Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 4.3

    MEDIUM
    CVE-2024-13208

    The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_... Read more

    Affected Products : wp_google_map
    • Published: Feb. 15, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Cross-Site Scripting
  • 4.3

    MEDIUM
    CVE-2024-13306

    The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_... Read more

    Affected Products : wp_google_map
    • Published: Feb. 15, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Cross-Site Scripting
  • 6.1

    MEDIUM
    CVE-2024-13603

    The Wise Forms WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks via malicious form submissions.... Read more

    Affected Products : wise_forms
    • Published: Feb. 17, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Cross-Site Scripting
  • 4.7

    MEDIUM
    CVE-2024-13608

    The Track Logins WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks... Read more

    Affected Products : track_logins
    • Published: Feb. 17, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Injection
  • 7.1

    HIGH
    CVE-2024-13625

    The Tube Video Ads Lite WordPress plugin through 1.5.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more

    Affected Products : tube_video_ads_lite
    • Published: Feb. 17, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Cross-Site Scripting
  • 4.8

    MEDIUM
    CVE-2024-10939

    The Image Widget WordPress plugin before 4.4.11 does not sanitise and escape some of its Image Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is... Read more

    Affected Products : image_widget
    • Published: Dec. 13, 2024
    • Modified: May. 14, 2025
  • 5.3

    MEDIUM
    CVE-2024-5333

    The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.... Read more

    Affected Products : the_events_calendar
    • Published: Dec. 16, 2024
    • Modified: May. 14, 2025
  • 9.8

    CRITICAL
    CVE-2023-52030

    TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setOpModeCfg function.... Read more

    Affected Products : a3700r_firmware a3700r
    • EPSS Score: %14.82
    • Published: Jan. 11, 2024
    • Modified: May. 14, 2025
  • 8.3

    HIGH
    CVE-2023-50930

    An issue was discovered in savignano S/Notify before 4.0.2 for Jira. While an administrative user is logged on, the configuration settings of S/Notify can be modified via a CSRF attack. The injection could be initiated by the administrator clicking a mali... Read more

    Affected Products : s-notify
    • EPSS Score: %0.05
    • Published: Jan. 09, 2024
    • Modified: May. 14, 2025
  • 6.5

    MEDIUM
    CVE-2023-47996

    An integer overflow vulnerability in Exif.cpp::jpeg_read_exif_dir in FreeImage 3.18.0 allows attackers to obtain information and cause a denial of service.... Read more

    Affected Products : freeimage
    • EPSS Score: %0.10
    • Published: Jan. 09, 2024
    • Modified: May. 14, 2025
  • 5.3

    MEDIUM
    CVE-2022-41587

    Uncaptured exceptions in the home screen module. Successful exploitation of this vulnerability may affect stability.... Read more

    Affected Products : emui
    • EPSS Score: %0.06
    • Published: Oct. 14, 2022
    • Modified: May. 14, 2025
  • 5.4

    MEDIUM
    CVE-2024-10892

    The Cost Calculator Builder WordPress plugin before 3.2.43 does not have CSRF checks in some AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.... Read more

    Affected Products : cost_calculator_builder
    • Published: Dec. 18, 2024
    • Modified: May. 14, 2025
  • 7.8

    HIGH
    CVE-2025-4077

    A vulnerability classified as critical was found in code-projects School Billing System 1.0. This vulnerability affects the function searchrec. The manipulation of the argument Name leads to stack-based buffer overflow. It is possible to launch the attack... Read more

    Affected Products : school_billing_system
    • Published: Apr. 29, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Memory Corruption
  • 8.8

    HIGH
    CVE-2025-4080

    A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/view-request.php. The manipulation of the argument viewid leads to sql in... Read more

    Affected Products : online_nurse_hiring_system
    • Published: Apr. 29, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2019-10173

    It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling X... Read more

    • EPSS Score: %91.87
    • Published: Jul. 23, 2019
    • Modified: May. 14, 2025
  • 7.5

    HIGH
    CVE-2025-30202

    vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.5.2 and prior to 0.8.5 are vulnerable to denial of service and data exposure via ZeroMQ on multi-node vLLM deployment. In a multi-node vLLM depl... Read more

    Affected Products : vllm
    • Published: Apr. 30, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Denial of Service
  • 9.8

    CRITICAL
    CVE-2025-2907

    The Order Delivery Date WordPress plugin before 12.3.1 does not have authorization and CSRF checks when importing settings. Furthermore it also lacks proper checks to only update options relevant to the Order Delivery Date WordPress plugin before 12.3.1. ... Read more

    • Published: Apr. 26, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Authorization
  • 9.8

    CRITICAL
    CVE-2025-3998

    A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file renew.php?id=6. The manipulation of the argument ID leads to sql injection. The attack can be initiated rem... Read more

    Affected Products : membership_management_system
    • Published: Apr. 28, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Injection
  • 7.5

    HIGH
    CVE-2025-4021

    A vulnerability was found in code-projects Patient Record Management System 1.0. It has been classified as critical. This affects an unknown part of the file /edit_spatient.php. The manipulation of the argument ID leads to sql injection. It is possible to... Read more

    • Published: Apr. 28, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Injection
  • 8.8

    HIGH
    CVE-2025-4022

    A vulnerability was found in web-arena-x webarena up to 0.2.0. It has been declared as critical. This vulnerability affects the function HTMLContentEvaluator of the file webarena/evaluation_harness/evaluators.py. The manipulation of the argument target["u... Read more

    Affected Products : webarena
    • Published: Apr. 28, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Injection
Showing 20 of 291712 Results