Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.6

    CRITICAL
    CVE-2024-22093

    When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-bladed systems. A successful exploit can allow the attacker to cross a security boundary.  Note: Software vers... Read more

    • EPSS Score: %0.38
    • Published: Feb. 14, 2024
    • Modified: Jan. 23, 2025
  • 9.6

    CRITICAL
    CVE-2024-28231

    eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.14.0, 2.13.4, 2.12.3, 2.10.4, and 2.6.8, manipulated DATA Submessage can cause a heap overflow error in the Fast-DDS pr... Read more

    Affected Products : fast_dds
    • Published: Mar. 20, 2024
    • Modified: Jun. 30, 2025
  • 9.6

    CRITICAL
    CVE-2021-37981

    Heap buffer overflow in Skia in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.... Read more

    Affected Products : debian_linux chrome edge_chromium
    • EPSS Score: %1.62
    • Published: Nov. 02, 2021
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2022-26384

    If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code> but not <code>allow-scripts</code>, they were able to craft a link that, when clicked, would lead to JavaScript execution in violation of the sandbox. This vul... Read more

    Affected Products : firefox firefox_esr thunderbird
    • EPSS Score: %0.10
    • Published: Dec. 22, 2022
    • Modified: Apr. 16, 2025
  • 9.6

    CRITICAL
    CVE-2020-13292

    In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.... Read more

    Affected Products : gitlab
    • EPSS Score: %0.09
    • Published: Aug. 10, 2020
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2023-47797

    Reflected cross-site scripting (XSS) vulnerability on a content page’s edit page in Liferay Portal 7.4.3.94 through 7.4.3.95 allows remote attackers to inject arbitrary web script or HTML via the `p_l_back_url_title` parameter.... Read more

    Affected Products : liferay_portal
    • EPSS Score: %0.15
    • Published: Nov. 17, 2023
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2023-52138

    Engrampa is an archive manager for the MATE environment. Engrampa is found to be vulnerable to a Path Traversal vulnerability that can be leveraged to achieve full Remote Command Execution (RCE) on the target. While handling CPIO archives, the Engrampa Ar... Read more

    Affected Products : engrampa
    • EPSS Score: %1.88
    • Published: Feb. 05, 2024
    • Modified: Feb. 13, 2025
  • 9.6

    CRITICAL
    CVE-2024-33006

    An unauthenticated attacker can upload a malicious file to the server which when accessed by a victim can allow an attacker to completely compromise system.  ... Read more

    Affected Products : netweaver_application_server_abap
    • Published: May. 14, 2024
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2024-7024

    Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)... Read more

    Affected Products : chrome
    • Published: Sep. 23, 2024
    • Modified: Jan. 02, 2025
  • 9.6

    CRITICAL
    CVE-2024-20252

    Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affected ... Read more

    • EPSS Score: %7.07
    • Published: Feb. 07, 2024
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2022-1309

    Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.... Read more

    Affected Products : chrome edge_chromium
    • EPSS Score: %0.54
    • Published: Jul. 25, 2022
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2020-19947

    Cross Site Scripting vulnerability found in Markdown Edit allows a remote attacker to execute arbitrary code via the edit parameter of the webpage.... Read more

    Affected Products : markdown_edit
    • EPSS Score: %0.37
    • Published: Mar. 16, 2023
    • Modified: Feb. 26, 2025
  • 9.6

    CRITICAL
    CVE-2020-19825

    Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated privileges.... Read more

    Affected Products : kimai
    • EPSS Score: %0.39
    • Published: Feb. 15, 2023
    • Modified: Mar. 19, 2025
  • 9.6

    CRITICAL
    CVE-2020-16018

    Use after free in payments in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.... Read more

    Affected Products : chrome
    • EPSS Score: %0.32
    • Published: Jan. 08, 2021
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2020-16017

    Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.... Read more

    Affected Products : chrome
    • Actively Exploited
    • EPSS Score: %17.65
    • Published: Jan. 08, 2021
    • Modified: Feb. 05, 2025
  • 9.6

    CRITICAL
    CVE-2020-15999

    Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more

    • Actively Exploited
    • EPSS Score: %93.15
    • Published: Nov. 03, 2020
    • Modified: Feb. 05, 2025
  • 9.6

    CRITICAL
    CVE-2020-15961

    Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.... Read more

    • EPSS Score: %1.51
    • Published: Sep. 21, 2020
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2020-16025

    Heap buffer overflow in clipboard in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.... Read more

    Affected Products : chrome
    • EPSS Score: %0.84
    • Published: Jan. 08, 2021
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2017-14589

    It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur. An attacker who has restricted administration rights to Bamboo or who hosts a website that a Bamboo administrator visits, is able to exploit this v... Read more

    Affected Products : bamboo
    • EPSS Score: %0.44
    • Published: Dec. 13, 2017
    • Modified: Apr. 20, 2025
  • 9.6

    CRITICAL
    CVE-2018-0057

    On MX Series and M120/M320 platforms configured in a Broadband Edge (BBE) environment, subscribers logging in with DHCP Option 50 to request a specific IP address will be assigned the requested IP address, even if there is a static MAC to IP address bindi... Read more

    Affected Products : junos
    • EPSS Score: %0.34
    • Published: Oct. 10, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 292522 Results