Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.9

    MEDIUM
    CVE-2024-20921

    Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u391, 8u391-perf, 11.0.21, 17.0.9, 21.0.1; Oracle Gra... Read more

    Affected Products : jdk jre graalvm graalvm_for_jdk
    • Published: Feb. 17, 2024
    • Modified: May. 07, 2025
  • 5.3

    MEDIUM
    CVE-2024-20915

    Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Login - SSO). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network acc... Read more

    Affected Products : application_object_library
    • Published: Feb. 17, 2024
    • Modified: May. 07, 2025
  • 9.8

    CRITICAL
    CVE-2024-2702

    Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import allows importing settings and data, ultimately leading to XSS.This issue affects Olive One Click Demo Import: from n/a through 1.1.1. ... Read more

    Affected Products : olive_one_click_demo_import
    • Published: Mar. 20, 2024
    • Modified: May. 07, 2025
  • 5.3

    MEDIUM
    CVE-2023-7232

    The Backup and Restore WordPress WordPress plugin through 1.45 does not protect some log files containing sensitive information such as site configuration etc, allowing unauthenticated users to access such data... Read more

    Affected Products : backup_and_restore_wordpress
    • Published: Mar. 26, 2024
    • Modified: May. 07, 2025
  • 4.3

    MEDIUM
    CVE-2024-1745

    The Testimonial Slider WordPress plugin before 2.3.7 does not properly ensure that a user has the necessary capabilities to edit certain sensitive Testimonial Slider WordPress plugin before 2.3.7 settings, making it possible for users with at least the Au... Read more

    • Published: Mar. 26, 2024
    • Modified: May. 07, 2025
  • 5.3

    MEDIUM
    CVE-2024-29735

    Improper Preservation of Permissions vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.8.2 through 2.8.3. Airflow's local file task handler in Airflow incorrectly set permissions for all parent folders of log folder, in default con... Read more

    Affected Products : airflow
    • Published: Mar. 26, 2024
    • Modified: May. 07, 2025
  • 7.2

    HIGH
    CVE-2024-25420

    An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property component.... Read more

    Affected Products : openfire
    • Published: Mar. 26, 2024
    • Modified: May. 07, 2025
  • 9.8

    CRITICAL
    CVE-2024-25421

    An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CACHE component.... Read more

    Affected Products : openfire
    • Published: Mar. 26, 2024
    • Modified: May. 07, 2025
  • 6.1

    MEDIUM
    CVE-2024-2278

    Themify WordPress plugin before 1.4.4 does not sanitise and escape some of its Filters settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (f... Read more

    Affected Products : woocommerce_product_filter
    • Published: Apr. 01, 2024
    • Modified: May. 07, 2025
  • 9.8

    CRITICAL
    CVE-2024-29433

    A deserialization vulnerability in the FASTJSON component of Alldata v0.4.6 allows attackers to execute arbitrary commands via supplying crafted data.... Read more

    Affected Products : alldata
    • Published: Apr. 01, 2024
    • Modified: May. 07, 2025
  • 4.1

    MEDIUM
    CVE-2024-29435

    An issue discovered in Alldata v0.4.6 allows attacker to run arbitrary commands via the processId parameter.... Read more

    Affected Products : alldata
    • Published: Apr. 01, 2024
    • Modified: May. 07, 2025
  • 5.4

    MEDIUM
    CVE-2024-1274

    The My Calendar WordPress plugin before 3.4.24 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks (depending on the permissions set by the admin)... Read more

    Affected Products : my_calendar my_calendar
    • Published: Apr. 02, 2024
    • Modified: May. 07, 2025
  • 9.8

    CRITICAL
    CVE-2024-31002

    Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4 BitReader::ReadCache() at Ap4Utils.cpp component.... Read more

    Affected Products : bento4
    • Published: Apr. 02, 2024
    • Modified: May. 07, 2025
  • 8.8

    HIGH
    CVE-2024-31003

    Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4_MemoryByteStream::WritePartial at Ap4ByteStream.cpp.... Read more

    Affected Products : bento4
    • Published: Apr. 02, 2024
    • Modified: May. 07, 2025
  • 8.1

    HIGH
    CVE-2024-31005

    An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4MdhdAtom.cpp,AP4_MdhdAtom::AP4_MdhdAtom,mp4fragment... Read more

    Affected Products : bento4
    • Published: Apr. 02, 2024
    • Modified: May. 07, 2025
  • 8.8

    HIGH
    CVE-2024-53268

    Joplin is an open source, privacy-focused note taking app with sync capabilities for Windows, macOS, Linux, Android and iOS. In affected versions attackers are able to abuse the fact that openExternal is used without any filtering of URI schemes to obtain... Read more

    Affected Products : joplin
    • Published: Nov. 25, 2024
    • Modified: May. 07, 2025
  • 4.8

    MEDIUM
    CVE-2024-10704

    The Photo Gallery by 10Web WordPress plugin before 1.8.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is d... Read more

    Affected Products : photo_gallery
    • Published: Nov. 29, 2024
    • Modified: May. 07, 2025
  • 5.4

    MEDIUM
    CVE-2024-10980

    The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some of its Cookie Consent block options before outputting them back in a page/post w... Read more

    Affected Products : element_pack
    • Published: Nov. 29, 2024
    • Modified: May. 07, 2025
  • 4.8

    MEDIUM
    CVE-2024-10551

    The Sticky Social Icons WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disal... Read more

    Affected Products : sticky_social_icons
    • Published: Dec. 06, 2024
    • Modified: May. 07, 2025
  • 4.8

    MEDIUM
    CVE-2024-11183

    The Simple Side Tab WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed... Read more

    Affected Products : simple_side_tab
    • Published: Dec. 07, 2024
    • Modified: May. 06, 2025
Showing 20 of 291520 Results