Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2024-28392

    SQL injection vulnerability in pscartabandonmentpro v.2.0.11 and before allows a remote attacker to escalate privileges via the pscartabandonmentproFrontCAPUnsubscribeJobModuleFrontController::setEmailVisualized() method.... Read more

    Affected Products : abandoned_cart_reminder_pro
    • Published: Mar. 20, 2024
    • Modified: Sep. 18, 2025
  • 9.8

    CRITICAL
    CVE-2024-28395

    SQL injection vulnerability in Best-Kit bestkit_popup v.1.7.2 and before allows a remote attacker to escalate privileges via the bestkit_popup.php component.... Read more

    Affected Products : bestkit_popup
    • Published: Mar. 20, 2024
    • Modified: Sep. 18, 2025
  • 8.8

    HIGH
    CVE-2024-23755

    ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode.... Read more

    Affected Products : macos windows clickup
    • Published: Mar. 23, 2024
    • Modified: Sep. 18, 2025
  • 9.8

    CRITICAL
    CVE-2024-28386

    An issue in Home-Made.io fastmagsync v.1.7.51 and before allows a remote attacker to execute arbitrary code via the getPhpBin() component.... Read more

    Affected Products : fastmag_sync
    • Published: Mar. 25, 2024
    • Modified: Sep. 18, 2025
  • 7.5

    HIGH
    CVE-2024-28387

    An issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt component.... Read more

    Affected Products : axonaut
    • Published: Mar. 25, 2024
    • Modified: Sep. 18, 2025
  • 9.8

    CRITICAL
    CVE-2024-28393

    SQL injection vulnerability in scalapay v.1.2.41 and before allows a remote attacker to escalate privileges via the ScalapayReturnModuleFrontController::postProcess() method.... Read more

    Affected Products : scalapay
    • Published: Mar. 25, 2024
    • Modified: Sep. 18, 2025
  • 7.6

    HIGH
    CVE-2024-28434

    The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0. A crafted svg file can trigger the execution of the javascript code.... Read more

    Affected Products : twenty
    • Published: Mar. 25, 2024
    • Modified: Sep. 18, 2025
  • 5.4

    MEDIUM
    CVE-2024-28435

    The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload.... Read more

    Affected Products : twenty
    • Published: Mar. 25, 2024
    • Modified: Sep. 18, 2025
  • 7.5

    HIGH
    CVE-2025-55242

    Exposure of sensitive information to an unauthorized actor in Xbox allows an unauthorized attacker to disclose information over a network.... Read more

    Affected Products : xbox_gaming_services
    • Published: Sep. 04, 2025
    • Modified: Sep. 18, 2025
  • 10.0

    CRITICAL
    CVE-2024-25139

    In TP-Link Omada er605 1.0.1 through (v2.6) 2.2.3, a cloud-brd binary is susceptible to an integer overflow that leads to a heap-based buffer overflow. After heap shaping, an attacker can achieve code execution in the context of the cloud-brd binary that ... Read more

    Affected Products : omada_er605_firmware omada_er605
    • Published: Mar. 14, 2024
    • Modified: Sep. 18, 2025
  • 9.8

    CRITICAL
    CVE-2024-28388

    SQL injection vulnerability in SunnyToo stproductcomments module for PrestaShop v.1.0.5 and before, allows a remote attacker to escalate privileges and obtain sensitive information via the StProductCommentClass::getListcomments method.... Read more

    Affected Products : product_comments
    • Published: Mar. 14, 2024
    • Modified: Sep. 18, 2025
  • 7.5

    HIGH
    CVE-2022-46070

    GV-ASManager V6.0.1.0 contains a Local File Inclusion vulnerability in GeoWebServer via Path.... Read more

    Affected Products : gv-asmanager
    • Published: Mar. 11, 2024
    • Modified: Sep. 18, 2025
  • 8.8

    HIGH
    CVE-2024-25501

    An issue WinMail v.7.1 and v.5.1 and before allows a remote attacker to execute arbitrary code via a crafted script to the email parameter.... Read more

    Affected Products : winmail winmail
    • Published: Mar. 09, 2024
    • Modified: Sep. 18, 2025
  • 7.5

    HIGH
    CVE-2023-47415

    Cypress Solutions CTM-200 v2.7.1.5600 and below was discovered to contain an OS command injection vulnerability via the cli_text parameter.... Read more

    Affected Products : ctm-200_firmware ctm-200
    • Published: Mar. 07, 2024
    • Modified: Sep. 18, 2025
  • 8.8

    HIGH
    CVE-2024-2216

    A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided ... Read more

    Affected Products : docker docker-build-step
    • Published: Mar. 06, 2024
    • Modified: Sep. 18, 2025
  • 6.1

    MEDIUM
    CVE-2024-2215

    A cross-site request forgery (CSRF) vulnerability in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test parameters... Read more

    Affected Products : docker-build-step
    • Published: Mar. 06, 2024
    • Modified: Sep. 18, 2025
  • 6.3

    MEDIUM
    CVE-2024-28152

    In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy "Forks in the same account" allows changes to Jenkinsfiles from users without write acc... Read more

    Affected Products : bitbucket_branch_source
    • Published: Mar. 06, 2024
    • Modified: Sep. 18, 2025
  • 7.5

    HIGH
    CVE-2024-25398

    In Srelay (the SOCKS proxy and Relay) v.0.4.8p3, a specially crafted network payload can trigger a denial of service condition and disrupt the service.... Read more

    Affected Products : srelay
    • Published: Feb. 27, 2024
    • Modified: Sep. 18, 2025
  • 7.5

    HIGH
    CVE-2024-27356

    An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user information. This affects MT6000 4.5.5, XE3000 4.4.4, X3000 4.4.5, MT3000 4.5.0, MT2500 4.5.0, AXT1800 4.5.0, A... Read more

    • Published: Feb. 27, 2024
    • Modified: Sep. 18, 2025
  • 5.3

    MEDIUM
    CVE-2024-24720

    An issue was discovered in the Forgot password function in Innovaphone PBX before 14r1 devices. It provides information about whether a user exists on a system.... Read more

    Affected Products : innovaphone_pbx
    • Published: Feb. 27, 2024
    • Modified: Sep. 18, 2025
Showing 20 of 294690 Results