Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2024-24327

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass parameter in the setIpv6Cfg function.... Read more

    Affected Products : a3300r_firmware a3300r
    • Published: Jan. 30, 2024
    • Modified: May. 29, 2025
  • 9.8

    CRITICAL
    CVE-2024-50486

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo Acnoo Flutter API allows Authentication Bypass.This issue affects Acnoo Flutter API: from n/a through 1.0.5.... Read more

    Affected Products : flutter_api
    • Published: Oct. 28, 2024
    • Modified: Oct. 29, 2024
  • 9.8

    CRITICAL
    CVE-2024-50487

    Authentication Bypass Using an Alternate Path or Channel vulnerability in MaanTheme MaanStore API allows Authentication Bypass.This issue affects MaanStore API: from n/a through 1.0.1.... Read more

    Affected Products : maanstore_api
    • Published: Oct. 28, 2024
    • Modified: Oct. 31, 2024
  • 9.8

    CRITICAL
    CVE-2022-22522

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain full access to the device.... Read more

    • Published: Sep. 28, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2024-24543

    Buffer Overflow vulnerability in the function setSchedWifi in Tenda AC9 v.3.0, firmware version v.15.03.06.42_multi allows a remote attacker to cause a denial of service or run arbitrary code via crafted overflow data.... Read more

    Affected Products : ac9_firmware ac9
    • Published: Feb. 05, 2024
    • Modified: May. 15, 2025
  • 9.8

    CRITICAL
    CVE-2024-5063

    A vulnerability was found in PHPGurukul Online Course Registration System 3.1. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php. The manipulation of the argument username/password leads to sql injectio... Read more

    Affected Products : online_course_registration_system
    • Published: May. 17, 2024
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2024-24561

    Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In versions 0.3.10 and earlier, the bounds check for slices does not account for the ability for start + length to overflow when the values aren't literals. If a slice() functio... Read more

    Affected Products : vyper
    • Published: Feb. 01, 2024
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2024-5084

    The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file_upload_action' function in all versions up to, and including, 1.1.0. This makes it possible for unauthen... Read more

    Affected Products : hash_form
    • Published: May. 23, 2024
    • Modified: Feb. 27, 2025
  • 9.8

    CRITICAL
    CVE-2021-41609

    SQL injection in the ID parameter of the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve data from the application's backend database via boolean-based blind and UNION injection... Read more

    Affected Products : selectsurvey.net
    • Published: Jan. 28, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2024-5117

    A vulnerability, which was classified as critical, was found in SourceCodester Event Registration System 1.0. This affects an unknown part of the file portal.php. The manipulation of the argument username/password leads to sql injection. It is possible to... Read more

    • Published: May. 20, 2024
    • Modified: Feb. 10, 2025
  • 9.8

    CRITICAL
    CVE-2024-25089

    Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC named pipes.... Read more

    Affected Products : binisoft_windows_firewall_control
    • Published: Feb. 04, 2024
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-40357

    A security issue was discovered in Z-BlogPHP <= 1.7.2. A Server-Side Request Forgery (SSRF) vulnerability in the zb_users/plugin/UEditor/php/action_crawler.php file allows remote attackers to force the application to make arbitrary requests via injection ... Read more

    Affected Products : z-blogphp
    • Published: Sep. 20, 2022
    • Modified: May. 28, 2025
  • 9.8

    CRITICAL
    CVE-2024-29876

    SQL injection vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/reports/activitylogreport, 'sortby' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all... Read more

    Affected Products : sentrifugo sentrifugo
    • Published: Mar. 21, 2024
    • Modified: Jan. 24, 2025
  • 9.8

    CRITICAL
    CVE-2024-29937

    NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via a bug that is unrelated to memory corruption.... Read more

    Affected Products : freebsd openbsd openbsd
    • Published: Apr. 11, 2024
    • Modified: Jun. 17, 2025
  • 9.8

    CRITICAL
    CVE-2024-2850

    A vulnerability was found in Tenda AC15 15.03.05.18 and classified as critical. Affected by this issue is the function saveParentControlInfo of the file /goform/saveParentControlInfo. The manipulation of the argument urls leads to stack-based buffer overf... Read more

    Affected Products : ac15_firmware ac15
    • Published: Mar. 24, 2024
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2024-25302

    Sourcecodester Event Student Attendance System 1.0, allows SQL Injection via the 'student' parameter.... Read more

    Affected Products : event_student_attendance_system
    • Published: Feb. 09, 2024
    • Modified: May. 08, 2025
  • 9.8

    CRITICAL
    CVE-2024-2556

    A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been classified as critical. This affects an unknown part of the file attendance-info.php. The manipulation of the argument user_id leads to sql injection. It is possi... Read more

    • Published: Mar. 17, 2024
    • Modified: Feb. 18, 2025
  • 9.8

    CRITICAL
    CVE-2022-40434

    Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.... Read more

    Affected Products : softr
    • Published: Dec. 19, 2022
    • Modified: Apr. 17, 2025
  • 9.8

    CRITICAL
    CVE-2024-25350

    SQL Injection vulnerability in /zms/admin/edit-ticket.php in PHPGurukul Zoo Management System 1.0 via tickettype and tprice parameters.... Read more

    Affected Products : zoo_management_system
    • Published: Feb. 28, 2024
    • Modified: Mar. 27, 2025
  • 9.8

    CRITICAL
    CVE-2020-19692

    Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_module_read in the njs_module.c file.... Read more

    Affected Products : njs njs
    • Published: Apr. 04, 2023
    • Modified: Aug. 12, 2025
Showing 20 of 292769 Results