 47
    wireshark1p
    776
  • 48
    oretnom23112p
    761
  • 49
    broadcom286p
    692
  • 50
    novell111p
    677

Top Assigners

50 · CNA
  • 1
    mitre
    116.2k
  • 2
    GitHub_M
    19.8k
  • 3
    Patchstack
    17.5k
  • 4
    VulDB
    16.3k
  • 5
    Linux
    15.8k
  • 6
    redhat
    12.8k
  • 7
    Wordfence
    11.1k
  • 8
    oracle
    9.3k
  • 9
    apple
    8.7k
  • 10
    microsoft
    8.7k
  • 11
    ibm
    8.7k
  • 12
    adobe
    7.8k
  • 13
    VulnCheck
    7.7k
  • 15
    cisco
    6.7k
  • 16
    Chrome
    6.1k
  • 17
    google_android
    5.3k
  • 18
    WPScan
    5.2k
  • 19
    intel
    4.2k
  • 20
    icscert
    3.9k
  • 21
    qualcomm
    3.7k
  • 22
    certcc
    3.5k
  • 23
    zdi
    3.4k
  • 24
    jpcert
    3.3k
  • 25
    mozilla
    2.8k
  • 26
    talos
    2.5k
  • 27
    apache
    2.5k
  • 28
    dell
    2.5k
  • 29
    huawei
    2.3k
  • 31
    fortinet
    2.0k
  • 32
    siemens
    1.9k
  • 33
    hackerone
    1.7k
  • 34
    hpe
    1.7k
  • 35
    sap
    1.6k
  • 36
    GitLab
    1.6k
  • 37
    @huntrdev
    1.6k
  • 38
    jenkins
    1.6k
  • 39
    416baaa9-dc9f-4396-8d5f-8c081fb06d67
    1.2k
  • 40
    INCIBE
    1.1k
  • 41
    MediaTek
    1.1k
  • 42
    nvidia
    1.1k
  • 43
    juniper
    1.0k
  • 44
    hp
    1.0k
  • 45
    f5
    972
  • 46
    twcert
    915
  • 47
    @huntr_ai
    904
  • 48
    vmware
    901
  • 49
    snyk
    880
  • 50
    debian
    805

CVE Publish Timeline

last 3 years
169.6k
new CVEs · Sep 2023Sep 2026
155
avg / day
1.6k
peak Sep 2026
Sep 2023Mar 2024Sep 2024Mar 2025Sep 2025Mar 2026Sep 2026Sep 2026
05191.0k1.6k

Top ATT&CK

50 · technique

Top Products

50 · vulnerable
  • 1
    linux kernellinux
    15.0k
  • 2
    debian linuxdebian
    10.0k
  • 3
    androidgoogle
    8.3k
  • 4
    chromegoogle
    6.5k
  • 5
    windows server 2016microsoft
    5.4k
  • 6
    fedorafedoraproject
    5.4k
  • 7
    windows server 2019microsoft
    5.3k
  • 8
    windows server 2012microsoft
    4.4k
  • 9
    iphone osapple
    4.3k
  • 10
    ubuntu linuxcanonical
    4.1k
  • 11
    windows server 2022microsoft
    3.7k
  • 12
    windows server 2008microsoft
    3.6k
  • 13
    firefoxmozilla
    3.3k
  • 14
    mac os xapple
    3.2k
  • 15
    macosapple
    3.2k
  • 16
    windows 10microsoft
    3.0k
  • 17
    windows 10 1809microsoft
    2.8k
  • 18
    windows 10 21h2microsoft
    2.8k
  • 19
    windows 10 22h2microsoft
    2.8k
  • 20
    windows 10 1607microsoft
    2.4k
  • 21
    windows 7microsoft
    2.4k
  • 22
    windows server 2025microsoft
    2.3k
  • 23
    windows 11 24h2microsoft
    2.2k
  • 24
    windows 8.1microsoft
    2.2k
  • 25
    ipadosapple
    2.2k
  • 26
    tvosapple
    2.1k
  • 27
    windows 11 23h2microsoft
    2.1k
  • 28
    windows rt 8.1microsoft
    2.0k
  • 29
    enterprise linux desktopredhat
    1.9k
  • 30
    enterprise linuxredhat
    1.9k
  • 31
    watchosapple
    1.9k
  • 32
    thunderbirdmozilla
    1.9k
  • 33
    leapopensuse
    1.9k
  • 34
    enterprise linux serverredhat
    1.9k
  • 35
    enterprise linux workstationredhat
    1.8k
  • 36
    acrobat dcadobe
    1.8k
  • 37
    acrobat reader dcadobe
    1.8k
  • 38
    windows server 2022 23h2microsoft
    1.7k
  • 39
    safariapple
    1.7k
  • 40
    windows 11 22h2microsoft
    1.7k
  • 41
    internet explorermicrosoft
    1.6k
  • 42
    windows 11 25h2microsoft
    1.5k
  • 43
    opensuseopensuse
    1.5k
  • 44
    gitlabgitlab
    1.4k
  • 45
    acrobatadobe
    1.4k
  • 46
    mysqloracle
    1.3k
  • 47
    experience manageradobe
    1.3k
  • 48
    windows 10 1507microsoft
    1.2k
  • 49
    windows 11 26h1microsoft
    1.2k
  • 50
    wcd9380 firmwarequalcomm
    1.2k

