Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.3

    CRITICAL
    CVE-2023-6038

    A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to read arbitrary files on the server with the permissions of the user running the h2o-3 instance. This issue affects the default installati... Read more

    Affected Products : h2o
    • Published: Nov. 16, 2023
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2017-8204

    The Bastet driver of Honor 9 Huawei smart phones with software of versions earlier than Stanford-AL10C00B175 has a buffer overflow vulnerability due to the lack of parameter validation. An attacker tricks a user into installing a malicious APP which has t... Read more

    Affected Products : honor_9_firmware honor_9
    • Published: Nov. 22, 2017
    • Modified: Apr. 20, 2025
  • 9.3

    HIGH
    CVE-2017-0543

    A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code ... Read more

    Affected Products : android
    • Published: Apr. 07, 2017
    • Modified: Apr. 20, 2025
  • 9.3

    HIGH
    CVE-2009-0885

    Multiple heap-based buffer overflows in Media Commands 1.0 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long string in a (1) M3U, (2) M3l, (3) TXT, and (4) LRC playlist file.... Read more

    Affected Products : media_commands
    • Published: Mar. 12, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    CRITICAL
    CVE-2019-6741

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to January 2019 Security Update (SMR-JAN-2019 - SVE-2018-13467). User interaction is required to exploit this vulnerability in that... Read more

    Affected Products : galaxy_s9_firmware galaxy_s9
    • Published: Jun. 03, 2019
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2022-33257

    Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone.... Read more

    • Published: Mar. 10, 2023
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2024-25331

    DIR-822 Rev. B Firmware v2.02KRB09 and DIR-822-CA Rev. B Firmware v2.03WWb01 suffer from a LAN-Side Unauthenticated Remote Code Execution (RCE) vulnerability elevated from HNAP Stack-Based Buffer Overflow.... Read more

    Affected Products :
    • Published: Mar. 12, 2024
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2024-55978

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WalletStation.com Code Generator Pro allows SQL Injection.This issue affects Code Generator Pro: from n/a through 1.2.... Read more

    Affected Products :
    • Published: Dec. 16, 2024
    • Modified: Dec. 16, 2024
  • 9.3

    CRITICAL
    CVE-2024-6060

    An information disclosure vulnerability in Phloc Webscopes 7.0.0 allows local attackers with access to the log files to view logged HTTP requests that contain user passwords or other sensitive information.... Read more

    Affected Products :
    • Published: Jun. 25, 2024
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2023-28787

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.4. ... Read more

    • Published: Mar. 26, 2024
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2024-8074

    Improper Privilege Management vulnerability in Nomysoft Informatics Nomysem allows Collect Data as Provided by Users.This issue affects Nomysem: before 13.10.2024.... Read more

    Affected Products :
    • Published: Nov. 12, 2024
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2009-1605

    Heap-based buffer overflow in the loadexponentialfunc function in mupdf/pdf_function.c in MuPDF in the mupdf-20090223-win32 package, as used in SumatraPDF 0.9.3 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF file. NOTE: ... Read more

    Affected Products : sumatrapdf sumatrapdf
    • Published: May. 11, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    CRITICAL
    CVE-2024-0521

    Code Injection in paddlepaddle/paddle... Read more

    Affected Products : paddlepaddle paddle
    • Published: Jan. 20, 2024
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2009-2970

    Stack-based buffer overflow in the GetUiDllVersion function in an ActiveX control in UiCheck.dll before 1.0.0.7 in UiTV UiPlayer, as used in BaiduX and other products, allows remote attackers to execute arbitrary code via the filename parameter.... Read more

    Affected Products : uiplayer baidux
    • Published: Oct. 19, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    CRITICAL
    CVE-2025-26943

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jürgen Müller Easy Quotes allows Blind SQL Injection. This issue affects Easy Quotes: from n/a through 1.2.2.... Read more

    Affected Products :
    • Published: Feb. 25, 2025
    • Modified: Feb. 25, 2025
    • Vuln Type: Injection
  • 9.3

    CRITICAL
    CVE-2023-37538

    HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site). ... Read more

    Affected Products : digital_experience
    • Published: Oct. 11, 2023
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2018-0103

    A Buffer Overflow vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow a local attacker to execute arbitrary code on the system of a user. The attacker could exploit this vulnerability by sending the ... Read more

    • Published: Jan. 04, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2025-32778

    Web-Check is an all-in-one OSINT tool for analyzing any website. A command injection vulnerability exists in the screenshot API of the Web Check project (Lissy93/web-check). The issue stems from user-controlled input (url) being passed unsanitized into a ... Read more

    Affected Products :
    • Published: Apr. 15, 2025
    • Modified: Apr. 16, 2025
    • Vuln Type: Injection
  • 9.3

    CRITICAL
    CVE-2025-41370

    A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /... Read more

    Affected Products :
    • Published: Aug. 01, 2025
    • Modified: Aug. 04, 2025
    • Vuln Type: Injection
  • 9.3

    CRITICAL
    CVE-2024-1143

    Central Dogma versions prior to 0.64.1 is vulnerable to Cross-Site Scripting (XSS), which could allow for the leakage of user sessions and subsequent authentication bypass.... Read more

    Affected Products : central_dogma
    • Published: Feb. 02, 2024
    • Modified: Jun. 03, 2025
Showing 20 of 292801 Results