Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 3.8

    LOW
    CVE-2024-31144

    For a brief summary of Xapi terminology, see: https://xapi-project.github.io/xen-api/overview.html#object-model-overview Xapi contains functionality to backup and restore metadata about Virtual Machines and Storage Repositories (SRs). The metadata ... Read more

    Affected Products : xen
    • Published: Feb. 14, 2025
    • Modified: Apr. 26, 2025
    • Vuln Type: Misconfiguration
  • 7.5

    HIGH
    CVE-2024-31143

    An optional feature of PCI MSI called "Multiple Message" allows a device to use multiple consecutive interrupt vectors. Unlike for MSI-X, the setting up of these consecutive vectors needs to happen all in one go. In this handling an error path could be ... Read more

    Affected Products : xen
    • Published: Jul. 18, 2024
    • Modified: Apr. 26, 2025
  • 6.5

    MEDIUM
    CVE-2023-28746

    Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.... Read more

    Affected Products :
    • Published: Mar. 14, 2024
    • Modified: Apr. 26, 2025
  • 7.4

    HIGH
    CVE-2025-22228

    BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters as long as the first 72 characters are the same.... Read more

    Affected Products : spring_security
    • Published: Mar. 20, 2025
    • Modified: Apr. 25, 2025
    • Vuln Type: Authentication
  • 7.8

    HIGH
    CVE-2024-9287

    A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source v... Read more

    Affected Products : python
    • Published: Oct. 22, 2024
    • Modified: Apr. 25, 2025
  • 9.8

    CRITICAL
    CVE-2024-6096

    In Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an insecure type resolution vulnerability.... Read more

    Affected Products : telerik_reporting
    • Published: Jul. 24, 2024
    • Modified: Apr. 25, 2025
  • 5.9

    MEDIUM
    CVE-2024-10846

    The compose-go library component in versions v2.10-v2.4.0 allows an authorized user who sends malicious YAML payloads to cause the compose-go to consume excessive amount of Memory and CPU cycles while parsing YAML, such as used by Docker Compose from vers... Read more

    Affected Products :
    • Published: Jan. 23, 2025
    • Modified: Apr. 25, 2025
    • Vuln Type: Denial of Service
  • 7.5

    HIGH
    CVE-2018-5733

    A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eventually overflow a 32-bit reference counter, potentially causing dhcpd to crash. Affects ISC DHCP 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8,... Read more

    • EPSS Score: %25.82
    • Published: Jan. 16, 2019
    • Modified: Apr. 25, 2025
  • 4.9

    MEDIUM
    CVE-2022-45535

    AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. This vulnerability allows attackers to access database information.... Read more

    Affected Products : aerocms
    • EPSS Score: %0.09
    • Published: Nov. 22, 2022
    • Modified: Apr. 25, 2025
  • 4.9

    MEDIUM
    CVE-2022-45529

    AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\includes\edit_post.php. This vulnerability allows attackers to access database information.... Read more

    Affected Products : aerocms
    • EPSS Score: %0.09
    • Published: Nov. 22, 2022
    • Modified: Apr. 25, 2025
  • 7.5

    HIGH
    CVE-2022-45331

    AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the p_id parameter at \post.php. This vulnerability allows attackers to access database information.... Read more

    Affected Products : aerocms
    • EPSS Score: %0.08
    • Published: Nov. 22, 2022
    • Modified: Apr. 25, 2025
  • 7.5

    HIGH
    CVE-2022-45330

    AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This vulnerability allows attackers to access database information.... Read more

    Affected Products : aerocms
    • EPSS Score: %0.08
    • Published: Nov. 22, 2022
    • Modified: Apr. 25, 2025
  • 9.8

    CRITICAL
    CVE-2022-44808

    A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests. Before the HNAP API function can proces... Read more

    Affected Products : dir-823g_firmware dir-823g
    • EPSS Score: %5.08
    • Published: Nov. 22, 2022
    • Modified: Apr. 25, 2025
  • 9.8

    CRITICAL
    CVE-2022-44252

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function.... Read more

    Affected Products : lr350_firmware lr350
    • EPSS Score: %1.39
    • Published: Nov. 23, 2022
    • Modified: Apr. 25, 2025
  • 9.8

    CRITICAL
    CVE-2022-44251

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function.... Read more

    Affected Products : lr350_firmware lr350
    • EPSS Score: %1.39
    • Published: Nov. 23, 2022
    • Modified: Apr. 25, 2025
  • 9.8

    CRITICAL
    CVE-2022-44250

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function.... Read more

    Affected Products : lr350_firmware lr350
    • EPSS Score: %1.39
    • Published: Nov. 23, 2022
    • Modified: Apr. 25, 2025
  • 9.8

    CRITICAL
    CVE-2022-44249

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFile function.... Read more

    Affected Products : lr350_firmware lr350
    • EPSS Score: %1.39
    • Published: Nov. 23, 2022
    • Modified: Apr. 25, 2025
  • 9.8

    CRITICAL
    CVE-2022-44139

    Apartment Visitor Management System v1.0 is vulnerable to SQL Injection via /avms/index.php.... Read more

    • EPSS Score: %0.08
    • Published: Nov. 23, 2022
    • Modified: Apr. 25, 2025
  • 9.8

    CRITICAL
    CVE-2022-44120

    dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php.... Read more

    Affected Products : dedecmsv6
    • EPSS Score: %0.07
    • Published: Nov. 23, 2022
    • Modified: Apr. 25, 2025
  • 4.8

    MEDIUM
    CVE-2022-42985

    The ScratchLogin extension through 1.1 for MediaWiki does not escape verification failure messages, which allows users with administrator privileges to perform cross-site scripting (XSS).... Read more

    Affected Products : scratch_login
    • EPSS Score: %0.14
    • Published: Nov. 17, 2022
    • Modified: Apr. 25, 2025
Showing 20 of 291756 Results