Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2005-3435

    admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by obtaining the password hash for another user, for example through another Newsworld vulnerability, and specifying the hash in the pwd argument.... Read more

    Affected Products : newsworld
    • Published: Nov. 02, 2005
    • Modified: Apr. 03, 2025
  • 9.8

    CRITICAL
    CVE-2006-5610

    PHP remote file inclusion vulnerability in player/includes/common.php in Teake Nutma Foing, as modified in Fully Modded phpBB (phpbbfm) 2021.4.40, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.... Read more

    Affected Products : fully_modded_phpbb
    • Published: Oct. 31, 2006
    • Modified: Apr. 09, 2025
  • 9.8

    CRITICAL
    CVE-2007-0681

    profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to register.php.... Read more

    Affected Products : extcalendar
    • Published: Feb. 03, 2007
    • Modified: Apr. 09, 2025
  • 9.8

    CRITICAL
    CVE-2023-43548

    Memory corruption while parsing qcp clip with invalid chunk data size.... Read more

    • Published: Mar. 04, 2024
    • Modified: Aug. 11, 2025
  • 9.8

    CRITICAL
    CVE-2007-4043

    file.cgi in Secure Computing SecurityReporter (aka Network Security Analyzer) before 4.6.3 allows remote attackers to bypass authentication via a name parameter ending with a "%00.gif" sequence. NOTE: a separate traversal vulnerability could be leveraged ... Read more

    Affected Products : securityreporter
    • Published: Jul. 27, 2007
    • Modified: Apr. 09, 2025
  • 9.8

    CRITICAL
    CVE-2018-13342

    The server API in the Anda app relies on hardcoded credentials.... Read more

    Affected Products : anda
    • Published: Oct. 24, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-10732

    ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or process-zip-download.php, or add_user_form_* parameters to users-add.php.... Read more

    Affected Products : projectsend
    • Published: Oct. 29, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-18702

    spider.admincp.php in iCMS v7.0.11 allows SQL injection via admincp.php?app=spider&do=import_rule because the upfile content is base64 decoded, deserialized, and used for database insertion.... Read more

    Affected Products : icms
    • Published: Oct. 29, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-18728

    An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. They allow remote code execution via shell metacharacters in the usbName field to the __fastcall function with a POST request.... Read more

    • Published: Oct. 29, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-18729

    An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a heap-based buffer overflow vulnerability in the router's web server -- httpd. W... Read more

    • Published: Oct. 29, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-18785

    An issue was discovered in zzcms 8.3. SQL Injection exists in zs/subzs.php with a zzcmscpid cookie to zs/search.php.... Read more

    Affected Products : zzcms
    • Published: Oct. 29, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-18786

    An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie.... Read more

    Affected Products : zzcms
    • Published: Oct. 29, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-18791

    An issue was discovered in zzcms 8.3. SQL Injection exists in zs/search.php via a pxzs cookie.... Read more

    Affected Products : zzcms
    • Published: Oct. 29, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-18787

    An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs.php via a pxzs cookie.... Read more

    Affected Products : zzcms
    • Published: Oct. 29, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-18832

    admin/check.asp in DKCMS 9.4 allows SQL Injection via an ASPSESSIONID cookie to admin/admin.asp.... Read more

    Affected Products : dkcms
    • Published: Oct. 30, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-18835

    upload_template() in system/changeskin.php in DocCms 2016.5.12 allows remote attackers to execute arbitrary PHP code via a template file.... Read more

    Affected Products : doccms
    • Published: Oct. 30, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-1851

    IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the system, caused by improper deserialization. By sending a specially-crafted request to the RP service, an attacker could exploit this vul... Read more

    Affected Products : websphere_application_server
    • Published: Oct. 31, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2007-4290

    Multiple PHP remote file inclusion vulnerabilities in Guestbook Script 1.9 allow remote attackers to execute arbitrary PHP code via a URL in the script_root parameter to (1) delete.php, (2) edit.php, or (3) inc/common.inc.php; or (4) database.php, (5) ent... Read more

    Affected Products : guestbook_script
    • Published: Aug. 09, 2007
    • Modified: Apr. 09, 2025
  • 9.8

    CRITICAL
    CVE-2023-22388

    Memory Corruption in Multi-mode Call Processor while processing bit mask API.... Read more

    • Published: Nov. 07, 2023
    • Modified: Aug. 11, 2025
  • 9.8

    CRITICAL
    CVE-2007-5565

    PHP remote file inclusion vulnerability in includes/functions.php in phpSCMS 0.0.1-Alpha1 allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter. NOTE: this issue is disputed by CVE because the identified code is in a functi... Read more

    Affected Products : phpscms
    • Published: Oct. 18, 2007
    • Modified: Apr. 09, 2025
Showing 20 of 293186 Results