Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.7

    MEDIUM
    CVE-2020-24721

    An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-09-29, as used in COVID-19 applications on Android and iOS. It allows a user to be put in a position where he or she can be coerced into proving or disprov... Read more

    • Published: Sep. 30, 2020
    • Modified: Nov. 21, 2024
  • 5.7

    MEDIUM
    CVE-2019-5211

    The Huawei Share function of P20 phones with versions earlier than Emily-L29C 9.1.0.311 has an improper file management vulnerability. The attacker tricks the victim to perform certain operations on the mobile phone during file transfer. Because the file ... Read more

    Affected Products : p20_firmware p20
    • Published: Nov. 29, 2019
    • Modified: Nov. 21, 2024
  • 5.7

    MEDIUM
    CVE-2021-32793

    Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface version 5.5.1, the function to add domains to blocklists or allowlists is vulnerable to a stored cross-site-... Read more

    Affected Products : pi-hole web_interface
    • Published: Aug. 04, 2021
    • Modified: Nov. 21, 2024
  • 5.7

    MEDIUM
    CVE-2022-0245

    Cross-Site Request Forgery (CSRF) in GitHub repository livehelperchat/livehelperchat prior to 2.0.... Read more

    Affected Products : live_helper_chat livehelperchat
    • Published: Jan. 18, 2022
    • Modified: Nov. 21, 2024
  • 5.7

    MEDIUM
    CVE-2023-25569

    Apollo is a configuration management system. Prior to version 2.1.0, a low-privileged user can create a special web page. If an authenticated portal admin visits this page, the page can silently send a request to assign new roles for that user without any... Read more

    Affected Products : apollo
    • Published: Feb. 20, 2023
    • Modified: Nov. 21, 2024
  • 5.7

    MEDIUM
    CVE-2023-6146

    A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in the presentation of logging information to users. This vulnerability allowed a user with login access to the application to introduce XSS... Read more

    Affected Products : private_cloud_platform
    • Published: Dec. 08, 2023
    • Modified: Nov. 21, 2024
  • 5.7

    MEDIUM
    CVE-2023-29680

    Cleartext Transmission in set-cookie:ecos_pw: Tenda N301 v6.0, Firmware v12.02.01.61_multi allows an authenticated attacker on the LAN or WLAN to intercept communications with the router and obtain the password.... Read more

    Affected Products : n301_firmware n301
    • Published: May. 01, 2023
    • Modified: Jan. 30, 2025
  • 5.7

    MEDIUM
    CVE-2024-7391

    ChargePoint Home Flex Bluetooth Low Energy Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of ChargePoint Home Flex charging devices. User interaction i... Read more

    Affected Products : home_flex_firmware home_flex
    • Published: Nov. 22, 2024
    • Modified: Dec. 03, 2024
  • 5.7

    MEDIUM
    CVE-2024-27106

    Vulnerable data in transit in GE HealthCare EchoPAC products... Read more

    Affected Products :
    • Published: May. 14, 2024
    • Modified: Nov. 21, 2024
  • 5.7

    MEDIUM
    CVE-2024-9469

    A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and t... Read more

    Affected Products : cortex_xdr_agent windows
    • Published: Oct. 09, 2024
    • Modified: Oct. 15, 2024
  • 5.7

    MEDIUM
    CVE-2024-51011

    Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at pppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more

    • Published: Nov. 05, 2024
    • Modified: May. 21, 2025
  • 5.7

    MEDIUM
    CVE-2025-25188

    Hickory DNS is a Rust based DNS client, server, and resolver. A vulnerability present starting in version 0.8.0 and prior to versions 0.24.3 and 0.25.0-alpha.5 impacts Hickory DNS users relying on DNSSEC verification in the client library, stub resolver, ... Read more

    Affected Products :
    • Published: Feb. 10, 2025
    • Modified: Feb. 10, 2025
    • Vuln Type: Cryptography
  • 5.7

    MEDIUM
    CVE-2022-43539

    A vulnerability exists in the ClearPass Policy Manager cluster communications that allow for an attacker in a privileged network position to potentially obtain sensitive information. A successful exploit could allow an attacker to retrieve information th... Read more

    Affected Products : clearpass_policy_manager
    • Published: Jan. 05, 2023
    • Modified: Apr. 10, 2025
  • 5.7

    MEDIUM
    CVE-2024-32306

    Tenda AC10U v1.0 Firmware v15.03.06.49 has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.... Read more

    Affected Products : ac10u_firmware ac10u
    • Published: Apr. 17, 2024
    • Modified: Mar. 17, 2025
  • 5.7

    MEDIUM
    CVE-2022-28648

    In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered... Read more

    Affected Products : youtrack
    • Published: Apr. 05, 2022
    • Modified: Nov. 21, 2024
  • 5.7

    MEDIUM
    CVE-2024-51399

    Altai Technologies Ltd Altai IX500 Indoor 22 802.11ac Wave 2 AP After login, there are file reads in the background, and attackers can obtain sensitive information such as user credentials, system configuration, and database connection strings, which can ... Read more

    Affected Products :
    • Published: Nov. 01, 2024
    • Modified: Nov. 05, 2024
  • 5.7

    MEDIUM
    CVE-2024-49501

    Sysmac Studio provided by OMRON Corporation contains an incorrect authorization vulnerability. If this vulnerability is exploited, an attacker may access the program which is protected by Data Protection function.... Read more

    Affected Products :
    • Published: Nov. 01, 2024
    • Modified: Nov. 01, 2024
  • 5.7

    MEDIUM
    CVE-2023-46889

    Meross MSH30Q 4.5.23 is vulnerable to Cleartext Transmission of Sensitive Information. During the device setup phase, the MSH30Q creates an unprotected Wi-Fi access point. In this phase, MSH30Q needs to connect to the Internet through a Wi-Fi router. This... Read more

    Affected Products : msh30q_firmware msh30q
    • Published: Jan. 23, 2024
    • Modified: Jun. 17, 2025
  • 5.7

    MEDIUM
    CVE-2017-13318

    In HeifDataSource::readAt of HeifDecoderImpl.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitati... Read more

    Affected Products : android
    • Published: Jan. 28, 2025
    • Modified: Jul. 10, 2025
    • Vuln Type: Information Disclosure
  • 5.7

    MEDIUM
    CVE-2021-38451

    The affected product’s proprietary protocol CSC allows for calling numerous function codes. In order to call those function codes, the user must supply parameters. There is no sanitation on the value of the offset, which allows the client to specify any o... Read more

    Affected Products : versiondog
    • Published: Oct. 22, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 294799 Results