Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.5

    MEDIUM
    CVE-2025-28142

    Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the foldername in /boafrm/formDiskCreateShare.... Read more

    Affected Products : br-6478ac_v3_firmware br-6478ac_v3
    • Published: Apr. 15, 2025
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2024-52884

    An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of weak password obfuscation/encryption, an attacker with access to configuration exports (INI) is able to decrypt the passwords.... Read more

    Affected Products : mediant_session_border_controller
    • Published: Feb. 07, 2025
    • Modified: May. 01, 2025
  • 5.3

    MEDIUM
    CVE-2024-0855

    The Spiffy Calendar WordPress plugin before 4.9.9 doesn't check the event_author parameter, and allows any user to alter it when creating an event, leading to deceiving users/admins that a page was created by a Contributor+.... Read more

    Affected Products : spiffy_calendar
    • Published: Feb. 27, 2024
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2024-52883

    An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnerability, sensitive data can be read without any authentication.... Read more

    Affected Products : one_voice_operations_center
    • Published: Feb. 07, 2025
    • Modified: May. 01, 2025
  • 6.1

    MEDIUM
    CVE-2024-52882

    An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to improper neutralization of input via the devices API, an attacker can inject malicious JavaScript code (XSS) to attack logged-in administrator sessions.... Read more

    Affected Products : one_voice_operations_center
    • Published: Feb. 07, 2025
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2024-52881

    An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to the use of a hard-coded key, an attacker is able to decrypt sensitive data such as passwords extracted from the topology file.... Read more

    Affected Products : one_voice_operations_center
    • Published: Feb. 07, 2025
    • Modified: May. 01, 2025
  • 4.8

    MEDIUM
    CVE-2024-40410

    Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for encryption.... Read more

    Affected Products : thinfinity_workspace
    • Published: Nov. 13, 2024
    • Modified: May. 01, 2025
  • 7.3

    HIGH
    CVE-2024-40408

    Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges.... Read more

    Affected Products : thinfinity_workspace
    • Published: Nov. 13, 2024
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2024-40407

    A full path disclosure in Cybele Software Thinfinity Workspace before v7.0.2.113 allows attackers to obtain the root path of the application via unspecified vectors.... Read more

    Affected Products : thinfinity_workspace
    • Published: Nov. 13, 2024
    • Modified: May. 01, 2025
  • 8.1

    HIGH
    CVE-2024-40405

    Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafted request.... Read more

    Affected Products : thinfinity_workspace
    • Published: Nov. 13, 2024
    • Modified: May. 01, 2025
  • 9.8

    CRITICAL
    CVE-2024-40404

    Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connections are established.... Read more

    Affected Products : thinfinity_workspace
    • Published: Nov. 13, 2024
    • Modified: May. 01, 2025
  • 6.1

    MEDIUM
    CVE-2024-1106

    The Shariff Wrapper WordPress plugin before 4.6.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowe... Read more

    Affected Products : shariff_wrapper
    • Published: Feb. 27, 2024
    • Modified: May. 01, 2025
  • 5.3

    MEDIUM
    CVE-2022-45195

    SimpleXMQ before 3.4.0, as used in SimpleX Chat before 4.2, does not apply a key derivation function to intended data, which can interfere with forward secrecy and can have other impacts if there is a compromise of a single private key. This occurs in the... Read more

    Affected Products : simplex_chat simplexmq
    • EPSS Score: %0.14
    • Published: Nov. 12, 2022
    • Modified: May. 01, 2025
  • 4.7

    MEDIUM
    CVE-2022-45194

    CBRN-Analysis before 22 allows XXE attacks via am mws XML document, leading to NTLMv2-SSP hash disclosure.... Read more

    Affected Products : cbrn-analysis
    • EPSS Score: %0.09
    • Published: Nov. 12, 2022
    • Modified: May. 01, 2025
  • 9.8

    CRITICAL
    CVE-2022-45182

    Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter.... Read more

    Affected Products : pi-star_digital_voice_dashboard
    • EPSS Score: %0.44
    • Published: Nov. 11, 2022
    • Modified: May. 01, 2025
  • 6.5

    MEDIUM
    CVE-2022-45130

    Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian is a specific version of the Plesk product: version numbers were used through version 12, and then the convention was changed so t... Read more

    Affected Products : obsidian
    • EPSS Score: %0.39
    • Published: Nov. 10, 2022
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2022-45129

    Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422. This affects Payara Platform Community before 4.1.2.191.38, 5.x before 5.2022.4, and 6.x before 6.2... Read more

    Affected Products : payara
    • EPSS Score: %1.57
    • Published: Nov. 10, 2022
    • Modified: May. 01, 2025
  • 9.1

    CRITICAL
    CVE-2022-44727

    The EU Cookie Law GDPR (Banner + Blocker) module before 2.1.3 for PrestaShop allows SQL Injection via a cookie ( lgcookieslaw or __lglaw ).... Read more

    Affected Products : eu_cookie_law_gdpr
    • EPSS Score: %0.29
    • Published: Nov. 10, 2022
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2022-44561

    The preset launcher module has a permission verification vulnerability. Successful exploitation of this vulnerability makes unauthorized apps add arbitrary widgets and shortcuts without interaction.... Read more

    Affected Products : emui harmonyos
    • EPSS Score: %0.07
    • Published: Nov. 09, 2022
    • Modified: May. 01, 2025
  • 5.3

    MEDIUM
    CVE-2022-44560

    The launcher module has an Intent redirection vulnerability. Successful exploitation of this vulnerability may cause launcher module data to be modified.... Read more

    Affected Products : emui harmonyos
    • EPSS Score: %0.07
    • Published: Nov. 09, 2022
    • Modified: May. 01, 2025
Showing 20 of 291010 Results