Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.9

    MEDIUM
    CVE-2024-7567

    A denial-of-service vulnerability exists via the CIP/Modbus port in the Rockwell Automation Micro850/870 (2080 -L50E/2080 -L70E). If exploited, the CIP/Modbus communication may be disrupted for short duration.... Read more

    Affected Products : micro850_firmware micro870_firmware
    • Published: Aug. 13, 2024
    • Modified: Aug. 14, 2024
  • 6.5

    MEDIUM
    CVE-2024-42368

    OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs. The bearertokenauth extension's server authenticator perf... Read more

    Affected Products :
    • Published: Aug. 13, 2024
    • Modified: Aug. 14, 2024
  • 8.5

    HIGH
    CVE-2024-38206

    An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network.... Read more

    Affected Products : copilot_studio
    • Published: Aug. 06, 2024
    • Modified: Aug. 14, 2024
  • 8.2

    HIGH
    CVE-2024-38166

    An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamics 365 to spoof over a network by tricking a user to click on a link.... Read more

    • Published: Aug. 06, 2024
    • Modified: Aug. 14, 2024
  • 8.8

    HIGH
    CVE-2024-39091

    An OS command injection vulnerability in the ccm_debug component of MIPC Camera firmware prior to v5.4.1.240424171021 allows attackers within the same network to execute arbitrary code via a crafted HTML request.... Read more

    Affected Products : crater_2_firmware crater_2
    • Published: Aug. 12, 2024
    • Modified: Aug. 13, 2024
  • 9.9

    CRITICAL
    CVE-2024-6684

    Authentication Bypass Using an Alternate Path or Channel vulnerability in GST Electronics inohom Nova Panel N7 allows Authentication Bypass.This issue affects inohom Nova Panel N7: through 1.9.9.6. NOTE: The vendor was contacted and it was learned that th... Read more

    Affected Products :
    • Published: Aug. 12, 2024
    • Modified: Aug. 13, 2024
  • 8.8

    HIGH
    CVE-2024-42742

    In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUrlFilterRules. Authenticated Attackers can send malicious packet to execute arbitrary commands.... Read more

    Affected Products : x5000r_firmware x5000r
    • Published: Aug. 12, 2024
    • Modified: Aug. 13, 2024
  • 8.8

    HIGH
    CVE-2024-42623

    FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/delete/1... Read more

    Affected Products : frogcms
    • Published: Aug. 12, 2024
    • Modified: Aug. 13, 2024
  • 8.8

    HIGH
    CVE-2024-42743

    In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setSyslogCfg . Authenticated Attackers can send malicious packet to execute arbitrary commands.... Read more

    Affected Products : x5000r_firmware x5000r
    • Published: Aug. 12, 2024
    • Modified: Aug. 13, 2024
  • 8.8

    HIGH
    CVE-2024-42631

    FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/edit/1.... Read more

    Affected Products : frogcms
    • Published: Aug. 12, 2024
    • Modified: Aug. 13, 2024
  • 8.8

    HIGH
    CVE-2024-42627

    FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/delete/3.... Read more

    Affected Products : frogcms
    • Published: Aug. 12, 2024
    • Modified: Aug. 13, 2024
  • 9.8

    CRITICAL
    CVE-2024-42543

    TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.... Read more

    Affected Products : a3700r_firmware a3700r
    • Published: Aug. 12, 2024
    • Modified: Aug. 13, 2024
  • 9.8

    CRITICAL
    CVE-2024-42737

    In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in delBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands.... Read more

    Affected Products : x5000r_firmware x5000r
    • Published: Aug. 13, 2024
    • Modified: Aug. 13, 2024
  • 9.1

    CRITICAL
    CVE-2024-38200

    Microsoft Office Spoofing Vulnerability... Read more

    • Published: Aug. 12, 2024
    • Modified: Aug. 13, 2024
  • 8.8

    HIGH
    CVE-2024-42625

    FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/add... Read more

    Affected Products : frogcms
    • Published: Aug. 12, 2024
    • Modified: Aug. 13, 2024
  • 8.8

    HIGH
    CVE-2024-42747

    In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWanIeCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.... Read more

    Affected Products : x5000r_firmware x5000r
    • Published: Aug. 12, 2024
    • Modified: Aug. 13, 2024
  • 8.8

    HIGH
    CVE-2024-42741

    In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setL2tpServerCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.... Read more

    Affected Products : x5000r_firmware x5000r
    • Published: Aug. 12, 2024
    • Modified: Aug. 13, 2024
  • 6.1

    MEDIUM
    CVE-2024-21550

    SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management of registered charge points. Attackers can inject arbitrary HTML and Javascript code via WebSock... Read more

    Affected Products : steve
    • Published: Aug. 12, 2024
    • Modified: Aug. 13, 2024
  • 7.8

    HIGH
    CVE-2024-27442

    An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The zmmailboxdmgr binary, a component of ZCS, is intended to be executed by the zimbra user with root privileges for specific mailbox operations. However, an attacker can escalate privile... Read more

    Affected Products : collaboration
    • Published: Aug. 12, 2024
    • Modified: Aug. 13, 2024
  • 9.8

    CRITICAL
    CVE-2024-38530

    The Open eClass platform (formerly known as GUnet eClass) is a complete Course Management System. An arbitrary file upload vulnerability in the "save" functionality of the H5P module enables unauthenticated users to upload arbitrary files on the server's ... Read more

    Affected Products : openeclass
    • Published: Aug. 12, 2024
    • Modified: Aug. 13, 2024
Showing 20 of 290013 Results