Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.1

    HIGH
    CVE-2024-23182

    Relative path traversal vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.... Read more

    Affected Products : a-blog_cms
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 7.8

    HIGH
    CVE-2024-22956

    swftools 0.9.2 was discovered to contain a heap-use-after-free vulnerability via the function removeFromTo at swftools/src/swfc.c:838... Read more

    Affected Products : swftools
    • Published: Jan. 19, 2024
    • Modified: May. 30, 2025
  • 7.8

    HIGH
    CVE-2024-22915

    A heap-use-after-free was found in SWFTools v0.9.2, in the function swf_DeleteTag at rfxswf.c:1193. It allows an attacker to cause code execution.... Read more

    Affected Products : swftools
    • Published: Jan. 19, 2024
    • Modified: May. 30, 2025
  • 7.8

    HIGH
    CVE-2024-22913

    A heap-buffer-overflow was found in SWFTools v0.9.2, in the function swf5lex at lex.swf5.c:1321. It allows an attacker to cause code execution.... Read more

    Affected Products : swftools
    • Published: Jan. 19, 2024
    • Modified: May. 30, 2025
  • 9.8

    CRITICAL
    CVE-2024-22663

    TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg... Read more

    Affected Products : a3700r_firmware a3700r
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 9.8

    CRITICAL
    CVE-2024-22638

    liveSite v2019.1 was discovered to contain a remote code execution (RCE) vulenrabiity via the component /livesite/edit_designer_region.php or /livesite/add_email_campaign.php.... Read more

    Affected Products : livesite
    • Published: Jan. 25, 2024
    • Modified: May. 30, 2025
  • 8.8

    HIGH
    CVE-2024-22636

    PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature. This vulnerability is exploited via injecting a crafted payload into the Content field.... Read more

    Affected Products : pluxml
    • Published: Jan. 25, 2024
    • Modified: May. 30, 2025
  • 6.1

    MEDIUM
    CVE-2024-22497

    Cross Site Scripting (XSS) vulnerability in /admin/login password parameter in JFinalcms 5.0.0 allows attackers to run arbitrary code via crafted URL.... Read more

    Affected Products : jfinalcms
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 6.5

    MEDIUM
    CVE-2024-0814

    Incorrect security UI in Payments in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)... Read more

    Affected Products : fedora chrome edge_chromium
    • Published: Jan. 24, 2024
    • Modified: May. 30, 2025
  • 8.8

    HIGH
    CVE-2024-0812

    Inappropriate implementation in Accessibility in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)... Read more

    Affected Products : fedora chrome edge_chromium
    • Published: Jan. 24, 2024
    • Modified: May. 30, 2025
  • 9.8

    CRITICAL
    CVE-2024-0808

    Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)... Read more

    Affected Products : fedora debian_linux chrome edge_chromium
    • Published: Jan. 24, 2024
    • Modified: May. 30, 2025
  • 6.1

    MEDIUM
    CVE-2024-0758

    MolecularFaces before 0.3.0 is vulnerable to cross site scripting. A remote attacker can execute arbitrary JavaScript in the context of a victim browser via crafted molfiles. ... Read more

    Affected Products : molecularfaces
    • Published: Jan. 19, 2024
    • Modified: May. 30, 2025
  • 7.5

    HIGH
    CVE-2024-0743

    An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.9, and Thunderbird < 115.9.... Read more

    Affected Products : firefox firefox_esr thunderbird
    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 4.3

    MEDIUM
    CVE-2024-0742

    It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to prevent input after page load. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunde... Read more

    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 6.5

    MEDIUM
    CVE-2024-0741

    An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.... Read more

    • Published: Jan. 23, 2024
    • Modified: May. 30, 2025
  • 6.5

    MEDIUM
    CVE-2024-0679

    The ColorMag theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the plugin_action_callback() function in all versions up to, and including, 3.1.2. This makes it possible for authenticated attackers, with subscrib... Read more

    Affected Products : colormag
    • Published: Jan. 20, 2024
    • Modified: May. 30, 2025
  • 6.1

    MEDIUM
    CVE-2023-7194

    The Meris WordPress theme through 1.1.2 does not sanitise and escape some parameters before outputting them back in the page, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more

    Affected Products : meris_wp_theme
    • Published: Jan. 22, 2024
    • Modified: May. 30, 2025
  • 6.1

    MEDIUM
    CVE-2023-7170

    The EventON-RSVP WordPress plugin before 2.9.5 does not sanitise and escape some parameters before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more

    Affected Products : rsvp_events
    • Published: Jan. 22, 2024
    • Modified: May. 30, 2025
  • 7.2

    HIGH
    CVE-2023-7063

    The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all versions up to, and including, 1.8.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthent... Read more

    Affected Products : wpforms
    • Published: Jan. 20, 2024
    • Modified: May. 30, 2025
  • 4.8

    MEDIUM
    CVE-2023-6626

    The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability... Read more

    • Published: Jan. 22, 2024
    • Modified: May. 30, 2025
Showing 20 of 292796 Results