Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.4

    HIGH
    CVE-2024-28813

    An issue was discovered in Infinera hiT 7300 5.60.50. Undocumented privileged functions in the @CT management application allow an attacker to activate remote SSH access to the appliance via an unexpected network interface.... Read more

    Affected Products : hit_7300_firmware hit_7300
    • Published: Sep. 30, 2024
    • Modified: May. 30, 2025
  • 6.5

    MEDIUM
    CVE-2024-28807

    An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @CT desktop management application allows guest OS administrators to obtain various users' passwords by accessing memory dumps of the des... Read more

    Affected Products : hit_7300_firmware hit_7300
    • Published: Sep. 30, 2024
    • Modified: May. 30, 2025
  • 2.7

    LOW
    CVE-2024-28808

    An issue was discovered in Infinera hiT 7300 5.60.50. Hidden functionality in the web interface allows a remote authenticated attacker to access reserved information by accessing undocumented web applications.... Read more

    Affected Products : hit_7300_firmware hit_7300
    • Published: Sep. 30, 2024
    • Modified: May. 30, 2025
  • 8.8

    HIGH
    CVE-2025-48136

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Estatik Mortgage Calculator Estatik allows PHP Local File Inclusion. This issue affects Mortgage Calculator Estatik: from n/a through ... Read more

    • Published: May. 16, 2025
    • Modified: May. 30, 2025
    • Vuln Type: Path Traversal
  • 8.5

    HIGH
    CVE-2025-48137

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in proxymis Interview allows SQL Injection. This issue affects Interview: from n/a through 1.01.... Read more

    Affected Products : interview
    • Published: May. 16, 2025
    • Modified: May. 30, 2025
    • Vuln Type: Injection
  • 6.5

    MEDIUM
    CVE-2025-48135

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aptivadadev Aptivada for WP allows DOM-Based XSS. This issue affects Aptivada for WP: from n/a through 2.0.0.... Read more

    Affected Products : aptivada_for_wp
    • Published: May. 16, 2025
    • Modified: May. 30, 2025
    • Vuln Type: Cross-Site Scripting
  • 7.2

    HIGH
    CVE-2025-48134

    Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC WP Tabs allows Object Injection. This issue affects WP Tabs: from n/a through 2.2.11.... Read more

    Affected Products : wp_tabs
    • Published: May. 16, 2025
    • Modified: May. 30, 2025
    • Vuln Type: Injection
  • 6.5

    MEDIUM
    CVE-2025-48132

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pencilwp X Addons for Elementor allows Stored XSS. This issue affects X Addons for Elementor: from n/a through 1.0.14.... Read more

    Affected Products : x_addons_for_elementor
    • Published: May. 16, 2025
    • Modified: May. 30, 2025
    • Vuln Type: Cross-Site Scripting
  • 6.1

    MEDIUM
    CVE-2023-30394

    The MoveIt framework 1.1.11 for ROS allows cross-site scripting (XSS) via the API authentication function. NOTE: this issue is disputed by the original reporter because it has "no impact."... Read more

    Affected Products : moveit
    • EPSS Score: %0.26
    • Published: May. 11, 2023
    • Modified: May. 30, 2025
  • 8.8

    HIGH
    CVE-2024-35388

    TOTOLINK NR1800X v9.1.0u.6681_B20230703 was discovered to contain a stack overflow via the password parameter in the function urldecode... Read more

    Affected Products : nr1800x_firmware nr1800x
    • Published: May. 24, 2024
    • Modified: May. 30, 2025
  • 8.1

    HIGH
    CVE-2024-33377

    LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attackers can cause victim users to perform arbitrary operations via interaction with crafted elements on the web page.... Read more

    Affected Products : bl-w1210m_firmware bl-w1210m
    • Published: Jun. 14, 2024
    • Modified: May. 30, 2025
  • 9.8

    CRITICAL
    CVE-2024-33375

    LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.... Read more

    Affected Products : bl-w1210m_firmware bl-w1210m
    • Published: Jun. 14, 2024
    • Modified: May. 30, 2025
  • 8.8

    HIGH
    CVE-2024-3767

    A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. This vulnerability affects unknown code of the file /admin/edit-post.php. The manipulation of the argument posttitle/category leads to sql injection. The attack can be initiat... Read more

    Affected Products : news_portal news_portal_project
    • Published: Apr. 15, 2024
    • Modified: May. 30, 2025
  • 9.8

    CRITICAL
    CVE-2025-4226

    A vulnerability classified as critical has been found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. This affects an unknown part of the file /add-computer.php. The manipulation of the argument compname/comploc leads to sql injection. It is pos... Read more

    Affected Products : cyber_cafe_management_system
    • Published: May. 03, 2025
    • Modified: May. 30, 2025
    • Vuln Type: Injection
  • 8.8

    HIGH
    CVE-2025-4695

    A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /add-users.php. The manipulation of the argument uadd leads to sql injection. It is possibl... Read more

    Affected Products : cyber_cafe_management_system
    • Published: May. 15, 2025
    • Modified: May. 30, 2025
    • Vuln Type: Injection
  • 8.1

    HIGH
    CVE-2024-42514

    A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack due to inadequate access control checks. A successful exploit requires user i... Read more

    Affected Products : micontact_center_business
    • Published: Oct. 01, 2024
    • Modified: May. 30, 2025
  • 9.8

    CRITICAL
    CVE-2025-44881

    A command injection vulnerability in the component /cgi-bin/qos.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.... Read more

    Affected Products : wl-wn579a3_firmware wl-wn579a3
    • Published: May. 20, 2025
    • Modified: May. 30, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-44880

    A command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.... Read more

    Affected Products : wl-wn579a3_firmware wl-wn579a3
    • Published: May. 20, 2025
    • Modified: May. 30, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-44882

    A command injection vulnerability in the component /cgi-bin/firewall.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.... Read more

    Affected Products : wl-wn579a3_firmware wl-wn579a3
    • Published: May. 20, 2025
    • Modified: May. 30, 2025
    • Vuln Type: Injection
  • 8.8

    HIGH
    CVE-2025-33136

    IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to improper protection of assumed immutable data.... Read more

    Affected Products : linux_kernel aspera_faspex
    • Published: May. 22, 2025
    • Modified: May. 30, 2025
    • Vuln Type: Authorization
Showing 20 of 291794 Results