Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.7

    MEDIUM
    CVE-2025-2102

    Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Passwordless on Windows allows Privilege Escalation.This issue affects HYPR Passwordless: before 10.1.... Read more

    Affected Products :
    • Published: May. 21, 2025
    • Modified: May. 21, 2025
    • Vuln Type: Authorization
  • 5.7

    MEDIUM
    CVE-2024-46327

    An issue in the Http_handle object of VONETS VAP11G-300 v3.3.23.6.9 allows attackers to access sensitive files via a directory traversal.... Read more

    Affected Products : vap11g-300_firmware vap11g-300
    • Published: Sep. 26, 2024
    • Modified: Jun. 24, 2025
  • 5.7

    MEDIUM
    CVE-2023-38491

    Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites that might have potential attackers in the group of authenticated Panel users or that allow external visitors ... Read more

    Affected Products : kirby
    • Published: Jul. 27, 2023
    • Modified: Nov. 21, 2024
  • 5.7

    MEDIUM
    CVE-2024-52509

    Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. The Nextcloud mail app incorrectly allowed attaching shared files without download permissions as attachments. This allowed users to send them the files to themselves and t... Read more

    Affected Products : mail notes
    • Published: Nov. 15, 2024
    • Modified: Sep. 04, 2025
  • 5.7

    MEDIUM
    CVE-2024-52361

    IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9  stores user credentials in plain text which can be read by an authenticated user with access to the pod.... Read more

    • Published: Dec. 18, 2024
    • Modified: Aug. 08, 2025
  • 5.7

    MEDIUM
    CVE-2022-34572

    An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the telnet password via accessing the page tftp.txt.... Read more

    Affected Products : wifi-repeater_firmware
    • Published: Jul. 25, 2022
    • Modified: Nov. 21, 2024
  • 5.7

    MEDIUM
    CVE-2023-50121

    Autel EVO NANO drone flight control firmware version 1.6.5 is vulnerable to denial of service (DoS).... Read more

    • Published: Jan. 06, 2024
    • Modified: Apr. 17, 2025
  • 5.7

    MEDIUM
    CVE-2020-14292

    In the COVIDSafe application through 1.0.21 for Android, unsafe use of the Bluetooth transport option in the GATT connection allows attackers to trick the application into establishing a connection over Bluetooth BR/EDR transport, which reveals the public... Read more

    Affected Products : covidsafe
    • Published: Sep. 09, 2020
    • Modified: Nov. 21, 2024
  • 5.7

    MEDIUM
    CVE-2018-2389

    Under certain conditions a malicious user can inject log files of SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, hiding important information in the log file.... Read more

    Affected Products : internet_graphics_server
    • Published: Feb. 14, 2018
    • Modified: Nov. 21, 2024
  • 5.7

    MEDIUM
    CVE-2016-4315

    Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authentication of privileged users for requests that shutdown a server via a shutdown action to server-admin/proxy_ajaxprocessor.jsp.... Read more

    Affected Products : carbon
    • Published: Feb. 17, 2017
    • Modified: Apr. 20, 2025
  • 5.7

    MEDIUM
    CVE-2005-4825

    Cisco Clean Access 3.5.5 and earlier on the Secure Smart Manager allows remote attackers to bypass authentication and cause a denial of service (disk consumption), or make unauthorized files accessible, by uploading files through requests to certain JSP s... Read more

    • Published: Dec. 31, 2005
    • Modified: Apr. 03, 2025
  • 5.7

    MEDIUM
    CVE-2019-14680

    The admin-renamer-extended (aka Admin renamer extended) plugin 3.2.1 for WordPress allows wp-admin/plugins.php?page=admin-renamer-extended/admin.php CSRF.... Read more

    Affected Products : admin-renamer-extended
    • Published: Aug. 08, 2019
    • Modified: Nov. 21, 2024
  • 5.7

    MEDIUM
    CVE-2019-3419

    A security vulnerability exists in a management port in the version of ZTE's ZXMP M721V3.10P01B10_M2NCP. An attacker could exploit this vulnerability to build a link to the device and send specific packets to cause a denial of service.... Read more

    Affected Products : zxmp_m721_dx_firmware zxmp_m721_dx
    • Published: Oct. 31, 2019
    • Modified: Nov. 21, 2024
  • 5.7

    MEDIUM
    CVE-2020-24721

    An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-09-29, as used in COVID-19 applications on Android and iOS. It allows a user to be put in a position where he or she can be coerced into proving or disprov... Read more

    • Published: Sep. 30, 2020
    • Modified: Nov. 21, 2024
  • 5.7

    MEDIUM
    CVE-2019-5211

    The Huawei Share function of P20 phones with versions earlier than Emily-L29C 9.1.0.311 has an improper file management vulnerability. The attacker tricks the victim to perform certain operations on the mobile phone during file transfer. Because the file ... Read more

    Affected Products : p20_firmware p20
    • Published: Nov. 29, 2019
    • Modified: Nov. 21, 2024
  • 5.7

    MEDIUM
    CVE-2021-32793

    Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface version 5.5.1, the function to add domains to blocklists or allowlists is vulnerable to a stored cross-site-... Read more

    Affected Products : pi-hole web_interface
    • Published: Aug. 04, 2021
    • Modified: Nov. 21, 2024
  • 5.7

    MEDIUM
    CVE-2022-0245

    Cross-Site Request Forgery (CSRF) in GitHub repository livehelperchat/livehelperchat prior to 2.0.... Read more

    Affected Products : live_helper_chat livehelperchat
    • Published: Jan. 18, 2022
    • Modified: Nov. 21, 2024
  • 5.7

    MEDIUM
    CVE-2023-25569

    Apollo is a configuration management system. Prior to version 2.1.0, a low-privileged user can create a special web page. If an authenticated portal admin visits this page, the page can silently send a request to assign new roles for that user without any... Read more

    Affected Products : apollo
    • Published: Feb. 20, 2023
    • Modified: Nov. 21, 2024
  • 5.7

    MEDIUM
    CVE-2023-6146

    A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in the presentation of logging information to users. This vulnerability allowed a user with login access to the application to introduce XSS... Read more

    Affected Products : private_cloud_platform
    • Published: Dec. 08, 2023
    • Modified: Nov. 21, 2024
  • 5.7

    MEDIUM
    CVE-2023-29680

    Cleartext Transmission in set-cookie:ecos_pw: Tenda N301 v6.0, Firmware v12.02.01.61_multi allows an authenticated attacker on the LAN or WLAN to intercept communications with the router and obtain the password.... Read more

    Affected Products : n301_firmware n301
    • Published: May. 01, 2023
    • Modified: Jan. 30, 2025
Showing 20 of 294826 Results