Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.5

    MEDIUM
    CVE-2024-41130

    llama.cpp provides LLM inference in C/C++. Prior to b3427, llama.cpp contains a null pointer dereference in gguf_init_from_file. This vulnerability is fixed in b3427.... Read more

    Affected Products : llama.cpp llama.cpp
    • Published: Jul. 22, 2024
    • Modified: Aug. 27, 2025
  • 5.9

    MEDIUM
    CVE-2024-6388

    Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.... Read more

    Affected Products : ubuntu_advantage_desktop_daemon
    • Published: Jun. 27, 2024
    • Modified: Aug. 27, 2025
  • 5.5

    MEDIUM
    CVE-2015-7313

    LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (memory consumption and crash) via a crafted tiff file.... Read more

    Affected Products : libtiff
    • EPSS Score: %0.25
    • Published: Mar. 17, 2017
    • Modified: Aug. 27, 2025
  • 6.4

    MEDIUM
    CVE-2024-2165

    The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image alt parameter in all versions up to, and including, 7.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for a... Read more

    Affected Products : seopress
    • Published: Apr. 09, 2024
    • Modified: Aug. 27, 2025
  • 8.8

    HIGH
    CVE-2024-2125

    The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3. This is due to missing or incorrect nonce validation on the gallery_add function. This makes it po... Read more

    Affected Products : envialosimple
    • Published: Apr. 09, 2024
    • Modified: Aug. 27, 2025
  • 8.8

    HIGH
    CVE-2024-29169

    Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal audit REST API. A remote authenticated attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on t... Read more

    Affected Products : secure_connect_gateway
    • Published: Jun. 13, 2024
    • Modified: Aug. 27, 2025
  • 7.5

    HIGH
    CVE-2024-29152

    An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 2400, Exynos Modem 5123, and Exynos Modem 5300. The baseband so... Read more

    • Published: Jun. 04, 2024
    • Modified: Aug. 27, 2025
  • 8.4

    HIGH
    CVE-2024-27372

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_config_get_nl_params(), there is no input validation check on disc_attr->infrastructure_ssid_len coming from us... Read more

    • Published: Jun. 05, 2024
    • Modified: Aug. 27, 2025
  • 9.9

    CRITICAL
    CVE-2024-24830

    OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability has been identified in the "/api/{org_id}/users" endpoint. This vulnerability allows any authenticated reg... Read more

    Affected Products : openobserve
    • EPSS Score: %0.09
    • Published: Feb. 08, 2024
    • Modified: Aug. 27, 2025
  • 7.5

    HIGH
    CVE-2024-24731

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the htt... Read more

    Affected Products : gecko_os
    • Published: Jan. 31, 2025
    • Modified: Aug. 27, 2025
    • Vuln Type: Memory Corruption
  • 5.9

    MEDIUM
    CVE-2023-48368

    Improper input validation in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of service via local access.... Read more

    • Published: May. 16, 2024
    • Modified: Aug. 27, 2025
  • 5.5

    MEDIUM
    CVE-2023-47169

    Improper buffer restrictions in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of service via local access.... Read more

    • Published: May. 16, 2024
    • Modified: Aug. 27, 2025
  • 7.5

    HIGH
    CVE-2025-54939

    LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.... Read more

    • Published: Aug. 01, 2025
    • Modified: Aug. 27, 2025
    • Vuln Type: Memory Corruption
  • 2.1

    LOW
    CVE-2013-4229

    Cross-site scripting (XSS) vulnerability in the Monster Menus module 7.x-1.x before 7.x-1.12 for Drupal allows remote authenticated users with permissions to add pages to inject arbitrary web script or HTML via a title in the page settings.... Read more

    Affected Products : drupal monster_menus monster_menus
    • EPSS Score: %0.25
    • Published: Aug. 21, 2013
    • Modified: Aug. 27, 2025
  • 6.0

    MEDIUM
    CVE-2013-4230

    The mm_webform submodule in the Monster Menus module 6.x-6.x before 6.x-6.61 and 7.x-1.x before 7.x-1.13 for Drupal does not properly restrict access to webform submissions, which allows remote authenticated users with the "Who can read data submitted to ... Read more

    Affected Products : drupal monster_menus monster_menus
    • EPSS Score: %0.76
    • Published: Aug. 21, 2013
    • Modified: Aug. 27, 2025
  • 2.6

    LOW
    CVE-2013-4504

    The Monster Menus module 7.x-1.x before 7.x-1.15 allows remote attackers to read arbitrary node comments via a crafted URL.... Read more

    Affected Products : drupal monster_menus monster_menus
    • EPSS Score: %0.28
    • Published: May. 13, 2014
    • Modified: Aug. 27, 2025
  • 5.0

    MEDIUM
    CVE-2015-8095

    The recycle bin feature in the Monster Menus module 7.x-1.21 before 7.x-1.24 for Drupal does not properly remove nodes from view, which allows remote attackers to obtain sensitive information via an unspecified URL pattern.... Read more

    Affected Products : drupal monster_menus monster_menus
    • EPSS Score: %0.25
    • Published: Nov. 09, 2015
    • Modified: Aug. 27, 2025
  • 7.5

    HIGH
    CVE-2025-6188

    On affected platforms running Arista EOS, maliciously formed UDP packets with source port 3503 may be accepted by EOS. UDP Port 3503 is associated with LspPing Echo Reply. This can result in unexpected behaviors, especially for UDP based services that do ... Read more

    Affected Products : eos
    • Published: Aug. 25, 2025
    • Modified: Aug. 27, 2025
    • Vuln Type: Misconfiguration
  • 6.5

    MEDIUM
    CVE-2025-52450

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (abdoc api - create-data-source-from-file-upload modules) allows Absolute Path Traversal.This issue affects Tableau... Read more

    Affected Products :
    • Published: Aug. 22, 2025
    • Modified: Aug. 27, 2025
    • Vuln Type: Path Traversal
  • 7.5

    HIGH
    CVE-2025-3600

    In Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may lead to an unhandled exception resulting in a crash of the hosting process and denial of service.... Read more

    Affected Products : telerik_ui_for_asp.net_ajax
    • Published: May. 14, 2025
    • Modified: Aug. 27, 2025
    • Vuln Type: Denial of Service
Showing 20 of 292316 Results