Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.5

    MEDIUM
    CVE-2024-29368

    An arbitrary file upload vulnerability in the file handling module of moziloCMS v2.0 allows attackers to bypass extension restrictions via file renaming, potentially leading to unauthorized file execution or storage of malicious content.... Read more

    Affected Products : mozilocms
    • Published: Apr. 22, 2024
    • Modified: Apr. 30, 2025
  • 4.7

    MEDIUM
    CVE-2024-30890

    Cross Site Scripting vulnerability in ED01-CMS v.1.0 allows an attacker to obtain sensitive information via the categories.php component.... Read more

    Affected Products : ed01-cms
    • Published: Apr. 25, 2024
    • Modified: Apr. 30, 2025
  • 5.0

    MEDIUM
    CVE-2024-31574

    Cross Site Scripting vulnerability in TWCMS v.2.6 allows a local attacker to execute arbitrary code via a crafted script... Read more

    Affected Products : twcms
    • Published: Apr. 25, 2024
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2024-39331

    In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.... Read more

    Affected Products : emacs
    • Published: Jun. 23, 2024
    • Modified: Apr. 30, 2025
  • 6.1

    MEDIUM
    CVE-2024-45527

    REDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSRF via index.php?logout=1, and can also be used to insert a link to an external phishing website.... Read more

    Affected Products : redcap
    • Published: Sep. 02, 2024
    • Modified: Apr. 30, 2025
  • 8.1

    HIGH
    CVE-2025-30093

    HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before 24.6.1 allows authenticated attackers to bypass authorization restrictions.... Read more

    Affected Products : htcondor
    • Published: Mar. 27, 2025
    • Modified: Apr. 30, 2025
    • Vuln Type: Authorization
  • 5.4

    MEDIUM
    CVE-2024-55072

    A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows users to edit their own profile in order to give themselves more permissions or to change their household.... Read more

    Affected Products : mealie
    • Published: Mar. 27, 2025
    • Modified: Apr. 30, 2025
    • Vuln Type: Authorization
  • 7.5

    HIGH
    CVE-2024-57519

    An issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in lib/dbi/subscription.c file.... Read more

    Affected Products : open5gs
    • Published: Jan. 28, 2025
    • Modified: Apr. 30, 2025
    • Vuln Type: Denial of Service
  • 6.4

    MEDIUM
    CVE-2024-48954

    An issue was discovered in Logpoint before 7.5.0. Unvalidated input during the EventHub Collector setup by an authenticated user leads to Remote Code execution.... Read more

    Affected Products : siem
    • Published: Nov. 07, 2024
    • Modified: Apr. 30, 2025
  • 6.7

    MEDIUM
    CVE-2024-20021

    In atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0... Read more

    Affected Products : android mt6781 mt6785 mt6833 mt6853 mt6873 mt6877 mt6885 mt6893 mt8675 +36 more products
    • Published: May. 06, 2024
    • Modified: Apr. 30, 2025
  • 8.1

    HIGH
    CVE-2024-42991

    MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.... Read more

    Affected Products : mcms
    • Published: Sep. 03, 2024
    • Modified: Apr. 30, 2025
  • 6.7

    MEDIUM
    CVE-2024-20056

    In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08528185; ... Read more

    Affected Products : android openwrt rdk-b mt6781 mt6785 mt6789 mt6833 mt6835 mt6853 mt6855 +20 more products
    • Published: May. 06, 2024
    • Modified: Apr. 30, 2025
  • 6.4

    MEDIUM
    CVE-2024-49200

    An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential DXE memory corruption vulnerability has been identified. The root cause is use of a pointer originating from the value of an NVRAM varia... Read more

    Affected Products : kernel
    • Published: Apr. 15, 2025
    • Modified: Apr. 30, 2025
    • Vuln Type: Memory Corruption
  • 7.5

    HIGH
    CVE-2025-29088

    In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64-bit integer, and consequently some memory allocations may... Read more

    Affected Products : sqlite
    • Published: Apr. 10, 2025
    • Modified: Apr. 30, 2025
    • Vuln Type: Denial of Service
  • 7.2

    HIGH
    CVE-2024-20057

    In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08587881; Issue ... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6789 mt6833 mt6835 mt6853 mt6855 mt6873 +28 more products
    • Published: May. 06, 2024
    • Modified: Apr. 30, 2025
  • 8.8

    HIGH
    CVE-2025-29017

    A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the profile_pic parameter within pages_view_client.php.... Read more

    • Published: Apr. 10, 2025
    • Modified: Apr. 30, 2025
    • Vuln Type: Authentication
  • 4.4

    MEDIUM
    CVE-2024-20058

    In keyInstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580204; Issue ID... Read more

    Affected Products : android mt6785 mt6833 mt6853 mt6855 mt6893 mt8791t mt8797 mt6765 mt6768 +16 more products
    • Published: May. 06, 2024
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2025-22926

    An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename.... Read more

    Affected Products : opensis
    • Published: Apr. 03, 2025
    • Modified: Apr. 30, 2025
    • Vuln Type: Path Traversal
  • 6.7

    MEDIUM
    CVE-2024-20059

    In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue I... Read more

    Affected Products : android mt6781 mt6789 mt6833 mt6835 mt6853 mt6855 mt6877 mt6879 mt6883 +16 more products
    • Published: May. 06, 2024
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2024-38985

    janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via in... Read more

    Affected Products : depath
    • Published: Mar. 28, 2025
    • Modified: Apr. 30, 2025
    • Vuln Type: Misconfiguration
Showing 20 of 291216 Results