Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2024-30849

    Arbitrary file upload vulnerability in Sourcecodester Complete E-Commerce Site v1.0, allows remote attackers to execute arbitrary code via filename parameter in admin/products_photo.php.... Read more

    Affected Products : complete_e-commerce_site
    • Published: Apr. 05, 2024
    • Modified: May. 05, 2025
  • 6.1

    MEDIUM
    CVE-2024-32342

    A cross-site scripting (XSS) vulnerability in the Create Page of Boid CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Permalink parameter.... Read more

    Affected Products : boidcms
    • Published: Apr. 17, 2024
    • Modified: May. 05, 2025
  • 6.1

    MEDIUM
    CVE-2024-32343

    A cross-site scripting (XSS) vulnerability in the Create Page of Boid CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Content parameter.... Read more

    Affected Products : boidcms
    • Published: Apr. 17, 2024
    • Modified: May. 05, 2025
  • 5.3

    MEDIUM
    CVE-2024-32481

    Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. Starting in version 0.3.8 and prior to version 0.4.0b1, when looping over a `range` of the form `range(start, start + N)`, if `start` is negative, the execution will always reve... Read more

    Affected Products : vyper
    • Published: Apr. 25, 2024
    • Modified: May. 05, 2025
  • 4.9

    MEDIUM
    CVE-2024-25288

    SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php.... Read more

    • Published: Feb. 21, 2024
    • Modified: May. 05, 2025
  • 8.8

    HIGH
    CVE-2024-25165

    A global-buffer-overflow vulnerability was found in SWFTools v0.9.2, in the function LineText at lib/swf5compiler.flex.... Read more

    Affected Products : swftools
    • EPSS Score: %0.12
    • Published: Feb. 14, 2024
    • Modified: May. 05, 2025
  • 9.8

    CRITICAL
    CVE-2023-26793

    libmodbus v3.1.10 has a heap-based buffer overflow vulnerability in read_io_status function in src/modbus.c.... Read more

    Affected Products : libmodbus
    • Published: May. 01, 2024
    • Modified: May. 05, 2025
  • 5.5

    MEDIUM
    CVE-2024-35384

    An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_array_length function in the mjs.c file.... Read more

    Affected Products : mjs
    • Published: May. 21, 2024
    • Modified: May. 05, 2025
  • 4.3

    MEDIUM
    CVE-2024-35385

    An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_mk_ffi_sig function in the mjs.c file.... Read more

    Affected Products : mjs
    • Published: May. 21, 2024
    • Modified: May. 05, 2025
  • 6.5

    MEDIUM
    CVE-2025-32690

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Angelo Mandato PowerPress Podcasting allows DOM-Based XSS.This issue affects PowerPress Podcasting: from n/a through 11.12.5.... Read more

    Affected Products : powerpress
    • Published: Apr. 09, 2025
    • Modified: May. 05, 2025
    • Vuln Type: Cross-Site Scripting
  • 6.1

    MEDIUM
    CVE-2022-42799

    The issue was addressed with improved UI handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Visiting a malicious website may lead to user interface spoofing.... Read more

    • EPSS Score: %0.53
    • Published: Nov. 01, 2022
    • Modified: May. 05, 2025
  • 5.5

    MEDIUM
    CVE-2022-42798

    The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. Parsing a maliciously crafted audio ... Read more

    Affected Products : macos iphone_os tvos watchos ipados
    • EPSS Score: %0.06
    • Published: Nov. 01, 2022
    • Modified: May. 05, 2025
  • 7.0

    HIGH
    CVE-2022-42791

    A race condition was addressed with improved state handling. This issue is fixed in macOS Ventura 13. An app may be able to execute arbitrary code with kernel privileges.... Read more

    Affected Products : macos iphone_os
    • EPSS Score: %0.08
    • Published: Nov. 01, 2022
    • Modified: May. 05, 2025
  • 6.5

    MEDIUM
    CVE-2022-42318

    Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, ... Read more

    Affected Products : fedora debian_linux xen
    • EPSS Score: %0.04
    • Published: Nov. 01, 2022
    • Modified: May. 05, 2025
  • 8.2

    HIGH
    CVE-2022-36338

    An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An SMM callout vulnerability in the SMM driver FwBlockServiceSmm, creating SMM, leads to arbitrary code execution. An attacker can replace the pointer to the UEFI boot service GetVar... Read more

    Affected Products : insydeh2o
    • EPSS Score: %0.06
    • Published: Sep. 23, 2022
    • Modified: May. 05, 2025
  • 6.0

    MEDIUM
    CVE-2022-35896

    An issue SMM memory leak vulnerability in SMM driver (SMRAM was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An attacker can dump SMRAM contents via the software SMI provided by the FvbServicesRuntimeDxe driver to read the contents of SMRAM... Read more

    Affected Products : insydeh2o
    • EPSS Score: %0.06
    • Published: Sep. 22, 2022
    • Modified: May. 05, 2025
  • 8.2

    HIGH
    CVE-2022-35895

    An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The FwBlockSericceSmm driver does not properly validate input parameters for a software SMI routine, leading to memory corruption of arbitrary addresses including SMRAM, and possible... Read more

    Affected Products : insydeh2o
    • EPSS Score: %0.09
    • Published: Sep. 21, 2022
    • Modified: May. 05, 2025
  • 6.0

    MEDIUM
    CVE-2022-35894

    An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The SMI handler for the FwBlockServiceSmm driver uses an untrusted pointer as the location to copy data to an attacker-specified buffer, leading to information disclosure.... Read more

    Affected Products : insydeh2o
    • EPSS Score: %0.04
    • Published: Sep. 22, 2022
    • Modified: May. 05, 2025
  • 8.2

    HIGH
    CVE-2022-35893

    An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An SMM memory corruption vulnerability in the FvbServicesRuntimeDxe driver allows an attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalat... Read more

    Affected Products : insydeh2o
    • EPSS Score: %0.08
    • Published: Sep. 23, 2022
    • Modified: May. 05, 2025
  • 3.7

    LOW
    CVE-2022-35252

    When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to a... Read more

    • EPSS Score: %0.08
    • Published: Sep. 23, 2022
    • Modified: May. 05, 2025
Showing 20 of 291385 Results