Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.8

    HIGH
    CVE-2024-23726

    Ubee DDW365 XCNDDW365 devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame. A PSK is generated by us... Read more

    Affected Products : ddw365_firmware ddw365
    • EPSS Score: %0.70
    • Published: Jan. 21, 2024
    • Modified: May. 30, 2025
  • 6.1

    MEDIUM
    CVE-2024-23725

    Ghost before 5.76.0 allows XSS via a post excerpt in excerpt.js. An XSS payload can be rendered in post summaries.... Read more

    Affected Products : ghost
    • EPSS Score: %0.16
    • Published: Jan. 21, 2024
    • Modified: May. 30, 2025
  • 8.8

    HIGH
    CVE-2024-23689

    Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificate passwords via cl... Read more

    Affected Products : java_libraries
    • EPSS Score: %0.96
    • Published: Jan. 19, 2024
    • Modified: May. 30, 2025
  • 5.3

    MEDIUM
    CVE-2024-23685

    Hard-coded credentials in mod-remote-storage versions under 1.7.2 and from 2.0.0 to 2.0.3 allows unauthorized users to gain read access to mod-inventory-storage records including instances, holdings, items, contributor-types, and identifier-types. ... Read more

    Affected Products : mod-remote-storage
    • EPSS Score: %0.39
    • Published: Jan. 19, 2024
    • Modified: May. 30, 2025
  • 9.8

    CRITICAL
    CVE-2024-23679

    Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. An remote and unauthenticated attacker can use prior sessions due to the lack of invalidating session attributes. ... Read more

    Affected Products : xp
    • EPSS Score: %0.90
    • Published: Jan. 19, 2024
    • Modified: May. 30, 2025
  • 4.8

    MEDIUM
    CVE-2024-23387

    FusionPBX prior to 5.1.0 contains a cross-site scripting vulnerability. If this vulnerability is exploited by a remote authenticated attacker with an administrative privilege, an arbitrary script may be executed on the web browser of the user who is loggi... Read more

    Affected Products : fusionpbx
    • EPSS Score: %0.10
    • Published: Jan. 19, 2024
    • Modified: May. 30, 2025
  • 8.8

    HIGH
    CVE-2024-23348

    Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.... Read more

    Affected Products : a-blog_cms
    • EPSS Score: %0.47
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 5.5

    MEDIUM
    CVE-2024-23215

    An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14.3, watchOS 10.3, tvOS 17.3, iOS 17.3 and iPadOS 17.3. An app may be able to access user-sensitive data.... Read more

    Affected Products : macos iphone_os tvos watchos ipados
    • EPSS Score: %0.02
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 8.8

    HIGH
    CVE-2024-23214

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3. Processing maliciously crafted web content may lead to arbitrary code executi... Read more

    Affected Products : macos iphone_os ipados
    • EPSS Score: %0.26
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 7.8

    HIGH
    CVE-2024-23212

    The issue was addressed with improved memory handling. This issue is fixed in watchOS 10.3, tvOS 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, iOS 16.7.5 and iPadOS 16.7.5, macOS Ventura 13.6.4, macOS Monterey 12.7.3. An app may be able to execute ar... Read more

    Affected Products : macos iphone_os tvos watchos ipados
    • EPSS Score: %0.05
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 8.8

    HIGH
    CVE-2024-23209

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.3. Processing web content may lead to arbitrary code execution.... Read more

    Affected Products : macos
    • EPSS Score: %0.41
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 7.5

    HIGH
    CVE-2024-23204

    The issue was addressed with additional permissions checks. This issue is fixed in macOS Sonoma 14.3, watchOS 10.3, iOS 17.3 and iPadOS 17.3. A shortcut may be able to use sensitive data with certain actions without prompting the user.... Read more

    Affected Products : macos iphone_os watchos ipados
    • EPSS Score: %0.16
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 7.5

    HIGH
    CVE-2024-23203

    The issue was addressed with additional permissions checks. This issue is fixed in macOS Sonoma 14.3, iOS 17.3 and iPadOS 17.3. A shortcut may be able to use sensitive data with certain actions without prompting the user.... Read more

    Affected Products : macos iphone_os ipados
    • EPSS Score: %0.15
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 8.1

    HIGH
    CVE-2024-23182

    Relative path traversal vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.... Read more

    Affected Products : a-blog_cms
    • EPSS Score: %2.00
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 7.8

    HIGH
    CVE-2024-22956

    swftools 0.9.2 was discovered to contain a heap-use-after-free vulnerability via the function removeFromTo at swftools/src/swfc.c:838... Read more

    Affected Products : swftools
    • EPSS Score: %0.07
    • Published: Jan. 19, 2024
    • Modified: May. 30, 2025
  • 7.8

    HIGH
    CVE-2024-22915

    A heap-use-after-free was found in SWFTools v0.9.2, in the function swf_DeleteTag at rfxswf.c:1193. It allows an attacker to cause code execution.... Read more

    Affected Products : swftools
    • EPSS Score: %0.08
    • Published: Jan. 19, 2024
    • Modified: May. 30, 2025
  • 7.8

    HIGH
    CVE-2024-22913

    A heap-buffer-overflow was found in SWFTools v0.9.2, in the function swf5lex at lex.swf5.c:1321. It allows an attacker to cause code execution.... Read more

    Affected Products : swftools
    • EPSS Score: %0.07
    • Published: Jan. 19, 2024
    • Modified: May. 30, 2025
  • 9.8

    CRITICAL
    CVE-2024-22663

    TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg... Read more

    Affected Products : a3700r_firmware a3700r
    • EPSS Score: %4.76
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 9.8

    CRITICAL
    CVE-2024-22638

    liveSite v2019.1 was discovered to contain a remote code execution (RCE) vulenrabiity via the component /livesite/edit_designer_region.php or /livesite/add_email_campaign.php.... Read more

    Affected Products : livesite
    • EPSS Score: %4.18
    • Published: Jan. 25, 2024
    • Modified: May. 30, 2025
  • 8.8

    HIGH
    CVE-2024-22636

    PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature. This vulnerability is exploited via injecting a crafted payload into the Content field.... Read more

    Affected Products : pluxml
    • EPSS Score: %4.77
    • Published: Jan. 25, 2024
    • Modified: May. 30, 2025
Showing 20 of 292247 Results