Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.3

    HIGH
    CVE-2025-44647

    In TRENDnet TEW-WLC100P 2.03b03, the i_dont_care_about_security_and_use_aggressive_mode_psk option is enabled in the strongSwan configuration file, so that IKE Responders are allowed to use IKEv1 Aggressive Mode with Pre-Shared Keys to conduct offline att... Read more

    Affected Products : tew-wlc100p_firmware tew-wlc100p
    • Published: Jul. 21, 2025
    • Modified: Aug. 07, 2025
    • Vuln Type: Authentication
  • 9.8

    CRITICAL
    CVE-2025-44954

    RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.... Read more

    • Published: Aug. 04, 2025
    • Modified: Aug. 07, 2025
    • Vuln Type: Authentication
  • 7.8

    HIGH
    CVE-2025-0412

    Luxion KeyShot Viewer KSP File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot Viewer. User interaction is required to exploit ... Read more

    Affected Products : keyshot keyshot_viewer
    • Published: Jan. 13, 2025
    • Modified: Aug. 07, 2025
    • Vuln Type: Memory Corruption
  • 6.5

    MEDIUM
    CVE-2025-51045

    Phpgurukul Pre-School Enrollment System 1.0 contains a SQL injection vulnerability in the /admin/password-recovery.php file. This vulnerability is attributed to the insufficient validation of user input for the username parameter.... Read more

    Affected Products : pre-school_enrollment_system
    • Published: Jul. 29, 2025
    • Modified: Aug. 07, 2025
    • Vuln Type: Injection
  • 6.5

    MEDIUM
    CVE-2025-51044

    phpgurukul Nipah virus (NiV) Testing Management System 1.0 contains a SQL injection vulnerability in the /new-user-testing.php file, due to insufficient validation of user input for the " govtissuedid" parameter.... Read more

    • Published: Jul. 29, 2025
    • Modified: Aug. 07, 2025
    • Vuln Type: Injection
  • 5.3

    MEDIUM
    CVE-2023-42114

    Exim NTLM Challenge Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Exim. Authentication is not required to exploit this vulnerability. The... Read more

    Affected Products : exim
    • Published: May. 03, 2024
    • Modified: Aug. 07, 2025
  • 5.4

    MEDIUM
    CVE-2024-38277

    A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.... Read more

    Affected Products : moodle fedora
    • Published: Jun. 18, 2024
    • Modified: Aug. 07, 2025
  • 6.1

    MEDIUM
    CVE-2024-38274

    Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt.... Read more

    Affected Products : moodle fedora
    • Published: Jun. 18, 2024
    • Modified: Aug. 07, 2025
  • 7.2

    HIGH
    CVE-2024-23115

    Centreon updateGroups SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific fl... Read more

    Affected Products : centreon centreon_web
    • Published: Apr. 01, 2024
    • Modified: Aug. 07, 2025
  • 7.2

    HIGH
    CVE-2024-23116

    Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specif... Read more

    Affected Products : centreon centreon_web
    • Published: Apr. 01, 2024
    • Modified: Aug. 07, 2025
  • 7.2

    HIGH
    CVE-2024-23117

    Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. ... Read more

    Affected Products : centreon centreon_web
    • Published: Apr. 01, 2024
    • Modified: Aug. 07, 2025
  • 7.2

    HIGH
    CVE-2024-23118

    Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. Th... Read more

    Affected Products : centreon centreon_web
    • Published: Apr. 01, 2024
    • Modified: Aug. 07, 2025
  • 8.8

    HIGH
    CVE-2024-23119

    Centreon insertGraphTemplate SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The spec... Read more

    Affected Products : centreon centreon_web
    • Published: Apr. 01, 2024
    • Modified: Aug. 07, 2025
  • 8.8

    HIGH
    CVE-2024-0637

    Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific... Read more

    Affected Products : centreon centreon_web
    • Published: Apr. 01, 2024
    • Modified: Aug. 07, 2025
  • 6.5

    MEDIUM
    CVE-2024-1930

    No Limit on Number of Open Sessions / Bad Session Close Behaviour in dnf5daemon-server before 5.1.17 allows a malicious user to impact Availability via No Limit on Number of Open Sessions. There is no limit on how many sessions D-Bus clients may create ... Read more

    Affected Products : dnf5
    • Published: May. 08, 2024
    • Modified: Aug. 07, 2025
  • 5.5

    MEDIUM
    CVE-2024-4855

    Use after free issue in editcap could cause denial of service via crafted capture file... Read more

    Affected Products : fedora wireshark
    • Published: May. 14, 2024
    • Modified: Aug. 07, 2025
  • 7.8

    HIGH
    CVE-2023-37347

    Kofax Power PDF U3D File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulner... Read more

    Affected Products : kofax_power_pdf power_pdf
    • Published: May. 03, 2024
    • Modified: Aug. 07, 2025
  • 7.8

    HIGH
    CVE-2023-37348

    Kofax Power PDF U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulne... Read more

    Affected Products : kofax_power_pdf power_pdf
    • Published: May. 03, 2024
    • Modified: Aug. 07, 2025
  • 7.8

    HIGH
    CVE-2023-37349

    Kofax Power PDF PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulne... Read more

    Affected Products : kofax_power_pdf power_pdf
    • Published: May. 03, 2024
    • Modified: Aug. 07, 2025
  • 7.8

    HIGH
    CVE-2023-37343

    Kofax Power PDF JP2 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulne... Read more

    Affected Products : kofax_power_pdf power_pdf
    • Published: May. 03, 2024
    • Modified: Aug. 07, 2025
Showing 20 of 291358 Results