Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.6

    CRITICAL
    CVE-2020-9691

    Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more

    Affected Products : magento
    • Published: Jul. 29, 2020
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2020-6320

    SAP Marketing (Servlet), version-130,140,150, allows an authenticated attacker to invoke certain functions that are restricted. Limited knowledge of payload is required for an attacker to exploit the vulnerability and perform tasks related to contact and ... Read more

    Affected Products : marketing
    • Published: Sep. 09, 2020
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2020-15182

    The SOY Inquiry component of SOY CMS is affected by Cross-site Request Forgery (CSRF) and Remote Code Execution (RCE). The vulnerability affects versions 2.0.0.3 and earlier of SOY Inquiry. This allows remote attackers to force the administrator to edit f... Read more

    Affected Products : soy_cms soy_cms soy_inquiry soy_cms
    • Published: Sep. 17, 2020
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2020-26157

    Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing. This leads to remote code execution because of Node integration.... Read more

    Affected Products : leanote desktop
    • Published: Sep. 30, 2020
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2020-26903

    Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.10.11, RBR850 before 3.2.10.11, and RBS850 b... Read more

    • Published: Oct. 09, 2020
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2020-26907

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, and RBS850 before 3.2.16.6.... Read more

    • Published: Oct. 09, 2020
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2020-7750

    This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not escape SVG properly, which can be used to inject arbitrary elements into the DOM via the _transformMeasurements function.... Read more

    Affected Products : scratch-svg-renderer
    • Published: Oct. 21, 2020
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2020-18766

    A cross-site scripting (XSS) vulnerability AntSword v2.0.7 can remotely execute system commands.... Read more

    Affected Products : antsword
    • Published: Oct. 26, 2020
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2020-16608

    Notable 1.8.4 allows XSS via crafted Markdown text, with resultant remote code execution (because nodeIntegration in webPreferences is true).... Read more

    Affected Products : notable
    • Published: Dec. 10, 2020
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2024-40084

    A Buffer Overflow in the Boa webserver of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers to execute arbitrary code via exceptionally long HTTP methods or paths.... Read more

    Affected Products : vilo_5_firmware vilo_5
    • Published: Oct. 21, 2024
    • Modified: Jul. 07, 2025
  • 9.6

    CRITICAL
    CVE-2024-49674

    Cross-Site Request Forgery (CSRF) vulnerability in Lukas Huser EKC Tournament Manager allows Upload a Web Shell to a Web Server.This issue affects EKC Tournament Manager: from n/a through 2.2.1.... Read more

    Affected Products : ekc_tournament_manager
    • Published: Oct. 31, 2024
    • Modified: Nov. 01, 2024
  • 9.6

    CRITICAL
    CVE-2023-29120

    Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administrator’s privileges over the Waybox system.... Read more

    Affected Products : waybox_pro_firmware waybox_pro
    • Published: Nov. 05, 2024
    • Modified: Nov. 08, 2024
  • 9.6

    CRITICAL
    CVE-2024-54368

    Cross-Site Request Forgery (CSRF) vulnerability in Ruben Garza, Jr. GitSync allows Code Injection.This issue affects GitSync: from n/a through 1.1.0.... Read more

    Affected Products :
    • Published: Dec. 16, 2024
    • Modified: Dec. 16, 2024
  • 9.6

    CRITICAL
    CVE-2024-12626

    The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘a-0-o-search_field_value’ parameter in all versions up to, and including,... Read more

    Affected Products : automatorwp
    • Published: Dec. 19, 2024
    • Modified: Dec. 19, 2024
  • 9.6

    CRITICAL
    CVE-2025-24490

    Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to use prepared statements in the SQL query of boards reordering which allows an attacker to retrieve data from the database, via a SQL injection when reorderi... Read more

    Affected Products : mattermost_server mattermost
    • Published: Feb. 24, 2025
    • Modified: Feb. 24, 2025
    • Vuln Type: Injection
  • 9.6

    CRITICAL
    CVE-2025-23116

    An Authentication Bypass vulnerability on UniFi Protect Application with Auto-Adopt Bridge Devices enabled could allow a malicious actor with access to UniFi Protect Cameras adjacent network to take control of UniFi Protect Cameras.... Read more

    Affected Products : unifi_protect
    • Published: Mar. 01, 2025
    • Modified: Mar. 04, 2025
    • Vuln Type: Authentication
  • 9.6

    CRITICAL
    CVE-2025-29922

    kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.26.3, the identified vulnerability allows creating or deleting an object via the APIExport VirtualWorkspace in any arbitrary target... Read more

    Affected Products :
    • Published: Mar. 20, 2025
    • Modified: Mar. 20, 2025
    • Vuln Type: Authorization
  • 9.6

    CRITICAL
    CVE-2023-37293

    AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack-based buffer overflow via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability. ... Read more

    Affected Products : megarac_sp-x megarac_spx
    • Published: Jan. 09, 2024
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2023-48728

    A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb3ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a us... Read more

    Affected Products : avideo
    • Published: Jan. 10, 2024
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2024-21639

    CEF (Chromium Embedded Framework ) is a simple framework for embedding Chromium-based browsers in other applications. `CefLayeredWindowUpdaterOSR::OnAllocatedSharedMemory` does not check the size of the shared memory, which leads to out-of-bounds read out... Read more

    Affected Products : chromium_embedded_framework
    • Published: Jan. 12, 2024
    • Modified: Nov. 21, 2024
Showing 20 of 293437 Results