Vulnerability index

Browse CVEs

1,270 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness PHP File Inclusion (RFI/LFI)CWE-98 × clear
HIGH 8.8 CVE-2024-3849 The Click to Chat – HoliThemes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.35. This makes it p… Mitigation only Fix from $1,9502024-05-02 HIGH 8.8 CVE-2024-3500 The ElementsKit Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.0 via the Price Menu, Hotspo… Elementskit 3.6.1+ Fix from $1,9502024-05-02 HIGH 8.8 CVE-2024-3499 The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.0 via the gener… Elements Kit Elementor Addons 3.1.1+ Fix from $1,9502024-05-02 CRITICAL 9.3 CVE-2024-1600EPSS 33% A Local File Inclusion (LFI) vulnerability exists in the parisneo/lollms-webui application, specifically within the `/personalities` route. An attack… Lollms Web Ui 9.6+ Fix from $2,3002024-04-10 CRITICAL 9.8 CVE-2024-3136EPSS 5% The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'template' paramet… Masterstudy Lms 3.3.4+ Fix from $2,3002024-04-09 CRITICAL 9.8 CVE-2024-30849 Arbitrary file upload vulnerability in Sourcecodester Complete E-Commerce Site v1.0, allows remote attackers to execute arbitrary code via filename p… Complete E Commerce Site No fix yet Fix from $2,3002024-04-05 HIGH 8.8 CVE-2024-2047 The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.6 via the rende… Elements Kit Elementor Addons 3.0.7+ Fix from $1,9502024-03-30 HIGH 7.2 CVE-2024-3061 The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includ… Husky Products Filter Professional For Woocommerce 1.3.5.3+ Fix from $1,9502024-03-29 CRITICAL 9.8 CVE-2024-2411 The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'modal' parameter.… Masterstudy Lms 3.3.1+ Fix from $2,3002024-03-29 HIGH 8.8 CVE-2024-1382 The Restaurant Reservations plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 via the nd_rst_layou… Restaurant Reservations 2.0+ Fix from $1,9502024-03-07 CRITICAL 9.8 CVE-2023-6989EPSS 57% The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local File Inclusion in all versions u… Shield Security 18.5.10+ Fix from $2,3002024-02-05 HIGH 7.5 CVE-2023-52325 A local file inclusion vulnerability in one of Trend Micro Apex Central's widgets could allow a remote attacker to execute arbitrary code on affected… Apex Central Mitigation only Fix from $1,9502024-01-23 HIGH 7.8 CVE-2024-0315 Remote file inclusion vulnerability in FireEye Central Management affecting version 9.1.1.956704. This vulnerability allows an attacker to upload a m… Central Management Mitigation only Fix from $1,9502024-01-15 HIGH 7.2 CVE-2023-6583 The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via … Import And Export Users And Customers after 1.24.2 Fix from $1,9502024-01-11 HIGH 8.8 CVE-2023-49084EPSS 64% Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). While using the detected SQL … Cacti No fix yet Fix from $1,9502023-12-21 CRITICAL 9.8 CVE-2023-5815 The News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry) p… News \& Blog Designer Pack after 3.4.1 Fix from $2,3002023-11-22 HIGH 8.8 CVE-2023-5099 The HTML filter and csv-file search plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7 via the 'src' at… Html Filter And Csv File Search 2.8+ Fix from $1,9502023-10-31 HIGH 8.8 CVE-2023-5199 The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and including, 0.3 via the 'php-t… Php To Page after 0.3 Fix from $1,9502023-10-30 HIGH 8.8 CVE-2023-5250 The Grid Plus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.3 via a shortcode attribute. This allo… Grid Plus after 1.3.2 Fix from $1,9502023-10-30 CRITICAL 9.8 CVE-2023-4488 The Dropbox Folder Share for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7 via the editor-view.php file. Th… Dropbox Folder Share after 1.9.7 Fix from $2,3002023-10-20 HIGH 7.5 CVE-2023-31718 FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download. Fuxa after 1.1.12 Fix from $1,9502023-09-22 HIGH 7.5 CVE-2023-31716 FUXA <= 1.1.12 has a Local File Inclusion vulnerability via file=fuxa.log Fuxa after 1.1.12 Fix from $1,9502023-09-22 CRITICAL 9.8 CVE-2023-3452EPSS 7% The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'wp_abspath' parameter. This al… Canto after 3.0.4 Fix from $2,3002023-08-12 HIGH 8.8 CVE-2023-4195 PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3. Cockpit 2.6.3+ Fix from $1,9502023-08-06 HIGH 8.8 CVE-2023-2249EPSS 61% The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, a… Wpforo Forum after 2.1.7 Fix from $1,9502023-06-09 HIGH 8.8 CVE-2023-2551 PHP Remote File Inclusion in GitHub repository unilogies/bumsys prior to 2.1.1. Bumsys 2.1.1+ Fix from $1,9502023-05-05 HIGH 8.8 CVE-2023-24217 AgileBio Electronic Lab Notebook v4.234 was discovered to contain a local file inclusion vulnerability. Electronic Lab Notebook No fix yet Fix from $1,9502023-03-06 CRITICAL 9.8 CVE-2022-4606EPSS 35% PHP Remote File Inclusion in GitHub repository flatpressblog/flatpress prior to 1.3. Flatpress after 1.2.1 Fix from $2,3002022-12-18 CRITICAL 9.8 CVE-2022-4446 PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0. Corebos 8.0+ Fix from $2,3002022-12-13 HIGH 7.5 CVE-2022-44786 An issue was discovered in Appalti & Contratti 9.12.2. The target web applications allow Local File Inclusion in any page relying on the href paramet… Appalti \& Contratti No fix yet Fix from $1,9502022-11-21