Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.1

    HIGH
    CVE-2024-43238

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in weDevs weMail allows Reflected XSS.This issue affects weMail: from n/a through 1.14.5.... Read more

    Affected Products : wemail wemail
    • Published: Aug. 18, 2024
    • Modified: Aug. 15, 2025
  • 7.1

    HIGH
    CVE-2024-43958

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gianni Porto IntoTheDark allows Reflected XSS.This issue affects IntoTheDark: from n/a through 1.0.5.... Read more

    Affected Products : intothedark intothedark
    • Published: Aug. 29, 2024
    • Modified: Aug. 15, 2025
  • 8.8

    HIGH
    CVE-2024-4403

    A Cross-Site Request Forgery (CSRF) vulnerability exists in the restart_program function of the parisneo/lollms-webui v9.6. This vulnerability allows attackers to trick users into performing unintended actions, such as resetting the program without their ... Read more

    • Published: Jun. 10, 2024
    • Modified: Aug. 15, 2025
  • 8.0

    HIGH
    CVE-2024-46486

    TP-LINK TL-WDR5620 v2.3 was discovered to contain a remote code execution (RCE) vulnerability via the httpProcDataSrv function.... Read more

    Affected Products : tl-wdr5620_firmware tl-wdr5620
    • Published: Oct. 04, 2024
    • Modified: Aug. 15, 2025
  • 8.4

    HIGH
    CVE-2024-46954

    An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.... Read more

    Affected Products : ghostscript
    • Published: Nov. 10, 2024
    • Modified: Aug. 15, 2025
  • 8.0

    HIGH
    CVE-2024-48288

    TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification on both the frontend and backend.... Read more

    Affected Products : tl-ipc42c_firmware tl-ipc42c
    • Published: Nov. 21, 2024
    • Modified: Aug. 15, 2025
  • 5.5

    MEDIUM
    CVE-2024-49541

    Illustrator versions 29.0.0, 28.7.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this i... Read more

    Affected Products : macos windows illustrator
    • Published: Dec. 10, 2024
    • Modified: Aug. 15, 2025
  • 4.4

    MEDIUM
    CVE-2024-6971

    A path traversal vulnerability exists in the parisneo/lollms-webui repository, specifically in the `lollms_file_system.py` file. The functions `add_rag_database`, `toggle_mount_rag_database`, and `vectorize_folder` do not implement security measures such ... Read more

    Affected Products : lollms lollms-webui lollms-webui
    • Published: Oct. 11, 2024
    • Modified: Aug. 15, 2025
  • 7.8

    HIGH
    CVE-2025-2013

    Ashlar-Vellum Cobalt CO File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this v... Read more

    Affected Products : cobalt
    • Published: Mar. 11, 2025
    • Modified: Aug. 15, 2025
    • Vuln Type: Memory Corruption
  • 4.8

    MEDIUM
    CVE-2025-20180

    A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a u... Read more

    • Published: Feb. 05, 2025
    • Modified: Aug. 15, 2025
    • Vuln Type: Cross-Site Scripting
  • 7.2

    HIGH
    CVE-2024-0844

    The Popup More Popups, Lightboxes, and more popup modules plugin for WordPress is vulnerable to Local File Inclusion in version 2.1.6 via the ycfChangeElementData() function. This makes it possible for authenticated attackers, with administrator-level acc... Read more

    • Published: Feb. 02, 2024
    • Modified: Aug. 15, 2025
  • 7.8

    HIGH
    CVE-2024-13046

    Ashlar-Vellum Cobalt CO File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit t... Read more

    Affected Products : cobalt
    • Published: Dec. 30, 2024
    • Modified: Aug. 15, 2025
  • 6.4

    MEDIUM
    CVE-2024-1242

    The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button onclick attribute in all versions up to, and including, 4.10.18 due to insufficient input sanitization and output escaping. This makes it pos... Read more

    Affected Products : premium_addons_for_elementor
    • Published: Feb. 29, 2024
    • Modified: Aug. 15, 2025
  • 8.8

    HIGH
    CVE-2024-1522

    A Cross-Site Request Forgery (CSRF) vulnerability in the parisneo/lollms-webui project allows remote attackers to execute arbitrary code on a victim's system. The vulnerability stems from the `/execute_code` API endpoint, which does not properly validate ... Read more

    • Published: Mar. 30, 2024
    • Modified: Aug. 15, 2025
  • 8.2

    HIGH
    CVE-2024-1646

    parisneo/lollms-webui is vulnerable to authentication bypass due to insufficient protection over sensitive endpoints. The application checks if the host parameter is not '0.0.0.0' to restrict access, which is inadequate when the application is bound to a ... Read more

    • Published: Apr. 16, 2024
    • Modified: Aug. 15, 2025
  • 7.5

    HIGH
    CVE-2024-21459

    Information disclosure while handling beacon or probe response frame in STA.... Read more

    • Published: Aug. 05, 2024
    • Modified: Aug. 15, 2025
  • 7.8

    HIGH
    CVE-2024-21803

    Use After Free vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (bluetooth modules) allows Local Execution of Code. This vulnerability is associated with program files https://gitee.Com/anolis/cloud-kernel/blob/devel-5.10/net/bluetooth/af_blu... Read more

    Affected Products : linux_kernel
    • Published: Jan. 30, 2024
    • Modified: Aug. 15, 2025
  • 8.2

    HIGH
    CVE-2024-34949

    SQL injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function OrderLogic::getOrderList function, exploited at the /admin/order/lists.html endpoint.... Read more

    Affected Products : likeshop
    • Published: May. 20, 2024
    • Modified: Aug. 15, 2025
  • 5.3

    MEDIUM
    CVE-2021-30187

    CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command.... Read more

    • Published: May. 25, 2021
    • Modified: Aug. 15, 2025
  • 9.8

    CRITICAL
    CVE-2021-30188

    CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.... Read more

    • Published: May. 25, 2021
    • Modified: Aug. 15, 2025
Showing 20 of 292767 Results