Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2024-56145

    Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled. For these users an unspeci... Read more

    Affected Products : craft_cms
    • Actively Exploited
    • Published: Dec. 18, 2024
    • Modified: Jun. 03, 2025
  • 6.1

    MEDIUM
    CVE-2019-9978

    The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.... Read more

    Affected Products : social_warfare social_warfare_pro
    • Actively Exploited
    • Published: Mar. 24, 2019
    • Modified: Jun. 03, 2025
  • 9.8

    CRITICAL
    CVE-2024-23741

    An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.... Read more

    Affected Products : macos hyper hyper
    • Published: Jan. 28, 2024
    • Modified: Jun. 03, 2025
  • 5.4

    MEDIUM
    CVE-2024-23553

    A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute. ... Read more

    Affected Products : bigfix_platform
    • Published: Feb. 02, 2024
    • Modified: Jun. 03, 2025
  • 6.2

    MEDIUM
    CVE-2024-23550

    HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent. ... Read more

    Affected Products : hcl_launch hcl_devops_deploy
    • Published: Feb. 03, 2024
    • Modified: Jun. 03, 2025
  • 4.8

    MEDIUM
    CVE-2024-22241

    Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges can inject a malicious payload into the login banner and takeover the user account.   ... Read more

    Affected Products : aria_operations_for_networks
    • Published: Feb. 06, 2024
    • Modified: Jun. 03, 2025
  • 6.4

    MEDIUM
    CVE-2024-22238

    Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges may be able to inject malicious code into user profile configurations due to improper input sanitization. ... Read more

    Affected Products : aria_operations_for_networks
    • Published: Feb. 06, 2024
    • Modified: Jun. 03, 2025
  • 5.5

    MEDIUM
    CVE-2024-22236

    In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.10, test execution is vulnerable to local information disclosure via temporary directory created with unsafe permissions through the sh... Read more

    Affected Products : spring_cloud_contract
    • Published: Jan. 31, 2024
    • Modified: Jun. 03, 2025
  • 8.8

    HIGH
    CVE-2024-22022

    Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-privileged role to access the NTLM hash of the service account used by the Veeam Orchestrator Server Service.... Read more

    • Published: Feb. 07, 2024
    • Modified: Jun. 03, 2025
  • 8.8

    HIGH
    CVE-2024-21888

    A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator. ... Read more

    Affected Products : connect_secure policy_secure
    • Published: Jan. 31, 2024
    • Modified: Jun. 03, 2025
  • 8.8

    HIGH
    CVE-2024-21673

    This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.0 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C... Read more

    • Published: Jan. 16, 2024
    • Modified: Jun. 03, 2025
  • 5.4

    MEDIUM
    CVE-2024-20979

    Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 6.4.0.0.0, 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network acce... Read more

    Affected Products : bi_publisher
    • Published: Jan. 16, 2024
    • Modified: Jun. 03, 2025
  • 4.9

    MEDIUM
    CVE-2024-20971

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access... Read more

    Affected Products : mysql oncommand_insight mysql_server
    • Published: Jan. 16, 2024
    • Modified: Jun. 03, 2025
  • 5.5

    MEDIUM
    CVE-2024-20969

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via m... Read more

    Affected Products : mysql oncommand_insight mysql_server
    • Published: Jan. 16, 2024
    • Modified: Jun. 03, 2025
  • 4.4

    MEDIUM
    CVE-2024-20959

    Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Ora... Read more

    Affected Products : zfs_storage_appliance_kit
    • Published: Jan. 16, 2024
    • Modified: Jun. 03, 2025
  • 3.7

    LOW
    CVE-2024-20955

    Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Compiler). Supported versions that are affected are Oracle GraalVM for JDK: 17.0.9, 21.0.1; Oracle GraalVM Enterprise Edition: 20.3.12, 2... Read more

    Affected Products : graalvm graalvm_for_jdk
    • Published: Jan. 16, 2024
    • Modified: Jun. 03, 2025
  • 6.1

    MEDIUM
    CVE-2024-20938

    Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: ECC). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise O... Read more

    Affected Products : istore
    • Published: Jan. 16, 2024
    • Modified: Jun. 03, 2025
  • 6.1

    MEDIUM
    CVE-2024-20936

    Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access vi... Read more

    Affected Products : one-to-one_fulfillment
    • Published: Jan. 16, 2024
    • Modified: Jun. 03, 2025
  • 2.3

    LOW
    CVE-2024-20914

    Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Ora... Read more

    Affected Products : zfs_storage_appliance_kit
    • Published: Jan. 16, 2024
    • Modified: Jun. 03, 2025
  • 2.7

    LOW
    CVE-2024-20912

    Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Easily exploitable vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle ... Read more

    Affected Products : audit_vault_and_database_firewall
    • Published: Jan. 16, 2024
    • Modified: Jun. 03, 2025
Showing 20 of 293330 Results