Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.4

    CRITICAL
    CVE-2024-25527

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffair/worklog_template_show.aspx.... Read more

    Affected Products : ruvaroa
    • Published: May. 08, 2024
    • Modified: Apr. 17, 2025
  • 9.4

    CRITICAL
    CVE-2019-17354

    wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify data fields of the page.... Read more

    Affected Products : nbg-418n_v2_firmware nbg-418n_v2
    • Published: Oct. 09, 2019
    • Modified: Nov. 21, 2024
  • 9.4

    HIGH
    CVE-2015-8753

    SAP Afaria 7.0.6001.5 allows remote attackers to bypass authorization checks and wipe or lock mobile devices via a crafted request, related to "Insecure signature," aka SAP Security Note 2134905.... Read more

    Affected Products : afaria
    • Published: Jan. 08, 2016
    • Modified: Apr. 12, 2025
  • 9.4

    HIGH
    CVE-2019-14011

    Multiple Read overflows issue due to improper length check while decoding 3G attach accept/ SMS/ pdn connection reject/ esm data transport/ bearer modify context reject in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial... Read more

    • Published: Apr. 16, 2020
    • Modified: Nov. 21, 2024
  • 9.4

    HIGH
    CVE-2007-0921

    Portal Search allows remote attackers to redirect a URL to an arbitrary web site by placing the URL in the query string to the top-level URI.... Read more

    Affected Products : portal_search
    • Published: Feb. 14, 2007
    • Modified: Apr. 09, 2025
  • 9.4

    HIGH
    CVE-2008-5674

    Multiple array index errors in the HTTP server in Darkwet Network webcamXP 3.72.440.0 and earlier and beta 4.05.280 and earlier allow remote attackers to cause a denial of service (device crash) and read portions of memory via (1) an invalid camnum parame... Read more

    Affected Products : webcam_xp
    • Published: Dec. 19, 2008
    • Modified: Apr. 09, 2025
  • 9.4

    HIGH
    CVE-2020-11159

    Buffer over-read can happen while processing WPA,RSN IE of beacon and response frames if IE length is less than length of frame pointer being accessed in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connect... Read more

    • Published: Jun. 09, 2021
    • Modified: Nov. 21, 2024
  • 9.4

    CRITICAL
    CVE-2021-41592

    Blockstream c-lightning through 0.10.1 allows loss of funds because of dust HTLC exposure.... Read more

    Affected Products : c-lightning
    • Published: Oct. 04, 2021
    • Modified: Nov. 21, 2024
  • 9.4

    CRITICAL
    CVE-2024-31545

    Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/?page=user/manage_user&id=6.... Read more

    • Published: Apr. 22, 2024
    • Modified: Apr. 14, 2025
  • 9.4

    CRITICAL
    CVE-2024-6877

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Software Panel allows Reflected XSS.This issue affects Panel: before v2.3.24.... Read more

    Affected Products : panel
    • Published: Sep. 18, 2024
    • Modified: Sep. 25, 2024
  • 9.4

    CRITICAL
    CVE-2024-36455

    An improper input validation allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request.... Read more

    • Published: Jul. 15, 2024
    • Modified: Nov. 21, 2024
  • 9.4

    HIGH
    CVE-2019-10551

    String error while processing non standard SIP messages received can lead to buffer overread and then denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdrag... Read more

    • Published: Apr. 16, 2020
    • Modified: Nov. 21, 2024
  • 9.4

    CRITICAL
    CVE-2025-8426

    Marvell QConvergeConsole compressConfigFiles Directory Traversal Information Disclosure and Denial-of-Service Vulnerability. This vulnerability allows remote attackers to disclose sensitive information or to create a denial-of-service condition on affecte... Read more

    Affected Products : qconvergeconsole
    • Published: Jul. 31, 2025
    • Modified: Aug. 06, 2025
    • Vuln Type: Path Traversal
  • 9.4

    CRITICAL
    CVE-2024-34226

    SQL injection vulnerability in /php-sqlite-vms/?page=manage_visitor&id=1 in SourceCodester Visitor Management System 1.0 allow attackers to execute arbitrary SQL commands via the id parameters.... Read more

    Affected Products : visitor_management_system
    • Published: May. 14, 2024
    • Modified: Apr. 22, 2025
  • 9.4

    CRITICAL
    CVE-2024-47223

    A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successf... Read more

    Affected Products : micollab
    • Published: Oct. 21, 2024
    • Modified: Jul. 07, 2025
  • 9.4

    CRITICAL
    CVE-2024-25518

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /WorkFlow/wf_get_fields_approve.aspx.... Read more

    Affected Products : ruvaroa
    • Published: May. 08, 2024
    • Modified: Apr. 17, 2025
  • 9.4

    HIGH
    CVE-2015-0554

    The ADB (formerly Pirelli Broadband Solutions) P.DGA4001N router with firmware PDG_TEF_SP_4.06L.6 does not properly restrict access to the web interface, which allows remote attackers to obtain sensitive information or cause a denial of service (device re... Read more

    Affected Products : p.dga4001n_firmware p.dga4001n
    • Published: Jan. 21, 2015
    • Modified: Apr. 12, 2025
  • 9.4

    CRITICAL
    CVE-2024-38645

    A server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to read application data. We have already fixed the vulnerability in the following ... Read more

    Affected Products : notes_station_3
    • Published: Nov. 22, 2024
    • Modified: Nov. 22, 2024
  • 9.4

    CRITICAL
    CVE-2020-12041

    The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) telnet Command-Line Interface, grants access to sensitive data stored on the WBM that permits temporary configuration changes to network settings of the WBM, and allows the WBM to be reboot... Read more

    • Published: Jun. 29, 2020
    • Modified: Nov. 21, 2024
  • 9.4

    CRITICAL
    CVE-2024-36456

    This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file.... Read more

    • Published: Jul. 15, 2024
    • Modified: Nov. 21, 2024
Showing 20 of 292814 Results