Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.4

    CRITICAL
    CVE-2025-27133

    WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was discovered in the WeGIA application prior to version 3.2.15 at the `adicionar_tipo_exame.php` endpoint. This vulnerability allows an authorized attacker to execute arbit... Read more

    Affected Products : wegia
    • Published: Feb. 24, 2025
    • Modified: Feb. 24, 2025
    • Vuln Type: Injection
  • 9.4

    HIGH
    CVE-2007-2271

    Directory traversal vulnerability in Rajneel Lal TotaRam USP FOSS Distribution 1.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the dnld parameter.... Read more

    Affected Products : usp_foss_distribution
    • EPSS Score: %6.76
    • Published: Apr. 25, 2007
    • Modified: Apr. 09, 2025
  • 9.4

    CRITICAL
    CVE-2024-25527

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffair/worklog_template_show.aspx.... Read more

    Affected Products : ruvaroa
    • Published: May. 08, 2024
    • Modified: Apr. 17, 2025
  • 9.4

    CRITICAL
    CVE-2019-17354

    wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify data fields of the page.... Read more

    Affected Products : nbg-418n_v2_firmware nbg-418n_v2
    • EPSS Score: %0.30
    • Published: Oct. 09, 2019
    • Modified: Nov. 21, 2024
  • 9.4

    HIGH
    CVE-2014-6221

    The MSCAPI/MSCNG interface implementation in GSKit in IBM Rational ClearCase 7.1.2.x before 7.1.2.17, 8.0.0.x before 8.0.0.14, and 8.0.1.x before 8.0.1.7 does not properly generate random numbers, which makes it easier for remote attackers to defeat crypt... Read more

    Affected Products : rational_clearcase
    • EPSS Score: %0.63
    • Published: Apr. 06, 2015
    • Modified: Apr. 12, 2025
  • 9.4

    HIGH
    CVE-2015-8753

    SAP Afaria 7.0.6001.5 allows remote attackers to bypass authorization checks and wipe or lock mobile devices via a crafted request, related to "Insecure signature," aka SAP Security Note 2134905.... Read more

    Affected Products : afaria
    • EPSS Score: %0.47
    • Published: Jan. 08, 2016
    • Modified: Apr. 12, 2025
  • 9.4

    HIGH
    CVE-2019-14011

    Multiple Read overflows issue due to improper length check while decoding 3G attach accept/ SMS/ pdn connection reject/ esm data transport/ bearer modify context reject in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial... Read more

    • EPSS Score: %0.24
    • Published: Apr. 16, 2020
    • Modified: Nov. 21, 2024
  • 9.4

    HIGH
    CVE-2016-0699

    Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.2 and 12.0.3 allows remote attackers to affect confidentiality and integrity via vectors related to the Login sub-component.... Read more

    • EPSS Score: %0.67
    • Published: Apr. 21, 2016
    • Modified: Apr. 12, 2025
  • 9.4

    HIGH
    CVE-2005-4853

    The default configuration of the forum package in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050818 does not restrict edit permissions to a posting's owner, which allows remote authenticated users to edit arbitrar... Read more

    Affected Products : ez_publish
    • EPSS Score: %0.44
    • Published: Dec. 31, 2005
    • Modified: Apr. 03, 2025
  • 9.4

    HIGH
    CVE-2007-0921

    Portal Search allows remote attackers to redirect a URL to an arbitrary web site by placing the URL in the query string to the top-level URI.... Read more

    Affected Products : portal_search
    • EPSS Score: %0.69
    • Published: Feb. 14, 2007
    • Modified: Apr. 09, 2025
  • 9.4

    HIGH
    CVE-2002-2269

    Directory traversal vulnerability in Webster HTTP Server allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.... Read more

    Affected Products : webster_http_server
    • EPSS Score: %0.09
    • Published: Dec. 31, 2002
    • Modified: Apr. 03, 2025
  • 9.4

    HIGH
    CVE-2002-2268

    Buffer overflow in Webster HTTP Server allows remote attackers to execute arbitrary code via a long URL.... Read more

    Affected Products : webster_http_server
    • EPSS Score: %74.54
    • Published: Dec. 31, 2002
    • Modified: Apr. 03, 2025
  • 9.4

    HIGH
    CVE-2008-5674

    Multiple array index errors in the HTTP server in Darkwet Network webcamXP 3.72.440.0 and earlier and beta 4.05.280 and earlier allow remote attackers to cause a denial of service (device crash) and read portions of memory via (1) an invalid camnum parame... Read more

    Affected Products : webcam_xp
    • EPSS Score: %22.32
    • Published: Dec. 19, 2008
    • Modified: Apr. 09, 2025
  • 9.4

    HIGH
    CVE-2015-6259

    The JavaServer Pages (JSP) component in Cisco Integrated Management Controller (IMC) Supervisor before 1.0.0.1 and UCS Director (formerly Cloupia Unified Infrastructure Controller) before 5.2.0.1 allows remote attackers to write to arbitrary files via cra... Read more

    • EPSS Score: %1.06
    • Published: Sep. 04, 2015
    • Modified: Apr. 12, 2025
  • 9.4

    HIGH
    CVE-2010-3671

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 is open to a session fixation attack which allows remote attackers to hijack a victim's session.... Read more

    Affected Products : typo3
    • EPSS Score: %0.90
    • Published: Nov. 05, 2019
    • Modified: Nov. 21, 2024
  • 9.4

    HIGH
    CVE-2020-11285

    Buffer over-read while unpacking the RTCP packet we may read extra byte if wrong length is provided in RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdr... Read more

    • EPSS Score: %0.24
    • Published: May. 07, 2021
    • Modified: Nov. 21, 2024
  • 9.4

    HIGH
    CVE-2018-14989

    The Plum Compass Android device with a build fingerprint of PLUM/c179_hwf_221/c179_hwf_221:6.0/MRA58K/W16.51.5-22:user/release-keys contains a pre-installed platform app with a package name of com.android.settings (versionCode=23, versionName=6.0-eng.root... Read more

    Affected Products : compass_firmware compass
    • EPSS Score: %0.29
    • Published: Apr. 25, 2019
    • Modified: Nov. 21, 2024
  • 9.4

    HIGH
    CVE-2020-11159

    Buffer over-read can happen while processing WPA,RSN IE of beacon and response frames if IE length is less than length of frame pointer being accessed in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connect... Read more

    • EPSS Score: %0.24
    • Published: Jun. 09, 2021
    • Modified: Nov. 21, 2024
  • 9.4

    CRITICAL
    CVE-2021-41592

    Blockstream c-lightning through 0.10.1 allows loss of funds because of dust HTLC exposure.... Read more

    Affected Products : c-lightning
    • EPSS Score: %0.83
    • Published: Oct. 04, 2021
    • Modified: Nov. 21, 2024
  • 9.4

    CRITICAL
    CVE-2023-6718

    An authentication bypass vulnerability has been found in Repox, which allows a remote user to send a specially crafted POST request, due to the lack of any authentication method, resulting in the alteration or creation of users.... Read more

    Affected Products : repox
    • EPSS Score: %0.14
    • Published: Dec. 13, 2023
    • Modified: Nov. 21, 2024
Showing 20 of 291368 Results