Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    CRITICAL
    CVE-2024-25925

    Unrestricted Upload of File with Dangerous Type vulnerability in SYSBASICS WooCommerce Easy Checkout Field Editor, Fees & Discounts.This issue affects WooCommerce Easy Checkout Field Editor, Fees & Discounts: from n/a through 3.5.12. ... Read more

    Affected Products : easy_checkout_field_editor
    • Published: Feb. 26, 2024
    • Modified: May. 08, 2025
  • 10.0

    HIGH
    CVE-2017-8864

    Client-side enforcement using JavaScript of server-side security options on the Cohu 3960HD allows an attacker to manipulate options sent to the camera and cause malfunction or code execution, as demonstrated by a client-side "if (!passwordsAreEqual())" t... Read more

    Affected Products : 3960hd_firmware 3960hd
    • EPSS Score: %0.65
    • Published: Nov. 22, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    CRITICAL
    CVE-2022-33206

    Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An att... Read more

    • EPSS Score: %0.45
    • Published: Oct. 25, 2022
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2022-22055

    The Le-yan dental management system contains an SQL-injection vulnerability. An unauthenticated remote attacker can inject SQL commands into the input field of the login page to acquire administrator’s privilege and perform arbitrary operations on the sys... Read more

    Affected Products : le-yan_dental_management_system
    • EPSS Score: %3.16
    • Published: Jan. 14, 2022
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2012-2974

    The web interface on the SMC SMC8024L2 switch allows remote attackers to bypass authentication and obtain administrative access via a direct request to a .html file under (1) status/, (2) system/, (3) ports/, (4) trunks/, (5) vlans/, (6) qos/, (7) rstp/, ... Read more

    Affected Products : smc8024l2_switch
    • EPSS Score: %0.80
    • Published: Jul. 19, 2012
    • Modified: Apr. 11, 2025
  • 10.0

    CRITICAL
    CVE-2024-49257

    Unrestricted Upload of File with Dangerous Type vulnerability in Denis Azz Anonim Posting allows Upload a Web Shell to a Web Server.This issue affects Azz Anonim Posting: from n/a through 0.9.... Read more

    Affected Products :
    • Published: Oct. 16, 2024
    • Modified: Oct. 16, 2024
  • 10.0

    CRITICAL
    CVE-2024-49329

    Unrestricted Upload of File with Dangerous Type vulnerability in Vivek Tamrakar WP REST API FNS allows Upload a Web Shell to a Web Server.This issue affects WP REST API FNS: from n/a through 1.0.0.... Read more

    Affected Products : wp_rest_api_fns
    • Published: Oct. 20, 2024
    • Modified: Oct. 24, 2024
  • 10.0

    CRITICAL
    CVE-2024-49330

    Unrestricted Upload of File with Dangerous Type vulnerability in brx8r Nice Backgrounds allows Upload a Web Shell to a Web Server.This issue affects Nice Backgrounds: from n/a through 1.0.... Read more

    Affected Products : nice_backgrounds
    • Published: Oct. 20, 2024
    • Modified: Oct. 24, 2024
  • 10.0

    HIGH
    CVE-2019-7269

    Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.... Read more

    • EPSS Score: %20.77
    • Published: Jul. 02, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2024-23616

    A buffer overflow vulnerability exists in Symantec Server Management Suite version 7.9 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as SYSTEM. ... Read more

    Affected Products : symantec_server_management_suite
    • EPSS Score: %6.30
    • Published: Jan. 26, 2024
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2022-22486

    IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM ... Read more

    Affected Products : tivoli_workload_scheduler
    • EPSS Score: %0.02
    • Published: Feb. 03, 2023
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2024-25096

    Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto allows Code Injection.This issue affects Canto: from n/a through 3.0.7. ... Read more

    Affected Products : canto
    • Published: Apr. 03, 2024
    • Modified: Apr. 10, 2025
  • 10.0

    CRITICAL
    CVE-2024-25100

    Deserialization of Untrusted Data vulnerability in WP Swings Coupon Referral Program.This issue affects Coupon Referral Program: from n/a through 1.7.2. ... Read more

    Affected Products : coupon_referral_program
    • EPSS Score: %0.68
    • Published: Feb. 12, 2024
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2009-1043

    Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.... Read more

    Affected Products : windows_7 internet_explorer
    • EPSS Score: %39.92
    • Published: Mar. 23, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2012-3260

    Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1462.... Read more

    Affected Products : sitescope
    • EPSS Score: %68.58
    • Published: Sep. 25, 2012
    • Modified: Apr. 11, 2025
  • 10.0

    CRITICAL
    CVE-2021-26728

    Command injection and stack-based buffer overflow vulnerabilities in the KillDupUsr_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner Inc IAC-AST2500... Read more

    Affected Products : iac-ast2500a_firmware iac-ast2500a
    • EPSS Score: %0.64
    • Published: Oct. 24, 2022
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2024-2912

    An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by sending a specially crafted POST request. By exploiting this vulnerability, attackers can execute arbitrary commands on the server hosting t... Read more

    Affected Products :
    • Published: Apr. 16, 2024
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2006-6926

    Buffer overflow in eXtremail 2.1 has unknown impact and attack vectors, as demonstrated by VulnDisco Pack. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.... Read more

    Affected Products : extremail
    • EPSS Score: %0.38
    • Published: Jan. 13, 2007
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2022-23166

    Sysaid – Sysaid Local File Inclusion (LFI) – An unauthenticated attacker can access to the system by accessing to "/lib/tinymce/examples/index.html" path. in the "Insert/Edit Embedded Media" window Choose Type : iFrame and File/URL : [here is the LFI] Sol... Read more

    Affected Products : sysaid
    • EPSS Score: %0.44
    • Published: May. 12, 2022
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2014-6120

    IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.0 through 9.0.0.1, and 9.0.1 allow remote attackers to execute arbitrary commands on the installation serv... Read more

    • EPSS Score: %4.19
    • Published: Apr. 12, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 291358 Results