Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2025-22144

    NamelessMC is a free, easy to use & powerful website software for Minecraft servers. A user with admincp.core.emails or admincp.users.edit permissions can validate users and an attacker can reset their password. When the account is successfully approved b... Read more

    Affected Products : nameless
    • Published: Jan. 13, 2025
    • Modified: May. 13, 2025
    • Vuln Type: Authentication
  • 5.4

    MEDIUM
    CVE-2024-5644

    The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (fo... Read more

    Affected Products : tournamatch
    • Published: Jul. 13, 2024
    • Modified: May. 13, 2025
  • 7.5

    HIGH
    CVE-2025-29784

    NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the s parameter in GET requests for forum search functionality lacks length validation, allowing attackers to submit excessively long search q... Read more

    Affected Products : nameless
    • Published: Apr. 18, 2025
    • Modified: May. 13, 2025
    • Vuln Type: Denial of Service
  • 6.5

    MEDIUM
    CVE-2024-29804

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Heateor Fancy Comments WordPress allows Stored XSS.This issue affects Fancy Comments WordPress: from n/a through 1.2.14. ... Read more

    Affected Products : fancy_comments
    • Published: Mar. 27, 2024
    • Modified: May. 13, 2025
  • 7.1

    HIGH
    CVE-2025-30158

    NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the forum allows users to post iframe elements inside forum topics/comments/feed with no restriction on the iframe's width and height attribut... Read more

    Affected Products : nameless
    • Published: Apr. 18, 2025
    • Modified: May. 13, 2025
    • Vuln Type: Denial of Service
  • 7.3

    HIGH
    CVE-2025-30357

    NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, if a malicious user is leaving spam comments on many topics then an administrator, unable to manually remove each spam comment, may delete the... Read more

    Affected Products : nameless
    • Published: Apr. 18, 2025
    • Modified: May. 13, 2025
  • 5.4

    MEDIUM
    CVE-2024-6938

    A vulnerability has been found in SiYuan 3.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file PDF.js of the component PDF Handler. The manipulation leads to cross site scripting. The attack can be lau... Read more

    Affected Products : siyuan
    • Published: Jul. 21, 2024
    • Modified: May. 13, 2025
  • 7.1

    HIGH
    CVE-2025-31118

    NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, forum quick reply feature (view_topic.php) does not implement any spam prevention mechanism. This allows authenticated users to continuously p... Read more

    Affected Products : nameless
    • Published: Apr. 18, 2025
    • Modified: May. 13, 2025
    • Vuln Type: Denial of Service
  • 7.8

    HIGH
    CVE-2024-24245

    An issue in Canimaan Software LTD ClamXAV v3.1.2 through v3.6.1 and fixed in v.3.6.2 allows a local attacker to escalate privileges via the ClamXAV helper tool component.... Read more

    Affected Products : clamxav
    • Published: Apr. 09, 2024
    • Modified: May. 13, 2025
  • 5.3

    MEDIUM
    CVE-2025-31120

    NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, an insecure view count mechanism in the forum page allows an unauthenticated attacker to artificially increase the view count. The application... Read more

    Affected Products : nameless
    • Published: Apr. 18, 2025
    • Modified: May. 13, 2025
    • Vuln Type: Misconfiguration
  • 8.6

    HIGH
    CVE-2025-32389

    NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Prior to version 2.1.4, NamelessMC is vulnerable to SQL injection by providing an unexpected square bracket GET parameter syntax. Square bracket GET parameter syntax refe... Read more

    Affected Products : nameless
    • Published: Apr. 18, 2025
    • Modified: May. 13, 2025
    • Vuln Type: Injection
  • 6.3

    MEDIUM
    CVE-2025-22142

    NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In affected versions an admin can add the ability to have users fill out an additional field and users can inject javascript code into it that would be activated once a s... Read more

    Affected Products : nameless
    • Published: Jan. 13, 2025
    • Modified: May. 13, 2025
    • Vuln Type: Cross-Site Scripting
  • 7.5

    HIGH
    CVE-2024-8418

    A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can exploit this flaw by keeping a TCP connection open indefinitely, causing the server to become unresponsive... Read more

    Affected Products : enterprise_linux aardvark-dns
    • Published: Sep. 04, 2024
    • Modified: May. 13, 2025
  • 9.8

    CRITICAL
    CVE-2024-12442

    EnerSys AMPA versions 24.04 through 24.16, inclusive, are vulnerable to command injection leading to privileged remote shell access.... Read more

    Affected Products :
    • Published: May. 09, 2025
    • Modified: May. 13, 2025
    • Vuln Type: Injection
  • 7.5

    HIGH
    CVE-2023-6064

    The PayHere Payment Gateway WordPress plugin before 2.2.12 automatically creates publicly-accessible log files containing sensitive information when transactions occur.... Read more

    Affected Products : payhere_payment_gateway
    • EPSS Score: %0.39
    • Published: Jan. 01, 2024
    • Modified: May. 13, 2025
  • 7.2

    HIGH
    CVE-2022-42218

    Open Source SACCO Management System v1.0 vulnerable to SQL Injection via /sacco_shield/manage_loan.php.... Read more

    • EPSS Score: %0.09
    • Published: Oct. 18, 2022
    • Modified: May. 13, 2025
  • 6.1

    MEDIUM
    CVE-2022-42202

    TP-Link TL-WR841N 8.0 4.17.16 Build 120201 Rel.54750n is vulnerable to Cross Site Scripting (XSS).... Read more

    Affected Products : tl-wr841n_firmware tl-wr841n
    • EPSS Score: %0.11
    • Published: Oct. 18, 2022
    • Modified: May. 13, 2025
  • 7.5

    HIGH
    CVE-2022-42188

    In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server.... Read more

    Affected Products : lavalite
    • EPSS Score: %0.15
    • Published: Oct. 18, 2022
    • Modified: May. 13, 2025
  • 9.8

    CRITICAL
    CVE-2022-42165

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetDeviceName.... Read more

    Affected Products : ac10_firmware ac10
    • EPSS Score: %0.17
    • Published: Oct. 17, 2022
    • Modified: May. 13, 2025
  • 6.1

    MEDIUM
    CVE-2022-42116

    A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor in Liferay Portal 7.3.2 through 7.4.3.14, and Liferay DXP 7.3 before update 6, and 7.4 before update 15 allows remote attackers to inject arbitrary web sc... Read more

    Affected Products : liferay_portal dxp
    • EPSS Score: %0.18
    • Published: Oct. 18, 2022
    • Modified: May. 13, 2025
Showing 20 of 291728 Results