Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.1

    MEDIUM
    CVE-2024-12302

    The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its Campaign settings, which could allow authors and above to perform Stored Cross-Site Scripting attacks... Read more

    Affected Products : icegram_engage
    • Published: Jan. 06, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Cross-Site Scripting
  • 6.5

    MEDIUM
    CVE-2024-12311

    The Email Subscribers by Icegram Express WordPress plugin before 5.7.44 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks... Read more

    Affected Products : email_subscribers_\&_newsletters
    • Published: Jan. 06, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Injection
  • 2.7

    LOW
    CVE-2024-10102

    The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks... Read more

    Affected Products : robo_gallery robo_gallery
    • Published: Jan. 07, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Cross-Site Scripting
  • 7.0

    HIGH
    CVE-2025-30378

    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.... Read more

    • Published: May. 13, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Authentication
  • 9.8

    CRITICAL
    CVE-2024-8855

    The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing editors and above to perform SQL injection attacks... Read more

    Affected Products : wordpress_auction
    • Published: Jan. 07, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Injection
  • 4.8

    MEDIUM
    CVE-2024-8857

    The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Stored Cross-Site Scripting attacks.... Read more

    Affected Products : wordpress_auction
    • Published: Jan. 07, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Cross-Site Scripting
  • 9.8

    CRITICAL
    CVE-2025-3819

    A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/search-appointment.php. The manipulation of the argument searchdata lead... Read more

    Affected Products : men_salon_management_system
    • Published: Apr. 19, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Injection
  • 5.9

    MEDIUM
    CVE-2025-39444

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maxfoundry MaxButtons allows Stored XSS.This issue affects MaxButtons: from n/a through 9.8.3.... Read more

    Affected Products : maxbuttons
    • Published: Apr. 17, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Cross-Site Scripting
  • 9.8

    CRITICAL
    CVE-2023-43958

    An arbitrary file upload vulnerability in the component /jquery-file-upload/server/php/index.php of Hospital Management System v4.0 allows an unauthenticated attacker to upload any file to the server and execute arbitrary code.... Read more

    Affected Products : hospital_management_system
    • Published: Apr. 22, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Authentication
  • 4.9

    MEDIUM
    CVE-2025-47729

    The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to... Read more

    Affected Products : text_message_archiver
    • Actively Exploited
    • Published: May. 08, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Cryptography
  • 4.8

    MEDIUM
    CVE-2025-29568

    A vulnerability has been discovered in the code-projects Online Class and Exam Scheduling System 1.0. The issue affects some unknown features in the file /Scheduling/pages/class_sched.php. Manipulating the class parameter can lead to cross-site scripting ... Read more

    • Published: Apr. 24, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Cross-Site Scripting
  • 6.5

    MEDIUM
    CVE-2025-44134

    A vulnerability was found in Code-Projects Online Class and Exam Scheduling System 1.0 in the file /Scheduling/pages/class_save.php. Manipulation of parameter class will lead to SQL injection attacks.... Read more

    • Published: Apr. 24, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Injection
  • 6.5

    MEDIUM
    CVE-2025-44135

    A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0 in /Scheduling/pages/profile_update.php. Manipulating the parameter username will cause SQL injection attacks.... Read more

    • Published: Apr. 24, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Injection
  • 5.5

    MEDIUM
    CVE-2024-0340

    A vulnerability was found in vhost_new_msg in drivers/vhost/vhost.c in the Linux kernel, which does not properly initialize memory in messages passed between virtual guests and the host operating system in the vhost/vhost.c:vhost_new_msg() function. This ... Read more

    • EPSS Score: %0.01
    • Published: Jan. 09, 2024
    • Modified: May. 14, 2025
  • 6.5

    MEDIUM
    CVE-2025-32912

    A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause the libsoup client to crash.... Read more

    • Published: Apr. 14, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Denial of Service
  • 5.3

    MEDIUM
    CVE-2024-52616

    A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction ID... Read more

    Affected Products : enterprise_linux avahi
    • Published: Nov. 21, 2024
    • Modified: May. 14, 2025
  • 9.8

    CRITICAL
    CVE-2025-0793

    A vulnerability has been found in ESAFENET CDG V5 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /todoDetail.jsp. The manipulation of the argument flowId leads to sql injection. The attack can be launche... Read more

    Affected Products : cdg
    • Published: Jan. 29, 2025
    • Modified: May. 13, 2025
    • Vuln Type: Injection
  • 6.1

    MEDIUM
    CVE-2025-0794

    A vulnerability was found in ESAFENET CDG V5 and classified as problematic. Affected by this issue is some unknown functionality of the file /todoDetail.jsp. The manipulation of the argument curpage leads to cross site scripting. The attack may be launche... Read more

    Affected Products : cdg
    • Published: Jan. 29, 2025
    • Modified: May. 13, 2025
    • Vuln Type: Cross-Site Scripting
  • 6.1

    MEDIUM
    CVE-2025-0795

    A vulnerability was found in ESAFENET CDG V5. It has been classified as problematic. This affects an unknown part of the file /todolistjump.jsp. The manipulation of the argument flowId leads to cross site scripting. It is possible to initiate the attack r... Read more

    Affected Products : cdg
    • Published: Jan. 29, 2025
    • Modified: May. 13, 2025
    • Vuln Type: Cross-Site Scripting
  • 5.9

    MEDIUM
    CVE-2024-45627

    In Apache Linkis <1.7.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSource Manager Module will allow the attacker to read arbitrary files from the Linkis server. Therefore, th... Read more

    Affected Products : linkis
    • Published: Jan. 14, 2025
    • Modified: May. 13, 2025
    • Vuln Type: Information Disclosure
Showing 20 of 291615 Results