Exploit Sources

39,265 exploited
  • 1
    Exploitdbexploitdb
    25.1k
  • 2
    Github Pocgithub_poc
    11.0k
  • 3
    Metasploitmetasploit
    3.2k

KEV Velocity

last 14d
21
added · 14d
peak 4
09-08
09-06KEV additions / day09-19
Sources22/22
cisa_kev1,716 / 24habout 6 hours ago·csaf_cisco0 / 24habout 3 hours ago·csaf_oracle0 / 24habout 2 hours ago·csaf_redhat0 / 24h35 minutes ago·csaf_siemens0 / 24habout 2 hours ago·cve.org21,609 / 24h10 minutes ago·EPSS (FIRST.org)376,715 / 24habout 7 hours ago·euvd48,000 / 24h20 minutes ago·exploitdb47,160 / 24habout 4 hours ago·ghsa77 / 24habout 1 hour ago·github_poc517,635 / 24h10 minutes ago·metasploit6 days ago·misp6 days ago·mitre_attack6 days ago·mitre_capec6 days ago·mitre_cwe6 days ago·mitre_d3fend6 days ago·msrc0 / 24habout 3 hours ago·NVD API 2.02,562 / 24h5 minutes ago·osv288,226 / 24habout 5 hours ago·sigma3,757 / 24habout 4 hours ago·vulncheck_kev0 / 24habout 5 hours ago·cisa_kev1,716 / 24habout 6 hours ago·csaf_cisco0 / 24habout 3 hours ago·csaf_oracle0 / 24habout 2 hours ago·csaf_redhat0 / 24h35 minutes ago·csaf_siemens0 / 24habout 2 hours ago·cve.org21,609 / 24h10 minutes ago·EPSS (FIRST.org)376,715 / 24habout 7 hours ago·euvd48,000 / 24h20 minutes ago·exploitdb47,160 / 24habout 4 hours ago·ghsa77 / 24habout 1 hour ago·github_poc517,635 / 24h10 minutes ago·metasploit6 days ago·misp6 days ago·mitre_attack6 days ago·mitre_capec6 days ago·mitre_cwe6 days ago·mitre_d3fend6 days ago·msrc0 / 24habout 3 hours ago·NVD API 2.02,562 / 24h5 minutes ago·osv288,226 / 24habout 5 hours ago·sigma3,757 / 24habout 4 hours ago·vulncheck_kev0 / 24habout 5 hours ago·

