Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2024-9037

    A vulnerability classified as critical has been found in Codezips Internal Marks Calculation 1.0. Affected is an unknown function of the file index.php. The manipulation of the argument tid leads to sql injection. It is possible to launch the attack remot... Read more

    Affected Products : internal_marks_calculation
    • Published: Sep. 20, 2024
    • Modified: Aug. 27, 2025
  • 6.5

    MEDIUM
    CVE-2024-9036

    A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin_add.php. The manipulation of the argument image leads to unrestricted upload. The attack may be ini... Read more

    • Published: Sep. 20, 2024
    • Modified: Aug. 27, 2025
  • 7.5

    HIGH
    CVE-2024-9035

    A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/login.php of the component Admin Login. The manipulation of the argument username/password lea... Read more

    • Published: Sep. 20, 2024
    • Modified: Aug. 27, 2025
  • 7.5

    HIGH
    CVE-2024-9034

    A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument username leads to sql injection. The a... Read more

    • Published: Sep. 20, 2024
    • Modified: Aug. 27, 2025
  • 7.2

    HIGH
    CVE-2024-8914

    The Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.1 due to incorrect use of the wp_kses_allowed_html functi... Read more

    Affected Products :
    • Published: Sep. 25, 2024
    • Modified: Aug. 27, 2025
  • 9.9

    CRITICAL
    CVE-2024-8436

    The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_imageId' and 'edit_imageDelete' parameters in all versions up to, and including, 4.8.5 due to insufficient escaping on the user supplied param... Read more

    Affected Products : wp_easy_gallery
    • Published: Sep. 25, 2024
    • Modified: Aug. 27, 2025
  • 7.6

    HIGH
    CVE-2024-8058

    An improper parsing vulnerability was reported in the FileZ client that could allow a crafted file in the FileZ directory to read arbitrary files on the device due to URL preloading.... Read more

    Affected Products :
    • Published: Dec. 16, 2024
    • Modified: Aug. 27, 2025
  • 4.3

    MEDIUM
    CVE-2024-6352

    A malformed packet can cause a buffer overflow in the APS layer of the Ember ZNet stack and lead to an assert... Read more

    Affected Products :
    • Published: Jan. 13, 2025
    • Modified: Aug. 27, 2025
    • Vuln Type: Memory Corruption
  • 9.8

    CRITICAL
    CVE-2024-6163

    Certain http endpoints of Checkmk in Checkmk < 2.3.0p10 < 2.2.0p31, < 2.1.0p46, <= 2.0.0p39 allows remote attacker to bypass authentication and access data... Read more

    Affected Products : checkmk checkmk
    • Published: Jul. 08, 2024
    • Modified: Aug. 27, 2025
  • 6.5

    MEDIUM
    CVE-2024-56430

    OpenFHE through 1.2.3 has a NULL pointer dereference in BinFHEContext::EvalFloor in lib/binfhe-base-scheme.cpp.... Read more

    Affected Products :
    • Published: Dec. 25, 2024
    • Modified: Aug. 27, 2025
  • 7.1

    HIGH
    CVE-2024-56056

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kmfoysal06 SimpleCharm allows Reflected XSS.This issue affects SimpleCharm: from n/a through 1.4.3.... Read more

    Affected Products : simplecharm
    • Published: Jan. 07, 2025
    • Modified: Aug. 27, 2025
    • Vuln Type: Cross-Site Scripting
  • 8.3

    HIGH
    CVE-2024-55551

    An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can fur... Read more

    Affected Products : jdbc_driver
    • Published: Mar. 19, 2025
    • Modified: Aug. 27, 2025
    • Vuln Type: Injection
  • 5.5

    MEDIUM
    CVE-2024-54175

    IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow a local user to cause a denial of service due to an improper check for unusual or exceptional conditions.... Read more

    Affected Products : mq
    • Published: Feb. 28, 2025
    • Modified: Aug. 27, 2025
    • Vuln Type: Denial of Service
  • 8.1

    HIGH
    CVE-2024-53800

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rezgo Rezgo allows PHP Local File Inclusion.This issue affects Rezgo: from n/a through 4.15.... Read more

    Affected Products : rezgo_online_booking
    • Published: Jan. 07, 2025
    • Modified: Aug. 27, 2025
    • Vuln Type: Path Traversal
  • 8.1

    HIGH
    CVE-2024-52323

    Zohocorp ManageEngine Analytics Plus versions below 6100 are vulnerable to authenticated sensitive data exposure which allows the users to retrieve sensitive tokens associated to the org-admin account.... Read more

    Affected Products : manageengine_analytics_plus
    • Published: Nov. 27, 2024
    • Modified: Aug. 27, 2025
  • 7.1

    HIGH
    CVE-2024-51646

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saoshyant Saoshyant Element allows Reflected XSS.This issue affects Saoshyant Element: from n/a through 1.2.... Read more

    Affected Products :
    • Published: Dec. 18, 2024
    • Modified: Aug. 27, 2025
  • 6.5

    MEDIUM
    CVE-2024-50443

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Post Grid Team by WPXPO PostX allows Stored XSS.This issue affects PostX: from n/a through 4.1.12.... Read more

    Affected Products : postx
    • Published: Oct. 28, 2024
    • Modified: Aug. 27, 2025
  • 8.8

    HIGH
    CVE-2024-50408

    Deserialization of Untrusted Data vulnerability in Kiboko Labs Namaste! LMS allows Object Injection.This issue affects Namaste! LMS: from n/a through 2.6.3.... Read more

    Affected Products : namaste\!_lms
    • Published: Oct. 28, 2024
    • Modified: Aug. 27, 2025
  • 6.9

    MEDIUM
    CVE-2024-50313

    A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.16.0 only if the basic authentication mechanism is used by the application), Mendix Runtime V10.12 (All versions < V10.12.7 only if the basic authentication mechanism is used by... Read more

    Affected Products : mendix
    • Published: Nov. 12, 2024
    • Modified: Aug. 27, 2025
  • 7.5

    HIGH
    CVE-2024-4349

    A vulnerability has been found in SourceCodester Pisay Online E-Learning System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /lesson/controller.php. The manipulation of the argument file leads to u... Read more

    Affected Products : pisay_online_e-learning_system
    • Published: Apr. 30, 2024
    • Modified: Aug. 27, 2025
Showing 20 of 293493 Results