Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.2

    HIGH
    CVE-2025-26013

    An issue in Loggrove v.1.0 allows a remote attacker to obtain sensitive information via the read.py component.... Read more

    Affected Products : loggrove
    • Published: Feb. 21, 2025
    • Modified: Jun. 13, 2025
    • Vuln Type: Information Disclosure
  • 9.8

    CRITICAL
    CVE-2025-26014

    A Remote Code Execution (RCE) vulnerability in Loggrove v.1.0 allows a remote attacker to execute arbitrary code via the path parameter.... Read more

    Affected Products : loggrove
    • Published: Feb. 21, 2025
    • Modified: Jun. 13, 2025
    • Vuln Type: Path Traversal
  • 7.2

    HIGH
    CVE-2025-45752

    A vulnerability in SeedDMS 6.0.32 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the zip import functionality in the Extension Manager.... Read more

    Affected Products : seeddms
    • Published: May. 21, 2025
    • Modified: Jun. 13, 2025
    • Vuln Type: Authentication
  • 6.1

    MEDIUM
    CVE-2024-57529

    Cross Site Scripting vulnerability in Jeppesen JetPlanner Pro v.1.6.2.20 allows a remote attacker to execute arbitrary code.... Read more

    Affected Products : jetplanner
    • Published: May. 21, 2025
    • Modified: Jun. 13, 2025
    • Vuln Type: Cross-Site Scripting
  • 4.3

    MEDIUM
    CVE-2025-28099

    opencms V2.3 is vulnerable to Arbitrary file read in src/main/webapp/view/admin/document/dataPage.jsp,... Read more

    Affected Products : opencms
    • Published: Apr. 21, 2025
    • Modified: Jun. 13, 2025
    • Vuln Type: Path Traversal
  • 9.8

    CRITICAL
    CVE-2022-41572

    An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Privilege escalation can be accomplished on the server because nmap can be run as root. The attacker achieves total control over the server.... Read more

    Affected Products : eyesofnetwork
    • Published: Jan. 07, 2025
    • Modified: Jun. 13, 2025
    • Vuln Type: Authorization
  • 7.5

    HIGH
    CVE-2024-22893

    OpenSlides 4.0.15 verifies passwords by comparing password hashes using a function with content-dependent runtime. This can allow attackers to obtain information about the password hash using a timing attack.... Read more

    Affected Products : openslides
    • Published: Sep. 25, 2024
    • Modified: Jun. 13, 2025
  • 9.8

    CRITICAL
    CVE-2024-37759

    DataGear v5.0.0 and earlier was discovered to contain a SpEL (Spring Expression Language) expression injection vulnerability via the Data Viewing interface.... Read more

    Affected Products : datagear
    • Published: Jun. 24, 2024
    • Modified: Jun. 13, 2025
  • 8.8

    HIGH
    CVE-2024-37665

    An access control issue in Wvp GB28181 Pro 2.0 allows authenticated attackers to escalate privileges to Administrator via a crafted POST request.... Read more

    Affected Products : gb28181
    • Published: Jun. 12, 2024
    • Modified: Jun. 13, 2025
  • 6.5

    MEDIUM
    CVE-2024-36523

    An access control issue in Wvp GB28181 Pro 2.0 allows users to continue to access information in the application after deleting their own or administrator accounts. This is provided that the users do not log out of their deleted accounts.... Read more

    Affected Products : gb28181
    • Published: Jun. 12, 2024
    • Modified: Jun. 13, 2025
  • 6.1

    MEDIUM
    CVE-2024-39174

    A cross-site scripting (XSS) vulnerability in the Publish Article function of yzmcms v7.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a published article.... Read more

    Affected Products : yzmcms
    • Published: Jul. 05, 2024
    • Modified: Jun. 13, 2025
  • 5.5

    MEDIUM
    CVE-2024-37674

    Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity.... Read more

    Affected Products : moodle
    • Published: Jun. 20, 2024
    • Modified: Jun. 13, 2025
  • 5.4

    MEDIUM
    CVE-2025-46983

    Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more

    • Published: Jun. 10, 2025
    • Modified: Jun. 13, 2025
    • Vuln Type: Cross-Site Scripting
  • 5.4

    MEDIUM
    CVE-2025-46984

    Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more

    • Published: Jun. 10, 2025
    • Modified: Jun. 13, 2025
    • Vuln Type: Cross-Site Scripting
  • 5.4

    MEDIUM
    CVE-2025-46985

    Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more

    • Published: Jun. 10, 2025
    • Modified: Jun. 13, 2025
    • Vuln Type: Cross-Site Scripting
  • 5.4

    MEDIUM
    CVE-2025-46986

    Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more

    • Published: Jun. 10, 2025
    • Modified: Jun. 13, 2025
    • Vuln Type: Cross-Site Scripting
  • 5.4

    MEDIUM
    CVE-2025-46987

    Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more

    • Published: Jun. 10, 2025
    • Modified: Jun. 13, 2025
    • Vuln Type: Cross-Site Scripting
  • 6.2

    MEDIUM
    CVE-2024-53425

    A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue occurs when processing certain malformed MD5 model files, leading to an out-of-bounds read and potential application crash.... Read more

    Affected Products : assimp
    • Published: Nov. 21, 2024
    • Modified: Jun. 13, 2025
  • 5.4

    MEDIUM
    CVE-2025-46988

    Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more

    • Published: Jun. 10, 2025
    • Modified: Jun. 13, 2025
    • Vuln Type: Cross-Site Scripting
  • 9.1

    CRITICAL
    CVE-2024-52771

    DedeBIZ v6.3.0 was discovered to contain an arbitrary file deletion vulnerability via the component /admin/file_manage_view.... Read more

    Affected Products : dedebiz
    • Published: Nov. 20, 2024
    • Modified: Jun. 13, 2025
Showing 20 of 293426 Results