Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2024-55210

    An issue in TOTVS Framework (Linha Protheus) 12.1.2310 allows attackers to bypass multi-factor authentication (MFA) via a crafted websocket message.... Read more

    Affected Products : framework_\(linha_protheus\)
    • Published: Apr. 09, 2025
    • Modified: Apr. 30, 2025
  • 5.5

    MEDIUM
    CVE-2025-20934

    Improper access control in Sticker Center prior to SMR Apr-2025 Release 1 allows local attackers to access image files with system privilege.... Read more

    Affected Products : android
    • Published: Apr. 08, 2025
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2025-45947

    An issue in phpgurukul Online Banquet Booking System V1.2 allows an attacker to execute arbitrary code via the /obbs/change-password.php file of the My Account - Change Password component... Read more

    Affected Products : online_banquet_booking_system
    • Published: Apr. 28, 2025
    • Modified: Apr. 30, 2025
  • 5.0

    MEDIUM
    CVE-2025-25776

    Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Ticket Booking System v1.0 allows an attacker to execute arbitrary code into the Full Name and Address fields during user registration or p... Read more

    Affected Products : bus_ticket_booking_system
    • Published: Apr. 28, 2025
    • Modified: Apr. 30, 2025
  • 7.5

    HIGH
    CVE-2025-3955

    A vulnerability, which was classified as critical, was found in codeprojects Patient Record Management System 1.0. This affects an unknown part of the file /edit_rpatient.php.php. The manipulation of the argument id/lastname leads to sql injection. It is ... Read more

    Affected Products : patient_record_management_system
    • Published: Apr. 27, 2025
    • Modified: Apr. 30, 2025
  • 8.8

    HIGH
    CVE-2025-3968

    A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /api.php. The manipulation of the argument cat_id leads to sql injection. The attack can be... Read more

    Affected Products : news_publishing_site_dashboard
    • Published: Apr. 27, 2025
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2025-3969

    A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been rated as critical. This issue affects some unknown processing of the file /edit-category.php of the component Edit Category Page. The manipulation of the argument ca... Read more

    Affected Products : news_publishing_site_dashboard
    • Published: Apr. 27, 2025
    • Modified: Apr. 30, 2025
  • 3.5

    LOW
    CVE-2025-0627

    The WordPress Tag, Category, and Taxonomy Manager WordPress plugin before 3.30.0 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the ... Read more

    Affected Products : taxopress
    • Published: Apr. 28, 2025
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2025-4020

    A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /contact.php. The manipulation of the argument fname leads to sql injection. The attack... Read more

    Affected Products : old_age_home_management_system
    • Published: Apr. 28, 2025
    • Modified: Apr. 30, 2025
  • 7.8

    HIGH
    CVE-2023-21358

    In UWB Google, there is a possible way for a malicious app to masquerade as system app com.android.uwb.resources due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti... Read more

    Affected Products : android
    • EPSS Score: %0.01
    • Published: Oct. 30, 2023
    • Modified: Apr. 30, 2025
  • 7.5

    HIGH
    CVE-2022-45391

    Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier globally and unconditionally disables SSL/TLS certificate and hostname validation for the entire Jenkins controller JVM.... Read more

    • EPSS Score: %0.03
    • Published: Nov. 15, 2022
    • Modified: Apr. 30, 2025
  • 4.3

    MEDIUM
    CVE-2022-45390

    A missing permission check in Jenkins loader.io Plugin 1.0.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more

    Affected Products : loader.io
    • EPSS Score: %0.09
    • Published: Nov. 15, 2022
    • Modified: Apr. 30, 2025
  • 5.3

    MEDIUM
    CVE-2022-45389

    A missing permission check in Jenkins XP-Dev Plugin 1.0 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to an attacker-specified repository.... Read more

    Affected Products : xp-dev
    • EPSS Score: %0.11
    • Published: Nov. 15, 2022
    • Modified: Apr. 30, 2025
  • 7.5

    HIGH
    CVE-2022-45388

    Jenkins Config Rotator Plugin 2.0.1 and earlier does not restrict a file name query parameter in an HTTP endpoint, allowing unauthenticated attackers to read arbitrary files with '.xml' extension on the Jenkins controller file system.... Read more

    Affected Products : config_rotator
    • EPSS Score: %0.18
    • Published: Nov. 15, 2022
    • Modified: Apr. 30, 2025
  • 5.4

    MEDIUM
    CVE-2022-45387

    Jenkins BART Plugin 1.0.3 and earlier does not escape the parsed content of build logs before rendering it on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability.... Read more

    Affected Products : bart
    • EPSS Score: %6.94
    • Published: Nov. 15, 2022
    • Modified: Apr. 30, 2025
  • 5.5

    MEDIUM
    CVE-2022-45386

    Jenkins Violations Plugin 0.7.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.... Read more

    Affected Products : violations
    • EPSS Score: %0.08
    • Published: Nov. 15, 2022
    • Modified: Apr. 30, 2025
  • 7.5

    HIGH
    CVE-2022-45385

    A missing permission check in Jenkins CloudBees Docker Hub/Registry Notification Plugin 2.6.2 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository.... Read more

    • EPSS Score: %0.11
    • Published: Nov. 15, 2022
    • Modified: Apr. 30, 2025
  • 6.5

    MEDIUM
    CVE-2022-45384

    Jenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores the LDAP manager password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.... Read more

    Affected Products : reverse_proxy_auth
    • EPSS Score: %0.08
    • Published: Nov. 15, 2022
    • Modified: Apr. 30, 2025
  • 6.1

    MEDIUM
    CVE-2022-43119

    A cross-site scripting (XSS) vulnerability in Clansphere CMS v2011.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username parameter.... Read more

    Affected Products : clansphere
    • EPSS Score: %0.26
    • Published: Nov. 09, 2022
    • Modified: Apr. 30, 2025
  • 5.5

    MEDIUM
    CVE-2022-43071

    A stack overflow in the Catalog::readPageLabelTree2(Object*) function of XPDF v4.04 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.... Read more

    Affected Products : xpdf
    • EPSS Score: %0.06
    • Published: Nov. 15, 2022
    • Modified: Apr. 30, 2025
Showing 20 of 291124 Results