Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 108 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| CVE-2023-46604 KEV | CRITICAL | 9.0 | Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network… | — | cisa_kev | |
| CVE-2023-33246 KEV | CRITICAL | 9.0 | Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lac… | — | cisa_kev | |
| CVE-2023-27524 KEV | CRITICAL | 9.0 | Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authe… | — | cisa_kev | |
| CVE-2023-23752 KEV | CRITICAL | 9.0 | Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints. | — | cisa_kev | |
| CVE-2022-33891 KEV | CRITICAL | 9.0 | Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) a… | — | cisa_kev | |
| CVE-2022-24706 KEV | CRITICAL | 9.0 | Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to esca… | — | cisa_kev | |
| CVE-2022-24112 KEV | CRITICAL | 9.0 | Apache APISIX contains an authentication bypass vulnerability that allows for remote code execution. | — | cisa_kev | |
| CVE-2021-45046 KEV | CRITICAL | 9.0 | Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, wh… | — | cisa_kev | |
| CVE-2021-44228 KEV | CRITICAL | 9.0 | Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpo… | — | cisa_kev | |
| CVE-2021-42013 KEV | CRITICAL | 9.0 | Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if f… | — | cisa_kev | |
| CVE-2021-41773 KEV | CRITICAL | 9.0 | Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if f… | — | cisa_kev | |
| CVE-2021-40438 KEV | CRITICAL | 9.0 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. Th… | — | cisa_kev | |
| CVE-2020-25213 KEV | CRITICAL | 9.0 | WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execut… | — | cisa_kev | |
| CVE-2020-1956 KEV | CRITICAL | 9.0 | Apache Kylin contains an OS command injection vulnerability which could permit an attacker to perform remote code execut… | — | cisa_kev | |
| CVE-2020-1938 KEV | CRITICAL | 9.0 | Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP co… | — | cisa_kev | |
| CVE-2020-17530 KEV | CRITICAL | 9.0 | Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attr… | — | cisa_kev | |
| CVE-2020-17519 KEV | CRITICAL | 9.0 | Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local fil… | — | cisa_kev | |
| CVE-2020-13927 KEV | CRITICAL | 9.0 | The previous default setting for Airflow's Experimental API was to allow all API requests without authentication. | — | cisa_kev | |
| CVE-2020-13671 KEV | CRITICAL | 9.0 | Improper sanitization in the extension file names is present in Drupal core. | — | cisa_kev | |
| CVE-2020-11978 KEV | CRITICAL | 9.0 | A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow. | — | cisa_kev | |
| CVE-2020-11738 KEV | CRITICAL | 9.0 | WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy o… | — | cisa_kev | |
| CVE-2019-9978 KEV | CRITICAL | 9.0 | WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code executio… | — | cisa_kev | |
| CVE-2019-9082 KEV | CRITICAL | 9.0 | ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/inv… | — | cisa_kev | |
| CVE-2019-6340 KEV | CRITICAL | 9.0 | In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP cod… | — | cisa_kev | |
| CVE-2019-17558 KEV | CRITICAL | 9.0 | The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code exe… | — | cisa_kev |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →