Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2015-3252

    Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allows remote attackers to gain access by connecting to the VNC server.... Read more

    Affected Products : cloudstack
    • EPSS Score: %1.87
    • Published: Feb. 08, 2016
    • Modified: Apr. 12, 2025
  • 9.8

    CRITICAL
    CVE-2022-45982

    thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload.... Read more

    Affected Products : thinkphp
    • EPSS Score: %0.97
    • Published: Feb. 08, 2023
    • Modified: Mar. 25, 2025
  • 9.8

    CRITICAL
    CVE-2024-53438

    EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing ... Read more

    Affected Products : churchcrm
    • Published: Nov. 22, 2024
    • Modified: Mar. 28, 2025
  • 9.8

    CRITICAL
    CVE-2025-27641

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.951 Application 20.0.2368 allows Unauthenticated APIs for Single-Sign On V-2024-009.... Read more

    Affected Products : virtual_appliance vasion_print
    • Published: Mar. 05, 2025
    • Modified: Apr. 15, 2025
  • 9.8

    CRITICAL
    CVE-2023-24350

    D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the config.smtp_email_subject parameter at /goform/formSetEmail.... Read more

    Affected Products : dir-605l_firmware dir-605l
    • EPSS Score: %2.08
    • Published: Feb. 10, 2023
    • Modified: Mar. 24, 2025
  • 9.8

    CRITICAL
    CVE-2022-34440

    Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to th... Read more

    • EPSS Score: %0.13
    • Published: Jan. 11, 2023
    • Modified: May. 20, 2025
  • 9.8

    CRITICAL
    CVE-2023-26323

    A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary code.... Read more

    Affected Products : app_market
    • Published: Aug. 28, 2024
    • Modified: Mar. 27, 2025
  • 9.8

    CRITICAL
    CVE-2024-8999

    lunary-ai/lunary version v1.4.25 contains an improper access control vulnerability in the POST /api/v1/data-warehouse/bigquery endpoint. This vulnerability allows any user to export the entire database data by creating a stream to Google BigQuery without ... Read more

    Affected Products : lunary
    • Published: Mar. 20, 2025
    • Modified: Apr. 10, 2025
    • Vuln Type: Authorization
  • 9.8

    CRITICAL
    CVE-2024-8502

    A vulnerability in the RpcAgentServerLauncher class of modelscope/agentscope v0.0.6a3 allows for remote code execution (RCE) via deserialization of untrusted data using the dill library. The issue occurs in the AgentServerServicer.create_agent method, whe... Read more

    Affected Products : agentscope
    • Published: Mar. 20, 2025
    • Modified: Mar. 20, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-31049

    Deserialization of Untrusted Data vulnerability in themeton Dash allows Object Injection. This issue affects Dash: from n/a through 1.3.... Read more

    Affected Products :
    • Published: May. 23, 2025
    • Modified: May. 23, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2022-48175

    Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/ajax_request.... Read more

    Affected Products : rukovoditel
    • EPSS Score: %5.23
    • Published: Jan. 30, 2023
    • Modified: Mar. 28, 2025
  • 9.8

    CRITICAL
    CVE-2024-31807

    TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSyncWithHost function.... Read more

    Affected Products : ex200_firmware ex200
    • Published: Apr. 08, 2024
    • Modified: Mar. 18, 2025
  • 9.8

    CRITICAL
    CVE-2025-1307

    The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the newscrunch_install_and_activate_plugin() function in all versions up to, and including, 1.8.4.1. This makes it possible for authenticated a... Read more

    Affected Products : newscrunch
    • Published: Mar. 04, 2025
    • Modified: Mar. 04, 2025
    • Vuln Type: Authentication
  • 9.8

    CRITICAL
    CVE-2023-24762

    OS Command injection vulnerability in D-Link DIR-867 DIR_867_FW1.30B07 allows attackers to execute arbitrary commands via a crafted LocalIPAddress parameter for the SetVirtualServerSettings to HNAP1.... Read more

    Affected Products : dir-867_firmware dir-867
    • EPSS Score: %1.70
    • Published: Mar. 13, 2023
    • Modified: Mar. 03, 2025
  • 9.8

    CRITICAL
    CVE-2024-8262

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Proliz Software OBS allows Path Traversal.This issue affects OBS: before 24.0927.... Read more

    • Published: Mar. 03, 2025
    • Modified: Mar. 10, 2025
    • Vuln Type: Path Traversal
  • 9.8

    CRITICAL
    CVE-2024-25320

    Tongda OA v2017 and up to v11.9 was discovered to contain a SQL injection vulnerability via the $AFF_ID parameter at /affair/delete.php.... Read more

    • Published: Feb. 16, 2024
    • Modified: Mar. 19, 2025
  • 9.8

    CRITICAL
    CVE-2024-33403

    A SQL injection vulnerability in /model/get_events.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the event_id parameter.... Read more

    • Published: May. 06, 2024
    • Modified: Mar. 25, 2025
  • 9.8

    CRITICAL
    CVE-2024-38909

    Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.... Read more

    Affected Products : elfinder
    • Published: Jul. 30, 2024
    • Modified: Apr. 28, 2025
  • 9.8

    CRITICAL
    CVE-2022-35620

    D-LINK DIR-818LW A1:DIR818L_FW105b01 was discovered to contain a remote code execution (RCE) vulnerability via the function binary.soapcgi_main.... Read more

    Affected Products : dir-818l_firmware dir-818l
    • EPSS Score: %25.25
    • Published: Aug. 03, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-2094

    A vulnerability has been found in SourceCodester Vehicle Service Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/mechanics/manage_mechanic.php. The manipulation of the argument id leads to sql i... Read more

    • EPSS Score: %0.05
    • Published: Apr. 15, 2023
    • Modified: Feb. 06, 2025
Showing 20 of 291736 Results