Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.8

    HIGH
    CVE-2025-4372

    Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)... Read more

    Affected Products : chrome edge_chromium
    • Published: May. 06, 2025
    • Modified: May. 28, 2025
    • Vuln Type: Memory Corruption
  • 5.4

    MEDIUM
    CVE-2023-6487

    The LuckyWP Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Header Title' field in all versions up to and including 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for a... Read more

    Affected Products : luckywp_table_of_contents
    • Published: May. 22, 2024
    • Modified: May. 28, 2025
  • 6.1

    MEDIUM
    CVE-2024-2119

    The LuckyWP Table of Contents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the attrs parameter in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for u... Read more

    Affected Products : luckywp_table_of_contents
    • Published: May. 22, 2024
    • Modified: May. 28, 2025
  • 5.5

    MEDIUM
    CVE-2024-2953

    The LuckyWP Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenti... Read more

    Affected Products : luckywp_table_of_contents
    • Published: May. 22, 2024
    • Modified: May. 28, 2025
  • 9.8

    CRITICAL
    CVE-2024-35409

    WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.... Read more

    Affected Products : webid
    • Published: May. 22, 2024
    • Modified: May. 28, 2025
  • 6.4

    MEDIUM
    CVE-2024-1805

    The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button onclick attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated ... Read more

    • Published: May. 02, 2024
    • Modified: May. 28, 2025
  • 6.4

    MEDIUM
    CVE-2024-1840

    The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Author tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated... Read more

    • Published: May. 02, 2024
    • Modified: May. 28, 2025
  • 6.4

    MEDIUM
    CVE-2024-1841

    The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated ... Read more

    • Published: May. 02, 2024
    • Modified: May. 28, 2025
  • 6.4

    MEDIUM
    CVE-2024-1842

    The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Heading tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authentica... Read more

    • Published: May. 02, 2024
    • Modified: May. 28, 2025
  • 7.5

    HIGH
    CVE-2024-22871

    An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a denial of service (DoS) via the clojure.core$partial$fn__5920 function.... Read more

    Affected Products : fedora clojure
    • Published: Feb. 29, 2024
    • Modified: May. 28, 2025
  • 6.1

    MEDIUM
    CVE-2023-50378

    Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8    Impact : As it will be stored XSS, Could be exploited to perform unauthorized actions, varying from data access to session hijacking and delivering malicious pa... Read more

    Affected Products : ambari
    • Published: Mar. 01, 2024
    • Modified: May. 28, 2025
  • 7.5

    HIGH
    CVE-2024-27138

    ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva. Apache Archiva has a setting to disable user registration, however this restriction can be bypassed. As Apache Archiva has been retired, we do not expect to release ... Read more

    Affected Products : archiva
    • Published: Mar. 01, 2024
    • Modified: May. 28, 2025
  • 7.5

    HIGH
    CVE-2024-27139

    ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva: a vulnerability in Apache Archiva allows an unauthenticated attacker to modify account data, potentially leading to account takeover. This issue affects Apache Arch... Read more

    Affected Products : archiva
    • Published: Mar. 01, 2024
    • Modified: May. 28, 2025
  • 5.4

    MEDIUM
    CVE-2024-27140

    ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Archiva. This issue affects Apache Archiva: from 2.0.0. As this project is retired, we do not plan to release a... Read more

    Affected Products : archiva
    • Published: Mar. 01, 2024
    • Modified: May. 28, 2025
  • 7.5

    HIGH
    CVE-2024-24766

    CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, the Casa OS Login page disclosed the username enumeration vulnerability in the login page. An attacker can enumerate the CasaOS ... Read more

    Affected Products : casaos casaos-userservice
    • Published: Mar. 06, 2024
    • Modified: May. 28, 2025
  • 8.8

    HIGH
    CVE-2024-5709

    The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.7 via the 'layout_name' parameter. This makes it possible for authenticated attackers, with Author-level access and above, and ... Read more

    • Published: Aug. 06, 2024
    • Modified: May. 28, 2025
  • 6.1

    MEDIUM
    CVE-2024-7082

    The Easy Table of Contents WordPress plugin before 2.0.68 does not sanitise and escape some parameters, which could allow users with a role as low as Editor to perform Cross-Site Scripting attacks.... Read more

    Affected Products : easy_table_of_contents
    • Published: Aug. 06, 2024
    • Modified: May. 28, 2025
  • 4.8

    MEDIUM
    CVE-2024-7084

    The Ajax Search Lite WordPress plugin before 4.12.1 does not sanitise and escape some parameters, which could allow users with a role as low as Admin+ to perform Cross-Site Scripting attacks.... Read more

    Affected Products : ajax_search ajax_search
    • Published: Aug. 06, 2024
    • Modified: May. 28, 2025
  • 4.8

    MEDIUM
    CVE-2024-3973

    The House Manager WordPress plugin through 1.0.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more

    Affected Products : house_manager
    • Published: Aug. 07, 2024
    • Modified: May. 28, 2025
  • 4.8

    MEDIUM
    CVE-2024-6481

    The Search & Filter Pro WordPress plugin before 2.5.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disal... Read more

    Affected Products : search_\&_filter
    • Published: Aug. 08, 2024
    • Modified: May. 28, 2025
Showing 20 of 291722 Results