Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.3

    MEDIUM
    CVE-2022-45389

    A missing permission check in Jenkins XP-Dev Plugin 1.0 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to an attacker-specified repository.... Read more

    Affected Products : xp-dev
    • EPSS Score: %0.11
    • Published: Nov. 15, 2022
    • Modified: Apr. 30, 2025
  • 7.5

    HIGH
    CVE-2022-45388

    Jenkins Config Rotator Plugin 2.0.1 and earlier does not restrict a file name query parameter in an HTTP endpoint, allowing unauthenticated attackers to read arbitrary files with '.xml' extension on the Jenkins controller file system.... Read more

    Affected Products : config_rotator
    • EPSS Score: %0.18
    • Published: Nov. 15, 2022
    • Modified: Apr. 30, 2025
  • 5.4

    MEDIUM
    CVE-2022-45387

    Jenkins BART Plugin 1.0.3 and earlier does not escape the parsed content of build logs before rendering it on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability.... Read more

    Affected Products : bart
    • EPSS Score: %6.94
    • Published: Nov. 15, 2022
    • Modified: Apr. 30, 2025
  • 5.5

    MEDIUM
    CVE-2022-45386

    Jenkins Violations Plugin 0.7.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.... Read more

    Affected Products : violations
    • EPSS Score: %0.08
    • Published: Nov. 15, 2022
    • Modified: Apr. 30, 2025
  • 7.5

    HIGH
    CVE-2022-45385

    A missing permission check in Jenkins CloudBees Docker Hub/Registry Notification Plugin 2.6.2 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository.... Read more

    • EPSS Score: %0.11
    • Published: Nov. 15, 2022
    • Modified: Apr. 30, 2025
  • 6.5

    MEDIUM
    CVE-2022-45384

    Jenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores the LDAP manager password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.... Read more

    Affected Products : reverse_proxy_auth
    • EPSS Score: %0.08
    • Published: Nov. 15, 2022
    • Modified: Apr. 30, 2025
  • 6.1

    MEDIUM
    CVE-2022-43119

    A cross-site scripting (XSS) vulnerability in Clansphere CMS v2011.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username parameter.... Read more

    Affected Products : clansphere
    • EPSS Score: %0.26
    • Published: Nov. 09, 2022
    • Modified: Apr. 30, 2025
  • 5.5

    MEDIUM
    CVE-2022-43071

    A stack overflow in the Catalog::readPageLabelTree2(Object*) function of XPDF v4.04 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.... Read more

    Affected Products : xpdf
    • EPSS Score: %0.06
    • Published: Nov. 15, 2022
    • Modified: Apr. 30, 2025
  • 7.5

    HIGH
    CVE-2022-42978

    In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled. An unauthenticated attacker could access files on the remote system.... Read more

    Affected Products : confluence_data_center
    • EPSS Score: %0.61
    • Published: Nov. 15, 2022
    • Modified: Apr. 30, 2025
  • 6.1

    MEDIUM
    CVE-2021-25926

    In SiCKRAGE, versions 9.3.54.dev1 to 10.0.11.dev1 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly in the `quicksearch` feature. Therefore, an attacker can steal a user's sessionID to masquerade as a vi... Read more

    Affected Products : sickrage
    • EPSS Score: %0.33
    • Published: Apr. 12, 2021
    • Modified: Apr. 30, 2025
  • 5.4

    MEDIUM
    CVE-2021-25925

    in SiCKRAGE, versions 4.2.0 to 10.0.11.dev1 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly when processed by the server. Therefore, an attacker can inject arbitrary JavaScript code inside the application... Read more

    Affected Products : sickrage
    • EPSS Score: %0.18
    • Published: Apr. 12, 2021
    • Modified: Apr. 30, 2025
  • 5.4

    MEDIUM
    CVE-2021-25921

    In OpenEMR, versions 2.7.3-rc1 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly in the `Allergies` section. An attacker could lure an admin to enter a malicious payload and by that initiate the ex... Read more

    Affected Products : openemr
    • EPSS Score: %57.07
    • Published: Mar. 22, 2021
    • Modified: Apr. 30, 2025
  • 6.5

    MEDIUM
    CVE-2021-25920

    In OpenEMR, versions v2.7.2-rc1 to 6.0.0 are vulnerable to Improper Access Control when creating a new user, which leads to a malicious user able to read and send sensitive messages on behalf of the victim user.... Read more

    Affected Products : openemr
    • EPSS Score: %0.22
    • Published: Mar. 22, 2021
    • Modified: Apr. 30, 2025
  • 4.8

    MEDIUM
    CVE-2021-25919

    In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly. A highly privileged attacker could inject arbitrary code into input fields when creating a new user.... Read more

    Affected Products : openemr
    • EPSS Score: %58.97
    • Published: Mar. 22, 2021
    • Modified: Apr. 30, 2025
  • 4.8

    MEDIUM
    CVE-2021-25918

    In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the TOTP Authentication method page. A highly privileged attacker could inject arbitrary code into input... Read more

    Affected Products : openemr
    • EPSS Score: %2.80
    • Published: Mar. 22, 2021
    • Modified: Apr. 30, 2025
  • 4.8

    MEDIUM
    CVE-2021-25917

    In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the U2F USB Device authentication method page. A highly privileged attacker could inject arbitrary code ... Read more

    Affected Products : openemr
    • EPSS Score: %2.80
    • Published: Mar. 22, 2021
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2021-25916

    Prototype pollution vulnerability in 'patchmerge' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.... Read more

    Affected Products : patchmerge
    • EPSS Score: %2.95
    • Published: Mar. 16, 2021
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2021-25915

    Prototype pollution vulnerability in 'changeset' versions 0.0.1 through 0.2.5 allows an attacker to cause a denial of service and may lead to remote code execution.... Read more

    Affected Products : changeset
    • EPSS Score: %2.95
    • Published: Mar. 09, 2021
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2021-25914

    Prototype pollution vulnerability in 'object-collider' versions 1.0.0 through 1.0.3 allows attacker to cause a denial of service and may lead to remote code execution.... Read more

    Affected Products : object-collider
    • EPSS Score: %3.23
    • Published: Mar. 01, 2021
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2025-4027

    A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file /admin/rules.php. The manipulation of the argument pagetitle leads to sql injection. It is possible ... Read more

    Affected Products : old_age_home_management_system
    • Published: Apr. 28, 2025
    • Modified: Apr. 30, 2025
Showing 20 of 291021 Results