Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2024-53438

    EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing ... Read more

    Affected Products : churchcrm
    • Published: Nov. 22, 2024
    • Modified: Mar. 28, 2025
  • 9.8

    CRITICAL
    CVE-2025-27641

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.951 Application 20.0.2368 allows Unauthenticated APIs for Single-Sign On V-2024-009.... Read more

    Affected Products : virtual_appliance vasion_print
    • Published: Mar. 05, 2025
    • Modified: Apr. 15, 2025
  • 9.8

    CRITICAL
    CVE-2023-24350

    D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the config.smtp_email_subject parameter at /goform/formSetEmail.... Read more

    Affected Products : dir-605l_firmware dir-605l
    • EPSS Score: %2.08
    • Published: Feb. 10, 2023
    • Modified: Mar. 24, 2025
  • 9.8

    CRITICAL
    CVE-2023-26323

    A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary code.... Read more

    Affected Products : app_market
    • Published: Aug. 28, 2024
    • Modified: Mar. 27, 2025
  • 9.8

    CRITICAL
    CVE-2024-8999

    lunary-ai/lunary version v1.4.25 contains an improper access control vulnerability in the POST /api/v1/data-warehouse/bigquery endpoint. This vulnerability allows any user to export the entire database data by creating a stream to Google BigQuery without ... Read more

    Affected Products : lunary
    • Published: Mar. 20, 2025
    • Modified: Apr. 10, 2025
    • Vuln Type: Authorization
  • 9.8

    CRITICAL
    CVE-2024-8502

    A vulnerability in the RpcAgentServerLauncher class of modelscope/agentscope v0.0.6a3 allows for remote code execution (RCE) via deserialization of untrusted data using the dill library. The issue occurs in the AgentServerServicer.create_agent method, whe... Read more

    Affected Products : agentscope
    • Published: Mar. 20, 2025
    • Modified: Mar. 20, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-31049

    Deserialization of Untrusted Data vulnerability in themeton Dash allows Object Injection. This issue affects Dash: from n/a through 1.3.... Read more

    Affected Products :
    • Published: May. 23, 2025
    • Modified: May. 23, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2022-48175

    Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/ajax_request.... Read more

    Affected Products : rukovoditel
    • EPSS Score: %5.23
    • Published: Jan. 30, 2023
    • Modified: Mar. 28, 2025
  • 9.8

    CRITICAL
    CVE-2023-24762

    OS Command injection vulnerability in D-Link DIR-867 DIR_867_FW1.30B07 allows attackers to execute arbitrary commands via a crafted LocalIPAddress parameter for the SetVirtualServerSettings to HNAP1.... Read more

    Affected Products : dir-867_firmware dir-867
    • EPSS Score: %1.70
    • Published: Mar. 13, 2023
    • Modified: Mar. 03, 2025
  • 9.8

    CRITICAL
    CVE-2024-8262

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Proliz Software OBS allows Path Traversal.This issue affects OBS: before 24.0927.... Read more

    • Published: Mar. 03, 2025
    • Modified: Mar. 10, 2025
    • Vuln Type: Path Traversal
  • 9.8

    CRITICAL
    CVE-2024-33403

    A SQL injection vulnerability in /model/get_events.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the event_id parameter.... Read more

    • Published: May. 06, 2024
    • Modified: Mar. 25, 2025
  • 9.8

    CRITICAL
    CVE-2024-4267

    A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically within the 'open_file' module, version 9.5. The vulnerability arises due to improper neutralization of special elements used in a command within the 'open_file' ... Read more

    • Published: May. 22, 2024
    • Modified: Aug. 15, 2025
  • 9.8

    CRITICAL
    CVE-2021-30193

    CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write.... Read more

    • EPSS Score: %0.53
    • Published: May. 25, 2021
    • Modified: Aug. 15, 2025
  • 9.8

    CRITICAL
    CVE-2021-30189

    CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow.... Read more

    • EPSS Score: %0.57
    • Published: May. 25, 2021
    • Modified: Aug. 15, 2025
  • 9.8

    CRITICAL
    CVE-2021-30188

    CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.... Read more

    • EPSS Score: %0.57
    • Published: May. 25, 2021
    • Modified: Aug. 15, 2025
  • 9.8

    CRITICAL
    CVE-2025-8926

    A vulnerability was found in SourceCodester COVID 19 Testing Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument Username leads to sql injection. The attack can be laun... Read more

    • Published: Aug. 13, 2025
    • Modified: Aug. 15, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-55150

    Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, when using the /api/v1/convert/html/pdf endpoint to convert HTML to PDF, the backend calls a third-party tool to process it and include... Read more

    Affected Products : stirling_pdf
    • Published: Aug. 11, 2025
    • Modified: Aug. 15, 2025
  • 9.8

    CRITICAL
    CVE-2025-8932

    A vulnerability was determined in 1000 Projects Sales Management System 1.0. This vulnerability affects unknown code of the file /superstore/admin/sales.php. The manipulation of the argument ssalescat leads to sql injection. The attack can be initiated re... Read more

    Affected Products : sales_management_system
    • Published: Aug. 14, 2025
    • Modified: Aug. 15, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-51390

    TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a command injection vulnerability via the pin parameter in the setWiFiWpsConfig function.... Read more

    Affected Products : n600r_firmware n600r
    • Published: Aug. 04, 2025
    • Modified: Aug. 15, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-9022

    A vulnerability was identified in SourceCodester Online Bank Management System up to 1.0. This issue affects some unknown processing of the file /bank/statements.php. The manipulation of the argument email leads to sql injection. The attack may be initiat... Read more

    Affected Products : online_bank_management_system
    • Published: Aug. 15, 2025
    • Modified: Aug. 21, 2025
    • Vuln Type: Injection
Showing 20 of 292508 Results