Vulnerability index

Browse CVEs

1,270 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness PHP File Inclusion (RFI/LFI)CWE-98 × clear
HIGH 8.1 CVE-2024-53800 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in rezgo Rezgo rezgo allows PHP… Rezgo Online Booking 4.17.1+ Fix from $1,9502025-01-07 HIGH 7.5 CVE-2025-22364 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Service Shogun Ach Invoice A… Mitigation only Fix from $1,9502025-01-07 MEDIUM 6.5 CVE-2025-22305 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Essential Plugin Hero Banner… Mitigation only Fix from $1,6002025-01-07 HIGH 7.5 CVE-2024-56281 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in codemstory 워드프레스 결제 … Mitigation only Fix from $1,9502025-01-07 HIGH 7.5 CVE-2024-56282 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elicus WPMozo Addons Lite fo… Mitigation only Fix from $1,9502025-01-07 CRITICAL 9.8 CVE-2024-49649 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in hakeemnala Build App Online … Build App Online after 1.0.23 Fix from $2,3002025-01-07 MEDIUM 6.5 CVE-2024-56216 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themifyme Themify Builder th… Builder after 7.6.3 Fix from $1,6002024-12-31 HIGH 7.5 CVE-2024-56230 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Maidul Dynamic Product Categ… Mitigation only Fix from $1,9502024-12-31 HIGH 8.8 CVE-2024-12272 The WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor plugin for WordPress is vulnerable to Local Fi… Mitigation only Fix from $1,9502024-12-25 CRITICAL 9.8 CVE-2024-12571 The Store Locator for WordPress with Google Maps – LotsOfLocales plugin for WordPress is vulnerable to Local File Inclusion in version 3.98.9 via the… Mitigation only Fix from $2,3002024-12-20 HIGH 8.1 CVE-2024-54270 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axeptio Axeptio axeptio-sdk-… Mitigation only Fix from $1,9502024-12-18 HIGH 7.5 CVE-2024-54376 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Spider Themes EazyDocs eazyd… Mitigation only Fix from $1,9502024-12-16 HIGH 8.8 CVE-2024-12040 The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc… Mitigation only Fix from $1,9502024-12-12 HIGH 7.5 CVE-2024-54225 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in codegearthemes Designer desi… Mitigation only Fix from $1,9502024-12-09 CRITICAL 9.8 CVE-2024-12209EPSS 23% The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, … Mitigation only Fix from $2,3002024-12-08 HIGH 7.5 CVE-2024-53824 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in all_bootstrap_blocks All Boo… Mitigation only Fix from $1,9502024-12-06 HIGH 8.1 CVE-2024-11289 The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.5.9 via several functions like penci_ar… Mitigation only Fix from $1,9502024-12-06 HIGH 7.5 CVE-2024-51541 Local File Inclusion vulnerabilities allow access to sensitive system information.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Ser… Aspect Ent 12 Firmware 3.08.03+ Fix from $1,9502024-12-05 HIGH 8.8 CVE-2024-11429 The Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials plugin for WordPress is vulnerable to Local File In… Mitigation only Fix from $1,9502024-12-05 CRITICAL 9.8 CVE-2024-53739 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cool Plugins Cryptocurrency … Cryptocurrency Widgets For Elementor 1.6.5+ Fix from $2,3002024-11-30 HIGH 7.5 CVE-2024-52501 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebbyTemplate Office Locator… Mitigation only Fix from $1,9502024-11-28 HIGH 7.5 CVE-2024-52497 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in quomodosoft Shopready shopre… Mitigation only Fix from $1,9502024-11-28 HIGH 7.5 CVE-2024-52499 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ibrahim Pricing table addon … Mitigation only Fix from $1,9502024-11-28 HIGH 7.5 CVE-2024-52496 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AbsolutePlugins Absolute Add… Mitigation only Fix from $1,9502024-11-28 HIGH 8.8 CVE-2024-10873 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via th… Element Kit For Elementor 1.4.3+ Fix from $1,9502024-11-23 HIGH 8.8 CVE-2024-10898 The Contact Form 7 Email Add on plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 via the cf7_emai… Contact Form 7 Email Add On after 1.9 Fix from $1,9502024-11-21 HIGH 7.5 CVE-2024-52450 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in officialprocoders nBlocks nb… Mitigation only Fix from $1,9502024-11-20 CRITICAL 9.8 CVE-2024-52428 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Peter Ads Booster by Ads Pro… Ads Booster By Ads Pro after 1.12 Fix from $2,3002024-11-18 MEDIUM 5.3 CVE-2024-52386 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Classified Listi… Mitigation only Fix from $1,6002024-11-16 HIGH 8.1 CVE-2024-52381 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Shoaib Rehmat ZIJ KART zij-k… Mitigation only Fix from $1,9502024-11-14