Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2025-32103

    CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accessible by SMB at UNC share pathnames, bypassing SecurityManager restrictions.... Read more

    Affected Products : crushftp
    • Published: Apr. 15, 2025
    • Modified: Jun. 13, 2025
    • Vuln Type: Path Traversal
  • 5.3

    MEDIUM
    CVE-2025-49186

    The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.... Read more

    Affected Products :
    • Published: Jun. 12, 2025
    • Modified: Jun. 13, 2025
    • Vuln Type: Authentication
  • 7.5

    HIGH
    CVE-2025-49182

    Files in the source code contain login credentials for the admin user and the property configuration password, allowing an attacker to get full access to the application.... Read more

    Affected Products :
    • Published: Jun. 12, 2025
    • Modified: Jun. 13, 2025
    • Vuln Type: Information Disclosure
  • 9.0

    CRITICAL
    CVE-2024-55585

    In the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, resulting in unrestricted read and write access, as demonstrated by /api/v1/users/resetpassword.... Read more

    Affected Products :
    • Published: Jun. 07, 2025
    • Modified: Jun. 13, 2025
    • Vuln Type: Authentication
  • 5.3

    MEDIUM
    CVE-2024-6538

    A flaw was found in OpenShift Console. A Server Side Request Forgery (SSRF) attack can happen if an attacker supplies all or part of a URL to the server to query. The server is considered to be in a privileged network position and can often reach exposed ... Read more

    Affected Products : openshift_container_platform
    • Published: Nov. 25, 2024
    • Modified: Jun. 13, 2025
  • 9.8

    CRITICAL
    CVE-2025-5593

    A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. This affects an unknown part of the component HOST Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The ex... Read more

    Affected Products : freefloat_ftp_server ftp_server
    • Published: Jun. 04, 2025
    • Modified: Jun. 13, 2025
    • Vuln Type: Memory Corruption
  • 9.8

    CRITICAL
    CVE-2025-5594

    A vulnerability has been found in FreeFloat FTP Server 1.0 and classified as critical. This vulnerability affects unknown code of the component SET Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The explo... Read more

    Affected Products : freefloat_ftp_server ftp_server
    • Published: Jun. 04, 2025
    • Modified: Jun. 13, 2025
    • Vuln Type: Memory Corruption
  • 6.1

    MEDIUM
    CVE-2024-50677

    A cross-site scripting (XSS) vulnerability in OroPlatform CMS v5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search parameter.... Read more

    Affected Products : oroplatform orocommerce
    • Published: Dec. 06, 2024
    • Modified: Jun. 13, 2025
  • 4.3

    MEDIUM
    CVE-2024-48900

    A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipients can only access lists of those they are intended to have access to.... Read more

    Affected Products : moodle
    • Published: Nov. 13, 2024
    • Modified: Jun. 13, 2025
  • 7.2

    HIGH
    CVE-2024-46213

    REDAXO CMS v2.11.0 was discovered to contain a remote code execution (RCE) vulnerability.... Read more

    Affected Products : redaxo
    • Published: Oct. 16, 2024
    • Modified: Jun. 13, 2025
  • 5.5

    MEDIUM
    CVE-2024-48241

    An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function.... Read more

    Affected Products : radare2
    • Published: Oct. 30, 2024
    • Modified: Jun. 13, 2025
  • 6.5

    MEDIUM
    CVE-2024-48052

    In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no restrictions on the URL, which allows access to local target resources... Read more

    Affected Products : gradio
    • Published: Nov. 04, 2024
    • Modified: Jun. 13, 2025
  • 5.4

    MEDIUM
    CVE-2024-6766

    The shortcodes-ultimate-pro WordPress plugin before 7.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to... Read more

    Affected Products : shortcodes_ultimate
    • Published: Aug. 06, 2024
    • Modified: Jun. 13, 2025
  • 9.8

    CRITICAL
    CVE-2021-20588

    Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and ... Read more

    • Published: Feb. 19, 2021
    • Modified: Jun. 13, 2025
  • 9.8

    CRITICAL
    CVE-2021-20587

    Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions ... Read more

    • Published: Feb. 19, 2021
    • Modified: Jun. 13, 2025
  • 7.3

    HIGH
    CVE-2024-40560

    Tmall_demo before v2024.07.03 was discovered to contain a SQL injection vulnerability.... Read more

    Affected Products : tmall_demo
    • Published: Jul. 15, 2024
    • Modified: Jun. 13, 2025
  • 5.3

    MEDIUM
    CVE-2024-40555

    Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload vulnerability.... Read more

    Affected Products : tmall_demo
    • Published: Jul. 15, 2024
    • Modified: Jun. 13, 2025
  • 6.8

    MEDIUM
    CVE-2024-4977

    The Index WP MySQL For Speed WordPress plugin before 1.4.18 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more

    Affected Products : mysql index_wp_mysql_for_speed
    • Published: Jul. 13, 2024
    • Modified: Jun. 13, 2025
  • 4.4

    MEDIUM
    CVE-2024-30799

    An issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of service via the Breach Return Point function.... Read more

    Affected Products : px4_drone_autopilot
    • Published: Apr. 22, 2024
    • Modified: Jun. 12, 2025
  • 6.6

    MEDIUM
    CVE-2024-29460

    An issue in PX4 Autopilot v.1.14.0 allows an attacker to manipulate the flight path allowing for crashes of the drone via the home point location of the mission_block.cpp component.... Read more

    Affected Products : px4_drone_autopilot
    • Published: Apr. 10, 2024
    • Modified: Jun. 12, 2025
Showing 20 of 293496 Results