Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.9

    CRITICAL
    CVE-2022-26075

    An OS command injection vulnerability exists in the console infactory_wlan functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests ... Read more

    • EPSS Score: %9.34
    • Published: May. 12, 2022
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2024-8767

    Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 619, Acronis Backup extension for Plesk (Linux) before build 555, Acronis... Read more

    Affected Products :
    • Published: Sep. 17, 2024
    • Modified: Sep. 20, 2024
  • 9.9

    CRITICAL
    CVE-2023-3342

    The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and missing file type validation on the 'ur_upload_profile_pic' function in versions up to, and including, 3.0.2. This makes it possible f... Read more

    Affected Products : user_registration
    • EPSS Score: %3.34
    • Published: Jul. 13, 2023
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2023-29214

    XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper e... Read more

    Affected Products : xwiki
    • EPSS Score: %7.12
    • Published: Apr. 16, 2023
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2024-8621

    The Daily Prayer Time plugin for WordPress is vulnerable to SQL Injection via the 'max_word' attribute of the 'quran_verse' shortcode in all versions up to, and including, 2024.08.26 due to insufficient escaping on the user supplied parameter and lack of ... Read more

    Affected Products : daily_prayer_time
    • Published: Sep. 25, 2024
    • Modified: Oct. 02, 2024
  • 9.9

    CRITICAL
    CVE-2024-36393

    SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')... Read more

    Affected Products : sysaid
    • Published: Jun. 06, 2024
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2024-41799

    tgstation-server is a production scale tool for BYOND server management. Prior to 6.8.0, low permission users using the "Set .dme Path" privilege could potentially set malicious .dme files existing on the host machine to be compiled and executed. These .d... Read more

    Affected Products : tgstation-server
    • Published: Jul. 29, 2024
    • Modified: Aug. 19, 2025
  • 9.9

    CRITICAL
    CVE-2018-3832

    An exploitable firmware update vulnerability exists in Insteon Hub running firmware version 1013. The HTTP server allows for uploading arbitrary MPFS binaries that could be modified to enable access to hidden resources which allow for uploading unsigned f... Read more

    • EPSS Score: %0.42
    • Published: Aug. 23, 2018
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2018-3897

    An exploitable buffer overflow vulnerabilities exist in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub with Firmware version 0.20.17. The video-core process incorrectly extracts fields from a user-controlled JSON pa... Read more

    Affected Products : sth-eth-250_firmware sth-eth-250
    • EPSS Score: %0.22
    • Published: Sep. 10, 2018
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2025-47663

    Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System allows Upload a Web Shell to a Web Server. This issue affects Hospital Management System: from 47.0(20 through 11.... Read more

    Affected Products : hospital_management_system
    • Published: May. 23, 2025
    • Modified: May. 23, 2025
    • Vuln Type: Misconfiguration
  • 9.9

    CRITICAL
    CVE-2022-45808

    SQL Injection vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.... Read more

    Affected Products : learnpress
    • EPSS Score: %74.70
    • Published: Jan. 26, 2023
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2025-22133

    WeGIA is a web manager for charitable institutions. Prior to 3.2.8, a critical vulnerability was identified in the /WeGIA/html/socio/sistema/controller/controla_xlsx.php endpoint. The endpoint accepts file uploads without proper validation, allowing the u... Read more

    Affected Products : wegia
    • Published: Jan. 07, 2025
    • Modified: Apr. 09, 2025
    • Vuln Type: Authentication
  • 9.9

    CRITICAL
    CVE-2023-36355

    TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.... Read more

    Affected Products : tl-wr940n_firmware tl-wr940n
    • EPSS Score: %38.26
    • Published: Jun. 22, 2023
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2023-37462

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Improper escaping in the document `SkinsCode.XWikiSkinsSheet` leads to an injection vector from view right on that document to programming rights, or ... Read more

    Affected Products : xwiki
    • EPSS Score: %91.45
    • Published: Jul. 14, 2023
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2024-38369

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The content of a document included using `{{include reference="targetdocument"/}}` is executed with the right of the includer and not with the right o... Read more

    Affected Products : xwiki
    • Published: Jun. 24, 2024
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2023-4159

    Unrestricted Upload of File with Dangerous Type in GitHub repository omeka/omeka-s prior to 4.0.3.... Read more

    Affected Products : omeka_s
    • EPSS Score: %0.10
    • Published: Aug. 04, 2023
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2023-38049

    A BOLA vulnerability in GET, PUT, DELETE /appointments/{appointmentId} allows a low privileged user to fetch, modify or delete an appointment of any user (including admin). This results in unauthorized access and unauthorized data manipulation.... Read more

    Affected Products : easyappointments
    • Published: Jul. 09, 2024
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2024-44761

    An issue in EQ Enterprise Management System before v2.0.0 allows attackers to execute a directory traversal via crafted requests.... Read more

    Affected Products : eq_enterprise_management_system
    • Published: Aug. 28, 2024
    • Modified: Nov. 18, 2024
  • 9.9

    CRITICAL
    CVE-2024-48027

    Unrestricted Upload of File with Dangerous Type vulnerability in xaraartech External featured image from bing allows Upload a Web Shell to a Web Server.This issue affects External featured image from bing: from n/a through 1.0.2.... Read more

    Affected Products :
    • Published: Oct. 16, 2024
    • Modified: Oct. 16, 2024
  • 9.9

    CRITICAL
    CVE-2022-24900

    Piano LED Visualizer is software that allows LED lights to light up as a person plays a piano connected to a computer. Version 1.3 and prior are vulnerable to a path traversal attack. The `os.path.join` call is unsafe for use with untrusted input. When th... Read more

    Affected Products : piano_led_visualizer
    • EPSS Score: %82.86
    • Published: Apr. 29, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 291551 Results