Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.4

    MEDIUM
    CVE-2024-48954

    An issue was discovered in Logpoint before 7.5.0. Unvalidated input during the EventHub Collector setup by an authenticated user leads to Remote Code execution.... Read more

    Affected Products : siem
    • Published: Nov. 07, 2024
    • Modified: Apr. 30, 2025
  • 6.7

    MEDIUM
    CVE-2024-20021

    In atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0... Read more

    Affected Products : android mt6781 mt6785 mt6833 mt6853 mt6873 mt6877 mt6885 mt6893 mt8675 +36 more products
    • Published: May. 06, 2024
    • Modified: Apr. 30, 2025
  • 8.1

    HIGH
    CVE-2024-42991

    MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.... Read more

    Affected Products : mcms
    • Published: Sep. 03, 2024
    • Modified: Apr. 30, 2025
  • 6.7

    MEDIUM
    CVE-2024-20056

    In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08528185; ... Read more

    Affected Products : android openwrt rdk-b mt6781 mt6785 mt6789 mt6833 mt6835 mt6853 mt6855 +20 more products
    • Published: May. 06, 2024
    • Modified: Apr. 30, 2025
  • 6.4

    MEDIUM
    CVE-2024-49200

    An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential DXE memory corruption vulnerability has been identified. The root cause is use of a pointer originating from the value of an NVRAM varia... Read more

    Affected Products : kernel
    • Published: Apr. 15, 2025
    • Modified: Apr. 30, 2025
  • 7.5

    HIGH
    CVE-2025-29088

    In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64-bit integer, and consequently some memory allocations may... Read more

    Affected Products : sqlite
    • Published: Apr. 10, 2025
    • Modified: Apr. 30, 2025
  • 7.2

    HIGH
    CVE-2024-20057

    In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08587881; Issue ... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6789 mt6833 mt6835 mt6853 mt6855 mt6873 +28 more products
    • Published: May. 06, 2024
    • Modified: Apr. 30, 2025
  • 8.8

    HIGH
    CVE-2025-29017

    A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the profile_pic parameter within pages_view_client.php.... Read more

    • Published: Apr. 10, 2025
    • Modified: Apr. 30, 2025
  • 4.4

    MEDIUM
    CVE-2024-20058

    In keyInstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580204; Issue ID... Read more

    Affected Products : android mt6785 mt6833 mt6853 mt6855 mt6893 mt8791t mt8797 mt6765 mt6768 +16 more products
    • Published: May. 06, 2024
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2025-22926

    An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename.... Read more

    Affected Products : opensis
    • Published: Apr. 03, 2025
    • Modified: Apr. 30, 2025
  • 6.7

    MEDIUM
    CVE-2024-20059

    In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue I... Read more

    Affected Products : android mt6781 mt6789 mt6833 mt6835 mt6853 mt6855 mt6877 mt6879 mt6883 +16 more products
    • Published: May. 06, 2024
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2024-38985

    janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via in... Read more

    Affected Products : depath
    • Published: Mar. 28, 2025
    • Modified: Apr. 30, 2025
  • 5.9

    MEDIUM
    CVE-2024-20060

    In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue I... Read more

    Affected Products : android mt6781 mt6789 mt6833 mt6835 mt6853 mt6855 mt6877 mt6879 mt6883 +16 more products
    • Published: May. 06, 2024
    • Modified: Apr. 30, 2025
  • 8.8

    HIGH
    CVE-2024-37765

    Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.... Read more

    Affected Products : machform
    • Published: Jul. 01, 2024
    • Modified: Apr. 30, 2025
  • 5.4

    MEDIUM
    CVE-2024-37764

    MachForm up to version 19 is affected by an authenticated stored cross-site scripting.... Read more

    Affected Products : machform
    • Published: Jul. 01, 2024
    • Modified: Apr. 30, 2025
  • 5.4

    MEDIUM
    CVE-2024-37763

    MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can view compiled forms results.... Read more

    Affected Products : machform
    • Published: Jul. 01, 2024
    • Modified: Apr. 30, 2025
  • 9.9

    CRITICAL
    CVE-2024-37762

    MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.... Read more

    Affected Products : machform
    • Published: Jul. 01, 2024
    • Modified: Apr. 30, 2025
  • 7.5

    HIGH
    CVE-2024-48951

    An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoint's API Token leading to authentication bypass.... Read more

    Affected Products : siem
    • Published: Nov. 07, 2024
    • Modified: Apr. 30, 2025
  • 6.4

    MEDIUM
    CVE-2024-48952

    An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints without authentication. This static key vulnerability enables attackers to create custom JWT secret keys for una... Read more

    Affected Products : soar
    • Published: Nov. 07, 2024
    • Modified: Apr. 30, 2025
  • 7.5

    HIGH
    CVE-2024-48953

    An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users to register their own authentication plugins in Logpoi... Read more

    Affected Products : siem
    • Published: Nov. 07, 2024
    • Modified: Apr. 30, 2025
Showing 20 of 291058 Results