Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.3

    HIGH
    CVE-2024-0220

    B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code on the products ... Read more

    • Published: Feb. 22, 2024
    • Modified: May. 06, 2025
  • 9.8

    CRITICAL
    CVE-2025-2379

    A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /create-pass.php. The manipulation of the argument visname leads to sql injection. The ... Read more

    • Published: Mar. 17, 2025
    • Modified: May. 06, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-2380

    A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin-profile.php. The manipulation of the argument mobilenumber leads to sql injectio... Read more

    • Published: Mar. 17, 2025
    • Modified: May. 06, 2025
    • Vuln Type: Injection
  • 7.5

    HIGH
    CVE-2024-1104

    An unauthenticated remote attacker can bypass the brute force prevention mechanism and disturb the webservice for all users.... Read more

    Affected Products : webserv2
    • Published: Feb. 22, 2024
    • Modified: May. 06, 2025
  • 9.8

    CRITICAL
    CVE-2025-2381

    A vulnerability classified as critical has been found in PHPGurukul Curfew e-Pass Management System 1.0. Affected is an unknown function of the file /admin/search-pass.php. The manipulation of the argument searchdata leads to sql injection. It is possible... Read more

    Affected Products : curfew_e-pass_management_system
    • Published: Mar. 17, 2025
    • Modified: May. 06, 2025
    • Vuln Type: Injection
  • 7.8

    HIGH
    CVE-2024-37007

    A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.... Read more

    • Published: Jun. 25, 2024
    • Modified: May. 06, 2025
  • 6.1

    MEDIUM
    CVE-2022-40487

    ProcessWire v3.0.200 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Search Users and Search Pages function. These vulnerabilities allow attackers to execute arbitrary web scripts or HTML via injection of a crafted pa... Read more

    Affected Products : processwire
    • EPSS Score: %0.78
    • Published: Oct. 31, 2022
    • Modified: May. 06, 2025
  • 7.4

    HIGH
    CVE-2022-3308

    Insufficient policy enforcement in developer tools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)... Read more

    Affected Products : chrome edge_chromium
    • EPSS Score: %0.19
    • Published: Nov. 01, 2022
    • Modified: May. 06, 2025
  • 8.8

    HIGH
    CVE-2022-3307

    Use after free in media in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more

    Affected Products : chrome edge_chromium
    • EPSS Score: %0.31
    • Published: Nov. 01, 2022
    • Modified: May. 06, 2025
  • 8.8

    HIGH
    CVE-2022-3306

    Use after free in survey in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more

    Affected Products : chrome chrome_os
    • EPSS Score: %0.51
    • Published: Nov. 01, 2022
    • Modified: May. 06, 2025
  • 8.8

    HIGH
    CVE-2022-3305

    Use after free in survey in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more

    Affected Products : chrome chrome_os
    • EPSS Score: %0.58
    • Published: Nov. 01, 2022
    • Modified: May. 06, 2025
  • 10.0

    HIGH
    CVE-2018-6342

    react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a command to launch an editor. The input to that command was not properly sanitized, allowing an attacker who can make a network request to the... Read more

    Affected Products : windows react-dev-utils
    • EPSS Score: %0.79
    • Published: Dec. 31, 2018
    • Modified: May. 06, 2025
  • 6.1

    MEDIUM
    CVE-2018-6341

    React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of escaping could lead to a cross-site scripting vulnerability. This issue affected minor releases 16.0.x, 16.... Read more

    Affected Products : react
    • EPSS Score: %18.06
    • Published: Dec. 31, 2018
    • Modified: May. 06, 2025
  • 7.5

    HIGH
    CVE-2018-6337

    folly::secureRandom will re-use a buffer between parent and child processes when fork() is called. That will result in multiple forked children producing repeat (or similar) results. This affects HHVM 3.26 prior to 3.26.3 and the folly library between v20... Read more

    Affected Products : hhvm folly
    • EPSS Score: %0.29
    • Published: Dec. 31, 2018
    • Modified: May. 06, 2025
  • 9.8

    CRITICAL
    CVE-2018-6334

    Multipart-file uploads call variables to be improperly registered in the global scope. In cases where variables are not declared explicitly before being used this can lead to unexpected behavior. This affects all supported versions of HHVM prior to the pa... Read more

    Affected Products : hhvm
    • EPSS Score: %0.51
    • Published: Dec. 31, 2018
    • Modified: May. 06, 2025
  • 6.5

    MEDIUM
    CVE-2018-20622

    JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used.... Read more

    Affected Products : debian_linux jasper
    • EPSS Score: %1.50
    • Published: Dec. 31, 2018
    • Modified: May. 06, 2025
  • 8.8

    HIGH
    CVE-2018-20618

    ok-file-formats through 2018-10-16 has a heap-based buffer over-read in the ok_mo_decode2 function in ok_mo.c.... Read more

    Affected Products : ok-file-formats
    • EPSS Score: %0.40
    • Published: Dec. 31, 2018
    • Modified: May. 06, 2025
  • 6.6

    MEDIUM
    CVE-2018-19937

    A local, authenticated attacker can bypass the passcode in the VideoLAN VLC media player app before 3.1.5 for iOS by opening a URL and turning the phone.... Read more

    Affected Products : vlc_media_player vlc_for_mobile
    • EPSS Score: %0.04
    • Published: Dec. 31, 2018
    • Modified: May. 06, 2025
  • 9.8

    CRITICAL
    CVE-2018-18602

    The Cloud API on Guardzilla smart cameras allows user enumeration, with resultant arbitrary camera access and monitoring.... Read more

    • EPSS Score: %0.34
    • Published: Dec. 31, 2018
    • Modified: May. 06, 2025
  • 7.4

    HIGH
    CVE-2024-20327

    A vulnerability in the PPP over Ethernet (PPPoE) termination feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to crash the ppp_ma process, resulting in a denial of se... Read more

    • Published: Mar. 13, 2024
    • Modified: May. 06, 2025
Showing 20 of 291316 Results