Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.8

    HIGH
    CVE-2025-4891

    A vulnerability was found in code-projects Police Station Management System 1.0. It has been classified as critical. Affected is the function criminal::display of the file source.cpp of the component Display Record. The manipulation of the argument N lead... Read more

    • Published: May. 18, 2025
    • Modified: May. 27, 2025
    • Vuln Type: Memory Corruption
  • 6.5

    MEDIUM
    CVE-2025-5107

    A vulnerability was found in Fujian Kelixun 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /app/xml_cdr/xml_cdr_details.php. The manipulation of the argument uuid leads to sql injection. The attack can be initia... Read more

    Affected Products :
    • Published: May. 23, 2025
    • Modified: May. 27, 2025
    • Vuln Type: Injection
  • 6.5

    MEDIUM
    CVE-2023-5907

    The File Manager WordPress plugin before 6.3 does not restrict the file managers root directory, allowing an administrator to set a root outside of the WordPress root directory, giving access to system files and directories even in a multisite setup, wher... Read more

    Affected Products : file_manager
    • Published: Dec. 11, 2023
    • Modified: May. 27, 2025
  • 9.8

    CRITICAL
    CVE-2023-49417

    TOTOLink A7000R V9.1.0u.6115_B20201022 has a stack overflow vulnerability via setOpModeCfg.... Read more

    Affected Products : a7000r_firmware a7000r
    • Published: Dec. 11, 2023
    • Modified: May. 27, 2025
  • 9.8

    CRITICAL
    CVE-2023-48425

    U-Boot vulnerability resulting in persistent Code Execution ... Read more

    Affected Products : android chromecast_firmware chromecast
    • Published: Dec. 11, 2023
    • Modified: May. 27, 2025
  • 7.8

    HIGH
    CVE-2023-42908

    Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.... Read more

    Affected Products : macos
    • Published: Dec. 12, 2023
    • Modified: May. 27, 2025
  • 5.5

    MEDIUM
    CVE-2023-42884

    This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, macOS Ventura 13.6.3, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. An app may be able to disclose kernel memory.... Read more

    Affected Products : macos iphone_os tvos ipados
    • Published: Dec. 12, 2023
    • Modified: May. 27, 2025
  • 9.8

    CRITICAL
    CVE-2023-41117

    An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contain packages, standalone packages, and functions that run SECURITY DEFI... Read more

    Affected Products : postgres_advanced_server
    • Published: Dec. 12, 2023
    • Modified: May. 27, 2025
  • 4.3

    MEDIUM
    CVE-2023-36652

    A SQL Injection in the users searching REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to read database data via SQL commands injected in the search parameter.... Read more

    Affected Products : cryptospike
    • Published: Dec. 12, 2023
    • Modified: May. 27, 2025
  • 7.5

    HIGH
    CVE-2023-28465

    The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to certain directories via directory traversal, if an allowed directory name is a substring of the directory name chosen ... Read more

    Affected Products : hl7_fhir_core
    • Published: Dec. 12, 2023
    • Modified: May. 27, 2025
  • 6.5

    MEDIUM
    CVE-2022-41320

    Veritas System Recovery (VSR) versions 18 and 21 store a network destination password in the Windows registry during configuration of the backup configuration. This vulnerability could provide a Windows user (who has sufficient privileges) to access a net... Read more

    Affected Products : system_recovery
    • Published: Sep. 23, 2022
    • Modified: May. 27, 2025
  • 6.1

    MEDIUM
    CVE-2022-41319

    A Reflected Cross-Site Scripting (XSS) vulnerability affects the Veritas Desktop Laptop Option (DLO) application login page (aka the DLOServer/restore/login.jsp URI). This affects versions before 9.8 (e.g., 9.1 through 9.7).... Read more

    Affected Products : desktop_and_laptop_option
    • Published: Sep. 23, 2022
    • Modified: May. 27, 2025
  • 9.8

    CRITICAL
    CVE-2022-40869

    Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function fromDhcpListClient with a combined parameter "list*" ("%s%d","list").... Read more

    Affected Products : ac18_firmware ac15_firmware ac18 ac15
    • Published: Sep. 23, 2022
    • Modified: May. 27, 2025
  • 9.8

    CRITICAL
    CVE-2022-40865

    Tenda AC15 and AC18 routers V15.03.05.19 contain heap overflow vulnerabilities in the function setSchedWifi with the request /goform/openSchedWifi/... Read more

    Affected Products : ac18_firmware ac15_firmware ac18 ac15
    • Published: Sep. 23, 2022
    • Modified: May. 27, 2025
  • 6.5

    MEDIUM
    CVE-2022-40716

    HashiCorp Consul and Consul Enterprise up to 1.11.8, 1.12.4, and 1.13.1 do not check for multiple SAN URI values in a CSR on the internal RPC endpoint, enabling leverage of privileged access to bypass service mesh intentions. Fixed in 1.11.9, 1.12.5, and ... Read more

    Affected Products : consul
    • Published: Sep. 23, 2022
    • Modified: May. 27, 2025
  • 7.5

    HIGH
    CVE-2022-40188

    Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity. During an attack, an authoritative server must return large NS sets or address sets.... Read more

    Affected Products : fedora debian_linux knot_resolver
    • Published: Sep. 23, 2022
    • Modified: May. 27, 2025
  • 9.8

    CRITICAL
    CVE-2022-40089

    A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploitable when the directive allow_url_include is set to On.... Read more

    Affected Products : simple_college_website
    • Published: Sep. 22, 2022
    • Modified: May. 27, 2025
  • 6.1

    MEDIUM
    CVE-2022-40088

    Simple College Website v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /college_website/index.php?page=. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted paylo... Read more

    Affected Products : simple_college_website
    • Published: Sep. 22, 2022
    • Modified: May. 27, 2025
  • 9.8

    CRITICAL
    CVE-2022-40087

    Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_contents(). This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.... Read more

    Affected Products : simple_college_website
    • Published: Sep. 22, 2022
    • Modified: May. 27, 2025
  • 7.5

    HIGH
    CVE-2022-38936

    An issue has been found in PBC through 2022-8-27. A SEGV issue detected in the function pbc_wmessage_integer in src/wmessage.c:137.... Read more

    Affected Products : pbc
    • Published: Sep. 23, 2022
    • Modified: May. 27, 2025
Showing 20 of 293288 Results