Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2024-1034

    A vulnerability, which was classified as critical, was found in openBI up to 1.0.8. This affects the function uploadFile of the file /application/index/controller/File.php. The manipulation leads to unrestricted upload. It is possible to initiate the atta... Read more

    Affected Products : openbi openbi
    • EPSS Score: %0.10
    • Published: Jan. 30, 2024
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-5580

    A vulnerability classified as critical has been found in SourceCodester Library System 1.0. This affects an unknown part of the file index.php. The manipulation of the argument category leads to sql injection. It is possible to initiate the attack remotel... Read more

    Affected Products : library_system
    • EPSS Score: %0.05
    • Published: Oct. 14, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-5601

    The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, allowing any unauthenticated users to upload arbitrary files to the server, leading to RCE.... Read more

    • EPSS Score: %0.81
    • Published: Nov. 06, 2023
    • Modified: Mar. 25, 2025
  • 9.8

    CRITICAL
    CVE-2021-46427

    An SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Master.php.... Read more

    Affected Products : simple_chatbot_application
    • EPSS Score: %0.38
    • Published: Jan. 27, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-5716

    ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to access or modify arbitrary files by sending specific HTTP requests without permission.... Read more

    Affected Products : armoury_crate
    • EPSS Score: %1.72
    • Published: Jan. 19, 2024
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-5765

    Improper access control in the password analyzer feature in Devolutions Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to bypass permissions via data source switching. ... Read more

    Affected Products : windows remote_desktop_manager
    • EPSS Score: %0.09
    • Published: Nov. 01, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-5777

    Weintek EasyBuilder Pro contains a vulnerability that, even when the private key is immediately deleted after the crash report transmission is finished, the private key is exposed to the public, which could result in obtaining remote control of the cra... Read more

    Affected Products : easybuilder_pro
    • EPSS Score: %0.10
    • Published: Nov. 06, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-46457

    D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function ChgSambaUserSettings. This vulnerability allows attackers to execute arbitrary commands via the samba_name parameter.... Read more

    Affected Products : dir-823_pro_firmware dir-823_pro
    • EPSS Score: %7.87
    • Published: Feb. 04, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-5877

    The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliate-toolkit-starter/tools/atkp_imagereceiver.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URL's, includi... Read more

    Affected Products : affiliate-toolkit
    • EPSS Score: %0.34
    • Published: Jan. 01, 2024
    • Modified: Jun. 03, 2025
  • 9.8

    CRITICAL
    CVE-2023-52030

    TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setOpModeCfg function.... Read more

    Affected Products : a3700r_firmware a3700r
    • EPSS Score: %14.82
    • Published: Jan. 11, 2024
    • Modified: May. 14, 2025
  • 9.8

    CRITICAL
    CVE-2024-36260

    in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.... Read more

    Affected Products : openharmony openharmony
    • Published: Jul. 02, 2024
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-6014

    An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.... Read more

    Affected Products : mlflow
    • EPSS Score: %0.67
    • Published: Nov. 16, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-6036

    The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functions 'handle_auth_request' and 'hadle_login_request'. This makes it possible for non authenticated attacker... Read more

    • EPSS Score: %46.58
    • Published: Feb. 12, 2024
    • Modified: May. 06, 2025
  • 9.8

    CRITICAL
    CVE-2023-6078

    An OS Command Injection vulnerability exists in BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023. Upload of a specially crafted perl script can lead to arbitrary command execution.... Read more

    Affected Products : biovia_materials_studio
    • EPSS Score: %0.34
    • Published: Feb. 01, 2024
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-6190

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in İzmir Katip Çelebi University University Information Management System allows Absolute Path Traversal.This issue affects University Information Management Syst... Read more

    • EPSS Score: %0.20
    • Published: Dec. 27, 2023
    • Modified: Nov. 27, 2024
  • 9.8

    CRITICAL
    CVE-2024-36783

    TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_time parameter in the NTPSyncWithHost function.... Read more

    Affected Products : lr350_firmware lr350
    • Published: Jun. 03, 2024
    • Modified: Apr. 04, 2025
  • 9.8

    CRITICAL
    CVE-2023-30990

    IBM i 7.2, 7.3, 7.4, and 7.5 could allow a remote attacker to execute CL commands as QUSER, caused by an exploitation of DDM architecture. IBM X-Force ID: 254036.... Read more

    Affected Products : i i
    • EPSS Score: %0.21
    • Published: Jul. 04, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-6342

    Tyler Technologies Court Case Management Plus allows a remote attacker to authenticate as any user by manipulating at least the 'CmWebSearchPfp/Login.aspx?xyzldk=' and 'payforprint_CM/Redirector.ashx?userid=' parameters. The vulnerable "pay for print" fe... Read more

    Affected Products : court_case_management_plus
    • EPSS Score: %0.97
    • Published: Nov. 30, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2014-4861

    The Remote Desktop Launcher in Thycotic Secret Server before 8.6.000010 does not properly cleanup a temporary file that contains an encrypted password once a session has ended.... Read more

    Affected Products : secret_server
    • EPSS Score: %0.50
    • Published: Mar. 09, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-6416

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via signup2.php in the emailadd parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially cr... Read more

    Affected Products : voovi
    • EPSS Score: %0.18
    • Published: Nov. 30, 2023
    • Modified: Nov. 21, 2024
Showing 20 of 291638 Results