Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2022-37199

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list.... Read more

    Affected Products : jfinal_cms
    • Published: Aug. 23, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-37204

    Final CMS 5.1.0 is vulnerable to SQL Injection.... Read more

    Affected Products : jfinal_cms
    • Published: Sep. 20, 2022
    • Modified: May. 27, 2025
  • 9.8

    CRITICAL
    CVE-2022-37223

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list.... Read more

    Affected Products : jfinal_cms
    • Published: Aug. 23, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2020-22253

    Xiongmai Technology Co devices AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, and HI3518E_50H10L_S39 were all discovered to have port 9530 open which allows unauthenticated attackers to make arbitr... Read more

    • Published: Apr. 06, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2020-22819

    MKCMS V6.2 has SQL injection via the /ucenter/active.php verify parameter.... Read more

    Affected Products : mkcms
    • Published: Nov. 03, 2022
    • Modified: May. 05, 2025
  • 9.8

    CRITICAL
    CVE-2020-13167

    Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a command line with client-supplied parameters, and allows injection of shell metacharacters.... Read more

    Affected Products : netsweeper
    • Published: May. 19, 2020
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-6639

    An out-of-bounds write (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. A size used by memmove is read from the input file. This is fixed in 6.9d.... Read more

    Affected Products : mathtype
    • Published: Feb. 28, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-38325

    Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the filePath parameter at /goform/expandDlnaFile.... Read more

    Affected Products : ac18_firmware ac15_firmware ac18 ac15
    • Published: Sep. 15, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-28667

    The Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue. The tve_labels parameter of the tve_api_form_submit action is passed to the PHP unserialize() function without being sanitized or veri... Read more

    Affected Products : lead_generated
    • Published: Mar. 22, 2023
    • Modified: Feb. 25, 2025
  • 9.8

    CRITICAL
    CVE-2022-43762

     Lack of verification in B&R APROL Tbase server versions < R 4.2-07 may lead to memory leaks when receiving messages ... Read more

    Affected Products : industrial_automation_aprol
    • Published: Feb. 08, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2020-23691

    YFCMF v2.3.1 has a Remote Command Execution (RCE) vulnerability in the index.php.... Read more

    Affected Products : yfcmf
    • Published: May. 14, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-44096

    Sanitization Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.... Read more

    Affected Products : sanitization_management_system
    • Published: Nov. 30, 2022
    • Modified: Apr. 25, 2025
  • 9.8

    CRITICAL
    CVE-2022-44048

    The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-domains package. The affected version of d8s-htm is 0.... Read more

    Affected Products : d8s-urls
    • Published: Nov. 07, 2022
    • Modified: May. 05, 2025
  • 9.8

    CRITICAL
    CVE-2022-44176

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function fromSetRouteStatic.... Read more

    Affected Products : ac18_firmware ac18
    • Published: Nov. 21, 2022
    • Modified: Apr. 29, 2025
  • 9.8

    CRITICAL
    CVE-2020-13417

    An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters.... Read more

    • Published: May. 22, 2020
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2020-24199

    Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct remote code execution.... Read more

    Affected Products : car_rental_project
    • Published: Sep. 09, 2020
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-44938

    Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack.... Read more

    Affected Products : seeddms
    • Published: Dec. 08, 2022
    • Modified: Apr. 23, 2025
  • 9.8

    CRITICAL
    CVE-2020-24231

    Symmetric DS <3.12.0 uses mx4j to provide access to JMX over HTTP. mx4j, by default, has no auth and is available on all interfaces. An attacker can interact with JMX: get system info, and invoke MBean methods. It is possible to install additional MBeans ... Read more

    Affected Products : symmetricds
    • Published: Oct. 05, 2020
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-29778

    GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.... Read more

    Affected Products : gl-mt3000_firmware gl-mt3000
    • Published: May. 02, 2023
    • Modified: Jan. 30, 2025
  • 9.8

    CRITICAL
    CVE-2022-40111

    In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware.... Read more

    Affected Products : a3002r_firmware a3002r
    • Published: Sep. 06, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 293354 Results