Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2022-44204

    D-Link DIR3060 DIR3060A1_FW111B04.bin is vulnerable to Buffer Overflow.... Read more

    Affected Products : dir-3060_firmware dir-3060
    • EPSS Score: %4.53
    • Published: Nov. 18, 2022
    • Modified: Apr. 30, 2025
  • 5.3

    MEDIUM
    CVE-2022-44005

    An issue was discovered in BACKCLICK Professional 5.9.63. Due to the use of consecutive IDs in verification links, the newsletter sign-up functionality is vulnerable to the enumeration of subscribers' e-mail addresses. Furthermore, it is possible to subsc... Read more

    Affected Products : backclick
    • EPSS Score: %0.10
    • Published: Nov. 16, 2022
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2022-44004

    An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthenticated attackers can complete the password-reset process for any account and set a new password.... Read more

    Affected Products : backclick
    • EPSS Score: %0.22
    • Published: Nov. 16, 2022
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2022-44003

    An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the application is vulnerable to SQL injection at various locations.... Read more

    Affected Products : backclick
    • EPSS Score: %0.07
    • Published: Nov. 16, 2022
    • Modified: Apr. 30, 2025
  • 4.7

    MEDIUM
    CVE-2022-43673

    Wire through 3.22.3993 on Windows advertises deletion of sent messages; nonetheless, all messages can be retrieved (for a limited period of time) from the AppData\Roaming\Wire\IndexedDB\https_app.wire.com_0.indexeddb.leveldb database.... Read more

    Affected Products : wire wire-server
    • EPSS Score: %0.04
    • Published: Nov. 18, 2022
    • Modified: Apr. 30, 2025
  • 7.8

    HIGH
    CVE-2022-43308

    INTELBRAS SG 2404 MR 20180928-rel64938 allows authenticated attackers to arbitrarily create Administrator accounts via crafted user cookies.... Read more

    • EPSS Score: %0.03
    • Published: Nov. 18, 2022
    • Modified: Apr. 30, 2025
  • 7.5

    HIGH
    CVE-2022-43140

    kkFileView v4.1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component cn.keking.web.controller.OnlinePreviewController#getCorsFile. This vulnerability allows attackers to force the application to make arbitrary requests via in... Read more

    Affected Products : kkfileview
    • EPSS Score: %75.79
    • Published: Nov. 17, 2022
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2022-43138

    Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.... Read more

    Affected Products : dolibarr_erp\/crm
    • EPSS Score: %0.10
    • Published: Nov. 17, 2022
    • Modified: Apr. 30, 2025
  • 7.5

    HIGH
    CVE-2022-42982

    BKG Professional NtripCaster 2.0.39 allows querying information over the UDP protocol without authentication. The NTRIP sourcetable is typically quite long (tens of kBs) and can be requested with a packet of only 30 bytes. This presents a vector that can ... Read more

    Affected Products : bkg_professional_ntripcaster
    • EPSS Score: %0.20
    • Published: Nov. 17, 2022
    • Modified: Apr. 30, 2025
  • 7.2

    HIGH
    CVE-2022-42904

    Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.... Read more

    Affected Products : manageengine_admanager_plus
    • EPSS Score: %13.03
    • Published: Nov. 18, 2022
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2022-3600

    The Easy Digital Downloads WordPress plugin before 3.1.0.2 does not validate data when its output in a CSV file, which could lead to CSV injection.... Read more

    • EPSS Score: %0.54
    • Published: Nov. 21, 2022
    • Modified: Apr. 30, 2025
  • 4.3

    MEDIUM
    CVE-2022-3336

    The Event Monster WordPress plugin before 1.2.0 does not have CSRF check when deleting visitors, which could allow attackers to make logged in admin delete arbitrary visitors via a CSRF attack... Read more

    Affected Products : event_monster
    • EPSS Score: %0.17
    • Published: Nov. 21, 2022
    • Modified: Apr. 30, 2025
  • 7.5

    HIGH
    CVE-2022-38871

    In Free5gc v3.0.5, the AMF breaks due to malformed NAS messages.... Read more

    Affected Products : free5gc
    • EPSS Score: %0.08
    • Published: Nov. 18, 2022
    • Modified: Apr. 30, 2025
  • 6.7

    MEDIUM
    CVE-2022-20427

    In (TBD) of (TBD), there is a possible way to corrupt memory due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio... Read more

    Affected Products : android
    • EPSS Score: %0.01
    • Published: Nov. 17, 2022
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2021-24649

    The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption(). This could allow an attacker having ac... Read more

    Affected Products : wp_user_frontend
    • EPSS Score: %0.27
    • Published: Nov. 21, 2022
    • Modified: Apr. 30, 2025
  • 5.8

    MEDIUM
    CVE-2024-20291

    A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to send traffic that should be blocked throug... Read more

    • Published: Feb. 29, 2024
    • Modified: Apr. 30, 2025
  • 6.4

    MEDIUM
    CVE-2025-3457

    The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'oceanwp_icon' shortcode in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on user supplied attributes.... Read more

    Affected Products : ocean_extra
    • Published: Apr. 22, 2025
    • Modified: Apr. 30, 2025
    • Vuln Type: Cross-Site Scripting
  • 7.2

    HIGH
    CVE-2024-21682

    This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions). Assets Discovery, which can be downloaded via Atlassian Marketplace, is a network scanning tool that can be used with or without an agent with Jira... Read more

    Affected Products : assets_discovery_data_center
    • Published: Feb. 20, 2024
    • Modified: Apr. 30, 2025
  • 6.4

    MEDIUM
    CVE-2025-3458

    The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ocean_gallery_id’ parameter in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authe... Read more

    Affected Products : ocean_extra
    • Published: Apr. 22, 2025
    • Modified: Apr. 30, 2025
    • Vuln Type: Cross-Site Scripting
  • 9.8

    CRITICAL
    CVE-2025-3472

    The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shor... Read more

    Affected Products : ocean_extra
    • Published: Apr. 22, 2025
    • Modified: Apr. 30, 2025
    • Vuln Type: Authentication
Showing 20 of 291193 Results