Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2018-11792

    In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER on a table and ALL on a particular database allows a user to move the table to a database with ALL, which... Read more

    Affected Products : impala
    • EPSS Score: %0.55
    • Published: Oct. 24, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-13342

    The server API in the Anda app relies on hardcoded credentials.... Read more

    Affected Products : anda
    • EPSS Score: %0.36
    • Published: Oct. 24, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-10731

    ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the request parameter files, clients.php with the request parameter selected_clients, clients.php with the request paramete... Read more

    Affected Products : projectsend
    • EPSS Score: %0.31
    • Published: Oct. 29, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-10732

    ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or process-zip-download.php, or add_user_form_* parameters to users-add.php.... Read more

    Affected Products : projectsend
    • EPSS Score: %0.15
    • Published: Oct. 29, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-18702

    spider.admincp.php in iCMS v7.0.11 allows SQL injection via admincp.php?app=spider&do=import_rule because the upfile content is base64 decoded, deserialized, and used for database insertion.... Read more

    Affected Products : icms
    • EPSS Score: %0.26
    • Published: Oct. 29, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-18728

    An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. They allow remote code execution via shell metacharacters in the usbName field to the __fastcall function with a POST request.... Read more

    • EPSS Score: %3.11
    • Published: Oct. 29, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-18729

    An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a heap-based buffer overflow vulnerability in the router's web server -- httpd. W... Read more

    • EPSS Score: %0.45
    • Published: Oct. 29, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-18785

    An issue was discovered in zzcms 8.3. SQL Injection exists in zs/subzs.php with a zzcmscpid cookie to zs/search.php.... Read more

    Affected Products : zzcms
    • EPSS Score: %0.26
    • Published: Oct. 29, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-18786

    An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie.... Read more

    Affected Products : zzcms
    • EPSS Score: %0.26
    • Published: Oct. 29, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-18791

    An issue was discovered in zzcms 8.3. SQL Injection exists in zs/search.php via a pxzs cookie.... Read more

    Affected Products : zzcms
    • EPSS Score: %0.26
    • Published: Oct. 29, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-18787

    An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs.php via a pxzs cookie.... Read more

    Affected Products : zzcms
    • EPSS Score: %0.26
    • Published: Oct. 29, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-18832

    admin/check.asp in DKCMS 9.4 allows SQL Injection via an ASPSESSIONID cookie to admin/admin.asp.... Read more

    Affected Products : dkcms
    • EPSS Score: %0.26
    • Published: Oct. 30, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-18835

    upload_template() in system/changeskin.php in DocCms 2016.5.12 allows remote attackers to execute arbitrary PHP code via a template file.... Read more

    Affected Products : doccms
    • EPSS Score: %0.99
    • Published: Oct. 30, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-1851

    IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the system, caused by improper deserialization. By sending a specially-crafted request to the RP service, an attacker could exploit this vul... Read more

    Affected Products : websphere_application_server
    • EPSS Score: %5.29
    • Published: Oct. 31, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2007-4290

    Multiple PHP remote file inclusion vulnerabilities in Guestbook Script 1.9 allow remote attackers to execute arbitrary PHP code via a URL in the script_root parameter to (1) delete.php, (2) edit.php, or (3) inc/common.inc.php; or (4) database.php, (5) ent... Read more

    Affected Products : guestbook_script
    • EPSS Score: %0.97
    • Published: Aug. 09, 2007
    • Modified: Apr. 09, 2025
  • 9.8

    CRITICAL
    CVE-2023-22388

    Memory Corruption in Multi-mode Call Processor while processing bit mask API.... Read more

    • EPSS Score: %0.16
    • Published: Nov. 07, 2023
    • Modified: Aug. 11, 2025
  • 9.8

    CRITICAL
    CVE-2007-5565

    PHP remote file inclusion vulnerability in includes/functions.php in phpSCMS 0.0.1-Alpha1 allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter. NOTE: this issue is disputed by CVE because the identified code is in a functi... Read more

    Affected Products : phpscms
    • EPSS Score: %0.72
    • Published: Oct. 18, 2007
    • Modified: Apr. 09, 2025
  • 9.8

    CRITICAL
    CVE-2008-0174

    GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the passwords and gain privileges.... Read more

    • EPSS Score: %3.73
    • Published: Jan. 29, 2008
    • Modified: Apr. 09, 2025
  • 9.8

    CRITICAL
    CVE-2015-5052

    SQL injection vulnerability in Sefrengo before 1.6.5 beta2.... Read more

    Affected Products : sefrengo
    • EPSS Score: %0.31
    • Published: Sep. 07, 2017
    • Modified: Apr. 20, 2025
  • 9.8

    CRITICAL
    CVE-2009-1936

    _functions.php in cpCommerce 1.2.x, possibly including 1.2.9, sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass a protection mechanism to conduct remote file inclusion and directory traversal attacks, e... Read more

    Affected Products : cpcommerce
    • EPSS Score: %3.62
    • Published: Jun. 05, 2009
    • Modified: Apr. 09, 2025
Showing 20 of 291722 Results