Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2020-6065

    An exploitable out-of-bounds write vulnerability exists in the bmp_parsing function of the igcore19d.dll library of Accusoft ImageGear, version 19.5.0. A specially crafted BMP file can cause an out-of-bounds write, resulting in a remote code execution. An... Read more

    Affected Products : imagegear
    • Published: Feb. 11, 2020
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2024-48226

    Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.... Read more

    Affected Products : funadmin
    • Published: Oct. 25, 2024
    • Modified: Oct. 31, 2024
  • 9.8

    CRITICAL
    CVE-2022-32417

    PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php.... Read more

    Affected Products : pbootcms
    • Published: Jul. 14, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-38026

    SpotCam Co., Ltd. SpotCam FHD 2 has a vulnerability of using hard-coded uBoot credentials. An remote attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service. ... Read more

    Affected Products : fhd_2_firmware fhd_2
    • Published: Aug. 28, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2024-44550

    Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv.... Read more

    Affected Products : ax1806_firmware ax1806
    • Published: Aug. 26, 2024
    • Modified: Aug. 27, 2024
  • 9.8

    CRITICAL
    CVE-2023-3806

    A vulnerability, which was classified as critical, was found in SourceCodester House Rental and Property Listing System 1.0. Affected is an unknown function of the file btn_functions.php. The manipulation leads to unrestricted upload. It is possible to la... Read more

    • Published: Jul. 21, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2013-10009

    A vulnerability was found in DrAzraelTod pyChao and classified as critical. Affected by this issue is the function klauen/lesen of the file mod_fun/__init__.py. The manipulation leads to sql injection. The patch is identified as 9d8adbc07c384ba51c2583ce08... Read more

    Affected Products : pychao
    • Published: Jan. 07, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2020-7508

    A CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to gain full access by brute force.... Read more

    Affected Products : easergy_t300_firmware easergy_t300
    • Published: Jun. 16, 2020
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2024-1921

    A vulnerability, which was classified as critical, was found in osuuu LightPicture up to 1.2.2. Affected is an unknown function of the file /app/controller/Setup.php. The manipulation leads to unrestricted upload. It is possible to launch the attack remot... Read more

    Affected Products : lightpicture
    • Published: Feb. 27, 2024
    • Modified: Dec. 18, 2024
  • 9.8

    CRITICAL
    CVE-2022-28368

    Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file).... Read more

    Affected Products : dompdf
    • Published: Apr. 03, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-43201

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the hi_up parameter in the qos_ext.asp function.... Read more

    Affected Products : di-7200g_firmware di-7200g
    • Published: Sep. 20, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-38386

    Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.... Read more

    Affected Products : ninja_forms
    • Published: Jun. 19, 2024
    • Modified: Apr. 07, 2025
  • 9.8

    CRITICAL
    CVE-2023-43270

    dst-admin v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the userId parameter at /home/playerOperate.... Read more

    Affected Products : dst-admin
    • Published: Sep. 22, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2024-20450

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying... Read more

    • Published: Aug. 07, 2024
    • Modified: Aug. 23, 2024
  • 9.8

    CRITICAL
    CVE-2022-23882

    TuziCMS 2.0.6 is affected by SQL injection in \App\Manage\Controller\BannerController.class.php.... Read more

    Affected Products : tuzicms
    • Published: Mar. 28, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-47873

    Netcad KEOS 1.0 is vulnerable to XML External Entity (XXE) resulting in SSRF with XXE (remote).... Read more

    Affected Products : keos
    • Published: Jan. 31, 2023
    • Modified: Mar. 27, 2025
  • 9.8

    CRITICAL
    CVE-2024-51211

    SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to improper input validation of the $username_stn_id parameter, which can be manipulated by an attacker to inject... Read more

    Affected Products : opensis
    • Published: Nov. 08, 2024
    • Modified: Jul. 17, 2025
  • 9.8

    CRITICAL
    CVE-2009-3887

    ytnef has directory traversal... Read more

    Affected Products : ytnef
    • Published: Oct. 29, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-48008

    An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file.... Read more

    Affected Products : limesurvey
    • Published: Jan. 27, 2023
    • Modified: Mar. 28, 2025
  • 9.8

    CRITICAL
    CVE-2024-9088

    A vulnerability has been found in SourceCodester Telecom Billing Management System 1.0 and classified as critical. This vulnerability affects the function login. The manipulation of the argument uname leads to buffer overflow. The exploit has been disclos... Read more

    Affected Products : telecom_billing_management_system
    • Published: Sep. 22, 2024
    • Modified: Sep. 26, 2024
Showing 20 of 294299 Results