Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.1

    MEDIUM
    CVE-2024-0337

    The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on the travelpayouts_redirect variable. This makes it possible for unauthenticated attackers to redirect users ... Read more

    Affected Products : travelpayouts
    • Published: Mar. 20, 2024
    • Modified: May. 05, 2025
  • 8.8

    HIGH
    CVE-2024-0856

    The Appointment Booking Calendar WordPress plugin before 1.3.83 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as adding a booking to the calendar without paying... Read more

    Affected Products : appointment_booking_calendar
    • Published: Mar. 20, 2024
    • Modified: May. 05, 2025
  • 7.1

    HIGH
    CVE-2024-1983

    The Simple Ajax Chat WordPress plugin before 20240223 does not prevent visitors from using malicious Names when using the chat, which will be reflected unsanitized to other users.... Read more

    Affected Products : simple_ajax_chat
    • Published: Mar. 20, 2024
    • Modified: May. 05, 2025
  • 6.2

    MEDIUM
    CVE-2025-29316

    An issue in DataPatrol Screenshot watermark, printing watermark agent v.3.5.2.0 allows a physically proximate attacker to obtain sensitive information. NOTE: the Supplier disputes the Print Job Watermark Bypass claim because the watermark is added by hook... Read more

    Affected Products :
    • Published: Apr. 17, 2025
    • Modified: May. 05, 2025
    • Vuln Type: Information Disclosure
  • 6.5

    MEDIUM
    CVE-2022-43351

    Sanitization Management System v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component /classes/Master.php?f=delete_img.... Read more

    Affected Products : sanitization_management_system
    • EPSS Score: %0.10
    • Published: Nov. 07, 2022
    • Modified: May. 05, 2025
  • 7.2

    HIGH
    CVE-2022-43350

    Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.php?f=delete_inquiry.... Read more

    Affected Products : sanitization_management_system
    • EPSS Score: %0.09
    • Published: Nov. 07, 2022
    • Modified: May. 05, 2025
  • 7.5

    HIGH
    CVE-2022-43319

    An information disclosure vulnerability in the component vcs/downloadFiles.php?download=./search.php of Simple E-Learning System v1.0 allows attackers to read arbitrary files.... Read more

    Affected Products : simple_e-learning_system
    • EPSS Score: %0.12
    • Published: Nov. 07, 2022
    • Modified: May. 05, 2025
  • 8.8

    HIGH
    CVE-2022-43306

    The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-dates package. The affected version of d8s-htm is 0.1... Read more

    Affected Products : d8s-timer
    • EPSS Score: %0.12
    • Published: Nov. 07, 2022
    • Modified: May. 05, 2025
  • 9.8

    CRITICAL
    CVE-2022-43305

    The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-algorithms package. The affected version of d8s-htm ... Read more

    Affected Products : d8s-python
    • EPSS Score: %0.12
    • Published: Nov. 07, 2022
    • Modified: May. 05, 2025
  • 9.8

    CRITICAL
    CVE-2022-43304

    The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-uuids package. The affected version of d8s-htm is 0.1... Read more

    Affected Products : d8s-timer
    • EPSS Score: %0.12
    • Published: Nov. 07, 2022
    • Modified: May. 05, 2025
  • 9.8

    CRITICAL
    CVE-2022-43303

    The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-uuids package. The affected version of d8s-htm is 0... Read more

    Affected Products : d8s-strings
    • EPSS Score: %0.12
    • Published: Nov. 07, 2022
    • Modified: May. 05, 2025
  • 7.2

    HIGH
    CVE-2022-43052

    Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Users.php?f=delete.... Read more

    • EPSS Score: %0.09
    • Published: Nov. 07, 2022
    • Modified: May. 05, 2025
  • 7.2

    HIGH
    CVE-2022-43051

    Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Users.php?f=delete_test.... Read more

    • EPSS Score: %0.09
    • Published: Nov. 07, 2022
    • Modified: May. 05, 2025
  • 7.2

    HIGH
    CVE-2022-43050

    Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component update_profile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.... Read more

    • EPSS Score: %0.12
    • Published: Nov. 07, 2022
    • Modified: May. 05, 2025
  • 7.2

    HIGH
    CVE-2022-43049

    Canteen Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the component /youthappam/add-food.php.... Read more

    Affected Products : canteen_management_system
    • EPSS Score: %0.07
    • Published: Nov. 07, 2022
    • Modified: May. 05, 2025
  • 4.8

    MEDIUM
    CVE-2022-43046

    Food Ordering Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /foms/place-order.php.... Read more

    • EPSS Score: %0.12
    • Published: Nov. 07, 2022
    • Modified: May. 05, 2025
  • 7.2

    HIGH
    CVE-2022-42990

    Food Ordering Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /foms/all-orders.php?status=Cancelled%20by%20Customer.... Read more

    • EPSS Score: %0.07
    • Published: Nov. 07, 2022
    • Modified: May. 05, 2025
  • 7.5

    HIGH
    CVE-2022-42956

    The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain the cleartext master password.... Read more

    Affected Products : passwork
    • EPSS Score: %0.12
    • Published: Nov. 07, 2022
    • Modified: May. 05, 2025
  • 7.5

    HIGH
    CVE-2022-42955

    The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain cleartext cached credentials.... Read more

    Affected Products : passwork
    • EPSS Score: %0.12
    • Published: Nov. 07, 2022
    • Modified: May. 05, 2025
  • 4.6

    MEDIUM
    CVE-2024-32206

    A stored cross-site scripting (XSS) vulnerability in the component \affiche\admin\index.php of WUZHICMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $formdata parameter.... Read more

    Affected Products : wuzhicms
    • Published: Apr. 19, 2024
    • Modified: May. 05, 2025
Showing 20 of 291222 Results