Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.7

    MEDIUM
    CVE-2022-20505

    In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitationProduct: Andro... Read more

    Affected Products : android
    • Published: Dec. 16, 2022
    • Modified: Apr. 21, 2025
  • 6.7

    MEDIUM
    CVE-2022-20504

    In multiple locations of DreamManagerService.java, there is a missing permission check. This could lead to local escalation of privilege and dismissal of system dialogs with User execution privileges needed. User interaction is not needed for exploitation... Read more

    Affected Products : android
    • Published: Dec. 16, 2022
    • Modified: Apr. 21, 2025
  • 7.8

    HIGH
    CVE-2022-20503

    In onCreate of WifiDppConfiguratorActivity.java, there is a possible way for a guest user to add a WiFi configuration due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User ... Read more

    Affected Products : android
    • Published: Dec. 16, 2022
    • Modified: Apr. 21, 2025
  • 5.5

    MEDIUM
    CVE-2022-20199

    In multiple locations of NfcService.java, there is a possible disclosure of NFC tags due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more

    Affected Products : android
    • Published: Dec. 16, 2022
    • Modified: Apr. 21, 2025
  • 9.8

    CRITICAL
    CVE-2021-38241

    Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers to run arbitrary code via weak cipher in Shiro framework.... Read more

    Affected Products : ruoyi
    • Published: Dec. 16, 2022
    • Modified: Apr. 21, 2025
  • 6.5

    MEDIUM
    CVE-2024-34517

    The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.... Read more

    Affected Products : neo4j
    • Published: May. 07, 2024
    • Modified: Apr. 21, 2025
  • 9.8

    CRITICAL
    CVE-2024-10702

    A vulnerability classified as critical has been found in code-projects Simple Car Rental System 1.0. Affected is an unknown function of the file /signup.php. The manipulation of the argument fname leads to sql injection. It is possible to launch the attac... Read more

    • Published: Nov. 02, 2024
    • Modified: Apr. 21, 2025
  • 5.4

    MEDIUM
    CVE-2022-4699

    The MediaElement.js WordPress plugin through 4.2.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting atta... Read more

    Affected Products : mediaelement.js mediaelement.js
    • Published: Jan. 30, 2023
    • Modified: Apr. 21, 2025
  • 5.5

    MEDIUM
    CVE-2023-40032

    libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libvips versions 8.14.3 or earlier to segfault when attempting to parse a malformed UTF-8 character. Users should upgrade to libvips versio... Read more

    Affected Products : fedora libvips
    • Published: Sep. 11, 2023
    • Modified: Apr. 21, 2025
  • 5.4

    MEDIUM
    CVE-2022-4749

    The Posts List Designer by Category WordPress plugin before 3.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site S... Read more

    Affected Products : posts_list_designer
    • Published: Jan. 30, 2023
    • Modified: Apr. 21, 2025
  • 5.4

    MEDIUM
    CVE-2022-4667

    The RSS Aggregator by Feedzy WordPress plugin before 4.1.1 does not validate and escape some of its block options before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting att... Read more

    Affected Products : rss_aggregator_by_feedzy
    • Published: Jan. 30, 2023
    • Modified: Apr. 21, 2025
  • 6.1

    MEDIUM
    CVE-2025-2583

    A vulnerability was found in SimpleMachines SMF 2.1.4. It has been classified as problematic. This affects an unknown part of the file ManageNews.php. The manipulation of the argument subject/message leads to cross site scripting. It is possible to initia... Read more

    Affected Products : simple_machines_forum
    • Published: Mar. 21, 2025
    • Modified: Apr. 21, 2025
    • Vuln Type: Cross-Site Scripting
  • 5.4

    MEDIUM
    CVE-2025-2582

    A vulnerability was found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this issue is some unknown functionality of the file ManageAttachments.php. The manipulation of the argument Notice leads to cross site scripting. The attack ... Read more

    Affected Products : simple_machines_forum
    • Published: Mar. 21, 2025
    • Modified: Apr. 21, 2025
    • Vuln Type: Cross-Site Scripting
  • 5.5

    MEDIUM
    CVE-2022-20570

    Product: AndroidVersions: Android kernelAndroid ID: A-230660904References: N/A... Read more

    Affected Products : android
    • Published: Dec. 16, 2022
    • Modified: Apr. 21, 2025
  • 6.7

    MEDIUM
    CVE-2022-20569

    In thermal_cooling_device_stats_update of thermal_sysfs.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction i... Read more

    Affected Products : android
    • Published: Dec. 16, 2022
    • Modified: Apr. 21, 2025
  • 7.8

    HIGH
    CVE-2022-20568

    In (TBD) of (TBD), there is a possible way to corrupt kernel memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidV... Read more

    Affected Products : android
    • Published: Dec. 16, 2022
    • Modified: Apr. 21, 2025
  • 9.3

    CRITICAL
    CVE-2025-22371

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SicommNet BASEC (SaaS Service) login page allows an unauthenticated remote attacker to Bypass Authentication and execute arbitrary SQL commands.This issu... Read more

    Affected Products :
    • Published: Apr. 14, 2025
    • Modified: Apr. 21, 2025
    • Vuln Type: Injection
  • 9.1

    CRITICAL
    CVE-2024-38428

    url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.... Read more

    Affected Products : wget
    • Published: Jun. 16, 2024
    • Modified: Apr. 21, 2025
  • 7.8

    HIGH
    CVE-2022-20547

    In multiple functions of AdapterService.java, there is a possible way to manipulate Bluetooth state due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not... Read more

    Affected Products : android
    • Published: Dec. 16, 2022
    • Modified: Apr. 21, 2025
  • 7.5

    HIGH
    CVE-2024-12905

    An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal"). This vulnerability occurs when extracting a maliciously crafted tar file, which can result in unauthorize... Read more

    Affected Products : tar-fs
    • Published: Mar. 27, 2025
    • Modified: Apr. 20, 2025
    • Vuln Type: Path Traversal
Showing 20 of 293254 Results