Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.1

    MEDIUM
    CVE-2022-28977

    HtmlUtil.escapeRedirect in Liferay Portal 7.3.1 through 7.4.2, and Liferay DXP 7.0 fix pack 91 through 101, 7.1 fix pack 17 through 25, 7.2 fix pack 5 through 14, and 7.3 before service pack 3 can be circumvented by using multiple forward slashes, which a... Read more

    • Published: Sep. 22, 2022
    • Modified: May. 27, 2025
  • 7.1

    HIGH
    CVE-2021-41803

    HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC. Fixed in 1.11.9, 1.12.5, and 1.13.2."... Read more

    Affected Products : consul
    • Published: Sep. 23, 2022
    • Modified: May. 27, 2025
  • 3.7

    LOW
    CVE-2021-41136

    Puma is a HTTP 1.1 server for Ruby/Rack applications. Prior to versions 5.5.1 and 4.3.9, using `puma` with a proxy which forwards HTTP header values which contain the LF character could allow HTTP request smugggling. A client could smuggle a request throu... Read more

    Affected Products : debian_linux puma
    • Published: Oct. 12, 2021
    • Modified: May. 27, 2025
  • 6.5

    MEDIUM
    CVE-2020-26272

    The Electron framework lets users write cross-platform desktop applications using JavaScript, HTML and CSS. In versions of Electron IPC prior to 9.4.0, 10.2.0, 11.1.0, and 12.0.0-beta.9, messages sent from the main process to a subframe in the renderer pr... Read more

    Affected Products : electron
    • Published: Jan. 28, 2021
    • Modified: May. 27, 2025
  • 4.9

    MEDIUM
    CVE-2024-1310

    The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)... Read more

    Affected Products : woocommerce woocommerce
    • Published: Apr. 15, 2024
    • Modified: May. 27, 2025
  • 6.3

    MEDIUM
    CVE-2024-29461

    An issue in Floodlight SDN OpenFlow Controller v.1.2 allows a remote attacker to cause a denial of service via the datapath id component.... Read more

    • Published: Apr. 12, 2024
    • Modified: May. 27, 2025
  • 7.8

    HIGH
    CVE-2023-40486

    Maxon Cinema 4D SKP File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Maxon Cinema 4D. User interaction is required to exploit th... Read more

    Affected Products : cinema_4d
    • Published: May. 03, 2024
    • Modified: May. 27, 2025
  • 7.8

    HIGH
    CVE-2023-40482

    Maxon Cinema 4D SKP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Maxon Cinema 4D. User interaction is required to exploit this vulne... Read more

    Affected Products : cinema_4d
    • Published: May. 03, 2024
    • Modified: May. 27, 2025
  • 7.8

    HIGH
    CVE-2023-40483

    Maxon Cinema 4D SKP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Maxon Cinema 4D. User interaction is required to exploit this vulne... Read more

    Affected Products : cinema_4d
    • Published: May. 03, 2024
    • Modified: May. 27, 2025
  • 7.8

    HIGH
    CVE-2023-40484

    Maxon Cinema 4D SKP File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Maxon Cinema 4D. User interaction is required to exploit th... Read more

    Affected Products : cinema_4d
    • Published: May. 03, 2024
    • Modified: May. 27, 2025
  • 7.8

    HIGH
    CVE-2023-40485

    Maxon Cinema 4D SKP File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Maxon Cinema 4D. User interaction is required to exploit th... Read more

    Affected Products : cinema_4d
    • Published: May. 03, 2024
    • Modified: May. 27, 2025
  • 7.8

    HIGH
    CVE-2023-40487

    Maxon Cinema 4D SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Maxon Cinema 4D. User interaction is required to exploit this vulnerabil... Read more

    Affected Products : cinema_4d
    • Published: May. 03, 2024
    • Modified: May. 27, 2025
  • 7.8

    HIGH
    CVE-2023-40488

    Maxon Cinema 4D SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Maxon Cinema 4D. User interaction is required to exploit this vulnerabil... Read more

    Affected Products : cinema_4d
    • Published: May. 03, 2024
    • Modified: May. 27, 2025
  • 7.8

    HIGH
    CVE-2023-40489

    Maxon Cinema 4D SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Maxon Cinema 4D. User interaction is required to exploit this vulnerabil... Read more

    Affected Products : cinema_4d
    • Published: May. 03, 2024
    • Modified: May. 27, 2025
  • 8.8

    HIGH
    CVE-2024-31268

    Cross-Site Request Forgery (CSRF) vulnerability in AppPresser Team AppPresser.This issue affects AppPresser: from n/a through 4.3.0. ... Read more

    Affected Products : apppresser
    • Published: Apr. 12, 2024
    • Modified: May. 27, 2025
  • 6.1

    MEDIUM
    CVE-2023-44856

    Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the rstat, sender, and recipients' parameters of the sub_21D24 function in the acu_web file.... Read more

    • Published: Apr. 12, 2024
    • Modified: May. 27, 2025
  • 7.8

    HIGH
    CVE-2025-4891

    A vulnerability was found in code-projects Police Station Management System 1.0. It has been classified as critical. Affected is the function criminal::display of the file source.cpp of the component Display Record. The manipulation of the argument N lead... Read more

    • Published: May. 18, 2025
    • Modified: May. 27, 2025
    • Vuln Type: Memory Corruption
  • 6.5

    MEDIUM
    CVE-2025-5107

    A vulnerability was found in Fujian Kelixun 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /app/xml_cdr/xml_cdr_details.php. The manipulation of the argument uuid leads to sql injection. The attack can be initia... Read more

    Affected Products :
    • Published: May. 23, 2025
    • Modified: May. 27, 2025
    • Vuln Type: Injection
  • 6.5

    MEDIUM
    CVE-2023-5907

    The File Manager WordPress plugin before 6.3 does not restrict the file managers root directory, allowing an administrator to set a root outside of the WordPress root directory, giving access to system files and directories even in a multisite setup, wher... Read more

    Affected Products : file_manager
    • Published: Dec. 11, 2023
    • Modified: May. 27, 2025
  • 9.8

    CRITICAL
    CVE-2023-49417

    TOTOLink A7000R V9.1.0u.6115_B20201022 has a stack overflow vulnerability via setOpModeCfg.... Read more

    Affected Products : a7000r_firmware a7000r
    • Published: Dec. 11, 2023
    • Modified: May. 27, 2025
Showing 20 of 293284 Results