Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2018-1851

    IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the system, caused by improper deserialization. By sending a specially-crafted request to the RP service, an attacker could exploit this vul... Read more

    Affected Products : websphere_application_server
    • Published: Oct. 31, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2007-4290

    Multiple PHP remote file inclusion vulnerabilities in Guestbook Script 1.9 allow remote attackers to execute arbitrary PHP code via a URL in the script_root parameter to (1) delete.php, (2) edit.php, or (3) inc/common.inc.php; or (4) database.php, (5) ent... Read more

    Affected Products : guestbook_script
    • Published: Aug. 09, 2007
    • Modified: Apr. 09, 2025
  • 9.8

    CRITICAL
    CVE-2023-22388

    Memory Corruption in Multi-mode Call Processor while processing bit mask API.... Read more

    • Published: Nov. 07, 2023
    • Modified: Aug. 11, 2025
  • 9.8

    CRITICAL
    CVE-2007-5565

    PHP remote file inclusion vulnerability in includes/functions.php in phpSCMS 0.0.1-Alpha1 allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter. NOTE: this issue is disputed by CVE because the identified code is in a functi... Read more

    Affected Products : phpscms
    • Published: Oct. 18, 2007
    • Modified: Apr. 09, 2025
  • 9.8

    CRITICAL
    CVE-2015-5052

    SQL injection vulnerability in Sefrengo before 1.6.5 beta2.... Read more

    Affected Products : sefrengo
    • Published: Sep. 07, 2017
    • Modified: Apr. 20, 2025
  • 9.8

    CRITICAL
    CVE-2009-1936

    _functions.php in cpCommerce 1.2.x, possibly including 1.2.9, sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass a protection mechanism to conduct remote file inclusion and directory traversal attacks, e... Read more

    Affected Products : cpcommerce
    • Published: Jun. 05, 2009
    • Modified: Apr. 09, 2025
  • 9.8

    CRITICAL
    CVE-2022-41014

    Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequ... Read more

    Affected Products : quartz-gold_firmware quartz-gold
    • Published: Jan. 26, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2009-2168

    cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier sends a redirect to the web browser but does not exit when the supplied credentials are incorrect, which allows remote attackers to bypass authentication by providing arbitrary username and pa... Read more

    Affected Products : 7ammel
    • Published: Jun. 22, 2009
    • Modified: Apr. 09, 2025
  • 9.8

    CRITICAL
    CVE-2009-2367

    cgi-bin/makecgi-pro in Iomega StorCenter Pro generates predictable session IDs, which allows remote attackers to hijack active sessions and gain privileges via brute force guessing attacks on the session_id parameter.... Read more

    • Published: Jul. 08, 2009
    • Modified: Apr. 09, 2025
  • 9.8

    CRITICAL
    CVE-2009-3421

    login.php in Zenas PaoBacheca Guestbook 2.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1.... Read more

    Affected Products : pao-bacheca_guestbook
    • Published: Sep. 25, 2009
    • Modified: Apr. 09, 2025
  • 9.8

    CRITICAL
    CVE-2023-2595

    A vulnerability has been found in SourceCodester Billing Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file ajax_service.php of the component POST Parameter Handler. The manipulation of... Read more

    • Published: May. 09, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2010-3416

    Google Chrome before 6.0.472.59 on Linux does not properly implement the Khmer locale, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.... Read more

    Affected Products : linux_kernel chrome
    • Published: Sep. 16, 2010
    • Modified: Apr. 11, 2025
  • 9.8

    CRITICAL
    CVE-2023-1475

    A vulnerability, which was classified as critical, has been found in SourceCodester Canteen Management System 1.0. This issue affects the function query of the file createuser.php. The manipulation of the argument uemail leads to sql injection. The attack... Read more

    Affected Products : canteen_management_system
    • Published: Mar. 17, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-38299

    Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to login to a vulnerable service using an attached FIDO2 authenticator without passing a check of the user presence.... Read more

    Affected Products : webauthn_framwork
    • Published: Sep. 27, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2024-52295

    DataEase is an open source data visualization analysis tool. Prior to 2.10.2, DataEase allows attackers to forge jwt and take over services. The JWT secret is hardcoded in the code, and the UID and OID are hardcoded. The vulnerability has been fixed in v2... Read more

    Affected Products : dataease
    • Published: Nov. 13, 2024
    • Modified: Feb. 20, 2025
  • 9.8

    CRITICAL
    CVE-2015-0537

    Integer underflow in the base64-decoding implementation in EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3, RSA BSAFE Crypto-C Micro Edition (Crypto-C ME) before 4.0.4 and 4.1, and RSA BSAFE SSL-C 2.8.9 and earlier allows... Read more

    Affected Products : bsafe bsafe_crypto-c bsafe_ssl-c
    • Published: Aug. 20, 2015
    • Modified: Apr. 12, 2025
  • 9.8

    CRITICAL
    CVE-2018-19061

    DedeCMS 5.7 SP2 has SQL Injection via the dede\co_do.php ids parameter.... Read more

    Affected Products : dedecms
    • Published: Nov. 07, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-15439

    A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authentication mechanism of an affected device. The vulnerability exists because under specific circumstances, the affected so... Read more

    • Published: Nov. 08, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-6491

    Local Escalation of Privilege vulnerability to Micro Focus Universal CMDB, versions 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.00. The vulnerability could be remotely exploited to Local Escalation of Privilege.... Read more

    Affected Products : ucmdb_configuration_manager
    • Published: Apr. 24, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-5495

    All StorageGRID Webscale versions are susceptible to a vulnerability which could permit an unauthenticated attacker to communicate with systems on the same network as the StorageGRID Webscale Admin Node via HTTP or to take over services on the Admin Node.... Read more

    Affected Products : storagegrid_webscale
    • Published: Nov. 14, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 293329 Results