Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.5

    MEDIUM
    CVE-2018-6542

    In ZZIPlib 0.13.67, there is a bus error (when handling a disk64_trailer seek value) caused by loading of a misaligned address in the zzip_disk_findfirst function of zzip/mmapped.c.... Read more

    Affected Products : zziplib zziplib
    • EPSS Score: %0.28
    • Published: Feb. 02, 2018
    • Modified: Jul. 10, 2025
  • 5.5

    MEDIUM
    CVE-2025-27736

    Exposure of sensitive information to an unauthorized actor in Windows Power Dependency Coordinator allows an authorized attacker to disclose information locally.... Read more

    • Published: Apr. 08, 2025
    • Modified: Jul. 10, 2025
    • Vuln Type: Information Disclosure
  • 6.0

    MEDIUM
    CVE-2025-27735

    Insufficient verification of data authenticity in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.... Read more

    • Published: Apr. 08, 2025
    • Modified: Jul. 10, 2025
    • Vuln Type: Authorization
  • 6.3

    MEDIUM
    CVE-2024-32231

    Stash up to v0.25.1 was discovered to contain a SQL injection vulnerability via the sort parameter.... Read more

    Affected Products : stash
    • Published: Aug. 15, 2024
    • Modified: Jul. 10, 2025
  • 7.8

    HIGH
    CVE-2025-27733

    Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.... Read more

    • Published: Apr. 08, 2025
    • Modified: Jul. 10, 2025
    • Vuln Type: Memory Corruption
  • 6.5

    MEDIUM
    CVE-2024-45993

    Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb.... Read more

    Affected Products : giflib
    • Published: Sep. 30, 2024
    • Modified: Jul. 10, 2025
  • 6.5

    MEDIUM
    CVE-2024-43346

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wow-Company Modal Window allows Stored XSS.This issue affects Modal Window: from n/a through 6.0.3.... Read more

    Affected Products : modal_window
    • Published: Aug. 18, 2024
    • Modified: Jul. 10, 2025
  • 6.5

    MEDIUM
    CVE-2025-26664

    Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.... Read more

    • Published: Apr. 08, 2025
    • Modified: Jul. 10, 2025
    • Vuln Type: Information Disclosure
  • 5.4

    MEDIUM
    CVE-2024-45920

    A Stored Cross-Site Scripting (XSS) vulnerability in Solvait 24.4.2 allows remote attackers to inject malicious scripts into the application. This issue arises due to insufficient input validation and sanitization in "Intrest" feature.... Read more

    Affected Products : solvait
    • Published: Sep. 30, 2024
    • Modified: Jul. 10, 2025
  • 7.5

    HIGH
    CVE-2024-44860

    An information disclosure vulnerability in the /Letter/PrintQr/ endpoint of Solvait v24.4.2 allows attackers to access sensitive data via a crafted request.... Read more

    Affected Products : solvait
    • Published: Sep. 26, 2024
    • Modified: Jul. 10, 2025
  • 8.1

    HIGH
    CVE-2025-26663

    Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.... Read more

    • Published: Apr. 08, 2025
    • Modified: Jul. 10, 2025
    • Vuln Type: Memory Corruption
  • 7.5

    HIGH
    CVE-2025-37097

    A vulnerability in HPE Insight Remote Support (IRS) prior to v7.15.0.646 may allow an unauthenticated denial of service... Read more

    Affected Products : insight_remote_support
    • Published: Jul. 01, 2025
    • Modified: Jul. 10, 2025
    • Vuln Type: Denial of Service
  • 8.1

    HIGH
    CVE-2024-41659

    memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a c... Read more

    Affected Products : memos
    • Published: Aug. 20, 2024
    • Modified: Jul. 10, 2025
  • 7.5

    HIGH
    CVE-2025-37098

    A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.... Read more

    Affected Products : insight_remote_support
    • Published: Jul. 01, 2025
    • Modified: Jul. 10, 2025
    • Vuln Type: Path Traversal
  • 4.3

    MEDIUM
    CVE-2024-6883

    The Event Espresso 4 Decaf – Event Registration Event Ticketing plugin for WordPress is vulnerable to limited unauthorized plugin settings modification due to a missing capability check on the saveTimezoneString and some other functions in all versions up... Read more

    Affected Products : event_espresso
    • Published: Aug. 21, 2024
    • Modified: Jul. 10, 2025
  • 9.8

    CRITICAL
    CVE-2025-37099

    A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.... Read more

    Affected Products : insight_remote_support
    • Published: Jul. 01, 2025
    • Modified: Jul. 10, 2025
  • 8.1

    HIGH
    CVE-2024-46097

    TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section. When a new TestPlan is created, an ID with an incremental value is automatically generated. Using the edit function you can change the tplan_id parameter to another... Read more

    Affected Products : testlink
    • Published: Sep. 27, 2024
    • Modified: Jul. 10, 2025
  • 9.8

    CRITICAL
    CVE-2024-5335

    The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the _ultimate_store... Read more

    Affected Products : ultimate_store_kit
    • Published: Aug. 21, 2024
    • Modified: Jul. 10, 2025
  • 9.8

    CRITICAL
    CVE-2024-8030

    The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the _ultimate_store... Read more

    Affected Products : ultimate_store_kit
    • Published: Aug. 28, 2024
    • Modified: Jul. 10, 2025
  • 7.2

    HIGH
    CVE-2022-2440

    The Theme Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'images_array' parameter in versions up to, and including 2.8. This makes it possible for authenticated attackers with administrative privileges to call file... Read more

    Affected Products : theme_editor
    • Published: Aug. 29, 2024
    • Modified: Jul. 10, 2025
Showing 20 of 291737 Results