Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.3

    MEDIUM
    CVE-2024-40555

    Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload vulnerability.... Read more

    Affected Products : tmall_demo
    • Published: Jul. 15, 2024
    • Modified: Jun. 13, 2025
  • 6.8

    MEDIUM
    CVE-2024-4977

    The Index WP MySQL For Speed WordPress plugin before 1.4.18 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more

    Affected Products : mysql index_wp_mysql_for_speed
    • Published: Jul. 13, 2024
    • Modified: Jun. 13, 2025
  • 4.4

    MEDIUM
    CVE-2024-30799

    An issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of service via the Breach Return Point function.... Read more

    Affected Products : px4_drone_autopilot
    • Published: Apr. 22, 2024
    • Modified: Jun. 12, 2025
  • 6.6

    MEDIUM
    CVE-2024-29460

    An issue in PX4 Autopilot v.1.14.0 allows an attacker to manipulate the flight path allowing for crashes of the drone via the home point location of the mission_block.cpp component.... Read more

    Affected Products : px4_drone_autopilot
    • Published: Apr. 10, 2024
    • Modified: Jun. 12, 2025
  • 4.2

    MEDIUM
    CVE-2024-2260

    A session fixation vulnerability exists in the zenml-io/zenml application, where JWT tokens used for user authentication are not invalidated upon logout. This flaw allows an attacker to bypass authentication mechanisms by reusing a victim's JWT token.... Read more

    Affected Products : zenml
    • Published: Apr. 16, 2024
    • Modified: Jun. 12, 2025
  • 8.8

    HIGH
    CVE-2024-31759

    An issue in sanluan PublicCMS v.4.0.202302.e allows an attacker to escalate privileges via the change password function.... Read more

    Affected Products : publiccms
    • Published: Apr. 16, 2024
    • Modified: Jun. 12, 2025
  • 4.8

    MEDIUM
    CVE-2024-2996

    A vulnerability was found in Bdtask Multi-Store Inventory Management System up to 20240320. It has been classified as problematic. Affected is an unknown function of the component Page Title Handler. The manipulation leads to cross site scripting. It is p... Read more

    • Published: Mar. 27, 2024
    • Modified: Jun. 12, 2025
  • 5.4

    MEDIUM
    CVE-2024-2997

    A vulnerability was found in Bdtask Multi-Store Inventory Management System up to 20240320. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument Category Name/Model Name/Brand Na... Read more

    • Published: Mar. 27, 2024
    • Modified: Jun. 12, 2025
  • 5.4

    MEDIUM
    CVE-2024-2998

    A vulnerability was found in Bdtask Multi-Store Inventory Management System up to 20240320. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Store Update Page. The manipulation of the argument Store N... Read more

    • Published: Mar. 27, 2024
    • Modified: Jun. 12, 2025
  • 8.8

    HIGH
    CVE-2024-3013

    A vulnerability was found in FLIR AX8 up to 1.46.16. It has been rated as critical. This issue affects some unknown processing of the file /tools/test_login.php?action=register of the component User Registration. The manipulation leads to improper authori... Read more

    Affected Products : flir_ax8_firmware flir_ax8
    • Published: Mar. 28, 2024
    • Modified: Jun. 12, 2025
  • 6.9

    MEDIUM
    CVE-2025-31128

    gifplayer is a customizable jquery plugin to play and stop animated gifs. gifplayer contains a cross-site scripting (XSS) vulnerability. This vulnerability is fixed in 0.3.7.... Read more

    Affected Products :
    • Published: Mar. 31, 2025
    • Modified: Jun. 12, 2025
    • Vuln Type: Cross-Site Scripting
  • 7.2

    HIGH
    CVE-2025-25426

    yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface.... Read more

    Affected Products : yshopmall
    • Published: Mar. 04, 2025
    • Modified: Jun. 12, 2025
    • Vuln Type: Injection
  • 6.5

    MEDIUM
    CVE-2025-1799

    A vulnerability, which was classified as critical, was found in Zorlan SkyCaiji 2.9. This affects the function previewAction of the file vendor/skycaiji/app/admin/controller/Tool.php. The manipulation of the argument data leads to server-side request forg... Read more

    Affected Products : skycaiji
    • Published: Mar. 01, 2025
    • Modified: Jun. 12, 2025
    • Vuln Type: Server-Side Request Forgery
  • 5.4

    MEDIUM
    CVE-2025-46853

    Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more

    • Published: Jun. 10, 2025
    • Modified: Jun. 12, 2025
    • Vuln Type: Cross-Site Scripting
  • 9.8

    CRITICAL
    CVE-2025-1791

    A vulnerability has been found in Zorlan SkyCaiji 2.9 and classified as critical. This vulnerability affects the function fileAction of the file vendor/skycaiji/app/admin/controller/Tool.php. The manipulation of the argument save_data leads to unrestricte... Read more

    Affected Products : skycaiji
    • Published: Mar. 01, 2025
    • Modified: Jun. 12, 2025
    • Vuln Type: Authentication
  • 5.4

    MEDIUM
    CVE-2025-46865

    Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more

    • Published: Jun. 10, 2025
    • Modified: Jun. 12, 2025
    • Vuln Type: Cross-Site Scripting
  • 5.4

    MEDIUM
    CVE-2025-46866

    Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more

    • Published: Jun. 10, 2025
    • Modified: Jun. 12, 2025
  • 5.4

    MEDIUM
    CVE-2025-46870

    Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more

    • Published: Jun. 10, 2025
    • Modified: Jun. 12, 2025
    • Vuln Type: Cross-Site Scripting
  • 5.4

    MEDIUM
    CVE-2025-46871

    Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more

    • Published: Jun. 10, 2025
    • Modified: Jun. 12, 2025
    • Vuln Type: Cross-Site Scripting
  • 5.4

    MEDIUM
    CVE-2025-46872

    Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more

    • Published: Jun. 10, 2025
    • Modified: Jun. 12, 2025
    • Vuln Type: Cross-Site Scripting
Showing 20 of 293425 Results