Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2022-44048

    The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-domains package. The affected version of d8s-htm is 0.... Read more

    Affected Products : d8s-urls
    • EPSS Score: %0.12
    • Published: Nov. 07, 2022
    • Modified: May. 05, 2025
  • 9.8

    CRITICAL
    CVE-2022-44176

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function fromSetRouteStatic.... Read more

    Affected Products : ac18_firmware ac18
    • EPSS Score: %0.15
    • Published: Nov. 21, 2022
    • Modified: Apr. 29, 2025
  • 9.8

    CRITICAL
    CVE-2020-13417

    An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters.... Read more

    • EPSS Score: %1.17
    • Published: May. 22, 2020
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-39323

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Time based attack using a SQL injection in api REST user_to... Read more

    Affected Products : glpi
    • EPSS Score: %1.38
    • Published: Nov. 03, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-34064

    The Zibal package in PyPI v1.0.0 was discovered to contain a code execution backdoor. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.... Read more

    Affected Products : zibal
    • EPSS Score: %1.02
    • Published: Jun. 24, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2020-24199

    Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct remote code execution.... Read more

    Affected Products : car_rental_project
    • EPSS Score: %3.39
    • Published: Sep. 09, 2020
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-44938

    Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack.... Read more

    Affected Products : seeddms
    • EPSS Score: %0.11
    • Published: Dec. 08, 2022
    • Modified: Apr. 23, 2025
  • 9.8

    CRITICAL
    CVE-2023-29746

    An issue found in The Thaiger v.1.2 for Android allows unauthorized apps to cause a code execution attack by manipulating the SharedPreference files.... Read more

    Affected Products : the_thaiger
    • EPSS Score: %0.38
    • Published: Jun. 02, 2023
    • Modified: Jan. 31, 2025
  • 9.8

    CRITICAL
    CVE-2020-13561

    An out-of-bounds write vulnerability exists in the TIFF parser of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.... Read more

    Affected Products : imagegear
    • EPSS Score: %0.71
    • Published: Feb. 10, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2020-24231

    Symmetric DS <3.12.0 uses mx4j to provide access to JMX over HTTP. mx4j, by default, has no auth and is available on all interfaces. An attacker can interact with JMX: get system info, and invoke MBean methods. It is possible to install additional MBeans ... Read more

    Affected Products : symmetricds
    • EPSS Score: %1.02
    • Published: Oct. 05, 2020
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-29778

    GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.... Read more

    Affected Products : gl-mt3000_firmware gl-mt3000
    • EPSS Score: %25.38
    • Published: May. 02, 2023
    • Modified: Jan. 30, 2025
  • 9.8

    CRITICAL
    CVE-2022-40111

    In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware.... Read more

    Affected Products : a3002r_firmware a3002r
    • EPSS Score: %0.13
    • Published: Sep. 06, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-45174

    An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication for SAML Users can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/challenge endpoint. The correctness of the TOTP is n... Read more

    Affected Products : vdesk
    • EPSS Score: %0.02
    • Published: Apr. 14, 2023
    • Modified: Feb. 07, 2025
  • 9.8

    CRITICAL
    CVE-2022-45297

    EQ v1.5.31 to v2.2.0 was discovered to contain a SQL injection vulnerability via the UserPwd parameter.... Read more

    Affected Products : eq
    • EPSS Score: %0.24
    • Published: Jan. 31, 2023
    • Modified: Mar. 27, 2025
  • 9.8

    CRITICAL
    CVE-2021-42371

    lpar2rrd is a hardcoded system account in XoruX LPAR2RRD and STOR2RRD before 7.30.... Read more

    Affected Products : lpar2rrd stor2rrd
    • EPSS Score: %0.72
    • Published: Nov. 08, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-30192

    Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find().... Read more

    Affected Products : possearchproducts
    • EPSS Score: %50.16
    • Published: May. 12, 2023
    • Modified: Jan. 27, 2025
  • 9.8

    CRITICAL
    CVE-2022-44929

    An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profiles.... Read more

    Affected Products : dvg-g5402sp_firmware dvg-g5402sp
    • EPSS Score: %0.33
    • Published: Dec. 02, 2022
    • Modified: Apr. 24, 2025
  • 9.8

    CRITICAL
    CVE-2022-40431

    The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.... Read more

    Affected Products : d8s-pdfs
    • EPSS Score: %0.14
    • Published: Sep. 19, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-30376

    In Tenda AC15 V15.03.05.19, the function "henan_pppoe_user" contains a stack-based buffer overflow vulnerability.... Read more

    Affected Products : ac15_firmware ac15
    • EPSS Score: %0.12
    • Published: Apr. 24, 2023
    • Modified: Feb. 05, 2025
  • 9.8

    CRITICAL
    CVE-2023-30470

    A use-after-free related to unsound inference in the bytecode generation when optimizations are enabled for Hermes prior to commit da8990f737ebb9d9810633502f65ed462b819c09 could have been used by an attacker to achieve remote code execution. Note that thi... Read more

    Affected Products : hermes
    • EPSS Score: %2.20
    • Published: May. 18, 2023
    • Modified: Jan. 21, 2025
Showing 20 of 291736 Results