Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.4

    CRITICAL
    CVE-2021-27442

    The Weintek cMT product line is vulnerable to a cross-site scripting vulnerability, which could allow an unauthenticated remote attacker to inject malicious JavaScript code.... Read more

    • EPSS Score: %0.14
    • Published: May. 16, 2022
    • Modified: Nov. 21, 2024
  • 9.4

    CRITICAL
    CVE-2016-5843

    Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request System (OTRS) allow remote attackers to execute arbitrary SQL commands via crafted search parameters.... Read more

    Affected Products : faq
    • EPSS Score: %1.10
    • Published: Sep. 17, 2016
    • Modified: Apr. 12, 2025
  • 9.4

    CRITICAL
    CVE-2016-2296

    Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pages, which allows remote attackers to obtain sensitive information or modify data via unspecified vectors.... Read more

    • EPSS Score: %75.31
    • Published: May. 14, 2016
    • Modified: Apr. 12, 2025
  • 9.4

    CRITICAL
    CVE-2022-3224

    Misinterpretation of Input in GitHub repository ionicabizau/parse-url prior to 8.1.0.... Read more

    Affected Products : parse-url
    • EPSS Score: %0.18
    • Published: Sep. 15, 2022
    • Modified: Nov. 21, 2024
  • 9.4

    HIGH
    CVE-2016-1000112

    Unauthenticated remote .jpg file upload in contus-video-comments v1.0 wordpress plugin... Read more

    Affected Products : contus-video-comments
    • EPSS Score: %35.66
    • Published: Oct. 06, 2016
    • Modified: Apr. 12, 2025
  • 9.4

    CRITICAL
    CVE-2025-54071

    RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. In versions 4.0.0-beta.3 and below, an authenticated arbitrary file write vulnerability exists in the /api/saves endpoint. This ... Read more

    Affected Products :
    • Published: Jul. 21, 2025
    • Modified: Jul. 22, 2025
    • Vuln Type: Path Traversal
  • 9.4

    CRITICAL
    CVE-2025-34152

    An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) via the 'time' parameter of the '/protocol.csp?' endpoint. The input is processed by the internal date '-s' command without reboo... Read more

    Affected Products :
    • Published: Aug. 07, 2025
    • Modified: Aug. 07, 2025
    • Vuln Type: Injection
  • 9.4

    HIGH
    CVE-2016-8491

    The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write access via a remote shell.... Read more

    Affected Products : fortiwlc fortiwlc
    • EPSS Score: %0.27
    • Published: Feb. 01, 2017
    • Modified: Apr. 20, 2025
  • 9.4

    HIGH
    CVE-2021-38917

    IBM PowerVM Hypervisor FW860, FW940, and FW950 could allow an attacker that gains service access to the FSP can read and write arbitrary host system memory through a series of carefully crafted service procedures. IBM X-Force ID: 210018.... Read more

    Affected Products : powervm_hypervisor
    • EPSS Score: %0.21
    • Published: Dec. 10, 2021
    • Modified: Nov. 21, 2024
  • 9.4

    HIGH
    CVE-2021-39635

    ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions,so that normal apps (No phone permissions) can obtain some VoLTE sensitive information and manage VoLTE calls.Product: AndroidVersions... Read more

    Affected Products : android
    • EPSS Score: %0.08
    • Published: Feb. 11, 2022
    • Modified: Nov. 21, 2024
  • 9.4

    CRITICAL
    CVE-2022-0688

    Business Logic Errors in Packagist microweber/microweber prior to 1.2.11.... Read more

    Affected Products : microweber cockpit
    • EPSS Score: %0.33
    • Published: Feb. 20, 2022
    • Modified: Nov. 21, 2024
  • 9.4

    CRITICAL
    CVE-2023-6353

    Tyler Technologies Civil and Criminal Electronic Filing allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating the Upload.aspx 'enky' parameter. ... Read more

    Affected Products : court_case_management_plus
    • EPSS Score: %1.21
    • Published: Nov. 30, 2023
    • Modified: Nov. 21, 2024
  • 9.4

    CRITICAL
    CVE-2023-6354

    Tyler Technologies Magistrate Court Case Management Plus allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating the PDFViewer.aspx 'filename' parameter. ... Read more

    Affected Products : court_case_management_plus
    • EPSS Score: %1.04
    • Published: Nov. 30, 2023
    • Modified: Nov. 21, 2024
  • 9.4

    CRITICAL
    CVE-2024-1624

    An OS Command Injection vulnerability affecting documentation server on 3DEXPERIENCE from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x, SIMULIA Abaqus from Release 2022 through Release 2024, SIMULIA Isight from Release 2022 through Rele... Read more

    Affected Products : 3dexperience
    • Published: Mar. 01, 2024
    • Modified: Nov. 21, 2024
  • 9.4

    CRITICAL
    CVE-2024-28253

    OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. `CompiledRule::validateExpression` is also called from `PolicyRepository.prepare`.... Read more

    Affected Products : openmetadata
    • Published: Mar. 15, 2024
    • Modified: Nov. 21, 2024
  • 9.4

    CRITICAL
    CVE-2022-41271

    An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process Integration (PI) - version 7.50. This user can make use of an open naming and directory API to access services that could perform... Read more

    Affected Products : netweaver_process_integration
    • EPSS Score: %0.15
    • Published: Dec. 13, 2022
    • Modified: Nov. 21, 2024
  • 9.4

    CRITICAL
    CVE-2022-23555

    authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior to 2022.11.4 and 2022.10.4 are vulnerable to Improper Authentication. Token reuse in invitation URLs leads to access control bypass via the use of a diffe... Read more

    Affected Products : authentik
    • EPSS Score: %0.04
    • Published: Dec. 28, 2022
    • Modified: Nov. 21, 2024
  • 9.4

    CRITICAL
    CVE-2018-14786

    Becton, Dickinson and Company (BD) Alaris Plus medical syringe pumps (models Alaris GS, Alaris GH, Alaris CC, and Alaris TIVA) versions 2.3.6 and prior are affected by an improper authentication vulnerability where the software does not perform authentica... Read more

    • EPSS Score: %7.32
    • Published: Aug. 23, 2018
    • Modified: Nov. 21, 2024
  • 9.4

    CRITICAL
    CVE-2023-1898

    Atlas Copco Power Focus 6000 web server uses a small amount of session ID numbers. An attacker could enter a session ID number to retrieve data for an active user’s session.... Read more

    • EPSS Score: %0.08
    • Published: Jun. 12, 2023
    • Modified: Nov. 21, 2024
  • 9.4

    CRITICAL
    CVE-2023-4523

    Real Time Automation 460 Series products with versions prior to v8.9.8 are vulnerable to cross-site scripting, which could allow an attacker to run any JavaScript reference from the URL string. If this were to occur, the gateway's HTTP interface would re... Read more

    • EPSS Score: %0.08
    • Published: Sep. 27, 2023
    • Modified: Nov. 21, 2024
Showing 20 of 291384 Results