Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2022-3846

    The Workreap WordPress theme before 2.6.3 has a vulnerability with the notifications feature as it's possible to read any user's notification (employer or freelancer) as the notification ID is brute-forceable.... Read more

    Affected Products : workreap
    • Published: Dec. 05, 2022
    • Modified: Apr. 23, 2025
  • 4.8

    MEDIUM
    CVE-2022-3838

    The WPUpper Share Buttons WordPress plugin through 3.42 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disa... Read more

    Affected Products : wpupper_share_buttons
    • Published: Dec. 05, 2022
    • Modified: Apr. 23, 2025
  • 7.8

    HIGH
    CVE-2022-39099

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more

    Affected Products : android s8000 sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 +4 more products
    • Published: Dec. 06, 2022
    • Modified: Apr. 23, 2025
  • 7.8

    HIGH
    CVE-2022-39098

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more

    Affected Products : android s8000 sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 +4 more products
    • Published: Dec. 06, 2022
    • Modified: Apr. 23, 2025
  • 7.8

    HIGH
    CVE-2022-39097

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more

    Affected Products : android s8000 sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 +4 more products
    • Published: Dec. 06, 2022
    • Modified: Apr. 23, 2025
  • 7.8

    HIGH
    CVE-2022-39096

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more

    Affected Products : android s8000 sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 +4 more products
    • Published: Dec. 06, 2022
    • Modified: Apr. 23, 2025
  • 7.8

    HIGH
    CVE-2022-39095

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more

    Affected Products : android s8000 sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 +4 more products
    • Published: Dec. 06, 2022
    • Modified: Apr. 23, 2025
  • 7.8

    HIGH
    CVE-2022-39094

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more

    Affected Products : android s8000 sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 +4 more products
    • Published: Dec. 06, 2022
    • Modified: Apr. 23, 2025
  • 7.8

    HIGH
    CVE-2022-39093

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more

    Affected Products : android s8000 sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 +4 more products
    • Published: Dec. 06, 2022
    • Modified: Apr. 23, 2025
  • 7.8

    HIGH
    CVE-2022-39092

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more

    Affected Products : android s8000 sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 +4 more products
    • Published: Dec. 06, 2022
    • Modified: Apr. 23, 2025
  • 7.8

    HIGH
    CVE-2022-39091

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more

    Affected Products : android s8000 sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 +4 more products
    • Published: Dec. 06, 2022
    • Modified: Apr. 23, 2025
  • 7.8

    HIGH
    CVE-2022-39090

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more

    Affected Products : android s8000 sc7731e sc9832e sc9863a t310 t606 t610 t612 t616 +4 more products
    • Published: Dec. 06, 2022
    • Modified: Apr. 23, 2025
  • 5.4

    MEDIUM
    CVE-2022-25630

    An authenticated user can embed malicious content with XSS into the admin group policy page.... Read more

    Affected Products : messaging_gateway
    • Published: Dec. 09, 2022
    • Modified: Apr. 23, 2025
  • 5.4

    MEDIUM
    CVE-2022-25629

    An authenticated user who has the privilege to add/edit annotations on the Content tab, can craft a malicious annotation that can be executed on the annotations page (Annotation Text Column).... Read more

    Affected Products : messaging_gateway
    • Published: Dec. 09, 2022
    • Modified: Apr. 23, 2025
  • 7.2

    HIGH
    CVE-2022-1540

    The PostmagThemes Demo Import WordPress plugin through 1.0.7 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as PHP) leading to RCE.... Read more

    Affected Products : postmagthemes_demo_import
    • Published: Dec. 05, 2022
    • Modified: Apr. 23, 2025
  • 9.8

    CRITICAL
    CVE-2020-6627

    The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a che... Read more

    • Published: Dec. 06, 2022
    • Modified: Apr. 23, 2025
  • 9.1

    CRITICAL
    CVE-2024-35049

    SurveyKing v1.3.1 was discovered to keep users' sessions active after logout. Related to an incomplete fix for CVE-2022-25590.... Read more

    Affected Products : surveyking
    • Published: May. 14, 2024
    • Modified: Apr. 23, 2025
  • 8.8

    HIGH
    CVE-2024-35050

    An issue in SurveyKing v1.3.1 allows attackers to escalate privileges via re-using the session ID of a user that was deleted by an Admin.... Read more

    Affected Products : surveyking
    • Published: May. 14, 2024
    • Modified: Apr. 23, 2025
  • 9.8

    CRITICAL
    CVE-2025-3174

    A vulnerability has been found in Project Worlds Online Lawyer Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /searchLawyer.php. The manipulation of the argument experience leads to... Read more

    • Published: Apr. 03, 2025
    • Modified: Apr. 23, 2025
    • Vuln Type: Injection
  • 8.8

    HIGH
    CVE-2024-44817

    SQL Injection vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the id parameter in the adv2.php component.... Read more

    Affected Products : zzcms
    • Published: Sep. 04, 2024
    • Modified: Apr. 23, 2025
Showing 20 of 293620 Results