Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.0

    MEDIUM
    CVE-2024-56662

    In the Linux kernel, the following vulnerability has been resolved: acpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl Fix an issue detected by syzbot with KASAN: BUG: KASAN: vmalloc-out-of-bounds in cmd_to_func drivers/acpi/nfit/ core.c:416 [inli... Read more

    Affected Products : linux_kernel
    • Published: Dec. 27, 2024
    • Modified: May. 21, 2025
  • 7.1

    HIGH
    CVE-2024-50705

    Unauthenticated reflected cross-site scripting (XSS) vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary scripts via the page parameter.... Read more

    Affected Products : tripleplay
    • Published: Mar. 04, 2025
    • Modified: May. 21, 2025
    • Vuln Type: Cross-Site Scripting
  • 5.4

    MEDIUM
    CVE-2025-1955

    A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /Scheduling/scheduling/pages/profile.php. The manipulation of the ar... Read more

    • Published: Mar. 04, 2025
    • Modified: May. 21, 2025
    • Vuln Type: Cross-Site Scripting
  • 5.4

    MEDIUM
    CVE-2024-48246

    Vehicle Management System 1.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the "Name" parameter of /vehicle-management/booking.php.... Read more

    • Published: Mar. 05, 2025
    • Modified: May. 21, 2025
    • Vuln Type: Cross-Site Scripting
  • 6.5

    MEDIUM
    CVE-2024-37605

    A NULL pointer dereference in D-Link DIR-860L REVB_FIRMWARE_2.04.B04_ic5b allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.... Read more

    Affected Products : dir-860l_firmware dir-860l
    • Published: Dec. 17, 2024
    • Modified: May. 21, 2025
  • 6.1

    MEDIUM
    CVE-2024-13868

    The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against hig... Read more

    • Published: Mar. 06, 2025
    • Modified: May. 21, 2025
    • Vuln Type: Cross-Site Scripting
  • 5.3

    MEDIUM
    CVE-2024-36831

    A NULL pointer dereference in the plugins_call_handle_uri_clean function of D-Link DAP-1520 REVA_FIRMWARE_1.10B04_BETA02_HOTFIX allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request without authentication.... Read more

    Affected Products : dap-1520_firmware dap-1520
    • Published: Dec. 17, 2024
    • Modified: May. 21, 2025
  • 7.6

    HIGH
    CVE-2025-0624

    A flaw was found in grub2. During the network boot process, when trying to search for the configuration file, grub copies data from a user controlled environment variable into an internal buffer using the grub_strcpy() function. During this step, it fails... Read more

    • Published: Feb. 19, 2025
    • Modified: May. 21, 2025
    • Vuln Type: Memory Corruption
  • 9.8

    CRITICAL
    CVE-2022-40942

    Tenda TX3 US_TX3V1.0br_V16.03.13.11 is vulnerable to stack overflow via compare_parentcontrol_time.... Read more

    Affected Products : tx3_firmware tx3
    • EPSS Score: %10.84
    • Published: Sep. 28, 2022
    • Modified: May. 21, 2025
  • 9.8

    CRITICAL
    CVE-2022-40929

    XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).... Read more

    Affected Products : xxl-job
    • EPSS Score: %0.19
    • Published: Sep. 28, 2022
    • Modified: May. 21, 2025
  • 8.8

    HIGH
    CVE-2022-40878

    In Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to achieve Remote Code Execution (RCE).... Read more

    Affected Products : exam_reviewer_management_system
    • EPSS Score: %19.56
    • Published: Sep. 27, 2022
    • Modified: May. 21, 2025
  • 9.8

    CRITICAL
    CVE-2022-40877

    Exam Reviewer Management System 1.0 is vulnerable to SQL Injection via the ‘id’ parameter.... Read more

    Affected Products : exam_reviewer_management_system
    • EPSS Score: %0.08
    • Published: Sep. 27, 2022
    • Modified: May. 21, 2025
  • 4.3

    MEDIUM
    CVE-2022-40817

    Zammad 5.2.1 has a fine-grained permission model that allows to configure read-only access to tickets. However, agents were still wrongly able to perform some operations on such tickets, like adding and removing links, tags. and related answers. This issu... Read more

    Affected Products : zammad
    • EPSS Score: %0.14
    • Published: Sep. 27, 2022
    • Modified: May. 21, 2025
  • 6.5

    MEDIUM
    CVE-2022-40816

    Zammad 5.2.1 is vulnerable to Incorrect Access Control. Zammad's asset handling mechanism has logic to ensure that customer users are not able to see personal information of other users. This logic was not effective when used through a web socket connecti... Read more

    Affected Products : zammad
    • EPSS Score: %0.17
    • Published: Sep. 27, 2022
    • Modified: May. 21, 2025
  • 8.8

    HIGH
    CVE-2022-40497

    Wazuh v3.6.1 - v3.13.5, v4.0.0 - v4.2.7, and v4.3.0 - v4.3.7 were discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Response endpoint.... Read more

    Affected Products : wazuh
    • EPSS Score: %2.13
    • Published: Sep. 28, 2022
    • Modified: May. 21, 2025
  • 8.8

    HIGH
    CVE-2022-40486

    TP Link Archer AX10 V1 Firmware Version 1.3.1 Build 20220401 Rel. 57450(5553) was discovered to allow authenticated attackers to execute arbitrary code via a crafted backup file.... Read more

    • EPSS Score: %1.72
    • Published: Sep. 28, 2022
    • Modified: May. 21, 2025
  • 9.8

    CRITICAL
    CVE-2022-40475

    TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection via the component /cgi-bin/downloadFile.cgi.... Read more

    Affected Products : a860r_firmware a860r
    • EPSS Score: %1.40
    • Published: Sep. 29, 2022
    • Modified: May. 21, 2025
  • 7.2

    HIGH
    CVE-2022-40354

    Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_booking.php.... Read more

    • EPSS Score: %0.09
    • Published: Sep. 27, 2022
    • Modified: May. 21, 2025
  • 7.8

    HIGH
    CVE-2022-40126

    A misconfiguration in the Service Mode profile directory of Clash for Windows v0.19.9 allows attackers to escalate privileges and execute arbitrary commands when Service Mode is activated.... Read more

    Affected Products : clash
    • EPSS Score: %0.08
    • Published: Sep. 29, 2022
    • Modified: May. 21, 2025
  • 9.6

    CRITICAL
    CVE-2022-40083

    Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component. This vulnerability can be leveraged by attackers to cause a Server-Side Request Forgery (SSRF).... Read more

    Affected Products : echo
    • EPSS Score: %71.35
    • Published: Sep. 28, 2022
    • Modified: May. 21, 2025
Showing 20 of 292275 Results