Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2022-38871

    In Free5gc v3.0.5, the AMF breaks due to malformed NAS messages.... Read more

    Affected Products : free5gc
    • EPSS Score: %0.08
    • Published: Nov. 18, 2022
    • Modified: Apr. 30, 2025
  • 6.7

    MEDIUM
    CVE-2022-20427

    In (TBD) of (TBD), there is a possible way to corrupt memory due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio... Read more

    Affected Products : android
    • EPSS Score: %0.01
    • Published: Nov. 17, 2022
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2021-24649

    The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption(). This could allow an attacker having ac... Read more

    Affected Products : wp_user_frontend
    • EPSS Score: %0.27
    • Published: Nov. 21, 2022
    • Modified: Apr. 30, 2025
  • 5.8

    MEDIUM
    CVE-2024-20291

    A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to send traffic that should be blocked throug... Read more

    • Published: Feb. 29, 2024
    • Modified: Apr. 30, 2025
  • 6.4

    MEDIUM
    CVE-2025-3457

    The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'oceanwp_icon' shortcode in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on user supplied attributes.... Read more

    Affected Products : ocean_extra
    • Published: Apr. 22, 2025
    • Modified: Apr. 30, 2025
    • Vuln Type: Cross-Site Scripting
  • 7.2

    HIGH
    CVE-2024-21682

    This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions). Assets Discovery, which can be downloaded via Atlassian Marketplace, is a network scanning tool that can be used with or without an agent with Jira... Read more

    Affected Products : assets_discovery_data_center
    • Published: Feb. 20, 2024
    • Modified: Apr. 30, 2025
  • 6.4

    MEDIUM
    CVE-2025-3458

    The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ocean_gallery_id’ parameter in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authe... Read more

    Affected Products : ocean_extra
    • Published: Apr. 22, 2025
    • Modified: Apr. 30, 2025
    • Vuln Type: Cross-Site Scripting
  • 9.8

    CRITICAL
    CVE-2025-3472

    The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shor... Read more

    Affected Products : ocean_extra
    • Published: Apr. 22, 2025
    • Modified: Apr. 30, 2025
    • Vuln Type: Authentication
  • 4.8

    MEDIUM
    CVE-2025-25431

    Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the The ssid key of wifi_data parameter on the /captive_portal.htm page.... Read more

    • Published: Feb. 28, 2025
    • Modified: Apr. 30, 2025
    • Vuln Type: Cross-Site Scripting
  • 6.5

    MEDIUM
    CVE-2025-29743

    D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting.... Read more

    Affected Products : dir-816_firmware dir-816
    • Published: Apr. 22, 2025
    • Modified: Apr. 30, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-45427

    In Tenda AC9 v1.0 with firmware V15.03.05.14_multi, the security parameter of /goform/WifiBasicSet has a stack overflow vulnerability, which can lead to remote arbitrary code execution.... Read more

    Affected Products : ac9_firmware ac9
    • Published: Apr. 23, 2025
    • Modified: Apr. 30, 2025
    • Vuln Type: Memory Corruption
  • 9.8

    CRITICAL
    CVE-2025-3341

    A vulnerability, which was classified as critical, was found in codeprojects Online Restaurant Management System 1.0. This affects an unknown part of the file /admin/reservation_view.php. The manipulation of the argument ID leads to sql injection. It is p... Read more

    • Published: Apr. 07, 2025
    • Modified: Apr. 30, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-3342

    A vulnerability has been found in codeprojects Online Restaurant Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/payment_save.php. The manipulation of the argument ID leads to sql injection. The... Read more

    • Published: Apr. 07, 2025
    • Modified: Apr. 30, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-3343

    A vulnerability was found in codeprojects Online Restaurant Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/reservation_update.php. The manipulation of the argument ID leads to sql injection.... Read more

    • Published: Apr. 07, 2025
    • Modified: Apr. 30, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-3344

    A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/assign_save.php. The manipulation of the argument ID leads to sql injection. It is po... Read more

    • Published: Apr. 07, 2025
    • Modified: Apr. 30, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-3345

    A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/combo.php. The manipulation of the argument del leads to sql... Read more

    • Published: Apr. 07, 2025
    • Modified: Apr. 30, 2025
    • Vuln Type: Injection
  • 7.5

    HIGH
    CVE-2025-29087

    In SQLite 3.44.0 through 3.49.0 before 3.49.1, the concat_ws() SQL function can cause memory to be written beyond the end of a malloc-allocated buffer. If the separator argument is attacker-controlled and has a large string (e.g., 2MB or more), an integer... Read more

    Affected Products : sqlite
    • Published: Apr. 07, 2025
    • Modified: Apr. 30, 2025
    • Vuln Type: Memory Corruption
  • 7.5

    HIGH
    CVE-2024-27570

    LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the generate_conf_router function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more

    • Published: Mar. 01, 2024
    • Modified: Apr. 30, 2025
  • 7.5

    HIGH
    CVE-2024-27572

    LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the updateCurAPlist function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more

    • Published: Mar. 01, 2024
    • Modified: Apr. 30, 2025
  • 7.5

    HIGH
    CVE-2024-27571

    LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the makeCurRemoteApList function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more

    • Published: Mar. 01, 2024
    • Modified: Apr. 30, 2025
Showing 20 of 291170 Results