Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    CRITICAL
    CVE-2025-1744

    Out-of-bounds Write vulnerability in radareorg radare2 allows heap-based buffer over-read or buffer overflow.This issue affects radare2: before <5.9.9.... Read more

    Affected Products : radare2
    • Published: Feb. 28, 2025
    • Modified: Jul. 01, 2025
    • Vuln Type: Memory Corruption
  • 7.2

    HIGH
    CVE-2025-6842

    A vulnerability was found in code-projects Product Inventory System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/edit_user.php. The manipulation of the argument ID leads to sql injection. The attack may be ... Read more

    Affected Products : product_inventory_system
    • Published: Jun. 29, 2025
    • Modified: Jul. 01, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-47787

    Emlog is an open source website building system. Emlog Pro prior to version 2.5.10 contains a file upload vulnerability. The store.php component contains a critical security flaw where it fails to properly validate the contents of remotely downloaded ZIP ... Read more

    Affected Products : emlog
    • Published: May. 15, 2025
    • Modified: Jul. 01, 2025
    • Vuln Type: Authentication
  • 5.4

    MEDIUM
    CVE-2024-39730

    IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click ... Read more

    Affected Products : datacap datacap_navigator
    • Published: Jun. 28, 2025
    • Modified: Jul. 01, 2025
    • Vuln Type: Cross-Site Request Forgery
  • 4.3

    MEDIUM
    CVE-2025-36026

    IBM Datacap 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The... Read more

    Affected Products : datacap datacap_navigator
    • Published: Jun. 28, 2025
    • Modified: Jul. 01, 2025
    • Vuln Type: Authentication
  • 5.4

    MEDIUM
    CVE-2025-36027

    IBM Datacap 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click action... Read more

    Affected Products : datacap datacap_navigator
    • Published: Jun. 28, 2025
    • Modified: Jul. 01, 2025
    • Vuln Type: Cross-Site Request Forgery
  • 9.1

    CRITICAL
    CVE-2024-37770

    14Finger v1.1 was discovered to contain a remote command execution (RCE) vulnerability in the fingerprint function. This vulnerability allows attackers to execute arbitrary commands via a crafted payload.... Read more

    Affected Products : 14finger
    • Published: Jul. 10, 2024
    • Modified: Jul. 01, 2025
  • 7.5

    HIGH
    CVE-2024-37767

    Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information via a crafted GET request.... Read more

    Affected Products : 14finger
    • Published: Jul. 05, 2024
    • Modified: Jul. 01, 2025
  • 4.3

    MEDIUM
    CVE-2024-23937

    This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the debug interface. ... Read more

    Affected Products : gecko_os
    • Published: Jan. 31, 2025
    • Modified: Jul. 01, 2025
    • Vuln Type: Information Disclosure
  • 7.3

    HIGH
    CVE-2024-23929

    This vulnerability allows network-adjacent attackers to create arbitrary files on affected installations of Pioneer DMH-WT7600NEX devices. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypa... Read more

    • Published: Jan. 31, 2025
    • Modified: Jul. 01, 2025
    • Vuln Type: Path Traversal
  • 8.8

    HIGH
    CVE-2024-23921

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the wlanapp... Read more

    • Published: Jan. 31, 2025
    • Modified: Jul. 01, 2025
    • Vuln Type: Authentication
  • 8.8

    HIGH
    CVE-2024-23920

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the onboard... Read more

    • Published: Jan. 31, 2025
    • Modified: Jul. 01, 2025
    • Vuln Type: Authentication
  • 8.1

    HIGH
    CVE-2023-4428

    Out of bounds memory access in CSS in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)... Read more

    Affected Products : fedora debian_linux chrome edge_chromium
    • Published: Aug. 23, 2023
    • Modified: Jul. 01, 2025
  • 9.8

    CRITICAL
    CVE-2023-40890

    A stack-based buffer overflow vulnerability exists in the lookup_sequence function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally inp... Read more

    Affected Products : zbar
    • Published: Aug. 29, 2023
    • Modified: Jul. 01, 2025
  • 5.4

    MEDIUM
    CVE-2023-40282

    Improper authentication vulnerability in Rakuten WiFi Pocket all versions allows a network-adjacent attacker to log in to the product's Management Screen. As a result, sensitive information may be obtained and/or the settings may be changed.... Read more

    Affected Products : wifi_pocket_firmware wifi_pocket
    • Published: Aug. 23, 2023
    • Modified: Jul. 01, 2025
  • 7.5

    HIGH
    CVE-2023-32559

    A privilege escalation vulnerability exists in the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x. The use of the deprecated API `process.binding()` can bypass the policy mechanism by requiring internal modules and eventua... Read more

    Affected Products : node.js
    • Published: Aug. 24, 2023
    • Modified: Jul. 01, 2025
  • 8.8

    HIGH
    CVE-2024-50930

    An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code.... Read more

    • Published: Dec. 10, 2024
    • Modified: Jul. 01, 2025
  • 9.8

    CRITICAL
    CVE-2025-6822

    A vulnerability was found in code-projects Inventory Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /php_action/removeProduct.php. The manipulation of the argument productId leads to sql inject... Read more

    Affected Products : inventory_management_system
    • Published: Jun. 28, 2025
    • Modified: Jul. 01, 2025
    • Vuln Type: Injection
  • 4.6

    MEDIUM
    CVE-2024-50931

    Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions.... Read more

    • Published: Dec. 10, 2024
    • Modified: Jul. 01, 2025
  • 5.9

    MEDIUM
    CVE-2024-30192

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GS Plugins GS Pins for Pinterest allows Stored XSS.This issue affects GS Pins for Pinterest: from n/a through 1.8.2. ... Read more

    Affected Products : gs_pinterest_portfolio
    • Published: Mar. 27, 2024
    • Modified: Jul. 01, 2025
Showing 20 of 294210 Results