Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.1

    MEDIUM
    CVE-2023-1413

    The WP VR WordPress plugin before 8.2.9 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more

    Affected Products : wp_vr wp_vr
    • Published: Apr. 17, 2023
    • Modified: Apr. 23, 2025
  • 4.8

    MEDIUM
    CVE-2023-1400

    The Modern Events Calendar Lite WordPress plugin before 6.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability i... Read more

    Affected Products : modern_events_calendar_lite
    • Published: Mar. 27, 2023
    • Modified: Apr. 23, 2025
  • 7.5

    HIGH
    CVE-2023-1390

    A remote denial of service vulnerability was found in the Linux kernel’s TIPC kernel module. The while loop in tipc_link_xmit() hits an unknown state while attempting to parse SKBs, which are not in the queue. Sending two small UDP packets to a system wit... Read more

    Affected Products : linux_kernel
    • Published: Mar. 16, 2023
    • Modified: Apr. 23, 2025
  • 7.8

    HIGH
    CVE-2023-1252

    A use-after-free flaw was found in the Linux kernel’s Ext4 File System in how a user triggers several file operations simultaneously with the overlay FS usage. This flaw allows a local user to crash or potentially escalate their privileges on the system. ... Read more

    Affected Products : linux_kernel
    • Published: Mar. 23, 2023
    • Modified: Apr. 23, 2025
  • 7.8

    HIGH
    CVE-2023-1118

    A flaw use after free in the Linux kernel integrated infrared receiver/transceiver driver was found in the way user detaching rc device. A local user could use this flaw to crash the system or potentially escalate their privileges on the system.... Read more

    Affected Products : linux_kernel
    • Published: Mar. 02, 2023
    • Modified: Apr. 23, 2025
  • 6.6

    MEDIUM
    CVE-2023-1073

    A memory corruption flaw was found in the Linux kernel’s human interface device (HID) subsystem in how a user inserts a malicious USB device. This flaw allows a local user to crash or potentially escalate their privileges on the system.... Read more

    Affected Products : linux_kernel enterprise_linux fedora
    • Published: Mar. 27, 2023
    • Modified: Apr. 23, 2025
  • 7.8

    HIGH
    CVE-2023-0950

    Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a spreadsheet document that will cause an array index underflow when loaded. In the affected versions of Libre... Read more

    Affected Products : debian_linux libreoffice
    • Published: May. 25, 2023
    • Modified: Apr. 23, 2025
  • 8.8

    HIGH
    CVE-2023-0603

    The Sloth Logo Customizer WordPress plugin through 2.0.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack... Read more

    Affected Products : sloth_logo_customizer
    • Published: May. 08, 2023
    • Modified: Apr. 23, 2025
  • 7.2

    HIGH
    CVE-2023-0329

    The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator rol... Read more

    Affected Products : website_builder
    • Published: May. 30, 2023
    • Modified: Apr. 23, 2025
  • 5.4

    MEDIUM
    CVE-2022-4827

    The WP Tiles WordPress plugin through 1.1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Store... Read more

    Affected Products : wp_tiles
    • Published: Apr. 10, 2023
    • Modified: Apr. 23, 2025
  • 9.8

    CRITICAL
    CVE-2022-46383

    RackN Digital Rebar through 4.6.14, 4.7 through 4.7.22, 4.8 through 4.8.5, 4.9 through 4.9.12, and 4.10 through 4.10.8 has exposed a privileged token via a public API endpoint (Incorrect Access Control). The token can be used to escalate privileges within... Read more

    Affected Products : digital_rebar
    • Published: Dec. 06, 2022
    • Modified: Apr. 23, 2025
  • 8.8

    HIGH
    CVE-2022-46382

    RackN Digital Rebar through 4.6.14, 4.7 through 4.7.22, 4.8 through 4.8.5, 4.9 through 4.9.12, and 4.10 through 4.10.8 has Insecure Permissions. After signing into Digital Rebar, users are issued authentication tokens tied to their account to perform acti... Read more

    Affected Products : digital_rebar
    • Published: Dec. 06, 2022
    • Modified: Apr. 23, 2025
  • 7.5

    HIGH
    CVE-2022-44030

    Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.... Read more

    Affected Products : redmine
    • Published: Dec. 06, 2022
    • Modified: Apr. 23, 2025
  • 6.1

    MEDIUM
    CVE-2022-43369

    AutoTaxi Stand Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component search.php.... Read more

    • Published: Dec. 06, 2022
    • Modified: Apr. 23, 2025
  • 4.8

    MEDIUM
    CVE-2022-37406

    Cross-site scripting vulnerability in Aficio SP 4210N firmware versions prior to Web Support 1.05 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.... Read more

    • Published: Dec. 07, 2022
    • Modified: Apr. 23, 2025
  • 6.5

    MEDIUM
    CVE-2022-34840

    Use of hard-coded credentials vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to alter?configuration settings of the device. The affected products/versions are as follows: WZR-300HP firmware Ver. 2.00 and earlier, WZR-... Read more

    • Published: Dec. 07, 2022
    • Modified: Apr. 23, 2025
  • 6.1

    MEDIUM
    CVE-2022-2311

    The Find and Replace All WordPress plugin before 1.3 does not sanitize and escape some parameters from its setting page before outputting them back to the user, leading to a Reflected Cross-Site Scripting issue.... Read more

    Affected Products : find_and_replace_all
    • Published: Nov. 28, 2022
    • Modified: Apr. 23, 2025
  • 7.5

    HIGH
    CVE-2022-29244

    npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=<name>`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 an... Read more

    • Published: Jun. 13, 2022
    • Modified: Apr. 23, 2025
  • 5.4

    MEDIUM
    CVE-2020-36656

    The Spectra WordPress plugin before 1.15.0 does not sanitize user input as it reaches its style HTML attribute, allowing contributors to conduct stored XSS attacks via the plugin's Gutenberg blocks.... Read more

    Affected Products : spectra
    • Published: Feb. 21, 2023
    • Modified: Apr. 23, 2025
  • 9.8

    CRITICAL
    CVE-2025-3439

    The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.1 via deserialization of untrusted input from the 'field_v... Read more

    Affected Products : everest_forms
    • Published: Apr. 11, 2025
    • Modified: Apr. 23, 2025
    • Vuln Type: Injection
Showing 20 of 293612 Results