Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2021-31758

    An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setportList allows attackers to execute arbitrary code on the system via a crafted post request.... Read more

    Affected Products : ac11_firmware ac11
    • Published: May. 07, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2021-31891

    A vulnerability has been identified in Desigo CC (All versions with OIS Extension Module), GMA-Manager (All versions with OIS running on Debian 9 or earlier), Operation Scheduler (All versions with OIS running on Debian 9 or earlier), Siveillance Control ... Read more

    • Published: Sep. 14, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2022-29730

    USR IOT 4G LTE Industrial Cellular VPN Router v1.0.36 was discovered to contain hard-coded credentials for its highest privileged account. The credentials cannot be altered through normal operation of the device.... Read more

    • Published: Jun. 02, 2022
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2025-32440

    NetAlertX is a network, presence scanner and alert framework. Prior to version 25.4.14, it is possible to bypass the authentication mechanism of NetAlertX to update settings without authentication. An attacker can trigger sensitive functions within util.p... Read more

    Affected Products : netalertx
    • Published: May. 27, 2025
    • Modified: Jul. 11, 2025
    • Vuln Type: Authentication
  • 10.0

    HIGH
    CVE-2020-28951

    libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names. This is related to uci_parse_package in file.c and uci_strdup in util.c.... Read more

    Affected Products : openwrt
    • Published: Nov. 19, 2020
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2022-25438

    Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the SetIPTVCfg function.... Read more

    Affected Products : ac9_firmware ac9
    • Published: Mar. 18, 2022
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2020-7165

    A iccselectcommand expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).... Read more

    Affected Products : intelligent_management_center
    • Published: Oct. 19, 2020
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2021-32671

    Flarum is a forum software for building communities. Flarum's translation system allowed for string inputs to be converted into HTML DOM nodes when rendered. This change was made after v0.1.0-beta.16 (our last beta before v1.0.0) and was not noticed or do... Read more

    Affected Products : flarum
    • Published: Jun. 07, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    • Published: Apr. 05, 2024
    • Modified: Jul. 24, 2025
  • 10.0

    CRITICAL
    CVE-2024-23615

    A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 10.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root. ... Read more

    Affected Products : symantec_messaging_gateway
    • Published: Jan. 26, 2024
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2013-3686

    cgi-bin/operator/param in AirLive WL2600CAM and possibly other camera models allows remote attackers to obtain the administrator password via a list action.... Read more

    Affected Products : airlive_wl2600cam
    • Published: Oct. 11, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2009-3341

    Buffer overflow on the Linksys WRT54GL wireless router allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.10 through 8.11. NOTE: as of 20090917, this disclosure ... Read more

    Affected Products : wrt54gl_firmware wrt54gl
    • Published: Sep. 24, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    CRITICAL
    CVE-2021-25387

    An improper input validation vulnerability in sflacfd_get_frm() in libsflacextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.... Read more

    Affected Products : android dex
    • Published: Jun. 11, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2007-1160

    webSPELL 4.0, and possibly later versions, allows remote attackers to bypass authentication via a ws_auth cookie, a different vulnerability than CVE-2006-4782.... Read more

    Affected Products : webspell
    • Published: Mar. 02, 2007
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2006-3722

    Unspecified vulnerability in PeopleSoft Enterprise Portal for Oracle PeopleSoft Enterprise Portal 8.4 Bundle #16, 8.8 Bundle #10, and 8.9 Bundle #3 has unknown impact and attack vectors, aka Oracle Vuln# PSE01.... Read more

    • Published: Jul. 21, 2006
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2014-9993

    In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 615/16/SD 415, SD 617, ... Read more

    • Published: Apr. 18, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2013-3712

    SUSE Studio Onsite 1.3.x before 1.3.6 and SUSE Studio Extension for System z 1.3 uses "static" secret tokens, which has unspecified impact and vectors.... Read more

    • Published: Feb. 26, 2014
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2018-11031

    application/home/controller/debug.php in PHPRAP 1.0.4 through 1.0.8 has SSRF via the /debug URI, as demonstrated by an api[url]=file:////etc/passwd&api[method]=get POST request.... Read more

    Affected Products : phprap
    • Published: May. 14, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2006-7153

    PHP remote file inclusion vulnerability in index.php in MiniBB Forum 2 allows remote attackers to execute arbitrary code via a URL in the pathToFiles parameter.... Read more

    Affected Products : forum
    • Published: Mar. 07, 2007
    • Modified: Apr. 09, 2025
  • 10.0

    CRITICAL
    CVE-2022-31126

    Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to code execution by sending a specially crafted HTTP request to /app/options.py file.... Read more

    Affected Products : roxy-wi
    • Published: Jul. 06, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 293284 Results