Latest CVE Feed
-
9.6
CRITICALCVE-2022-41924
A vulnerability identified in the Tailscale Windows client allows a malicious website to reconfigure the Tailscale daemon `tailscaled`, which can then be used to remotely execute code. In the Tailscale Windows client, the local API was bound to a local TC... Read more
- EPSS Score: %50.81
- Published: Nov. 23, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-28102
discordrb is an implementation of the Discord API using Ruby. In discordrb before commit `91e13043ffa` the `encoder.rb` file unsafely constructs a shell string using the file parameter, which can potentially leave clients of discordrb vulnerable to comman... Read more
Affected Products : discordrb- EPSS Score: %0.82
- Published: Mar. 27, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-23718
Cross site scripting (XSS) vulnerability in xujinliang zibbs 1.0, allows attackers to execute arbitrary code via the route parameter to index.php.... Read more
Affected Products : zibbs- EPSS Score: %0.73
- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICAL- EPSS Score: %0.48
- Published: Sep. 16, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-42967
Caret is vulnerable to an XSS attack when the user opens a crafted Markdown file when preview mode is enabled. This directly leads to client-side code execution.... Read more
Affected Products : caret- EPSS Score: %0.11
- Published: Jan. 11, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-42627
Multiple stored cross-site scripting (XSS) vulnerabilities in the Commerce module in Liferay Portal 7.3.5 through 7.4.3.91, and Liferay DXP 7.3 update 33 and earlier, and 7.4 before update 92 allow remote attackers to inject arbitrary web script or HTML v... Read more
- EPSS Score: %0.16
- Published: Oct. 17, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-26905
Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.10.11, RBR850 before 3.2.10.11, and RBS850 b... Read more
Affected Products : rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware rbs850_firmware cbr40_firmware rbk752 rbr750 rbs750 +4 more products- EPSS Score: %0.15
- Published: Oct. 09, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-51633
Centreon sysName Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. User interaction is required to exploit this vulnerability. The specifi... Read more
- Published: May. 03, 2024
- Modified: Nov. 25, 2024
-
9.6
CRITICALCVE-2022-3708
The Web Stories plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including 1.24.0 due to insufficient validation of URLs supplied via the 'url' parameter found via the /v1/hotlink/proxy REST API Endpoint. This makes... Read more
Affected Products : web_stories- EPSS Score: %0.35
- Published: Oct. 28, 2022
- Modified: May. 05, 2025
-
9.6
CRITICALCVE-2024-40643
Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by a non letter character will not be considered html. As such it is possible to do an XSS by putting an "illegal" tag within a tag.... Read more
Affected Products : joplin- Published: Sep. 09, 2024
- Modified: Sep. 17, 2024
-
9.6
CRITICALCVE-2022-0153
SQL Injection in GitHub repository forkcms/forkcms prior to 5.11.1.... Read more
Affected Products : fork_cms- EPSS Score: %0.26
- Published: Mar. 24, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-22718
Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the client_id parameter in the application URL.... Read more
Affected Products : form_tools- Published: Apr. 11, 2024
- Modified: Apr. 08, 2025
-
9.6
CRITICALCVE-2024-7568
The Favicon Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the output_sub_admin_page_0 function. This makes it possible for unauthen... Read more
Affected Products : favicon_generator- Published: Aug. 24, 2024
- Modified: Sep. 27, 2024
-
9.6
CRITICALCVE-2024-7982
The Registrations for the Events Calendar WordPress plugin before 2.12.4 does not sanitise and escape some parameters when accepting event registrations, which could allow unauthenticated users to perform Cross-Site Scripting attacks.... Read more
Affected Products : registrations_for_the_events_calendar- Published: Nov. 08, 2024
- Modified: May. 15, 2025
-
9.6
CRITICALCVE-2020-23719
Cross site scripting (XSS) vulnerability in application/controllers/AdminController.php in xujinliang zibbs 1.0, allows attackers to execute arbitrary code via the bbsmeta parameter.... Read more
Affected Products : zibbs- EPSS Score: %0.73
- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-32600
Deserialization of Untrusted Data vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.9.5. ... Read more
Affected Products : master_slider- Published: Apr. 18, 2024
- Modified: May. 27, 2025
-
9.6
CRITICALCVE-2024-46367
A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the username field. This can lead to privilege escalation when the payload is... Read more
Affected Products : krayin_crm- Published: Sep. 27, 2024
- Modified: Jul. 09, 2025
-
9.6
CRITICALCVE-2020-26902
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.15.25, RBR850 before 3.2.15.25, and RBS850 before 3.2.15.25... Read more
Affected Products : rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware rbs850_firmware rbk752 rbr750 rbs750 rbk852 +2 more products- EPSS Score: %1.77
- Published: Oct. 09, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-38055
A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} allows a low privileged user to fetch, modify or delete the services of any user (including admin). This results in unauthorized access and unauthorized data manipulation.... Read more
Affected Products : easyappointments- Published: Jul. 09, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-47877
A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web script or HTML in the Logs page via the log module 'log'.... Read more
Affected Products : jedox- EPSS Score: %1.34
- Published: May. 02, 2023
- Modified: Jan. 30, 2025