Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2022-40890

    A vulnerability in /src/amf/amf-context.c in Open5GS 2.4.10 and earlier leads to AMF denial of service.... Read more

    Affected Products : open5gs
    • Published: Sep. 29, 2022
    • Modified: May. 21, 2025
  • 5.5

    MEDIUM
    CVE-2022-40363

    A buffer overflow in the component nfc_device_load_mifare_ul_data of Flipper Devices Inc., Flipper Zero before v0.65.2 allows attackers to cause a Denial of Service (DoS) via a crafted NFC file.... Read more

    Affected Products : flipper_zero_firmware flipper_zero
    • Published: Sep. 29, 2022
    • Modified: May. 21, 2025
  • 4.3

    MEDIUM
    CVE-2022-32170

    The “Bytebase” application does not restrict low privilege user to access admin “projects“ for which an unauthorized user can view the “projects“ created by “Admin” and the affected endpoint is “/api/project?user=${userId}”.... Read more

    Affected Products : bytebase
    • Published: Sep. 28, 2022
    • Modified: May. 21, 2025
  • 4.3

    MEDIUM
    CVE-2022-32169

    The “Bytebase” application does not restrict low privilege user to access “admin issues“ for which an unauthorized user can view the “OPEN” and “CLOSED” issues by “Admin” and the affected endpoint is “/issue”.... Read more

    Affected Products : bytebase
    • Published: Sep. 28, 2022
    • Modified: May. 21, 2025
  • 9.1

    CRITICAL
    CVE-2022-30935

    An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any user through the use of a bad randomness function. This allows the attacker to get valid sessions for arbitrary users, and optionally ... Read more

    Affected Products : b2evolution
    • Published: Sep. 28, 2022
    • Modified: May. 21, 2025
  • 6.5

    MEDIUM
    CVE-2025-4901

    A vulnerability classified as problematic was found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected by this vulnerability is the function sub_41E304 of the file /H5/state_view.data of the component HTTP Endpoint. The manipulation leads to information d... Read more

    Affected Products : di-7003g_firmware di-7003g
    • Published: May. 19, 2025
    • Modified: May. 21, 2025
    • Vuln Type: Information Disclosure
  • 7.5

    HIGH
    CVE-2025-4756

    A vulnerability was found in D-Link DI-7003GV2 24.04.18D1 R(68125). It has been declared as problematic. This vulnerability affects unknown code of the file /H5/restart.asp. The manipulation leads to denial of service. The attack can be initiated remotely... Read more

    Affected Products : di-7003g_firmware di-7003g
    • Published: May. 16, 2025
    • Modified: May. 21, 2025
    • Vuln Type: Denial of Service
  • 7.5

    HIGH
    CVE-2025-4902

    A vulnerability, which was classified as problematic, has been found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected by this issue is the function sub_48F4F0 of the file /H5/versionupdate.data. The manipulation leads to information disclosure. The atta... Read more

    Affected Products : di-7003g_firmware di-7003g
    • Published: May. 19, 2025
    • Modified: May. 21, 2025
    • Vuln Type: Information Disclosure
  • 6.4

    MEDIUM
    CVE-2025-3878

    The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_verify shortcode in all versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping o... Read more

    Affected Products : sms_alert_order_notifications
    • Published: May. 10, 2025
    • Modified: May. 21, 2025
    • Vuln Type: Cross-Site Scripting
  • 8.8

    HIGH
    CVE-2025-3876

    The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insufficient user OTP validation in the handleWpLoginCreateUserAction() function in all versions up to, and including, 3.8.1. This makes it p... Read more

    Affected Products : sms_alert_order_notifications
    • Published: May. 10, 2025
    • Modified: May. 21, 2025
    • Vuln Type: Authentication
  • 9.8

    CRITICAL
    CVE-2024-48150

    D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function.... Read more

    Affected Products : dir-820l_firmware dir-820l
    • Published: Oct. 14, 2024
    • Modified: May. 21, 2025
  • 9.8

    CRITICAL
    CVE-2025-4911

    A vulnerability, which was classified as critical, was found in PHPGurukul Zoo Management System 2.1. Affected is an unknown function of the file /admin/view-foreigner-ticket.php. The manipulation of the argument viewid leads to sql injection. It is possi... Read more

    Affected Products : zoo_management_system
    • Published: May. 19, 2025
    • Modified: May. 21, 2025
    • Vuln Type: Injection
  • 7.5

    HIGH
    CVE-2024-36832

    A NULL pointer dereference in D-Link DAP-1513 REVA_FIRMWARE_1.01 allows attackers to cause a Denial of Service (DoS) via a crafted web request without authentication. The vulnerability occurs in the /bin/webs binary of the firmware. When /bin/webs receive... Read more

    Affected Products : dap-1513_firmware dap-1513
    • Published: Dec. 17, 2024
    • Modified: May. 21, 2025
  • 9.8

    CRITICAL
    CVE-2024-44411

    D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function.... Read more

    Affected Products : di-8300_firmware di-8300
    • Published: Sep. 09, 2024
    • Modified: May. 21, 2025
  • 9.8

    CRITICAL
    CVE-2024-57045

    A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page.... Read more

    Affected Products : dir-859_a3_firmware dir-859_a3
    • Published: Feb. 18, 2025
    • Modified: May. 21, 2025
    • Vuln Type: Authentication
  • 7.5

    HIGH
    CVE-2024-34950

    D-Link DIR-822+ v1.0.5 was discovered to contain a stack-based buffer overflow vulnerability in the SetNetworkTomographySettings module.... Read more

    • Published: May. 14, 2024
    • Modified: May. 21, 2025
  • 5.4

    MEDIUM
    CVE-2024-33111

    D-Link DIR-845L router <=v1.01KRb03 is vulnerable to Cross Site Scripting (XSS) via /htdocs/webinc/js/bsc_sms_inbox.php.... Read more

    Affected Products : dir-845l_firmware dir-845l
    • Published: May. 06, 2024
    • Modified: May. 21, 2025
  • 7.5

    HIGH
    CVE-2024-33112

    D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func.... Read more

    Affected Products : dir-845l_firmware dir-845l
    • Published: May. 06, 2024
    • Modified: May. 21, 2025
  • 5.3

    MEDIUM
    CVE-2024-33113

    D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.... Read more

    Affected Products : dir-845l_firmware dir-845l
    • Published: May. 06, 2024
    • Modified: May. 21, 2025
  • 9.1

    CRITICAL
    CVE-2024-33110

    D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Permission Bypass via the getcfg.php component.... Read more

    Affected Products : dir-845l_firmware dir-845l
    • Published: May. 06, 2024
    • Modified: May. 21, 2025
Showing 20 of 292811 Results