Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.8

    HIGH
    CVE-2025-9174

    A vulnerability was determined in neurobin shc up to 4.0.3. This vulnerability affects the function make of the file src/shc.c of the component Filename Handler. Executing manipulation can lead to os command injection. The attack can only be executed loca... Read more

    Affected Products : shc
    • Published: Aug. 19, 2025
    • Modified: Sep. 15, 2025
    • Vuln Type: Injection
  • 7.8

    HIGH
    CVE-2025-33120

    IBM QRadar SIEM 7.5 through 7.5.0 UP13 could allow an authenticated user to escalate their privileges via a misconfigured cronjob due to execution with unnecessary privileges.... Read more

    • Published: Aug. 22, 2025
    • Modified: Sep. 15, 2025
    • Vuln Type: Authorization
  • 5.4

    MEDIUM
    CVE-2025-36042

    IBM QRadar SIEM 7.5 through 7.5.0 Dashboard is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials... Read more

    • Published: Aug. 22, 2025
    • Modified: Sep. 15, 2025
    • Vuln Type: Cross-Site Scripting
  • 8.8

    HIGH
    CVE-2025-55573

    QuantumNous new-api v.0.8.5.2 is vulnerable to Cross Site Scripting (XSS).... Read more

    Affected Products : new_api
    • Published: Aug. 22, 2025
    • Modified: Sep. 15, 2025
    • Vuln Type: Cross-Site Scripting
  • 6.1

    MEDIUM
    CVE-2025-55574

    Cross Site Scripting vulnerability in docmost v.0.21.0 and before allows an attacker to execute arbitrary code... Read more

    Affected Products : docmost
    • Published: Aug. 25, 2025
    • Modified: Sep. 15, 2025
    • Vuln Type: Cross-Site Scripting
  • 7.1

    HIGH
    CVE-2025-29901

    A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in... Read more

    Affected Products : file_station
    • Published: Aug. 26, 2025
    • Modified: Sep. 15, 2025
    • Vuln Type: Denial of Service
  • 9.1

    CRITICAL
    CVE-2025-55526

    n8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via the download_workflow function within api_server.py... Read more

    Affected Products : windows_11 fastapi pydantic uvicorn
    • Published: Aug. 26, 2025
    • Modified: Sep. 15, 2025
    • Vuln Type: Path Traversal
  • 5.3

    MEDIUM
    CVE-2024-32213

    The LoMag WareHouse Management application version 1.0.20.120 and older were found to allow weak passwords. By default, hard-coded passwords of 10 characters with little or no complexity are allowed.... Read more

    Affected Products : lomag_warehouse_management
    • Published: May. 01, 2024
    • Modified: Sep. 15, 2025
  • 8.8

    HIGH
    CVE-2025-33073

    Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.... Read more

    • Published: Jun. 10, 2025
    • Modified: Sep. 15, 2025
    • Vuln Type: Authorization
  • 2.1

    LOW
    CVE-2025-27238

    Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to them.... Read more

    Affected Products : zabbix
    • Published: Sep. 12, 2025
    • Modified: Sep. 15, 2025
    • Vuln Type: Authorization
  • 8.8

    HIGH
    • Published: Jun. 11, 2024
    • Modified: Sep. 15, 2025
  • 6.1

    MEDIUM
    CVE-2022-43018

    OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the email parameter in the Check Email function.... Read more

    Affected Products : opencats
    • Published: Oct. 19, 2022
    • Modified: Sep. 15, 2025
  • 6.1

    MEDIUM
    CVE-2022-43017

    OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component.... Read more

    Affected Products : opencats
    • Published: Oct. 19, 2022
    • Modified: Sep. 15, 2025
  • 6.1

    MEDIUM
    CVE-2022-43016

    OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component.... Read more

    Affected Products : opencats
    • Published: Oct. 19, 2022
    • Modified: Sep. 15, 2025
  • 6.1

    MEDIUM
    CVE-2022-43015

    OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage parameter.... Read more

    Affected Products : opencats
    • Published: Oct. 19, 2022
    • Modified: Sep. 15, 2025
  • 6.1

    MEDIUM
    CVE-2022-43014

    OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the joborderID parameter.... Read more

    Affected Products : opencats
    • Published: Oct. 19, 2022
    • Modified: Sep. 15, 2025
  • 9.8

    CRITICAL
    CVE-2024-33078

    Tencent Libpag v4.3 is vulnerable to Buffer Overflow. A user can send a crafted image to trigger a overflow leading to remote code execution.... Read more

    Affected Products : libpag
    • Published: May. 01, 2024
    • Modified: Sep. 15, 2025
  • 8.8

    HIGH
    CVE-2024-33428

    Buffer-Overflow vulnerability at conv.c:68 of stsaz phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via the a crafted .wav file.... Read more

    Affected Products : phiola
    • Published: May. 01, 2024
    • Modified: Sep. 15, 2025
  • 6.5

    MEDIUM
    CVE-2025-53640

    Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Starting in version 2.2 and prior to version 3.3.7, an endpoint used to display details of users listed in certain fields (such as ACLs) could... Read more

    Affected Products : indico
    • Published: Jul. 14, 2025
    • Modified: Sep. 15, 2025
    • Vuln Type: Information Disclosure
  • 8.5

    HIGH
    CVE-2025-7883

    A vulnerability classified as critical has been found in Eluktronics Control Center 5.23.51.41. Affected is an unknown function of the file \AiStoneService\MyControlCenter\Command of the component Powershell Script Handler. The manipulation leads to comma... Read more

    Affected Products : control_center
    • Published: Jul. 20, 2025
    • Modified: Sep. 15, 2025
    • Vuln Type: Injection
Showing 20 of 294276 Results