Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2019-12193

    H3C H3Cloud OS all versions allows SQL injection via the ear/grid_event sidx parameter.... Read more

    Affected Products : h3cloud_os
    • EPSS Score: %0.26
    • Published: Jul. 19, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-17137

    Prezi Next 1.3.101.11 has a documented purpose of creating HTML5 presentations but has SE_DEBUG_PRIVILEGE on Windows, which might allow attackers to bypass intended access restrictions.... Read more

    Affected Products : next
    • EPSS Score: %0.43
    • Published: Sep. 17, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-1627

    MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. This affects: Mule 3.8.x,3.9.x,4.x runtime released before February 2, 2021.... Read more

    Affected Products : mule
    • EPSS Score: %0.41
    • Published: Mar. 26, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2013-7429

    The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct XML injection attacks via the url parameter to plugin_googlemap2_proxy.php.... Read more

    Affected Products : googlemaps
    • EPSS Score: %1.58
    • Published: Sep. 14, 2017
    • Modified: Apr. 20, 2025
  • 9.8

    CRITICAL
    CVE-2017-1002020

    Vulnerability in wordpress plugin surveys v1.01.8, The code in survey_form.php does not sanitize the action variable before placing it inside of an SQL query.... Read more

    Affected Products : surveys
    • EPSS Score: %10.91
    • Published: Sep. 14, 2017
    • Modified: Apr. 20, 2025
  • 9.8

    CRITICAL
    CVE-2017-12698

    An Improper Authentication issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Specially crafted requests allow a possible authentication bypass that could allow remote code execution.... Read more

    Affected Products : webaccess
    • EPSS Score: %6.85
    • Published: Aug. 30, 2017
    • Modified: Apr. 20, 2025
  • 9.8

    CRITICAL
    CVE-2017-12471

    The cnb_parse_lev function in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact by leveraging failure to check for out-of-bounds conditions, which triggers an invalid read in the hexdump function.... Read more

    Affected Products : ccn-lite
    • EPSS Score: %0.41
    • Published: Feb. 07, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2019-19307

    An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infinite loop), or possibly cause an out-of-bounds write, by sending a crafted MQTT protocol packet.... Read more

    Affected Products : mongoose
    • EPSS Score: %2.96
    • Published: Nov. 26, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-0570

    Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.... Read more

    Affected Products : mruby
    • EPSS Score: %0.27
    • Published: Feb. 14, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-11569

    Controller/ListController.php in Eventum 3.5.0 is vulnerable to Deserialization of Untrusted Data. Fixed in version 3.5.2.... Read more

    Affected Products : eventum
    • EPSS Score: %0.40
    • Published: Sep. 05, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2019-15823

    The wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass.... Read more

    Affected Products : wps_hide_login
    • EPSS Score: %0.92
    • Published: Aug. 30, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-26793

    libmodbus v3.1.10 has a heap-based buffer overflow vulnerability in read_io_status function in src/modbus.c.... Read more

    Affected Products : libmodbus
    • Published: May. 01, 2024
    • Modified: May. 05, 2025
  • 9.8

    CRITICAL
    CVE-2020-16165

    The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to the /api/blade-log/api/list ascs and desc parameters.... Read more

    Affected Products : springblade springblade
    • EPSS Score: %0.24
    • Published: Jul. 30, 2020
    • Modified: Jun. 03, 2025
  • 9.8

    CRITICAL
    CVE-2023-50434

    emdns_resolve_raw in emdns.c in emdns through fbd1eef calls strlen with an input that may not be '\0' terminated, leading to a stack-based buffer over-read. This can be triggered by a remote adversary that can send DNS requests to the emdns server. The im... Read more

    Affected Products :
    • Published: Apr. 29, 2024
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-37181

    72crm 9.0 has an Arbitrary file upload vulnerability.... Read more

    Affected Products : wukong_crm
    • EPSS Score: %0.38
    • Published: Aug. 24, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-4851

    A vulnerability has been found in IBOS OA 4.5.5 and classified as critical. This vulnerability affects unknown code of the file ?r=dashboard/position/edit&op=member. The manipulation leads to sql injection. The attack can be initiated remotely. The exploi... Read more

    Affected Products : ibos
    • EPSS Score: %0.04
    • Published: Sep. 09, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-37112

    BlueCMS 1.6 has SQL injection in line 55 of admin/model.php... Read more

    Affected Products : bluecms bluecms
    • EPSS Score: %0.25
    • Published: Aug. 23, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-29805

    A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attackers to execute arbitrary code via a crafted XML payload.... Read more

    Affected Products : fishbowl
    • EPSS Score: %10.06
    • Published: Aug. 19, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2024-32161

    jizhiCMS 2.5 suffers from a File upload vulnerability.... Read more

    Affected Products : jizhicms
    • Published: Apr. 17, 2024
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-20365

    Product: AndroidVersions: Android kernelAndroid ID: A-229632566References: N/A... Read more

    Affected Products : android
    • EPSS Score: %0.15
    • Published: Aug. 11, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 291221 Results