Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2023-41364

    In tine through 2023.01.14.325, the sort parameter of the /index.php endpoint allows SQL Injection.... Read more

    Affected Products : tine
    • EPSS Score: %0.08
    • Published: Sep. 01, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-22891

    A missing authorization vulnerability exists in Citrix ShareFile Storage Zones Controller before 5.7.3, 5.8.3, 5.9.3, 5.10.1 and 5.11.18 may allow unauthenticated remote compromise of the Storage Zones Controller.... Read more

    Affected Products : sharefile_storagezones_controller
    • EPSS Score: %0.51
    • Published: May. 27, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-4257

    Unchecked user input length in /subsys/net/l2/wifi/wifi_shell.c can cause buffer overflows.... Read more

    Affected Products : zephyr
    • EPSS Score: %0.43
    • Published: Oct. 13, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-20388

    Comtrend CM-6200un 123.447.007 and CM-6300n 123.553mp1.005 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.... Read more

    • EPSS Score: %0.64
    • Published: Dec. 23, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-20477

    An issue was discovered in S-CMS 3.0. It allows SQL Injection via the bank/callback1.php P_no field.... Read more

    Affected Products : s-cms
    • EPSS Score: %0.26
    • Published: Dec. 26, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-3956

    The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data, modification of data and loss of data due to a missing capability check on the 'events_receiver' function in versions up to, and including, 0.0.9.18. This makes it poss... Read more

    Affected Products : instawp_connect
    • EPSS Score: %0.67
    • Published: Jul. 27, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-43154

    In Macrob7 Macs Framework Content Management System (CMS) 1.1.4f, loose comparison in "isValidLogin()" function during login attempt results in PHP type confusion vulnerability that leads to authentication bypass and takeover of the administrator account.... Read more

    Affected Products : macs_cms
    • EPSS Score: %0.42
    • Published: Sep. 27, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-23150

    SA-WR915ND router firmware v17.35.1 was discovered to be vulnerable to code execution.... Read more

    Affected Products : sa-wr915nd_firmware sa-wr915nd
    • EPSS Score: %0.17
    • Published: Mar. 16, 2023
    • Modified: Feb. 26, 2025
  • 9.8

    CRITICAL
    CVE-2023-23302

    The `Toybox.GenericChannel.setDeviceConfig` API method in CIQ API version 1.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copying various attributes. A malicious application could call the API method with spe... Read more

    Affected Products : connect-iq
    • EPSS Score: %0.33
    • Published: May. 23, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-2347

    A vulnerability was found in SourceCodester Service Provider Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/services/manage_service.php. The manipulation of the argument id leads to sql ... Read more

    • EPSS Score: %0.05
    • Published: Apr. 27, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-22388

    There is an Integer Overflow Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause certain codes to be executed.... Read more

    Affected Products : emui magic_ui
    • EPSS Score: %0.24
    • Published: Aug. 02, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2020-26772

    Command Injection in PPGo_Jobs v2.8.0 allows remote attackers to execute arbitrary code via the 'AjaxRun()' function.... Read more

    Affected Products : ppgo_jobs
    • EPSS Score: %2.73
    • Published: Sep. 08, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-2302

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: OPSS). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker ... Read more

    Affected Products : platform_security_for_java
    • EPSS Score: %52.53
    • Published: Apr. 22, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-24150

    A command injection vulnerability in the serverIp parameter in the function meshSlaveDlfw of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.... Read more

    Affected Products : t8_firmware t8
    • EPSS Score: %1.63
    • Published: Feb. 03, 2023
    • Modified: Mar. 26, 2025
  • 9.8

    CRITICAL
    CVE-2023-24052

    An issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via the change password functionality as it does not prompt for the current password.... Read more

    Affected Products : ac21000_g6_firmware ac21000_g6
    • EPSS Score: %0.09
    • Published: Dec. 04, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-24166

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/formWifiBasicSet.... Read more

    Affected Products : ac18_firmware ac18
    • EPSS Score: %0.39
    • Published: Jan. 26, 2023
    • Modified: Mar. 28, 2025
  • 9.8

    CRITICAL
    CVE-2023-24199

    Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at delete_ticket.php.... Read more

    Affected Products : raffle_draw_system
    • EPSS Score: %0.07
    • Published: Feb. 06, 2023
    • Modified: Mar. 26, 2025
  • 9.8

    CRITICAL
    CVE-2023-24033

    The Samsung Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T512 baseband modem chipsets do not properly check format types specified by the Session Description Protocol (SDP) module, which can lead to a denial of service.... Read more

    • EPSS Score: %0.56
    • Published: Mar. 13, 2023
    • Modified: Mar. 03, 2025
  • 9.8

    CRITICAL
    CVE-2023-24643

    Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateBlankTxtview.php.... Read more

    Affected Products : judging_management_system
    • EPSS Score: %0.07
    • Published: Mar. 03, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2020-3934

    TAIWAN SECOM CO., LTD., a Door Access Control and Personnel Attendance Management system, contains a vulnerability of Pre-auth SQL Injection, allowing attackers to inject a specific SQL command.... Read more

    • EPSS Score: %0.38
    • Published: Feb. 11, 2020
    • Modified: Nov. 21, 2024
Showing 20 of 291878 Results