Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.6

    HIGH
    CVE-2015-0576

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in HSDPA.... Read more

    Affected Products : android
    • EPSS Score: %0.14
    • Published: Aug. 18, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2017-12949

    lib\modules\contributors\contributor_list_table.php in the Podlove Podcast Publisher plugin 2.5.3 and earlier for WordPress has SQL injection in the orderby parameter to wp-admin/admin.php, exploitable through CSRF.... Read more

    Affected Products : podlove_podcast_publisher
    • EPSS Score: %0.72
    • Published: Aug. 18, 2017
    • Modified: Apr. 20, 2025
  • 6.1

    MEDIUM
    CVE-2017-16884

    Cross-site scripting (XSS) vulnerability in MistServer before 2.13 allows remote attackers to inject arbitrary web script or HTML via vectors related to failed authentication requests alerts.... Read more

    Affected Products : mistserver
    • EPSS Score: %8.04
    • Published: Dec. 07, 2017
    • Modified: Apr. 20, 2025
  • 9.8

    CRITICAL
    CVE-2017-12776

    SQL injection vulnerability in reports.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the delreport parameter.... Read more

    Affected Products : nexusphp
    • EPSS Score: %0.49
    • Published: Aug. 18, 2017
    • Modified: Apr. 20, 2025
  • 6.5

    MEDIUM
    CVE-2017-12623

    An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The fix to properly handle XML External Entities was applied on the Apache NiFi 1.4.0 release. Users running a ... Read more

    Affected Products : nifi
    • EPSS Score: %0.51
    • Published: Oct. 10, 2017
    • Modified: Apr. 20, 2025
  • 5.9

    MEDIUM
    CVE-2014-9686

    The Googlemaps plugin 3.2 and earlier for Joomla! allows remote attackers with control of a sub-domain belonging to a victim domain to cause a denial of service via the 'url' parameter to plugin_googlemap3_kmlprxy.php. NOTE: this vulnerability exists bec... Read more

    Affected Products : googlemaps
    • EPSS Score: %0.86
    • Published: Sep. 28, 2017
    • Modified: Apr. 20, 2025
  • 6.1

    MEDIUM
    CVE-2017-12413

    AXIS 2100 devices 2.43 have XSS via the URI, possibly related to admin/admin.shtml.... Read more

    • EPSS Score: %0.21
    • Published: Aug. 04, 2017
    • Modified: Apr. 20, 2025
  • 9.8

    CRITICAL
    CVE-2014-8621

    SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execute arbitrary SQL commands via the sl_custom_field parameter to sl-xml.php.... Read more

    Affected Products : store_locator
    • EPSS Score: %2.55
    • Published: Oct. 16, 2017
    • Modified: Apr. 20, 2025
  • 6.1

    MEDIUM
    CVE-2017-10838

    Cross-site scripting vulnerability in SEO Panel prior to version 3.11.0 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.... Read more

    Affected Products : seo_panel
    • EPSS Score: %0.21
    • Published: Aug. 29, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2017-12271

    A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute unwanted actions on an affected device. The vulnerability is due to a lack of cross-site request forgery (CSRF) protection. An attacker ... Read more

    • EPSS Score: %0.28
    • Published: Oct. 19, 2017
    • Modified: Apr. 20, 2025
  • 6.1

    MEDIUM
    CVE-2014-9310

    Cross-site scripting (XSS) vulnerability in the WordPress Backup to Dropbox plugin before 4.1 for WordPress.... Read more

    Affected Products : wordpress_backup_to_dropbox
    • EPSS Score: %0.40
    • Published: Jun. 07, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2014-8903

    IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10 and 6.0.5 before 6.0.5.6 allows remote authenticated users to load arbitrary Java classes via unspecified vectors.... Read more

    Affected Products : curam_social_program_management
    • EPSS Score: %0.85
    • Published: Aug. 02, 2017
    • Modified: Apr. 20, 2025
  • 5.4

    MEDIUM
    CVE-2017-16781

    The installer in MyBB before 1.8.13 has XSS.... Read more

    Affected Products : mybb
    • EPSS Score: %0.27
    • Published: Nov. 10, 2017
    • Modified: Apr. 20, 2025
  • 7.5

    HIGH
    CVE-2014-7851

    oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session data to gain that user's privileges by replacing their session token with th... Read more

    Affected Products : ovirt-engine ovirt
    • EPSS Score: %0.39
    • Published: Oct. 16, 2017
    • Modified: Apr. 20, 2025
  • 9.8

    CRITICAL
    CVE-2017-11161

    Multiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to label.php; or (2) type parameter to synotheme.php.... Read more

    Affected Products : photo_station
    • EPSS Score: %0.58
    • Published: Sep. 08, 2017
    • Modified: Apr. 20, 2025
  • 7.5

    HIGH
    CVE-2017-15581

    In the "Diary with lock" (aka WriteDiary) application 4.72 for Android, neither HTTPS nor other encryption is used for transmitting data, despite the documentation that the product is intended for "a personal journal of ... secrets and feelings," which al... Read more

    Affected Products : diary_with_lock
    • EPSS Score: %0.75
    • Published: Oct. 27, 2017
    • Modified: Apr. 20, 2025
  • 7.5

    HIGH
    CVE-2017-11155

    An information exposure vulnerability in index.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to obtain sensitive system information via unspecified vectors.... Read more

    Affected Products : photo_station
    • EPSS Score: %35.18
    • Published: Aug. 08, 2017
    • Modified: Apr. 20, 2025
  • 6.1

    MEDIUM
    CVE-2017-10801

    phpSocial (formerly phpDolphin) before 3.0.1 has XSS in the PATH_INFO to the search/tag/ URI.... Read more

    Affected Products : phpsocial
    • EPSS Score: %0.30
    • Published: Jul. 19, 2017
    • Modified: Apr. 20, 2025
  • 4.8

    MEDIUM
    CVE-2017-7241

    A cross-site scripting (XSS) vulnerability in the MantisBT Move Attachments page (move_attachments_page.php, part of admin tools) allows remote attackers to inject arbitrary code through a crafted 'type' parameter, if Content Security Protection (CSP) set... Read more

    Affected Products : mantisbt
    • EPSS Score: %0.80
    • Published: Mar. 31, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2017-5156

    A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The client request may be forged from a different site. This will allow an external site to access internal RDP systems o... Read more

    • EPSS Score: %0.13
    • Published: Apr. 20, 2017
    • Modified: Apr. 20, 2025
Showing 20 of 292495 Results