Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.9

    CRITICAL
    CVE-2022-26780

    Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigg... Read more

    • EPSS Score: %0.88
    • Published: May. 12, 2022
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2021-38163

    SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operat... Read more

    Affected Products : netweaver
    • Actively Exploited
    • EPSS Score: %88.32
    • Published: Sep. 14, 2021
    • Modified: Mar. 13, 2025
  • 9.9

    CRITICAL
    CVE-2021-43928

    Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in mail sending and receiving component in Synology Mail Station before 20211105-10315 allows remote authenticated users to execute arbitrary commands... Read more

    Affected Products : mail_station
    • EPSS Score: %1.06
    • Published: Feb. 07, 2022
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2017-6513

    The WHMCS Reseller Module V2 2.0.2 in Softaculous Virtualizor before 2.9.1.0 does not verify the user correctly, which allows remote authenticated users to control other virtual machines managed by Virtualizor by accessing a modified URL.... Read more

    Affected Products : whmcs_reseller_module virtualizor
    • EPSS Score: %0.81
    • Published: Mar. 11, 2017
    • Modified: Apr. 20, 2025
  • 9.9

    CRITICAL
    CVE-2023-27881

    A user could use the “Upload Resource” functionality to upload files to any location on the disk. ... Read more

    Affected Products : vuforia_studio
    • EPSS Score: %0.06
    • Published: Jun. 07, 2023
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2023-29510

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In XWiki, every user can add translations that are only applied to the current user. This also allows overriding existing translations. Such translati... Read more

    Affected Products : xwiki
    • EPSS Score: %3.02
    • Published: Apr. 19, 2023
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2023-35150

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.40m-2 and prior to versions 14.4.8, 14.10.4, and 15.0, any user with view rights on any document can execute code with programmi... Read more

    Affected Products : xwiki
    • EPSS Score: %33.48
    • Published: Jun. 23, 2023
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2022-34827

    Carel Boss Mini 1.5.0 has Improper Access Control.... Read more

    Affected Products : boss_mini_firmware boss_mini
    • EPSS Score: %0.09
    • Published: Nov. 18, 2022
    • Modified: Apr. 29, 2025
  • 9.9

    CRITICAL
    CVE-2023-26475

    XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execute the content in a restricted context. This allows executing anything with the right of the author of any document by annotating the do... Read more

    Affected Products : xwiki
    • EPSS Score: %29.36
    • Published: Mar. 02, 2023
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2023-46808

    An file upload vulnerability in Ivanti ITSM before 2023.4, allows an authenticated remote user to perform file writes to the server. Successful exploitation may lead to execution of commands in the context of non-root user. ... Read more

    Affected Products : neurons_for_itsm
    • Published: Mar. 31, 2024
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2024-31465

    XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.20, 15.5.4, and 15.9-rc-1, any user with edit right on any page can execute any code on the server by adding an object of type `XWiki.SearchSuggestSourceCl... Read more

    Affected Products : xwiki
    • Published: Apr. 10, 2024
    • Modified: Jan. 09, 2025
  • 9.9

    CRITICAL
    CVE-2024-3342

    The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to SQL Injection via the 'events' attribute of the 'mp-timetable' shortcode in all versions up to, and including, 2.4.11 due to insufficient escaping on the user supplied par... Read more

    Affected Products : timetable_and_event_schedule
    • Published: Apr. 27, 2024
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2023-52219

    Deserialization of Untrusted Data vulnerability in Gecka Gecka Terms Thumbnails.This issue affects Gecka Terms Thumbnails: from n/a through 1.1. ... Read more

    Affected Products : terms_thumbnails
    • EPSS Score: %0.63
    • Published: Jan. 08, 2024
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2024-37091

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in StylemixThemes Consulting Elementor Widgets, StylemixThemes Masterstudy Elementor Widgets allows OS Command Injection.This issue affects Consulting Elemen... Read more

    Affected Products : consulting_elementor_widgets
    • Published: Jun. 24, 2024
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2024-4197

    An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component. Affected versions include all versions prior to 11.1.3.1.... Read more

    Affected Products : ip_office
    • Published: Jun. 25, 2024
    • Modified: Jan. 21, 2025
  • 9.9

    CRITICAL
    CVE-2023-33318

    Unrestricted Upload of File with Dangerous Type vulnerability in WooCommerce AutomateWoo.This issue affects AutomateWoo: from n/a through 4.9.40. ... Read more

    Affected Products : automatewoo
    • EPSS Score: %0.31
    • Published: Dec. 20, 2023
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2022-1698

    Allowing long password leads to denial of service in GitHub repository causefx/organizr prior to 2.1.2000. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.... Read more

    Affected Products : organizr
    • EPSS Score: %0.30
    • Published: May. 12, 2022
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2024-3549

    The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSortPostType' parameter in all versions up to, and including, 7.4.1 due to insufficient escaping on the user supplied parameter and lack of... Read more

    Affected Products : blog2social
    • Published: Jun. 11, 2024
    • Modified: Jun. 05, 2025
  • 9.9

    CRITICAL
    CVE-2018-3874

    An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer, which has a size of 32 bytes. An atta... Read more

    Affected Products : sth-eth-250_firmware sth-eth-250
    • EPSS Score: %0.38
    • Published: Sep. 21, 2018
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2024-42480

    Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an "open at the top" range definition in RBAC for etcd roles leading to some TCPs API servers being able to read, write, and delete the data of other con... Read more

    Affected Products : kamaji
    • Published: Aug. 12, 2024
    • Modified: Aug. 16, 2024
Showing 20 of 292425 Results