Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2024-5475

    The Responsive video embed WordPress plugin before 0.5.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to ... Read more

    Affected Products : responsive_video_embed
    • Published: Jun. 20, 2024
    • Modified: Jun. 17, 2025
  • 8.3

    HIGH
    CVE-2024-4749

    The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.... Read more

    Affected Products : wp_emember
    • Published: Jun. 04, 2024
    • Modified: Jun. 17, 2025
  • 2.5

    LOW
    CVE-2025-5648

    A vulnerability was found in Radare2 5.9.9. It has been classified as problematic. Affected is the function r_cons_pal_init in the library /libr/cons/pal.c of the component radiff2. The manipulation of the argument -T leads to memory corruption. An attack... Read more

    Affected Products : radare2
    • Published: Jun. 05, 2025
    • Modified: Jun. 17, 2025
    • Vuln Type: Memory Corruption
  • 6.5

    MEDIUM
    CVE-2024-1076

    The SSL Zen WordPress plugin before 4.6.0 does not properly prevent directory listing of the private keys folder, as it only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacker to ... Read more

    Affected Products : ssl_zen
    • Published: May. 08, 2024
    • Modified: Jun. 17, 2025
  • 6.5

    MEDIUM
    CVE-2024-28294

    Limbas up to v5.2.14 was discovered to contain a SQL injection vulnerability via the ftid parameter.... Read more

    Affected Products : limbas
    • Published: Apr. 29, 2024
    • Modified: Jun. 17, 2025
  • 5.3

    MEDIUM
    CVE-2024-0868

    The coreActivity: Activity Logging plugin for WordPress plugin before 2.1 retrieved IP addresses of requests via headers such X-FORWARDED to log them, allowing users to spoof them by providing an arbitrary value... Read more

    Affected Products : coreactivity
    • Published: Apr. 17, 2024
    • Modified: Jun. 17, 2025
  • 6.1

    MEDIUM
    CVE-2023-4826

    The SocialDriver WordPress theme before version 2024 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties resulting in a cross-site scripting (XSS) attack.... Read more

    Affected Products : socialdriver
    • Published: Feb. 23, 2024
    • Modified: Jun. 17, 2025
  • 7.5

    HIGH
    CVE-2025-27956

    Directory Traversal vulnerability in WebLaudos 24.2 (04) allows a remote attacker to obtain sensitive information via the id parameter.... Read more

    Affected Products : weblaudos
    • Published: Jun. 02, 2025
    • Modified: Jun. 17, 2025
    • Vuln Type: Path Traversal
  • 6.1

    MEDIUM
    CVE-2024-50599

    A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Zimbra Collaboration Suite (ZCS) 8.8.15, affecting one of the webmail calendar endpoints. This arises from improper handling of user-supplied input, allowing an attacker to inject... Read more

    Affected Products : zimbra_collaboration_suite
    • Published: Nov. 07, 2024
    • Modified: Jun. 17, 2025
  • 8.8

    HIGH
    CVE-2025-5431

    A vulnerability, which was classified as critical, was found in AssamLook CMS 1.0. Affected is an unknown function of the file /department-profile.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotel... Read more

    Affected Products : assamlook_cms
    • Published: Jun. 02, 2025
    • Modified: Jun. 17, 2025
    • Vuln Type: Injection
  • 9.1

    CRITICAL
    CVE-2024-31815

    In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh... Read more

    Affected Products : ex200_firmware ex200
    • Published: Apr. 08, 2024
    • Modified: Jun. 17, 2025
  • 8.8

    HIGH
    CVE-2024-24279

    An issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated privileges via vsVerifyPassword and vsSetFingerPrintPower functions.... Read more

    Affected Products : secdiskapp
    • Published: Apr. 08, 2024
    • Modified: Jun. 17, 2025
  • 6.5

    MEDIUM
    CVE-2024-21507

    Versions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the keyFromFields function, resulting in cache poisoning. An attacker can inject a colon (:) character within a value of the attacker-crafted key.... Read more

    Affected Products : mysql2
    • Published: Apr. 10, 2024
    • Modified: Jun. 17, 2025
  • 7.2

    HIGH
    CVE-2025-39240

    Some Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected... Read more

    Affected Products :
    • Published: Jun. 13, 2025
    • Modified: Jun. 17, 2025
    • Vuln Type: Authentication
  • 5.6

    MEDIUM
    CVE-2025-22242

    Worker process denial of service through file read operation. .A vulnerability exists in the Master's “pub_ret” method which is exposed to all minions. The un-sanitized input value “jid” is used to construct a path which is then opened for reading. An att... Read more

    Affected Products : salt
    • Published: Jun. 13, 2025
    • Modified: Jun. 17, 2025
    • Vuln Type: Denial of Service
  • 5.6

    MEDIUM
    CVE-2025-22241

    File contents overwrite the VirtKey class is called when “on-demand pillar” data is requested and uses un-validated input to create paths to the “pki directory”. The functionality is used to auto-accept Minion authentication keys based on a pre-placed “au... Read more

    Affected Products : salt
    • Published: Jun. 13, 2025
    • Modified: Jun. 17, 2025
    • Vuln Type: Path Traversal
  • 5.9

    MEDIUM
    CVE-2024-13772

    The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.6.1. This is due to a lack of password randomization and user validation through the fb_ajax... Read more

    Affected Products : civi civi
    • Published: Mar. 14, 2025
    • Modified: Jun. 17, 2025
    • Vuln Type: Authentication
  • 7.5

    HIGH
    CVE-2023-52285

    ExamSys 9150244 allows SQL Injection via the /Support/action/Pages.php s_score2 parameter.... Read more

    Affected Products : examsys
    • Published: Jan. 17, 2024
    • Modified: Jun. 17, 2025
  • 4.3

    MEDIUM
    CVE-2023-40264

    An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated path traversal in the user interface.... Read more

    Affected Products : openscape_voice_trace_manager_v8
    • Published: Feb. 08, 2024
    • Modified: Jun. 17, 2025
  • 3.3

    LOW
    CVE-2023-28197

    An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.3, macOS Big Sur 11.7.5, macOS Monterey 12.6.4. An app may be able to access user-sensitive data.... Read more

    Affected Products : macos
    • Published: Jan. 10, 2024
    • Modified: Jun. 17, 2025
Showing 20 of 293588 Results