Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2023-24108

    MvcTools 6d48cd6830fc1df1d8c9d61caa1805fd6a1b7737 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attackers to access sensitive user information and execute arbitrary code.... Read more

    Affected Products : mvctools
    • Published: Feb. 22, 2023
    • Modified: Mar. 13, 2025
  • 9.8

    CRITICAL
    CVE-2023-0960

    A vulnerability was found in SeaCMS 11.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /data/config.ftp.php of the component Picture Management. The manipulation leads to deserialization. The attack may be... Read more

    Affected Products : seacms
    • Published: Feb. 22, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-0963

    A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file Users.php of the component POST Request Handler. The manipulation leads to improper access controls. ... Read more

    • Published: Feb. 22, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-24812

    Misskey is an open source, decentralized social media platform. In versions prior to 13.3.3 SQL injection is possible due to insufficient parameter validation in the note search API by tag (notes/search-by-tag). This has been fixed in version 13.3.3. User... Read more

    Affected Products : misskey
    • Published: Feb. 22, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-0939

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NTN Information Technologies Online Services Software allows SQL Injection.This issue affects Online Services Software: before 1.17. ... Read more

    Affected Products : online_services
    • Published: Feb. 23, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-0986

    A vulnerability classified as critical has been found in SourceCodester Sales Tracker Management System 1.0. This affects an unknown part of the file admin/?page=user/manage_user of the component Edit User. The manipulation of the argument id leads to sql... Read more

    Affected Products : sales_tracker_management_system
    • Published: Feb. 23, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-24104

    Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets.... Read more

    • Published: Feb. 23, 2023
    • Modified: Mar. 18, 2025
  • 9.8

    CRITICAL
    CVE-2023-24212

    Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the timeType function at /goform/SetSysTimeCfg.... Read more

    Affected Products : ax3_firmware ax3
    • Published: Feb. 23, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-9079

    For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DOM) of the page. In addition, adversaries can inject HTML script tags and HTML tags with JavaScript handler... Read more

    • Published: Sep. 28, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-33224

    File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file.... Read more

    Affected Products : umbraco_forms
    • Published: Feb. 24, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-35370

    An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function.... Read more

    Affected Products : imcat
    • Published: Feb. 24, 2023
    • Modified: Mar. 12, 2025
  • 9.8

    CRITICAL
    CVE-2023-24189

    An XML External Entity (XXE) vulnerability in urule v2.1.7 allows attackers to execute arbitrary code via uploading a crafted XML file to /urule/common/saveFile.... Read more

    Affected Products : urule
    • Published: Feb. 24, 2023
    • Modified: Mar. 12, 2025
  • 9.8

    CRITICAL
    CVE-2022-48259

    There is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation could allow attackers to gain higher privileges.... Read more

    Affected Products : bisheng-wnm_firmware bisheng-wnm
    • Published: Feb. 27, 2023
    • Modified: Mar. 11, 2025
  • 9.8

    CRITICAL
    CVE-2018-17786

    On D-Link DIR-823G devices, ExportSettings.sh, upload_settings.cgi, GetDownLoadSyslog.sh, and upload_firmware.cgi do not require authentication, which allows remote attackers to execute arbitrary code.... Read more

    • Published: Oct. 02, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-22748

    There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploita... Read more

    Affected Products : arubaos sd-wan
    • Published: Mar. 01, 2023
    • Modified: Mar. 07, 2025
  • 9.8

    CRITICAL
    CVE-2023-22750

    There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploita... Read more

    Affected Products : arubaos sd-wan
    • Published: Mar. 01, 2023
    • Modified: Mar. 07, 2025
  • 9.8

    CRITICAL
    CVE-2018-17881

    On D-Link DIR-823G 2018-09-19 devices, the GoAhead configuration allows /HNAP1 SetPasswdSettings commands without authentication to trigger an admin password change.... Read more

    • Published: Oct. 03, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-1114

    Missing Authorization vulnerability in Eskom e-Belediye allows Information Elicitation.This issue affects e-Belediye: from 1.0.0.95 before 1.0.0.100. ... Read more

    Affected Products : e-belediye
    • Published: Mar. 01, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-37937

    Pre-auth memory corruption in HPE Serviceguard... Read more

    Affected Products : serviceguard_for_linux
    • Published: Mar. 01, 2023
    • Modified: Mar. 17, 2025
  • 9.8

    CRITICAL
    CVE-2021-4328

    A vulnerability has been found in 狮子鱼CMS and classified as critical. Affected by this vulnerability is the function goods_detail of the file ApiController.class.php. The manipulation of the argument goods_id leads to sql injection. The attack can be launc... Read more

    Affected Products : lionfish_cms
    • Published: Mar. 02, 2023
    • Modified: Nov. 21, 2024
Showing 20 of 294423 Results