Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.6

    CRITICAL
    CVE-2021-21803

    This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.... Read more

    Affected Products : r-seenet
    • EPSS Score: %73.89
    • Published: Jul. 16, 2021
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2023-37261

    OpenComputers is a Minecraft mod that adds programmable computers and robots to the game. This issue affects every version of OpenComputers with the Internet Card feature enabled; that is, OpenComputers 1.2.0 until 1.8.3 in their most common, default conf... Read more

    Affected Products : opencomputers
    • EPSS Score: %0.16
    • Published: Jul. 07, 2023
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2020-14438

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK842 before 3.2.15.25, R... Read more

    • EPSS Score: %1.54
    • Published: Jun. 18, 2020
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2023-1717

    Prototype pollution in bitrix/templates/bitrix24/components/bitrix/menu/left_vertical/script.js in Bitrix24 22.0.300 allows remote attackers to execute arbitrary JavaScript code in the victim’s browser, and possibly execute arbitrary PHP code on the serv... Read more

    Affected Products : bitrix24
    • EPSS Score: %1.79
    • Published: Nov. 01, 2023
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2023-1892

    Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8.... Read more

    Affected Products : sidekiq
    • EPSS Score: %74.40
    • Published: Apr. 21, 2023
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2020-26901

    Certain NETGEAR devices are affected by disclosure of sensitive information. This affects RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.15.25, RBR850 before 3.2.15.25, and RBS850 before 3.2.15.25.... Read more

    • EPSS Score: %0.10
    • Published: Oct. 09, 2020
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2023-46117

    reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities. A vulnerability has been identified in reconftw where inadequate validation of retrieved subdom... Read more

    Affected Products : reconftw
    • EPSS Score: %2.95
    • Published: Oct. 20, 2023
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2024-31650

    A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Last Name parameter.... Read more

    • Published: Apr. 15, 2024
    • Modified: Apr. 10, 2025
  • 9.6

    CRITICAL
    CVE-2023-50707

    Through the exploitation of active user sessions, an attacker could send custom requests to cause a denial-of-service condition on the device. ... Read more

    Affected Products : bcu_500_firmware bcu_500
    • EPSS Score: %0.08
    • Published: Dec. 20, 2023
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2024-4404

    The ElementsKit PRO plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.6.2 via the 'render_raw' function. This can allow authenticated attackers, with contributor-level permissions and above, to make web ... Read more

    Affected Products : elementskit
    • Published: Jun. 14, 2024
    • Modified: Jan. 10, 2025
  • 9.6

    CRITICAL
    CVE-2024-24275

    Cross Site Scripting vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the global search function.... Read more

    Affected Products : windows teamwire
    • Published: Mar. 05, 2024
    • Modified: Mar. 27, 2025
  • 9.6

    CRITICAL
    CVE-2024-54139

    Combodo iTop is an open source and web-based IT service management platform. Prior to versions 2.7.11, 3.1.2, and 3.2.0., iTop has a cross-site scripting vulnerability that can lead to cross-site request forgery on the `_table_id` parameter. Versions 2.7.... Read more

    Affected Products : itop
    • Published: Dec. 13, 2024
    • Modified: Mar. 11, 2025
  • 9.6

    CRITICAL
    CVE-2024-32986

    PWAsForFirefox is a tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox. Due to improper sanitization of web app properties (such as name, description, shortcuts), web apps were able to inject additional lines into XDG Desktop E... Read more

    Affected Products :
    • Published: May. 03, 2024
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2024-38164

    An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link.... Read more

    Affected Products : groupme
    • Published: Jul. 23, 2024
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2022-41654

    An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerabili... Read more

    Affected Products : ghost
    • EPSS Score: %0.25
    • Published: Dec. 22, 2022
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2024-27107

    Weak account password in GE HealthCare EchoPAC products... Read more

    Affected Products :
    • Published: May. 14, 2024
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2023-7018

    Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.... Read more

    Affected Products : transformers
    • EPSS Score: %0.14
    • Published: Dec. 20, 2023
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2023-35158

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the restore template to perfor... Read more

    Affected Products : xwiki
    • EPSS Score: %7.64
    • Published: Jun. 23, 2023
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2023-3110

    Description: A vulnerability in SiLabs Unify Gateway 1.3.1 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.... Read more

    Affected Products : unify_software_development_kit
    • EPSS Score: %0.05
    • Published: Jun. 21, 2023
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2021-29067

    Certain NETGEAR devices are affected by authentication bypass. This affects RBW30 before 2.6.2.2, RBS40V before 2.6.2.4, RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12, RBK752 be... Read more

    • EPSS Score: %0.14
    • Published: Mar. 23, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 291358 Results