Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 109 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| CVE-2019-11043 KEV | CRITICAL | 9.0 | In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocat… | — | cisa_kev | |
| CVE-2019-1003030 KEV | CRITICAL | 9.0 | Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity … | — | cisa_kev | |
| CVE-2019-1003029 KEV | CRITICAL | 9.0 | Jenkins Script Security Plugin contains a protection mechanism failure, allowing an attacker to bypass the sandbox. | — | cisa_kev | |
| CVE-2019-0211 KEV | CRITICAL | 9.0 | Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (inc… | — | cisa_kev | |
| CVE-2019-0193 KEV | CRITICAL | 9.0 | The optional Apache Solr module DataImportHandler contains a code injection vulnerability. | — | cisa_kev | |
| CVE-2018-7602 KEV | CRITICAL | 9.0 | A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit mu… | — | cisa_kev | |
| CVE-2018-7600 KEV | CRITICAL | 9.0 | Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vecto… | — | cisa_kev | |
| CVE-2018-20062 KEV | CRITICAL | 9.0 | ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of th… | — | cisa_kev | |
| CVE-2018-11776 KEV | CRITICAL | 9.0 | Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alw… | — | cisa_kev | |
| CVE-2017-9841 KEV | CRITICAL | 9.0 | PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as… | — | cisa_kev | |
| CVE-2017-9805 KEV | CRITICAL | 9.0 | Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filter… | — | cisa_kev | |
| CVE-2017-9791 KEV | CRITICAL | 9.0 | The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw messa… | — | cisa_kev | |
| CVE-2017-5638 KEV | CRITICAL | 9.0 | Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote … | — | cisa_kev | |
| CVE-2017-12617 KEV | CRITICAL | 9.0 | When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP … | — | cisa_kev | |
| CVE-2017-12615 KEV | CRITICAL | 9.0 | When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a sp… | — | cisa_kev | |
| CVE-2016-8735 KEV | CRITICAL | 9.0 | Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener … | — | cisa_kev | |
| CVE-2016-4437 KEV | CRITICAL | 9.0 | Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restric… | — | cisa_kev | |
| CVE-2016-3088 KEV | CRITICAL | 9.0 | The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an H… | — | cisa_kev | |
| CVE-2016-10033 KEV | CRITICAL | 9.0 | PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied input. Specifically, thi… | — | cisa_kev | |
| CVE-2013-2251 KEV | CRITICAL | 9.0 | Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions. | — | cisa_kev | |
| CVE-2012-1823 KEV | CRITICAL | 9.0 | sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote… | — | cisa_kev | |
| CVE-2012-0391 KEV | CRITICAL | 9.0 | The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability t… | — | cisa_kev | |
| CVE-2009-1151 KEV | CRITICAL | 9.0 | Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in … | — | cisa_kev | |
| CVE-2006-1547 KEV | CRITICAL | 9.0 | ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-… | — | cisa_kev | |
| c9d5c661-bc81-4706-b930-6e3309f3d705 | < 2.9.14 |
CRITICAL | 9.0 | The Affiliates Manager plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.9.13. Thi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →