Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.6

    CRITICAL
    CVE-2023-48292

    The XWiki Admin Tools Application provides tools to help the administration of XWiki. Starting in version 4.4 and prior to version 4.5.1, a cross site request forgery vulnerability in the admin tool for executing shell commands on the server allows an att... Read more

    Affected Products : xwiki admin_tools
    • EPSS Score: %0.26
    • Published: Nov. 20, 2023
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2020-35391

    Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related issue to CVE-2017-14942. NOTE: the vulnerability report... Read more

    Affected Products : f3_firmware f3
    • EPSS Score: %16.96
    • Published: Jan. 01, 2021
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2019-9835

    The receiver (aka bridge) component of Fujitsu Wireless Keyboard Set LX901 GK900 devices allows Keystroke Injection. This occurs because it accepts unencrypted 2.4 GHz packets, even though all legitimate communication uses AES encryption.... Read more

    • EPSS Score: %0.06
    • Published: Mar. 15, 2019
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2020-14441

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK842 before 3.2.15.25, R... Read more

    • EPSS Score: %1.54
    • Published: Jun. 18, 2020
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2021-29065

    NETGEAR RBR850 devices before 3.2.10.11 are affected by authentication bypass.... Read more

    Affected Products : rbr850_firmware rbr850
    • EPSS Score: %0.10
    • Published: Mar. 23, 2021
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2022-23510

    cube-js is a headless business intelligence platform. In version 0.31.23 all authenticated Cube clients could bypass SQL row-level security and run arbitrary SQL via the newly introduced /v1/sql-runner endpoint. This issue has been resolved in version 0.3... Read more

    Affected Products : cube.js
    • EPSS Score: %0.03
    • Published: Dec. 09, 2022
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2021-24229

    The Jetpack Scan team identified a Reflected Cross-Site Scripting via the patreon_save_attachment_patreon_level AJAX action of the Patreon WordPress plugin before 1.7.2. This AJAX hook is used to update the pledge level required by Patreon subscribers to ... Read more

    Affected Products : patreon_wordpress
    • EPSS Score: %0.64
    • Published: Apr. 12, 2021
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2021-45502

    Certain NETGEAR devices are affected by authentication bypass. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RB... Read more

    • EPSS Score: %0.10
    • Published: Dec. 26, 2021
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2021-45514

    NETGEAR XR1000 devices before 1.0.0.58 are affected by command injection by an unauthenticated attacker.... Read more

    Affected Products : xr1000_firmware xr1000
    • EPSS Score: %0.41
    • Published: Dec. 26, 2021
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2021-45626

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK20 before 2.6.1.36, RBR20 before 2.6.1.36, RBS20 before 2.6.1.38, RBK40 before 2.6.1.36, RBR40 before 2.6.1.36, RBS40 before 2.6.1.38, RBK50 before 2... Read more

    • EPSS Score: %0.51
    • Published: Dec. 26, 2021
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2021-45628

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 3.2.18.2, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR85... Read more

    • EPSS Score: %0.76
    • Published: Dec. 26, 2021
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2020-12076

    The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One consequence of this is stored XSS.... Read more

    Affected Products : data_tables_generator
    • EPSS Score: %0.11
    • Published: Apr. 23, 2020
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2022-41924

    A vulnerability identified in the Tailscale Windows client allows a malicious website to reconfigure the Tailscale daemon `tailscaled`, which can then be used to remotely execute code. In the Tailscale Windows client, the local API was bound to a local TC... Read more

    Affected Products : windows tailscale
    • EPSS Score: %50.81
    • Published: Nov. 23, 2022
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2023-28102

    discordrb is an implementation of the Discord API using Ruby. In discordrb before commit `91e13043ffa` the `encoder.rb` file unsafely constructs a shell string using the file parameter, which can potentially leave clients of discordrb vulnerable to comman... Read more

    Affected Products : discordrb
    • EPSS Score: %0.82
    • Published: Mar. 27, 2023
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2020-23718

    Cross site scripting (XSS) vulnerability in xujinliang zibbs 1.0, allows attackers to execute arbitrary code via the route parameter to index.php.... Read more

    Affected Products : zibbs
    • EPSS Score: %0.73
    • Published: Nov. 02, 2021
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2020-24374

    A DNS rebinding vulnerability in Freebox v5 before 1.5.29.... Read more

    Affected Products : freebox_hd_firmware freebox_hd
    • EPSS Score: %0.48
    • Published: Sep. 16, 2020
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2022-42967

    Caret is vulnerable to an XSS attack when the user opens a crafted Markdown file when preview mode is enabled. This directly leads to client-side code execution.... Read more

    Affected Products : caret
    • EPSS Score: %0.11
    • Published: Jan. 11, 2023
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2023-42627

    Multiple stored cross-site scripting (XSS) vulnerabilities in the Commerce module in Liferay Portal 7.3.5 through 7.4.3.91, and Liferay DXP 7.3 update 33 and earlier, and 7.4 before update 92 allow remote attackers to inject arbitrary web script or HTML v... Read more

    • EPSS Score: %0.16
    • Published: Oct. 17, 2023
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2020-26905

    Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.10.11, RBR850 before 3.2.10.11, and RBS850 b... Read more

    • EPSS Score: %0.15
    • Published: Oct. 09, 2020
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2023-51633

    Centreon sysName Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. User interaction is required to exploit this vulnerability. The specifi... Read more

    Affected Products : centreon centreon_web
    • Published: May. 03, 2024
    • Modified: Nov. 25, 2024
Showing 20 of 292517 Results