Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.5

    MEDIUM
    CVE-2024-48743

    Cross Site Scripting vulnerability in Sentry v.6.0.9 allows a remote attacker to execute arbitrary code via the z parameter.... Read more

    Affected Products : sentry
    • Published: Oct. 25, 2024
    • Modified: May. 01, 2025
  • 4.3

    MEDIUM
    CVE-2023-7198

    The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete private notes associated with different user accounts. This poses a significant s... Read more

    Affected Products : wp_dashboard_notes
    • Published: Feb. 27, 2024
    • Modified: May. 01, 2025
  • 6.5

    MEDIUM
    CVE-2025-3474

    Missing Authentication for Critical Function vulnerability in Drupal Panels allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Panels: from 0.0.0 before 4.9.0.... Read more

    Affected Products : panels
    • Published: Apr. 09, 2025
    • Modified: May. 01, 2025
  • 6.1

    MEDIUM
    CVE-2024-10276

    A vulnerability has been found in Telestream Sentry 6.0.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /?page=reports of the component Reports Page. The manipulation of the argument z leads to cross... Read more

    Affected Products : sentry
    • Published: Oct. 23, 2024
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2025-31692

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.... Read more

    Affected Products : drupal artificial_intelligence
    • Published: Mar. 31, 2025
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2025-31674

    Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, fr... Read more

    Affected Products : drupal
    • Published: Mar. 31, 2025
    • Modified: May. 01, 2025
  • 7.8

    HIGH
    CVE-2024-30202

    In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.... Read more

    Affected Products : emacs org_mode
    • Published: Mar. 25, 2024
    • Modified: May. 01, 2025
  • 5.5

    MEDIUM
    CVE-2024-30203

    In Emacs before 29.3, Gnus treats inline MIME contents as trusted.... Read more

    Affected Products : debian_linux emacs org_mode
    • Published: Mar. 25, 2024
    • Modified: May. 01, 2025
  • 2.8

    LOW
    CVE-2024-30204

    In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.... Read more

    Affected Products : debian_linux emacs org_mode
    • Published: Mar. 25, 2024
    • Modified: May. 01, 2025
  • 7.1

    HIGH
    CVE-2024-30205

    In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.... Read more

    Affected Products : debian_linux emacs org_mode
    • Published: Mar. 25, 2024
    • Modified: May. 01, 2025
  • 6.1

    MEDIUM
    CVE-2023-7202

    The Fatal Error Notify WordPress plugin before 1.5.3 does not have authorisation and CSRF checks in its test_error AJAX action, allowing any authenticated users, such as subscriber to call it and spam the admin email address with error messages. The issue... Read more

    Affected Products : fatal_error_notify
    • Published: Feb. 27, 2024
    • Modified: May. 01, 2025
  • 8.8

    HIGH
    CVE-2024-42586

    A Cross-Site Request Forgery (CSRF) in the component categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.... Read more

    Affected Products : warehouse_inventory_system
    • Published: Aug. 20, 2024
    • Modified: May. 01, 2025
  • 8.8

    HIGH
    CVE-2024-42585

    A Cross-Site Request Forgery (CSRF) in the component delete_media.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.... Read more

    Affected Products : warehouse_inventory_system
    • Published: Aug. 20, 2024
    • Modified: May. 01, 2025
  • 8.0

    HIGH
    CVE-2024-42578

    A Cross-Site Request Forgery (CSRF) in the component edit_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.... Read more

    • Published: Aug. 20, 2024
    • Modified: May. 01, 2025
  • 8.8

    HIGH
    CVE-2024-42576

    A Cross-Site Request Forgery (CSRF) in the component edit_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.... Read more

    Affected Products : warehouse_inventory_system
    • Published: Aug. 20, 2024
    • Modified: May. 01, 2025
  • 6.5

    MEDIUM
    CVE-2025-28145

    Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via partition in /boafrm/formDiskFormat.... Read more

    Affected Products : br-6478ac_v3_firmware br-6478ac_v3
    • Published: Apr. 15, 2025
    • Modified: May. 01, 2025
  • 6.5

    MEDIUM
    CVE-2025-28143

    Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the groupname at the /boafrm/formDiskCreateGroup.... Read more

    Affected Products : br-6478ac_v3_firmware br-6478ac_v3
    • Published: Apr. 15, 2025
    • Modified: May. 01, 2025
  • 6.5

    MEDIUM
    CVE-2025-28142

    Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the foldername in /boafrm/formDiskCreateShare.... Read more

    Affected Products : br-6478ac_v3_firmware br-6478ac_v3
    • Published: Apr. 15, 2025
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2024-52884

    An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of weak password obfuscation/encryption, an attacker with access to configuration exports (INI) is able to decrypt the passwords.... Read more

    Affected Products : mediant_session_border_controller
    • Published: Feb. 07, 2025
    • Modified: May. 01, 2025
  • 5.3

    MEDIUM
    CVE-2024-0855

    The Spiffy Calendar WordPress plugin before 4.9.9 doesn't check the event_author parameter, and allows any user to alter it when creating an event, leading to deceiving users/admins that a page was created by a Contributor+.... Read more

    Affected Products : spiffy_calendar
    • Published: Feb. 27, 2024
    • Modified: May. 01, 2025
Showing 20 of 291058 Results