Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.9

    CRITICAL
    CVE-2021-32829

    ZStack is open source IaaS(infrastructure as a service) software aiming to automate datacenters, managing resources of compute, storage, and networking all by APIs. Affected versions of ZStack REST API are vulnerable to post-authentication Remote Code Exe... Read more

    Affected Products : zstack rest_api
    • Published: Aug. 17, 2021
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2024-51478

    YesWiki is a wiki system written in PHP. Prior to 4.4.5, the use of a weak cryptographic algorithm and a hard-coded salt to hash the password reset key allows it to be recovered and used to reset the password of any account. This issue is fixed in 4.4.5.... Read more

    Affected Products : yeswiki
    • Published: Oct. 31, 2024
    • Modified: May. 09, 2025
  • 9.9

    CRITICAL
    CVE-2024-50480

    Unrestricted Upload of File with Dangerous Type vulnerability in azexo Marketing Automation by AZEXO allows Upload a Web Shell to a Web Server.This issue affects Marketing Automation by AZEXO: from n/a through 1.27.80.... Read more

    Affected Products :
    • Published: Oct. 29, 2024
    • Modified: Oct. 29, 2024
  • 9.9

    CRITICAL
    CVE-2020-6100

    An exploitable memory corruption vulnerability exists in AMD atidxx64.dll 26.20.15019.19000 graphics driver. A specially crafted pixel shader can cause memory corruption vulnerability. An attacker can provide a specially crafted shader file to trigger thi... Read more

    • Published: Jul. 20, 2020
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2021-32016

    An issue was discovered in JUMP AMS 3.6.0.04.009-2487. A JUMP SOAP endpoint permitted the writing of arbitrary files to a user-controlled location on the remote filesystem (with user-controlled content) via directory traversal, potentially leading to remo... Read more

    Affected Products : asset_management
    • Published: Aug. 03, 2021
    • Modified: May. 30, 2025
  • 9.9

    CRITICAL
    CVE-2021-32008

    This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname to restricted directory, allows logged in GateManager admin to delete system Files or Directories.... Read more

    Affected Products : gatemanager
    • Published: Mar. 04, 2022
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2021-30120

    Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Thus rendering 2FA useless. Detailed description --- Duri... Read more

    Affected Products : vsa
    • Published: Jul. 09, 2021
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2021-27449

    Mesa Labs AmegaView Versions 3.0 and prior has a command injection vulnerability that can be exploited to execute commands in the web server.... Read more

    Affected Products : amegaview
    • Published: Dec. 21, 2021
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2020-1112

    An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.... Read more

    • Published: May. 21, 2020
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2021-26867

    Windows Hyper-V Remote Code Execution Vulnerability... Read more

    • Published: Mar. 11, 2021
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2021-26753

    NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all a... Read more

    Affected Products : nedi
    • Published: Feb. 12, 2021
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2021-26334

    The AMDPowerProfiler.sys driver of AMD μProf tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation and ring-0 code execution by the lower privileged user.... Read more

    Affected Products : linux_kernel windows amd_uprof
    • Published: Dec. 01, 2021
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2021-26424

    Windows TCP/IP Remote Code Execution Vulnerability... Read more

    • Published: Aug. 12, 2021
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2021-25320

    A Improper Access Control vulnerability in Rancher, allows users in the cluster to make request to cloud providers by creating requests with the cloud-credential ID. Rancher in this case would attach the requested credentials without further checks This i... Read more

    Affected Products : rancher
    • Published: Jul. 15, 2021
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2025-20286

    A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execute limited admini... Read more

    Affected Products : identity_services_engine
    • Published: Jun. 04, 2025
    • Modified: Jun. 05, 2025
    • Vuln Type: Misconfiguration
  • 9.9

    CRITICAL
    CVE-2024-22116

    An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default escaping for script parameters enabled this user ability to execute arbitrary code via the Ping script, th... Read more

    Affected Products : zabbix
    • Published: Aug. 12, 2024
    • Modified: Dec. 04, 2024
  • 9.9

    CRITICAL
    CVE-2024-49669

    Unrestricted Upload of File with Dangerous Type vulnerability in Alexander De Ridder INK Official allows Upload a Web Shell to a Web Server.This issue affects INK Official: from n/a through 4.1.2.... Read more

    Affected Products :
    • Published: Oct. 23, 2024
    • Modified: Oct. 25, 2024
  • 9.9

    CRITICAL
    CVE-2017-7175

    NfSen before 1.3.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the customfmt parameter (aka the "Custom output format" field).... Read more

    Affected Products : nfsen
    • Published: Jul. 10, 2017
    • Modified: Apr. 20, 2025
  • 9.9

    CRITICAL
    CVE-2021-1411

    Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive informa... Read more

    Affected Products : jabber
    • Published: Mar. 24, 2021
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2020-3495

    A vulnerability in Cisco Jabber for Windows could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is due to improper validation of message contents. An attacker could exploit this vulnerability by sending specially cra... Read more

    Affected Products : jabber
    • Published: Sep. 04, 2020
    • Modified: Nov. 21, 2024
Showing 20 of 292801 Results