Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.3

    MEDIUM
    CVE-2024-22049

    httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames... Read more

    Affected Products : httparty
    • Published: Jan. 04, 2024
    • Modified: Jun. 03, 2025
  • 7.5

    HIGH
    CVE-2024-21909

    PeterO.Cbor versions 4.0.0 through 4.5.0 are vulnerable to a denial of service vulnerability. An attacker may trigger the denial of service condition by providing crafted data to the DecodeFromBytes or other decoding mechanisms in PeterO.Cbor. Dependin... Read more

    Affected Products : cbor
    • Published: Jan. 03, 2024
    • Modified: Jun. 03, 2025
  • 8.8

    HIGH
    CVE-2024-21773

    Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands on the product that has pre-specified target devices and blocked URLs in parental control se... Read more

    • Published: Jan. 11, 2024
    • Modified: Jun. 03, 2025
  • 6.1

    MEDIUM
    CVE-2024-21732

    FlyCms through abbaa5a allows XSS via the permission management feature.... Read more

    Affected Products : flycms
    • Published: Jan. 01, 2024
    • Modified: Jun. 03, 2025
  • 5.5

    MEDIUM
    CVE-2024-20805

    Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.... Read more

    Affected Products : android android dex myfiles
    • Published: Jan. 04, 2024
    • Modified: Jun. 03, 2025
  • 5.3

    MEDIUM
    CVE-2024-0333

    Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.216 allowed an attacker in a privileged network position to install a malicious extension via a crafted HTML page. (Chromium security severity: High)... Read more

    Affected Products : fedora chrome edge_chromium
    • Published: Jan. 10, 2024
    • Modified: Jun. 03, 2025
  • 5.3

    MEDIUM
    CVE-2023-6984

    The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.13. This is due to missing or incorrect nonce validation in the powerpac... Read more

    Affected Products : powerpack_addons_for_elementor
    • Published: Jan. 03, 2024
    • Modified: Jun. 03, 2025
  • 6.5

    MEDIUM
    CVE-2023-6830

    The Formidable Forms plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 6.7. This vulnerability allows unauthenticated users to inject arbitrary HTML code into form fields. When the form data is viewed by an administrat... Read more

    Affected Products : formidable_form_builder
    • Published: Jan. 09, 2024
    • Modified: Jun. 03, 2025
  • 8.6

    HIGH
    CVE-2023-6600

    The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cross-Site Scripting due to a missing capability check on the update_settings() function hooked via admin_init i... Read more

    Affected Products : omgf
    • Published: Jan. 03, 2024
    • Modified: Jun. 03, 2025
  • 5.4

    MEDIUM
    CVE-2023-6551

    As a simple library, class.upload.php does not perform an in-depth check on uploaded files, allowing a stored XSS vulnerability when the default configuration is used. Developers must be aware of that fact and use extension whitelisting accompanied by ... Read more

    Affected Products : class.upload.php
    • Published: Jan. 04, 2024
    • Modified: Jun. 03, 2025
  • 8.8

    HIGH
    CVE-2023-6528

    The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution.... Read more

    Affected Products : slider_revolution
    • Published: Jan. 08, 2024
    • Modified: Jun. 03, 2025
  • 4.3

    MEDIUM
    CVE-2023-6506

    The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.5.0 via the send_backup_codes_email due to missing validation on a user controlled key. Thi... Read more

    Affected Products : wp_2fa wp_2fa
    • Published: Jan. 11, 2024
    • Modified: Jun. 03, 2025
  • 4.3

    MEDIUM
    CVE-2023-6223

    The LearnPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.5.7 via the /wp-json/lp/v1/profile/course-tab REST API due to missing validation on the 'userID' user controlled key. This make... Read more

    Affected Products : learnpress
    • Published: Jan. 11, 2024
    • Modified: Jun. 03, 2025
  • 6.5

    MEDIUM
    CVE-2023-6158

    The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the evo_eventpost_update_meta function in all versions up to, and including... Read more

    Affected Products : eventon eventon-lite
    • Published: Jan. 10, 2024
    • Modified: Jun. 03, 2025
  • 6.5

    MEDIUM
    CVE-2023-6139

    The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Denial of Service attacks.... Read more

    Affected Products : essential_real_estate
    • Published: Jan. 08, 2024
    • Modified: Jun. 03, 2025
  • 7.5

    HIGH
    CVE-2023-6042

    Any unauthenticated user may send e-mail from the site with any title or content to the admin... Read more

    Affected Products : getwid_-_gutenberg_blocks getwid
    • Published: Jan. 08, 2024
    • Modified: Jun. 03, 2025
  • 9.8

    CRITICAL
    CVE-2023-5877

    The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliate-toolkit-starter/tools/atkp_imagereceiver.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URL's, includi... Read more

    Affected Products : affiliate-toolkit
    • Published: Jan. 01, 2024
    • Modified: Jun. 03, 2025
  • 5.9

    MEDIUM
    CVE-2023-52323

    PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.... Read more

    Affected Products : pycryptodome pycryptodomex
    • Published: Jan. 05, 2024
    • Modified: Jun. 03, 2025
  • 6.1

    MEDIUM
    CVE-2023-52322

    ecrire/public/assembler.php in SPIP before 4.1.13 and 4.2.x before 4.2.7 allows XSS because input from _request() is not restricted to safe characters such as alphanumerics.... Read more

    Affected Products : spip
    • Published: Jan. 04, 2024
    • Modified: Jun. 03, 2025
  • 6.5

    MEDIUM
    CVE-2023-52271

    The wsftprm.sys kernel driver 2.0.0.0 in Topaz Antifraud allows low-privileged attackers to kill any (Protected Process Light) process via an IOCTL (which will be named at a later time).... Read more

    Affected Products : antifraud
    • Published: Jan. 08, 2024
    • Modified: Jun. 03, 2025
Showing 20 of 292860 Results