Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2023-50693

    An issue in Jester v.0.6.0 and before allows a remote attacker to send a malicious crafted request.... Read more

    Affected Products : jester
    • EPSS Score: %1.17
    • Published: Jan. 19, 2024
    • Modified: May. 30, 2025
  • 7.8

    HIGH
    CVE-2023-50274

    HPE OneView may allow command injection with local privilege escalation.... Read more

    Affected Products : oneview
    • EPSS Score: %0.28
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 8.8

    HIGH
    CVE-2023-47352

    Technicolor TC8715D devices have predictable default WPA2 security passwords. An attacker who scans for SSID and BSSID values may be able to predict these passwords.... Read more

    Affected Products : tc8715d_firmware tc8715d
    • EPSS Score: %0.05
    • Published: Jan. 22, 2024
    • Modified: May. 30, 2025
  • 7.8

    HIGH
    CVE-2023-47200

    A plug-in manager origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged... Read more

    Affected Products : apex_one
    • EPSS Score: %0.03
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 7.8

    HIGH
    CVE-2023-47199

    An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the ta... Read more

    Affected Products : apex_one
    • EPSS Score: %0.03
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 7.8

    HIGH
    CVE-2023-47194

    An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the ta... Read more

    Affected Products : apex_one
    • EPSS Score: %0.03
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 7.5

    HIGH
    CVE-2023-47035

    RPTC 0x3b08c was discovered to not conduct status checks on the parameter tradingOpen. This vulnerability can allow attackers to conduct unauthorized transfer operations.... Read more

    Affected Products : reptilian_coin
    • EPSS Score: %0.07
    • Published: Jan. 19, 2024
    • Modified: May. 30, 2025
  • 7.5

    HIGH
    CVE-2023-47033

    MultiSigWallet 0xF0C99 was discovered to contain a reentrancy vulnerability via the function executeTransaction.... Read more

    Affected Products : multisigwallet
    • EPSS Score: %0.15
    • Published: Jan. 19, 2024
    • Modified: May. 30, 2025
  • 6.1

    MEDIUM
    CVE-2023-45889

    A Universal Cross Site Scripting (UXSS) vulnerability in ClassLink OneClick Extension through 10.8 allows remote attackers to inject JavaScript into any webpage. NOTE: this issue exists because of an incomplete fix for CVE-2022-48612.... Read more

    Affected Products : oneclick
    • EPSS Score: %0.15
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 5.4

    MEDIUM
    CVE-2023-44001

    An issue in Ailand clinic mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more

    Affected Products : line
    • EPSS Score: %0.08
    • Published: Jan. 24, 2024
    • Modified: May. 30, 2025
  • 5.4

    MEDIUM
    CVE-2023-43991

    An issue in PRIMA CLINIC mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more

    Affected Products : line
    • EPSS Score: %0.08
    • Published: Jan. 24, 2024
    • Modified: May. 30, 2025
  • 5.4

    MEDIUM
    CVE-2023-43990

    An issue in cherub-hair mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more

    Affected Products : line
    • EPSS Score: %0.08
    • Published: Jan. 24, 2024
    • Modified: May. 30, 2025
  • 5.4

    MEDIUM
    CVE-2023-42143

    Missing Integrity Check in Shelly TRV 20220811-152343/v2.1.8@5afc928c allows malicious users to create a backdoor by redirecting the device to an attacker-controlled machine which serves the manipulated firmware file. The device is updated with the manipu... Read more

    Affected Products : trv_firmware trv
    • EPSS Score: %0.14
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 6.1

    MEDIUM
    CVE-2023-41178

    Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided by an attacker. Please note, this vulnerability is similar to,... Read more

    Affected Products : mobile_security
    • EPSS Score: %0.41
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 6.1

    MEDIUM
    CVE-2023-41177

    Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided by an attacker. Please note, this vulnerability is similar to,... Read more

    Affected Products : mobile_security
    • EPSS Score: %0.29
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 9.8

    CRITICAL
    CVE-2023-35835

    An issue was discovered in SolaX Pocket WiFi 3 through 3.001.02. The device provides a WiFi access point for initial configuration. The WiFi network provided has no network authentication (such as an encryption key) and persists permanently, including aft... Read more

    • EPSS Score: %0.20
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 9.8

    CRITICAL
    CVE-2023-33759

    SpliceCom Maximiser Soft PBX v1.5 and before does not restrict excessive authentication attempts, allowing attackers to bypass authentication via a brute force attack.... Read more

    Affected Products : maximiser_soft_pbx
    • EPSS Score: %0.04
    • Published: Jan. 25, 2024
    • Modified: May. 30, 2025
  • 9.8

    CRITICAL
    CVE-2023-31654

    Redis raft master-1b8bd86 to master-7b46079 was discovered to contain an ODR violation via the component hiredisAllocFns at /opt/fs/redisraft/deps/hiredis/alloc.c.... Read more

    Affected Products : redisraft
    • EPSS Score: %0.24
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 9.1

    CRITICAL
    CVE-2021-42147

    Buffer over-read vulnerability in the dtls_sha256_update function in Contiki-NG tinyDTLS through master branch 53a0d97 allows remote attackers to cause a denial of service via crafted data packet.... Read more

    Affected Products : tinydtls
    • EPSS Score: %0.35
    • Published: Jan. 24, 2024
    • Modified: May. 30, 2025
  • 4.4

    MEDIUM
    CVE-2020-36772

    CloudLinux CageFS 7.0.8-2 or below insufficiently restricts file paths supplied to the sendmail proxy command. This allows local users to read and write arbitrary files of certain file formats outside the CageFS environment.... Read more

    Affected Products : cagefs
    • EPSS Score: %0.02
    • Published: Jan. 22, 2024
    • Modified: May. 30, 2025
Showing 20 of 291779 Results