Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2023-43552

    Memory corruption while processing MBSSID beacon containing several subelement IE.... Read more

    • Published: Mar. 04, 2024
    • Modified: Aug. 11, 2025
  • 9.8

    CRITICAL
    CVE-2023-43553

    Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE.... Read more

    • Published: Mar. 04, 2024
    • Modified: Jan. 09, 2025
  • 9.8

    CRITICAL
    CVE-2024-2077

    A vulnerability classified as critical has been found in SourceCodester Simple Online Bidding System 1.0. This affects an unknown part of the file index.php. The manipulation of the argument category_id leads to sql injection. It is possible to initiate t... Read more

    Affected Products : simple_online_bidding_system
    • Published: Mar. 01, 2024
    • Modified: Dec. 09, 2024
  • 9.8

    CRITICAL
    CVE-2023-45592

    A CWE-250 “Execution with Unnecessary Privileges” vulnerability in the embedded Chromium browser (due to the binary being executed with the “--no-sandbox” option and with root privileges) exacerbates the impacts of successful attacks executed against the ... Read more

    Affected Products : imx6
    • Published: Mar. 05, 2024
    • Modified: Apr. 10, 2025
  • 9.8

    CRITICAL
    CVE-2024-24098

    Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection via the News Feed.... Read more

    • Published: Mar. 05, 2024
    • Modified: Jan. 21, 2025
  • 9.8

    CRITICAL
    CVE-2024-27764

    An issue in Jeewms v.3.7 and before allows a remote attacker to escalate privileges via the AuthInterceptor component.... Read more

    Affected Products : jeewms
    • Published: Mar. 05, 2024
    • Modified: Jan. 21, 2025
  • 9.8

    CRITICAL
    CVE-2024-28213

    nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbitrary code via unsafe Java objects deserialization.... Read more

    Affected Products : ngrinder
    • Published: Mar. 07, 2024
    • Modified: May. 07, 2025
  • 9.8

    CRITICAL
    CVE-2024-0917

    remote code execution in paddlepaddle/paddle 2.6.0... Read more

    Affected Products : paddlepaddle paddle
    • Published: Mar. 07, 2024
    • Modified: Jan. 19, 2025
  • 9.8

    CRITICAL
    CVE-2024-2268

    A vulnerability was found in keerti1924 Online-Book-Store-Website 1.0. It has been classified as critical. Affected is an unknown function of the file /product_update.php?update=1. The manipulation of the argument update_image leads to unrestricted upload... Read more

    Affected Products : online_bookstore_website
    • Published: Mar. 07, 2024
    • Modified: Mar. 12, 2025
  • 9.8

    CRITICAL
    CVE-2024-2271

    A vulnerability classified as critical has been found in keerti1924 Online-Book-Store-Website 1.0. This affects an unknown part of the file /shop.php of the component HTTP POST Request Handler. The manipulation of the argument product_name leads to sql in... Read more

    Affected Products : online_bookstore_website
    • Published: Mar. 08, 2024
    • Modified: Mar. 12, 2025
  • 9.8

    CRITICAL
    CVE-2023-49340

    An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to escalate privileges and bypass authentication via incorrect access control in the web management portal.... Read more

    Affected Products :
    • Published: Mar. 09, 2024
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2024-25996

    An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is limited to the service user.... Read more

    • Published: Mar. 12, 2024
    • Modified: Jan. 23, 2025
  • 9.8

    CRITICAL
    CVE-2024-28535

    Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the mitInterface parameter of fromAddressNat function.... Read more

    Affected Products : ac18_firmware
    • Published: Mar. 12, 2024
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-38535

    Use of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2. The vulnerability could compromise the cryptographic keys.  ... Read more

    Affected Products : exceed_turbox
    • Published: Mar. 13, 2024
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2024-2514

    A vulnerability classified as critical was found in MAGESH-K21 Online-College-Event-Hall-Reservation-System 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument email leads to sql injecti... Read more

    • Published: Mar. 15, 2024
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2024-2563

    A vulnerability has been found in PandaXGO PandaX up to 20240310 and classified as critical. This vulnerability affects the function DeleteImage of the file /apps/system/router/upload.go. The manipulation of the argument fileName with the input ../../../.... Read more

    Affected Products : pandax
    • Published: Mar. 17, 2024
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2024-2572

    A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /task-details.php. The manipulation leads to execution after redirect. The attack may be... Read more

    • Published: Mar. 18, 2024
    • Modified: Feb. 20, 2025
  • 9.8

    CRITICAL
    CVE-2024-2575

    A vulnerability, which was classified as critical, has been found in SourceCodester Employee Task Management System 1.0. Affected by this issue is some unknown functionality of the file /task-details.php. The manipulation of the argument task_id leads to ... Read more

    • Published: Mar. 18, 2024
    • Modified: Feb. 20, 2025
  • 9.8

    CRITICAL
    CVE-2024-28537

    Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the page parameter of fromNatStaticSetting function.... Read more

    Affected Products : ac18_firmware ac18
    • Published: Mar. 18, 2024
    • Modified: Mar. 13, 2025
  • 9.8

    CRITICAL
    CVE-2024-2702

    Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import allows importing settings and data, ultimately leading to XSS.This issue affects Olive One Click Demo Import: from n/a through 1.1.1. ... Read more

    Affected Products : olive_one_click_demo_import
    • Published: Mar. 20, 2024
    • Modified: May. 07, 2025
Showing 20 of 293259 Results