Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.6

    CRITICAL
    CVE-2015-20105

    The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make logged in admin change them via a CSRF attack. Furthermore, due to the lack of escaping when they are outputting, it cou... Read more

    Affected Products : clickbank_affiliate_ads
    • EPSS Score: %0.25
    • Published: Dec. 02, 2021
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2021-44458

    Linux users running Lens 5.2.6 and earlier could be compromised by visiting a malicious website. The malicious website could make websocket connections from the victim's browser to Lens and so operate the local terminal feature. This would allow the attac... Read more

    Affected Products : linux_kernel lens
    • EPSS Score: %0.14
    • Published: Jan. 10, 2022
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2017-3882

    A vulnerability in the Universal Plug-and-Play (UPnP) implementation in the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, Layer 2-adjacent attacker to execute arbitrary code or cause a denial of service (DoS) condition. The remote co... Read more

    • EPSS Score: %0.79
    • Published: May. 16, 2017
    • Modified: Apr. 20, 2025
  • 9.6

    CRITICAL
    CVE-2016-6256

    SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcellerator/exec/soap/vP.001sap0003.in_WCSX/com.sap.b1i.vplatform.runtime/INB_WS_CALL_SYNC_XPT/INB_WS_CALL_SYNC... Read more

    Affected Products : business_one
    • EPSS Score: %10.06
    • Published: May. 26, 2017
    • Modified: Apr. 20, 2025
  • 9.6

    CRITICAL
    CVE-2022-21241

    Cross-site scripting vulnerability in CSV+ prior to 0.8.1 allows a remote unauthenticated attacker to inject an arbitrary script or an arbitrary OS command via a specially crafted CSV file that contains HTML a tag.... Read more

    Affected Products : csv\+
    • EPSS Score: %30.00
    • Published: Feb. 08, 2022
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2021-44749

    A vulnerability affecting F-Secure SAFE browser protection was discovered improper URL handling can be triggered to cause universal cross-site scripting through browsing protection in a SAFE web browser. User interaction is required prior to exploitation.... Read more

    Affected Products : safe
    • EPSS Score: %1.06
    • Published: Mar. 06, 2022
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2023-46732

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to reflected cross-site scripting (RXSS) via the `rev` parameter that is used in the content of the content menu without escaping.... Read more

    Affected Products : xwiki
    • EPSS Score: %53.73
    • Published: Nov. 06, 2023
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2023-46242

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to execute a content with the right of any user via a crafted URL. A user must have `programming` privileges in ord... Read more

    Affected Products : xwiki
    • EPSS Score: %3.25
    • Published: Nov. 07, 2023
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2023-36019

    Microsoft Power Platform Connector Spoofing Vulnerability... Read more

    Affected Products : azure_logic_apps power_platform
    • EPSS Score: %1.09
    • Published: Dec. 12, 2023
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2023-29050

    The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the intended hierarchy. Unauthorized users could break confidentiality of information in the directory and pote... Read more

    Affected Products : open-xchange_appsuite ox_app_suite
    • EPSS Score: %0.11
    • Published: Jan. 08, 2024
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2024-24593

    A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform allows a remote attacker to impersonate a user by sending API requests via maliciously crafted html. Exploitation o... Read more

    Affected Products : clearml
    • EPSS Score: %0.42
    • Published: Feb. 06, 2024
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2022-46332

    The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored cross-site scripting vulnerability that enables an anonymous email sender to gain admin privileges within the user interface. This affects all versions 8.19.0 ... Read more

    Affected Products : enterprise_protection
    • EPSS Score: %0.43
    • Published: Dec. 06, 2022
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2024-25147

    Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions allows remote attack... Read more

    • Published: Feb. 21, 2024
    • Modified: Jan. 28, 2025
  • 9.6

    CRITICAL
    CVE-2024-26269

    Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Liferay DXP 7.4 before update 38, 7.3 before update 11, 7.2 before fix pack 20, and older unsupported versions allows remote atta... Read more

    • Published: Feb. 21, 2024
    • Modified: Jan. 28, 2025
  • 9.6

    CRITICAL
    CVE-2024-0440

    Attacker, with permission to submit a link or submits a link via POST to be collected that is using the file:// protocol can then introspect host files and other relatively stored files.... Read more

    Affected Products : anythingllm
    • Published: Feb. 26, 2024
    • Modified: Feb. 27, 2025
  • 9.6

    CRITICAL
    CVE-2024-0550

    A user who is privileged already `manager` or `admin` can set their profile picture via the frontend API using a relative filepath to then user the PFP GET API to download any valid files. The attacker would have to have been granted privileged permissio... Read more

    Affected Products : anythingllm
    • Published: Feb. 28, 2024
    • Modified: Jan. 10, 2025
  • 9.6

    CRITICAL
    CVE-2020-35124

    A cross-site scripting (XSS) vulnerability in the assets component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript through the Referer header of asset downloads.... Read more

    Affected Products : mautic
    • EPSS Score: %1.14
    • Published: Jan. 28, 2021
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2021-32692

    Activity Watch is a free and open-source automated time tracker. Versions prior to 0.11.0 allow an attacker to execute arbitrary commands on any macOS machine with ActivityWatch running. The attacker can exploit this vulnerability by having the user visit... Read more

    Affected Products : macos activitywatch
    • EPSS Score: %0.06
    • Published: Dec. 23, 2022
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2017-2792

    An exploitable heap corruption vulnerability exists in the iBldDirInfo functionality of Antenna House DMC HTMLFilter used by MarkLogic 8.0-6. A specially crafted xls file can cause a heap corruption resulting in arbitrary code execution. An attacker can p... Read more

    Affected Products : marklogic
    • EPSS Score: %0.65
    • Published: Sep. 07, 2018
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2018-3679

    Escalation of privilege in Reference UI in Intel Data Center Manager SDK 5.0 and before may allow an unauthorized remote unauthenticated user to potentially execute code via administrator privileges.... Read more

    Affected Products : data_center_manager
    • EPSS Score: %0.38
    • Published: Sep. 12, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 291722 Results