Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.2

    HIGH
    CVE-2021-20022

    SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.... Read more

    • Actively Exploited
    • EPSS Score: %46.26
    • Published: Apr. 09, 2021
    • Modified: Jul. 30, 2025
  • 9.8

    CRITICAL
    CVE-2021-20038

    A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute code as a 'nobody' user in the appliance. This vulnerability affected SMA 200,... Read more

    • Actively Exploited
    • EPSS Score: %94.29
    • Published: Dec. 08, 2021
    • Modified: Jul. 30, 2025
  • 5.5

    MEDIUM
    CVE-2024-29745

    there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more

    Affected Products : android
    • Actively Exploited
    • Published: Apr. 05, 2024
    • Modified: Jul. 30, 2025
  • 9.0

    HIGH
    CVE-2025-3820

    A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644) and classified as critical. Affected by this issue is the function cgiSysUplinkCheckSet of the file /bin/httpd. The manipulation of the argument hostIp1/hostIp2 leads to stack-base... Read more

    Affected Products : i24_firmware i24 w12_firmware w12
    • Published: Apr. 19, 2025
    • Modified: Jul. 30, 2025
  • 9.0

    HIGH
    CVE-2025-3802

    A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). It has been declared as critical. This vulnerability affects the function cgiPingSet of the file /bin/httpd. The manipulation of the argument pingIP leads to stack-based buffer ov... Read more

    Affected Products : i24_firmware i24 w12_firmware w12
    • Published: Apr. 19, 2025
    • Modified: Jul. 30, 2025
  • 9.0

    HIGH
    CVE-2025-3803

    A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). It has been rated as critical. This issue affects the function cgiSysScheduleRebootSet of the file /bin/httpd. The manipulation of the argument rebootDate leads to stack-based buf... Read more

    Affected Products : i24_firmware i24 w12_firmware w12
    • Published: Apr. 19, 2025
    • Modified: Jul. 30, 2025
  • 9.0

    HIGH
    CVE-2025-4007

    A vulnerability classified as critical was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). Affected by this vulnerability is the function cgidhcpsCfgSet of the file /goform/modules of the component httpd. The manipulation of the argument json lead... Read more

    Affected Products : i24_firmware i24 w12_firmware w12
    • Published: Apr. 28, 2025
    • Modified: Jul. 30, 2025
  • 7.1

    HIGH
    CVE-2024-4254

    The 'deploy-website.yml' workflow in the gradio-app/gradio repository, specifically in the 'main' branch, is vulnerable to secrets exfiltration due to improper authorization. The vulnerability arises from the workflow's explicit checkout and execution of ... Read more

    Affected Products : gradio video
    • Published: Jun. 04, 2024
    • Modified: Jul. 30, 2025
  • 5.3

    MEDIUM
    CVE-2024-36473

    Trend Micro VPN Proxy One Pro, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite or create attack but is limited to local Denial of Service (DoS) and under specific conditions can lead to elevation of privileges.... Read more

    Affected Products : vpn_proxy_one
    • Published: Jun. 10, 2024
    • Modified: Jul. 30, 2025
  • 9.8

    CRITICAL
    CVE-2025-8179

    A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. Affected by this vulnerability is an unknown functionality of the file /admin/changeimage.php. The manipulation of the argument editid leads... Read more

    • Published: Jul. 26, 2025
    • Modified: Jul. 30, 2025
  • 6.3

    MEDIUM
    CVE-2025-47943

    Gogs is an open source self-hosted Git service. In application version 0.14.0+dev and prior, there is a stored cross-site scripting (XSS) vulnerability present in Gogs, which allows client-side Javascript code execution. The vulnerability is caused by the... Read more

    Affected Products : gogs
    • Published: Jun. 24, 2025
    • Modified: Jul. 30, 2025
  • 8.8

    HIGH
    CVE-2025-24196

    A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An attacker with user privileges may be able to read kernel memory.... Read more

    Affected Products : macos
    • Published: Mar. 31, 2025
    • Modified: Jul. 30, 2025
  • 6.8

    MEDIUM
    CVE-2025-0140

    An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app even if the GlobalProtect app configuration would not normally permit ... Read more

    Affected Products : globalprotect_app
    • Published: Jul. 09, 2025
    • Modified: Jul. 30, 2025
  • 10.0

    CRITICAL
    CVE-2025-0982

    Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an actor to execute arbitrary unsandboxed code via crafted JavaScript code executed by the Rhino engine. Effective January 24, 2025, Application Integration will ... Read more

    Affected Products : application_integration
    • Published: Feb. 06, 2025
    • Modified: Jul. 30, 2025
  • 9.8

    CRITICAL
    CVE-2025-22992

    A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >= 11.6.9. The vulnerability is caused by improper handling of user-supplied input in the data query parameter, allowing attackers to execute arbitrary SQL comma... Read more

    Affected Products : emoncms
    • Published: Feb. 06, 2025
    • Modified: Jul. 30, 2025
  • 9.8

    CRITICAL
    CVE-2025-0896

    Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. This could result in unauthorized access by an attacker.... Read more

    Affected Products : orthanc
    • Published: Feb. 13, 2025
    • Modified: Jul. 30, 2025
  • 9.8

    CRITICAL
    CVE-2025-0838

    There exists a heap buffer overflow vulnerable in Abseil-cpp. The sized constructors, reserve(), and rehash() methods of absl::{flat,node}hash{set,map} did not impose an upper bound on their size argument. As a result, it was possible for a caller to pass... Read more

    Affected Products : debian_linux common_libraries
    • Published: Feb. 21, 2025
    • Modified: Jul. 30, 2025
  • 7.5

    HIGH
    CVE-2024-37183

    Plain text credentials and session ID can be captured with a network sniffer.... Read more

    • Published: Jun. 20, 2024
    • Modified: Jul. 30, 2025
  • 9.8

    CRITICAL
    CVE-2025-8249

    A vulnerability, which was classified as critical, has been found in code-projects Exam Form Submission 1.0. This issue affects some unknown processing of the file /admin/update_s3.php. The manipulation of the argument credits leads to sql injection. The ... Read more

    Affected Products : exam_form_submission
    • Published: Jul. 28, 2025
    • Modified: Jul. 30, 2025
  • 8.7

    HIGH
    CVE-2024-32943

    An attacker may be able to cause a denial-of-service condition by sending many SSH packets repeatedly.... Read more

    • Published: Jun. 20, 2024
    • Modified: Jul. 30, 2025
Showing 20 of 291024 Results