Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.5

    MEDIUM
    CVE-2025-48135

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aptivadadev Aptivada for WP allows DOM-Based XSS. This issue affects Aptivada for WP: from n/a through 2.0.0.... Read more

    Affected Products : aptivada_for_wp
    • Published: May. 16, 2025
    • Modified: May. 30, 2025
    • Vuln Type: Cross-Site Scripting
  • 7.2

    HIGH
    CVE-2025-48134

    Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC WP Tabs allows Object Injection. This issue affects WP Tabs: from n/a through 2.2.11.... Read more

    Affected Products : wp_tabs
    • Published: May. 16, 2025
    • Modified: May. 30, 2025
    • Vuln Type: Injection
  • 6.5

    MEDIUM
    CVE-2025-48132

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pencilwp X Addons for Elementor allows Stored XSS. This issue affects X Addons for Elementor: from n/a through 1.0.14.... Read more

    Affected Products : x_addons_for_elementor
    • Published: May. 16, 2025
    • Modified: May. 30, 2025
    • Vuln Type: Cross-Site Scripting
  • 6.1

    MEDIUM
    CVE-2023-30394

    The MoveIt framework 1.1.11 for ROS allows cross-site scripting (XSS) via the API authentication function. NOTE: this issue is disputed by the original reporter because it has "no impact."... Read more

    Affected Products : moveit
    • Published: May. 11, 2023
    • Modified: May. 30, 2025
  • 8.8

    HIGH
    CVE-2024-35388

    TOTOLINK NR1800X v9.1.0u.6681_B20230703 was discovered to contain a stack overflow via the password parameter in the function urldecode... Read more

    Affected Products : nr1800x_firmware nr1800x
    • Published: May. 24, 2024
    • Modified: May. 30, 2025
  • 8.1

    HIGH
    CVE-2024-33377

    LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attackers can cause victim users to perform arbitrary operations via interaction with crafted elements on the web page.... Read more

    Affected Products : bl-w1210m_firmware bl-w1210m
    • Published: Jun. 14, 2024
    • Modified: May. 30, 2025
  • 9.8

    CRITICAL
    CVE-2024-33375

    LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.... Read more

    Affected Products : bl-w1210m_firmware bl-w1210m
    • Published: Jun. 14, 2024
    • Modified: May. 30, 2025
  • 8.8

    HIGH
    CVE-2024-3767

    A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. This vulnerability affects unknown code of the file /admin/edit-post.php. The manipulation of the argument posttitle/category leads to sql injection. The attack can be initiat... Read more

    Affected Products : news_portal news_portal_project
    • Published: Apr. 15, 2024
    • Modified: May. 30, 2025
  • 9.8

    CRITICAL
    CVE-2025-4226

    A vulnerability classified as critical has been found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. This affects an unknown part of the file /add-computer.php. The manipulation of the argument compname/comploc leads to sql injection. It is pos... Read more

    Affected Products : cyber_cafe_management_system
    • Published: May. 03, 2025
    • Modified: May. 30, 2025
    • Vuln Type: Injection
  • 8.8

    HIGH
    CVE-2025-4695

    A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /add-users.php. The manipulation of the argument uadd leads to sql injection. It is possibl... Read more

    Affected Products : cyber_cafe_management_system
    • Published: May. 15, 2025
    • Modified: May. 30, 2025
    • Vuln Type: Injection
  • 8.1

    HIGH
    CVE-2024-42514

    A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack due to inadequate access control checks. A successful exploit requires user i... Read more

    Affected Products : micontact_center_business
    • Published: Oct. 01, 2024
    • Modified: May. 30, 2025
  • 9.8

    CRITICAL
    CVE-2025-44881

    A command injection vulnerability in the component /cgi-bin/qos.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.... Read more

    Affected Products : wl-wn579a3_firmware wl-wn579a3
    • Published: May. 20, 2025
    • Modified: May. 30, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-44880

    A command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.... Read more

    Affected Products : wl-wn579a3_firmware wl-wn579a3
    • Published: May. 20, 2025
    • Modified: May. 30, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-44882

    A command injection vulnerability in the component /cgi-bin/firewall.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.... Read more

    Affected Products : wl-wn579a3_firmware wl-wn579a3
    • Published: May. 20, 2025
    • Modified: May. 30, 2025
    • Vuln Type: Injection
  • 8.8

    HIGH
    CVE-2025-33136

    IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to improper protection of assumed immutable data.... Read more

    Affected Products : linux_kernel aspera_faspex
    • Published: May. 22, 2025
    • Modified: May. 30, 2025
    • Vuln Type: Authorization
  • 8.8

    HIGH
    CVE-2025-33137

    IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to client-side enforcement of server-side security.... Read more

    Affected Products : linux_kernel aspera_faspex
    • Published: May. 22, 2025
    • Modified: May. 30, 2025
    • Vuln Type: Authentication
  • 6.1

    MEDIUM
    CVE-2025-33138

    IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.... Read more

    Affected Products : linux_kernel aspera_faspex
    • Published: May. 22, 2025
    • Modified: May. 30, 2025
    • Vuln Type: Cross-Site Scripting
  • 8.8

    HIGH
    CVE-2024-52874

    In Infoblox NETMRI before 7.6.1, authenticated users can perform SQL injection attacks.... Read more

    Affected Products : netmri
    • Published: May. 22, 2025
    • Modified: May. 30, 2025
    • Vuln Type: Injection
  • 6.0

    MEDIUM
    CVE-2025-48066

    wire-webapp is the web application for the open-source messaging service Wire. A bug fix caused a regression causing an issue with function to delete local data. Instructing the client to delete its local database on user logout does not result in deletio... Read more

    Affected Products : wire-webapp
    • Published: May. 22, 2025
    • Modified: May. 30, 2025
    • Vuln Type: Misconfiguration
  • 7.7

    HIGH
    CVE-2025-48075

    Fiber is an Express-inspired web framework written in Go. Starting in version 2.52.6 and prior to version 2.52.7, `fiber.Ctx.BodyParser` can map flat data to nested slices using `key[idx]value` syntax, but when idx is negative, it causes a panic instead o... Read more

    Affected Products : fiber
    • Published: May. 22, 2025
    • Modified: May. 30, 2025
    • Vuln Type: Denial of Service
Showing 20 of 292795 Results