Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2022-22994

    A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an attacker could trick a NAS device into loading through an unsecured HTTP call. This was a result insufficient verification of calls to the device. The vulner... Read more

    • Published: Jan. 28, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2024-24681

    An issue was discovered in Yealink Configuration Encrypt Tool (AES version) and Yealink Configuration Encrypt Tool (RSA version before 1.2). There is a single hardcoded key (used to encrypt provisioning documents) across customers' installations.... Read more

    Affected Products : configuration_encryption_tool
    • Published: Feb. 23, 2024
    • Modified: Mar. 25, 2025
  • 9.8

    CRITICAL
    CVE-2022-46590

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.netstat_rsname parameter in the tools_netstat (sub_41E730) function.... Read more

    Affected Products : tew-755ap_firmware tew-755ap
    • Published: Dec. 30, 2022
    • Modified: Apr. 11, 2025
  • 9.8

    CRITICAL
    CVE-2017-11161

    Multiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to label.php; or (2) type parameter to synotheme.php.... Read more

    Affected Products : photo_station
    • Published: Sep. 08, 2017
    • Modified: Apr. 20, 2025
  • 9.8

    CRITICAL
    CVE-2024-45623

    D-Link DAP-2310 Hardware A Firmware 1.16RC028 allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the ATP binary that handles PHP HTTP GET requests for the Apache HTTP Server (httpd). NOTE: This vulnerability only affect... Read more

    Affected Products :
    • Published: Sep. 02, 2024
    • Modified: Sep. 03, 2024
  • 9.8

    CRITICAL
    CVE-2022-46640

    Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request.... Read more

    Affected Products : nanoleaf_desktop
    • Published: Apr. 18, 2023
    • Modified: Feb. 06, 2025
  • 9.8

    CRITICAL
    CVE-2024-45695

    The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device.... Read more

    Affected Products : dir-x4860_firmware dir-x4860
    • Published: Sep. 16, 2024
    • Modified: Sep. 17, 2024
  • 9.8

    CRITICAL
    CVE-2023-41355

    Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted package to modify the network routing table, resul... Read more

    Affected Products : g-040w-q_firmware g-040w-q
    • Published: Nov. 03, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-43534

    Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point.... Read more

    • Published: Feb. 06, 2024
    • Modified: Aug. 11, 2025
  • 9.8

    CRITICAL
    CVE-2022-2774

    A vulnerability was found in SourceCodester Library Management System. It has been declared as critical. This vulnerability affects unknown code of the file librarian/student.php. The manipulation of the argument title leads to sql injection. The attack c... Read more

    Affected Products : library_management_system
    • Published: Aug. 11, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2024-45999

    A SQL Injection vulnerability was discovered in Cloudlog 2.6.15, specifically within the get_station_info()function located in the file /application/models/Oqrs_model.php. The vulnerability is exploitable via the station_id parameter.... Read more

    Affected Products : cloudlog
    • Published: Oct. 01, 2024
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2024-46377

    Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function of the file rental/admin_class.php.... Read more

    • Published: Sep. 18, 2024
    • Modified: Apr. 16, 2025
  • 9.8

    CRITICAL
    CVE-2024-46419

    TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWizardCfg function via the ssid5g parameter.... Read more

    Affected Products : t8_firmware t8
    • Published: Sep. 16, 2024
    • Modified: Sep. 17, 2024
  • 9.8

    CRITICAL
    CVE-2023-41561

    Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter startIp and endIp at url /goform/SetPptpServerCfg.... Read more

    Affected Products : ac9_firmware ac5_firmware ac9 ac5
    • Published: Aug. 30, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-47003

    A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request.... Read more

    Affected Products : mura_cms
    • Published: Feb. 01, 2023
    • Modified: Mar. 27, 2025
  • 9.8

    CRITICAL
    CVE-2023-4183

    A vulnerability has been found in SourceCodester Inventory Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file edit_update.php of the component Password Handler. The manipulation of the argument user_id... Read more

    • Published: Aug. 06, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-47034

    A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication.... Read more

    Affected Products : playsms
    • Published: Feb. 13, 2023
    • Modified: Mar. 21, 2025
  • 9.8

    CRITICAL
    CVE-2024-42565

    ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/contact/delete?action=delete.... Read more

    Affected Products : erp erp
    • Published: Aug. 20, 2024
    • Modified: Jun. 17, 2025
  • 9.8

    CRITICAL
    CVE-2022-47071

    In NVS365 V01, the background network test function can trigger command execution.... Read more

    Affected Products : nvs-365-v01_firmware nvs-365-v01
    • Published: Feb. 06, 2023
    • Modified: Mar. 26, 2025
  • 9.8

    CRITICAL
    CVE-2024-42638

    H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.... Read more

    Affected Products : magic_b1st_firmware magic_b1st
    • Published: Aug. 16, 2024
    • Modified: Mar. 17, 2025
Showing 20 of 294505 Results