Top Threat Actors

drag to browse · all actors →
Storm-1175
Cybercrime

no aliases

CVEs attributed11 KEV-listed
11
UAT-11795
Cybercrime

no aliases

CVEs attributed9 KEV-listed
9
UAT-8616
Cybercrime

no aliases

CVEs attributed6 KEV-listed
6
UAT-8302
Cybercrime

no aliases

CVEs attributed3 KEV-listed
3
Inception Framework
APT
EspionageState-sponsored

aka: ATK116 · Blue Odin · Clean Ursa · Cloud Atlas +2

CVEs attributed3 KEV-listed
3
Dark Caracal
Cybercrime

aka: G0070

CVEs attributed3 KEV-listed
3
INJ3CTOR3
Cybercrime

no aliases

CVEs attributed1 KEV-listed
2
UNC5330
Cybercrime

no aliases

CVEs attributed2 KEV-listed
2
UNC5337
Cybercrime

no aliases

CVEs attributed2 KEV-listed
2
The Gentlemen
Ransomware

no aliases

CVEs attributed2 KEV-listed
2
Belsen Group
Cybercrime

no aliases

CVEs attributed2 KEV-listed
2
UNC6748
Cybercrime

no aliases

CVEs attributed2 KEV-listed
2
SandCat
Cybercrime

no aliases

CVEs attributed2 KEV-listed
2
Shadow-Earth-053
Cybercrime

no aliases

CVEs attributed2 KEV-listed
2
Mora_001
Ransomware

no aliases

CVEs attributed2 KEV-listed
2
UAT-7810
Cybercrime

no aliases

CVEs attributed2 KEV-listed
2
ScreamedJungle
Cybercrime

no aliases

CVEs attributed1 KEV-listed
2
APT31
APT

aka: BRONZE VINEWOOD · JUDGMENT PANDA · Red keres · TA412 +4

CVEs attributed2 KEV-listed
2
Water Sigbin
APT

aka: 8220 Gang

CVEs attributed2 KEV-listed
2
Void Blizzard
Cybercrime

aka: LAUNDRY BEAR · Laundry Bear · TA488 · UAC-0190

CVEs attributed2 KEV-listed
2
Turla
APT
EspionageState-sponsored

aka: ATK13 · Blue Python · G0010 · Group 88 +22

CVEs attributed2 KEV-listed
2
APT41
APT
State-sponsored

aka: Amoeba · BARIUM · BRONZE ATLAS · BRONZE EXPORT +17

CVEs attributed2 KEV-listed
2
TA459
APT

aka: G0062

CVEs attributed2 KEV-listed
2
Team46
Cybercrime

aka: TaxOff

CVEs attributed1 KEV-listed
2
DarkCasino
APT

no aliases

CVEs attributed1 KEV-listed
1
DragonForce
Hacktivist

no aliases

CVEs attributed1 KEV-listed
1
Denim Tsunami
Cybercrime

aka: DSIRF · KNOTWEED

CVEs attributed1 KEV-listed
1
Lilac Typhoon
APT

aka: DEV-0234

CVEs attributed1 KEV-listed
1
Opal Sleet
APT

aka: Konni · OSMIUM · Vedalia

CVEs attributed1 KEV-listed
1
Storm-1567
Ransomware

aka: Akira · GOLD SAHARA · PUNK SPIDER

CVEs attributed1 KEV-listed
1
ProCC
Cybercrime

no aliases

CVEs attributed1 KEV-listed
1
UNC5325
Cybercrime

no aliases

CVEs attributed1 KEV-listed
1
FlyingYeti
Cybercrime

aka: Flying Yeti · Storm-1837

CVEs attributed1 KEV-listed
1
Void Banshee
Cybercrime

no aliases

CVEs attributed1 KEV-listed
1
Earth Baxia
Cybercrime

no aliases

CVEs attributed1 KEV-listed
1
CosmicBeetle
Ransomware

no aliases

CVEs attributed1 KEV-listed
1
SongXY
APT

no aliases

CVEs attributed1 KEV-listed
1
Asnarök
Cybercrime

aka: Personal Panda

CVEs attributed1 KEV-listed
1
UNC5820
Cybercrime

no aliases

CVEs attributed1 KEV-listed
1
Tstark
Cybercrime

no aliases

CVEs attributed1 KEV-listed
1
UAC-0194
Cybercrime

no aliases

CVEs attributed1 KEV-listed
1
Ukrainian Cyber Alliance
Ransomware

aka: UCA

CVEs attributed1 KEV-listed
1
Operation ForumTroll
Cybercrime

no aliases

CVEs attributed1 KEV-listed
1
UAC-0226
Cybercrime

no aliases

CVEs attributed1 KEV-listed
1
Earth Lamia
Cybercrime

aka: UNC5454

CVEs attributed1 KEV-listed
1
UNC6485
Cybercrime

no aliases

CVEs attributed1 KEV-listed
1
UAT-8837
Cybercrime

no aliases

CVEs attributed1 KEV-listed
1
DarkPink
APT

aka: Saaiwc

CVEs attributed1 KEV-listed
1
UAT-6382
Cybercrime

no aliases

CVEs attributed
1
Amaranth-Dragon
Cybercrime

no aliases

CVEs attributed1 KEV-listed
1

Live Events

Reconnecting…