Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2025-7778

    The Icons Factory plugin for WordPress is vulnerable to Arbitrary File Deletion due to insufficient authorization and improper path validation within the delete_files() function in all versions up to, and including, 1.6.12. This makes it possible for unau... Read more

    Affected Products :
    • Published: Aug. 15, 2025
    • Modified: Aug. 15, 2025
    • Vuln Type: Authorization
  • 9.8

    CRITICAL
    CVE-2025-6679

    The Bit Form builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 2.20.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affec... Read more

    Affected Products :
    • Published: Aug. 15, 2025
    • Modified: Aug. 15, 2025
    • Vuln Type: Authentication
  • 9.8

    CRITICAL
    CVE-2017-3907

    Code Injection vulnerability in the ePolicy Orchestrator (ePO) extension in McAfee Threat Intelligence Exchange (TIE) Server 2.1.0 and earlier allows remote attackers to execute arbitrary HTML code to be reflected in the response web page via unspecified ... Read more

    • EPSS Score: %0.49
    • Published: Jun. 13, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2017-9819

    The National Payments Corporation of India BHIM application 1.3 for Android does not properly restrict use of the OTP feature, which makes it easier for attackers to bypass authentication.... Read more

    • EPSS Score: %0.55
    • Published: Aug. 24, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2000-1218

    The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to po... Read more

    • EPSS Score: %2.22
    • Published: Apr. 14, 2000
    • Modified: Apr. 03, 2025
  • 9.8

    CRITICAL
    CVE-2023-43453

    An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the IP parameter of the setDiagnosisCfg component.... Read more

    Affected Products : x6000r_firmware x6000r
    • EPSS Score: %3.93
    • Published: Dec. 01, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-34388

    An Improper Authentication vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote unauthenticated attacker to potentially perform session hijacking attack and bypass authentication. See product Instruction Manual Appendix... Read more

    Affected Products : sel-451_firmware sel-451
    • EPSS Score: %0.12
    • Published: Nov. 30, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2004-2214

    Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions via a URI with mixed case characters.... Read more

    Affected Products : appweb_http_server
    • EPSS Score: %0.62
    • Published: Dec. 31, 2004
    • Modified: Apr. 03, 2025
  • 9.8

    CRITICAL
    CVE-2024-6253

    A vulnerability was found in itsourcecode Online Food Ordering System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /purchase.php. The manipulation of the argument customer leads to sql injection. The att... Read more

    Affected Products : online_food_ordering_system
    • Published: Jun. 22, 2024
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-2363

    A vulnerability, which was classified as critical, has been found in SourceCodester Resort Reservation System 1.0. This issue affects some unknown processing of the file view_room.php. The manipulation of the argument id leads to sql injection. The attack... Read more

    • EPSS Score: %0.05
    • Published: Apr. 28, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2005-3435

    admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by obtaining the password hash for another user, for example through another Newsworld vulnerability, and specifying the hash in the pwd argument.... Read more

    Affected Products : newsworld
    • EPSS Score: %0.86
    • Published: Nov. 02, 2005
    • Modified: Apr. 03, 2025
  • 9.8

    CRITICAL
    CVE-2006-5610

    PHP remote file inclusion vulnerability in player/includes/common.php in Teake Nutma Foing, as modified in Fully Modded phpBB (phpbbfm) 2021.4.40, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.... Read more

    Affected Products : fully_modded_phpbb
    • EPSS Score: %1.04
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 9.8

    CRITICAL
    CVE-2007-0681

    profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to register.php.... Read more

    Affected Products : extcalendar
    • EPSS Score: %4.68
    • Published: Feb. 03, 2007
    • Modified: Apr. 09, 2025
  • 9.8

    CRITICAL
    CVE-2023-43548

    Memory corruption while parsing qcp clip with invalid chunk data size.... Read more

    • Published: Mar. 04, 2024
    • Modified: Aug. 11, 2025
  • 9.8

    CRITICAL
    CVE-2007-4043

    file.cgi in Secure Computing SecurityReporter (aka Network Security Analyzer) before 4.6.3 allows remote attackers to bypass authentication via a name parameter ending with a "%00.gif" sequence. NOTE: a separate traversal vulnerability could be leveraged ... Read more

    Affected Products : securityreporter
    • EPSS Score: %0.34
    • Published: Jul. 27, 2007
    • Modified: Apr. 09, 2025
  • 9.8

    CRITICAL
    CVE-2018-13342

    The server API in the Anda app relies on hardcoded credentials.... Read more

    Affected Products : anda
    • EPSS Score: %0.36
    • Published: Oct. 24, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-10732

    ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or process-zip-download.php, or add_user_form_* parameters to users-add.php.... Read more

    Affected Products : projectsend
    • EPSS Score: %0.15
    • Published: Oct. 29, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-18702

    spider.admincp.php in iCMS v7.0.11 allows SQL injection via admincp.php?app=spider&do=import_rule because the upfile content is base64 decoded, deserialized, and used for database insertion.... Read more

    Affected Products : icms
    • EPSS Score: %0.26
    • Published: Oct. 29, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-18728

    An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. They allow remote code execution via shell metacharacters in the usbName field to the __fastcall function with a POST request.... Read more

    • EPSS Score: %3.11
    • Published: Oct. 29, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-18729

    An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a heap-based buffer overflow vulnerability in the router's web server -- httpd. W... Read more

    • EPSS Score: %0.45
    • Published: Oct. 29, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 292511 Results