Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2019-16535

    In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve RCE or DoS via native protocol.... Read more

    Affected Products : clickhouse clickhouse
    • Published: Dec. 30, 2019
    • Modified: Jun. 25, 2025
  • 9.8

    CRITICAL
    CVE-2018-14670

    Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database.... Read more

    Affected Products : clickhouse clickhouse
    • Published: Aug. 15, 2019
    • Modified: Jun. 25, 2025
  • 9.8

    CRITICAL
    CVE-2018-14671

    In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remote Code Execution vulnerability.... Read more

    Affected Products : clickhouse clickhouse
    • Published: Aug. 15, 2019
    • Modified: Jun. 25, 2025
  • 8.8

    HIGH
    CVE-2018-14668

    In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_database" fields which led to Cross Protocol Request Forgery Attacks.... Read more

    Affected Products : clickhouse clickhouse
    • Published: Aug. 15, 2019
    • Modified: Jun. 25, 2025
  • 5.3

    MEDIUM
    CVE-2019-18657

    ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function.... Read more

    Affected Products : clickhouse clickhouse
    • Published: Oct. 31, 2019
    • Modified: Jun. 25, 2025
  • 7.5

    HIGH
    CVE-2018-14669

    ClickHouse MySQL client before versions 1.1.54390 had "LOAD DATA LOCAL INFILE" functionality enabled that allowed a malicious MySQL database read arbitrary files from the connected ClickHouse server.... Read more

    Affected Products : clickhouse clickhouse
    • Published: Aug. 15, 2019
    • Modified: Jun. 25, 2025
  • 5.3

    MEDIUM
    CVE-2018-14672

    In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messages.... Read more

    Affected Products : clickhouse clickhouse
    • Published: Aug. 15, 2019
    • Modified: Jun. 25, 2025
  • 9.8

    CRITICAL
    CVE-2025-26909

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in John Darrel Hide My WP Ghost allows PHP Local File Inclusion.This issue affects Hide My WP Ghost: from n/a through 5.4.01.... Read more

    Affected Products : hide_my_wp_ghost
    • Published: Mar. 27, 2025
    • Modified: Jun. 25, 2025
    • Vuln Type: Path Traversal
  • 4.8

    MEDIUM
    CVE-2024-11847

    The wp-svg-upload WordPress plugin through 1.0.0 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.... Read more

    Affected Products : _wp_svg_upload
    • Published: Mar. 26, 2025
    • Modified: Jun. 25, 2025
    • Vuln Type: Cross-Site Scripting
  • 7.5

    HIGH
    CVE-2025-5729

    A vulnerability, which was classified as critical, was found in code-projects Health Center Patient Record Management System 1.0. Affected is an unknown function of the file /birthing_record.php. The manipulation of the argument itr_no leads to sql inject... Read more

    Affected Products : patient_record_management_system
    • Published: Jun. 06, 2025
    • Modified: Jun. 25, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-5881

    A vulnerability was found in code-projects Chat System up to 1.0 and classified as critical. This issue affects some unknown processing of the file /user/confirm_password.php. The manipulation of the argument cid leads to sql injection. The attack may be ... Read more

    Affected Products : chat_system chat_system
    • Published: Jun. 09, 2025
    • Modified: Jun. 25, 2025
    • Vuln Type: Injection
  • 5.4

    MEDIUM
    CVE-2025-45055

    Silverpeas 6.4.2 contains a stored cross-site scripting (XSS) vulnerability in the event management module. An authenticated user can upload a malicious SVG file as an event attachment, which, when viewed by an administrator, executes embedded JavaScript ... Read more

    Affected Products : silverpeas
    • Published: Jun. 09, 2025
    • Modified: Jun. 25, 2025
    • Vuln Type: Cross-Site Scripting
  • 9.8

    CRITICAL
    CVE-2024-3566

    A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.... Read more

    • Published: Apr. 10, 2024
    • Modified: Jun. 25, 2025
  • 9.8

    CRITICAL
    CVE-2025-6420

    A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/add_room.php. The manipulation of the argument room_type leads to sql injec... Read more

    • Published: Jun. 21, 2025
    • Modified: Jun. 25, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-6419

    A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/edit_room.php. The manipulation of the argument room_type leads to sql injection. It... Read more

    • Published: Jun. 21, 2025
    • Modified: Jun. 25, 2025
    • Vuln Type: Injection
  • 9.0

    HIGH
    CVE-2025-6402

    A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm/formIpv6Setup of the component HTTP POST Request Handler. The manipulation of the argument submit... Read more

    Affected Products : x15_firmware x15
    • Published: Jun. 21, 2025
    • Modified: Jun. 25, 2025
    • Vuln Type: Memory Corruption
  • 5.1

    MEDIUM
    CVE-2025-6401

    A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101. It has been classified as problematic. This affects an unknown part of the file /boafrm/formFilter of the component HTTP POST Message Handler. The manipulation of the argument url leads to ... Read more

    Affected Products : n300rh_firmware n300rh
    • Published: Jun. 21, 2025
    • Modified: Jun. 25, 2025
    • Vuln Type: Denial of Service
  • 9.0

    HIGH
    CVE-2025-6400

    A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101 and classified as critical. Affected by this issue is some unknown functionality of the file /boafrm/formPortFw of the component HTTP POST Message Handler. The manipulation of the argument s... Read more

    Affected Products : n300rh_firmware n300rh
    • Published: Jun. 21, 2025
    • Modified: Jun. 25, 2025
    • Vuln Type: Memory Corruption
  • 9.0

    HIGH
    CVE-2025-6399

    A vulnerability, which was classified as critical, was found in TOTOLINK X15 1.0.0-B20230714.1105. Affected is an unknown function of the file /boafrm/formIPv6Addr of the component HTTP POST Request Handler. The manipulation of the argument submit-url lea... Read more

    Affected Products : x15_firmware x15
    • Published: Jun. 21, 2025
    • Modified: Jun. 25, 2025
    • Vuln Type: Memory Corruption
  • 9.8

    CRITICAL
    CVE-2025-6394

    A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /add_reserve.php. The manipulation of the argument firstname le... Read more

    • Published: Jun. 21, 2025
    • Modified: Jun. 25, 2025
    • Vuln Type: Injection
Showing 20 of 293656 Results