Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.6

    CRITICAL
    CVE-2020-24374

    A DNS rebinding vulnerability in Freebox v5 before 1.5.29.... Read more

    Affected Products : freebox_hd_firmware freebox_hd
    • Published: Sep. 16, 2020
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2022-42967

    Caret is vulnerable to an XSS attack when the user opens a crafted Markdown file when preview mode is enabled. This directly leads to client-side code execution.... Read more

    Affected Products : caret
    • Published: Jan. 11, 2023
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2023-42627

    Multiple stored cross-site scripting (XSS) vulnerabilities in the Commerce module in Liferay Portal 7.3.5 through 7.4.3.91, and Liferay DXP 7.3 update 33 and earlier, and 7.4 before update 92 allow remote attackers to inject arbitrary web script or HTML v... Read more

    • Published: Oct. 17, 2023
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2020-26905

    Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.10.11, RBR850 before 3.2.10.11, and RBS850 b... Read more

    • Published: Oct. 09, 2020
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2023-51633

    Centreon sysName Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. User interaction is required to exploit this vulnerability. The specifi... Read more

    Affected Products : centreon centreon_web
    • Published: May. 03, 2024
    • Modified: Nov. 25, 2024
  • 9.6

    CRITICAL
    CVE-2022-3708

    The Web Stories plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including 1.24.0 due to insufficient validation of URLs supplied via the 'url' parameter found via the /v1/hotlink/proxy REST API Endpoint. This makes... Read more

    Affected Products : web_stories
    • Published: Oct. 28, 2022
    • Modified: May. 05, 2025
  • 9.6

    CRITICAL
    CVE-2024-40643

    Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by a non letter character will not be considered html. As such it is possible to do an XSS by putting an "illegal" tag within a tag.... Read more

    Affected Products : joplin
    • Published: Sep. 09, 2024
    • Modified: Sep. 17, 2024
  • 9.6

    CRITICAL
    CVE-2022-0153

    SQL Injection in GitHub repository forkcms/forkcms prior to 5.11.1.... Read more

    Affected Products : fork_cms
    • Published: Mar. 24, 2022
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2024-22718

    Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the client_id parameter in the application URL.... Read more

    Affected Products : form_tools
    • Published: Apr. 11, 2024
    • Modified: Apr. 08, 2025
  • 9.6

    CRITICAL
    CVE-2024-7568

    The Favicon Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the output_sub_admin_page_0 function. This makes it possible for unauthen... Read more

    Affected Products : favicon_generator
    • Published: Aug. 24, 2024
    • Modified: Sep. 27, 2024
  • 9.6

    CRITICAL
    CVE-2024-7982

    The Registrations for the Events Calendar WordPress plugin before 2.12.4 does not sanitise and escape some parameters when accepting event registrations, which could allow unauthenticated users to perform Cross-Site Scripting attacks.... Read more

    • Published: Nov. 08, 2024
    • Modified: May. 15, 2025
  • 9.6

    CRITICAL
    CVE-2020-23719

    Cross site scripting (XSS) vulnerability in application/controllers/AdminController.php in xujinliang zibbs 1.0, allows attackers to execute arbitrary code via the bbsmeta parameter.... Read more

    Affected Products : zibbs
    • Published: Nov. 02, 2021
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2024-32600

    Deserialization of Untrusted Data vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.9.5. ... Read more

    Affected Products : master_slider
    • Published: Apr. 18, 2024
    • Modified: May. 27, 2025
  • 9.6

    CRITICAL
    CVE-2024-46367

    A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the username field. This can lead to privilege escalation when the payload is... Read more

    Affected Products : krayin_crm
    • Published: Sep. 27, 2024
    • Modified: Jul. 09, 2025
  • 9.6

    CRITICAL
    CVE-2020-26902

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.15.25, RBR850 before 3.2.15.25, and RBS850 before 3.2.15.25... Read more

    • Published: Oct. 09, 2020
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2023-38055

    A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} allows a low privileged user to fetch, modify or delete the services of any user (including admin). This results in unauthorized access and unauthorized data manipulation.... Read more

    Affected Products : easyappointments
    • Published: Jul. 09, 2024
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2022-47877

    A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web script or HTML in the Logs page via the log module 'log'.... Read more

    Affected Products : jedox
    • Published: May. 02, 2023
    • Modified: Jan. 30, 2025
  • 9.6

    CRITICAL
    CVE-2021-40909

    Cross site scripting (XSS) vulnerability in sourcecodester PHP CRUD without Refresh/Reload using Ajax and DataTables Tutorial v1 by oretnom23, allows remote attackers to execute arbitrary code via the first_name, last_name, and email parameters to /ajax_c... Read more

    • Published: Jan. 24, 2022
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2018-1000639

    LatexDraw version <=4.0 contains a XML External Entity (XXE) vulnerability in SVG parsing functionality that can result in disclosure of data, server side request forgery, port scanning, possible rce. This attack appear to be exploitable via Specially cra... Read more

    Affected Products : latexdraw
    • Published: Aug. 20, 2018
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2022-25069

    Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote code execution (RCE) via injecting a crafted payload into /lib/contentState/pasteCtrl.js.... Read more

    Affected Products : marktext
    • Published: Mar. 05, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 292803 Results