Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.1

    MEDIUM
    CVE-2022-33322

    Cross-site scripting vulnerability in Mitsubishi Electric consumer electronics products (Air Conditioning, Wi-Fi Interface, Refrigerator, HEMS adapter, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS ... Read more

    • EPSS Score: %0.78
    • Published: Nov. 08, 2022
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2022-27674

    Insufficient validation in the IOCTL input/output buffer in AMD μProf may allow an attacker to bypass bounds checks potentially leading to a Windows kernel crash resulting in denial of service.... Read more

    Affected Products : linux_kernel freebsd windows amd_uprof
    • EPSS Score: %0.08
    • Published: Nov. 09, 2022
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2022-23831

    Insufficient validation of the IOCTL input buffer in AMD μProf may allow an attacker to send an arbitrary buffer leading to a potential Windows kernel crash resulting in denial of service.... Read more

    Affected Products : linux_kernel freebsd windows amd_uprof
    • EPSS Score: %0.20
    • Published: Nov. 09, 2022
    • Modified: May. 01, 2025
  • 7.8

    HIGH
    CVE-2021-26391

    Insufficient verification of multiple header signatures while loading a Trusted Application (TA) may allow an attacker with privileges to gain code execution in that TA or the OS/kernel.... Read more

    • EPSS Score: %0.03
    • Published: Nov. 09, 2022
    • Modified: May. 01, 2025
  • 7.8

    HIGH
    CVE-2021-26360

    An attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC registers. This could allow potential corruption of AMD secure processor’s encrypted memory contents which may lead to arbitrary code ... Read more

    • EPSS Score: %0.04
    • Published: Nov. 09, 2022
    • Modified: May. 01, 2025
  • 6.1

    MEDIUM
    CVE-2023-0878

    Cross-site Scripting (XSS) - Generic in GitHub repository nuxt/framework prior to 3.2.1.... Read more

    Affected Products : framework nuxt
    • EPSS Score: %0.09
    • Published: Feb. 17, 2023
    • Modified: May. 01, 2025
  • 8.8

    HIGH
    CVE-2024-29514

    File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file.... Read more

    Affected Products : leptoncms
    • Published: Apr. 02, 2024
    • Modified: May. 01, 2025
  • 8.8

    HIGH
    CVE-2024-29515

    File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file to the save.php and config.php component.... Read more

    Affected Products : leptoncms lepton
    • Published: Mar. 25, 2024
    • Modified: May. 01, 2025
  • 5.4

    MEDIUM
    CVE-2024-28593

    The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it ... Read more

    Affected Products : moodle
    • Published: Mar. 22, 2024
    • Modified: May. 01, 2025
  • 6.1

    MEDIUM
    CVE-2024-29374

    A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.... Read more

    Affected Products : moodle
    • Published: Mar. 21, 2024
    • Modified: May. 01, 2025
  • 7.8

    HIGH
    CVE-2024-24520

    An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.... Read more

    Affected Products : leptoncms
    • Published: Mar. 21, 2024
    • Modified: May. 01, 2025
  • 8.3

    HIGH
    CVE-2023-4990

    Directory traversal vulnerability in MCL-Net versions prior to 4.6 Update Package (P01) may allow attackers to read arbitrary files.... Read more

    Affected Products : mcl-net_firmware mcl-net espeak_ng
    • EPSS Score: %0.20
    • Published: Oct. 11, 2023
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2024-25768

    OpenDMARC 1.4.2 contains a null pointer dereference vulnerability in /OpenDMARC/libopendmarc/opendmarc_policy.c.... Read more

    Affected Products : opendmarc
    • Published: Feb. 26, 2024
    • Modified: May. 01, 2025
  • 6.5

    MEDIUM
    CVE-2024-25767

    nanomq 0.21.2 contains a Use-After-Free vulnerability in /nanomq/nng/src/core/socket.c.... Read more

    Affected Products : nanomq
    • Published: Feb. 26, 2024
    • Modified: May. 01, 2025
  • 9.8

    CRITICAL
    CVE-2024-48176

    Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the verification code will not be refreshed after a failed login, which allows attackers to blast the username and password and log into t... Read more

    Affected Products : lylme_spage
    • Published: Nov. 05, 2024
    • Modified: May. 01, 2025
  • 6.5

    MEDIUM
    CVE-2024-35539

    Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerability allows attackers to post several comments before the spam protection checks if the comments are posted too frequently.... Read more

    Affected Products : typecho
    • Published: Aug. 19, 2024
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2023-7165

    The JetBackup WordPress plugin before 2.0.9.9 doesn't use index files to prevent public directory listing of sensitive directories in certain configurations, which allows malicious actors to leak backup files.... Read more

    Affected Products : jetbackup
    • Published: Feb. 27, 2024
    • Modified: May. 01, 2025
  • 9.8

    CRITICAL
    CVE-2024-33124

    Roothub v2.6 was discovered to contain a SQL injection vulnerability via the nodeTitle parameter in the parentNode() function..... Read more

    Affected Products : roothub
    • Published: May. 07, 2024
    • Modified: May. 01, 2025
  • 9.8

    CRITICAL
    CVE-2024-33120

    Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vulnerability allows attackers to execute arbitrary code via a crafted JSP file.... Read more

    Affected Products : roothub
    • Published: May. 07, 2024
    • Modified: May. 01, 2025
  • 6.3

    MEDIUM
    CVE-2024-33122

    Roothub v2.6 was discovered to contain a SQL injection vulnerability via the topic parameter in the list() function.... Read more

    Affected Products : roothub
    • Published: May. 07, 2024
    • Modified: May. 01, 2025
Showing 20 of 291124 Results