Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2024-48227

    Funadmin 5.0.2 has a logical flaw in the Curd one click command deletion function, which can result in a Denial of Service (DOS).... Read more

    Affected Products : funadmin
    • Published: Oct. 25, 2024
    • Modified: Oct. 31, 2024
  • 9.8

    CRITICAL
    CVE-2024-48223

    Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.... Read more

    Affected Products : funadmin
    • Published: Oct. 25, 2024
    • Modified: Oct. 31, 2024
  • 9.8

    CRITICAL
    CVE-2024-48222

    Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit.... Read more

    Affected Products : funadmin
    • Published: Oct. 25, 2024
    • Modified: Oct. 31, 2024
  • 9.8

    CRITICAL
    CVE-2024-48218

    Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list.... Read more

    Affected Products : funadmin
    • Published: Oct. 25, 2024
    • Modified: Oct. 31, 2024
  • 9.8

    CRITICAL
    CVE-2024-48226

    Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.... Read more

    Affected Products : funadmin
    • Published: Oct. 25, 2024
    • Modified: Oct. 31, 2024
  • 9.1

    CRITICAL
    CVE-2024-48225

    Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile.... Read more

    Affected Products : funadmin
    • Published: Oct. 25, 2024
    • Modified: Oct. 31, 2024
  • 5.0

    MEDIUM
    CVE-2023-31310

    Improper input validation in Power Management Firmware (PMFW) may allow an attacker with privileges to send a malformed input for the "set temperature input selection" command, potentially resulting in a loss of integrity and/or availability.... Read more

    Affected Products :
    • Published: Aug. 13, 2024
    • Modified: Oct. 31, 2024
  • 7.5

    HIGH
    CVE-2024-48224

    Funadmin v5.0.2 has an arbitrary file read vulnerability in /curd/index/editfile.... Read more

    Affected Products : funadmin
    • Published: Oct. 25, 2024
    • Modified: Oct. 31, 2024
  • 7.1

    HIGH
    CVE-2024-49635

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Manzurul Haque Banner Slider allows Reflected XSS.This issue affects Banner Slider: from n/a through 2.1.... Read more

    Affected Products : banner_slider
    • Published: Oct. 29, 2024
    • Modified: Oct. 31, 2024
  • 5.3

    MEDIUM
    CVE-2023-50355

    HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information to launch another, more focused attack.... Read more

    Affected Products : sametime
    • Published: Oct. 23, 2024
    • Modified: Oct. 31, 2024
  • 5.5

    MEDIUM
    CVE-2024-49980

    In the Linux kernel, the following vulnerability has been resolved: vrf: revert "vrf: Remove unnecessary RCU-bh critical section" This reverts commit 504fc6f4f7f681d2a03aa5f68aad549d90eab853. dev_queue_xmit_nit is expected to be called with BH disabled... Read more

    Affected Products : linux_kernel
    • Published: Oct. 21, 2024
    • Modified: Oct. 31, 2024
  • 5.5

    MEDIUM
    CVE-2022-49000

    In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix PCI device refcount leak in has_external_pci() for_each_pci_dev() is implemented by pci_get_device(). The comment of pci_get_device() says that it will increase the refe... Read more

    Affected Products : linux_kernel
    • Published: Oct. 21, 2024
    • Modified: Oct. 31, 2024
  • 7.1

    HIGH
    CVE-2024-49637

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Foxskav Bet WC 2018 Russia allows Reflected XSS.This issue affects Bet WC 2018 Russia: from n/a through 2.1.... Read more

    Affected Products : bet_wc_2018_russia
    • Published: Oct. 29, 2024
    • Modified: Oct. 31, 2024
  • 7.1

    HIGH
    CVE-2024-49636

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Prashant Mavinkurve Agile Video Player Lite allows Reflected XSS.This issue affects Agile Video Player Lite: from n/a through 1.0.... Read more

    Affected Products : agile_video_player_lite
    • Published: Oct. 29, 2024
    • Modified: Oct. 31, 2024
  • 7.1

    HIGH
    CVE-2022-48999

    In the Linux kernel, the following vulnerability has been resolved: ipv4: Handle attempt to delete multipath route when fib_info contains an nh reference Gwangun Jung reported a slab-out-of-bounds access in fib_nh_match: fib_nh_match+0xf98/0x1130 li... Read more

    Affected Products : linux_kernel
    • Published: Oct. 21, 2024
    • Modified: Oct. 31, 2024
  • 7.2

    HIGH
    CVE-2024-41153

    Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of arbitrary system commands. If exploited, an attacker with write access to the web UI can execute commands on the device with root privil... Read more

    • Published: Oct. 29, 2024
    • Modified: Oct. 31, 2024
  • 5.5

    MEDIUM
    CVE-2024-20462

    A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter firmware could allow an authenticated, local attacker with low privileges to view passwords on an affected device. This vulnerability i... Read more

    • Published: Oct. 16, 2024
    • Modified: Oct. 31, 2024
  • 6.1

    MEDIUM
    CVE-2024-20460

    A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user. This vulnerability ... Read more

    • Published: Oct. 16, 2024
    • Modified: Oct. 31, 2024
  • 7.1

    HIGH
    CVE-2024-20421

    A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affec... Read more

    • Published: Oct. 16, 2024
    • Modified: Oct. 31, 2024
  • 8.8

    HIGH
    CVE-2024-20420

    A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an authenticated, remote attacker with low privileges to run commands as an Admin user. This vulnerability is due to incorrect ... Read more

    • Published: Oct. 16, 2024
    • Modified: Oct. 31, 2024
Showing 20 of 291275 Results