Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.2

    HIGH
    CVE-2024-46213

    REDAXO CMS v2.11.0 was discovered to contain a remote code execution (RCE) vulnerability.... Read more

    Affected Products : redaxo
    • Published: Oct. 16, 2024
    • Modified: Jun. 13, 2025
  • 5.5

    MEDIUM
    CVE-2024-48241

    An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function.... Read more

    Affected Products : radare2
    • Published: Oct. 30, 2024
    • Modified: Jun. 13, 2025
  • 6.5

    MEDIUM
    CVE-2024-48052

    In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no restrictions on the URL, which allows access to local target resources... Read more

    Affected Products : gradio
    • Published: Nov. 04, 2024
    • Modified: Jun. 13, 2025
  • 5.4

    MEDIUM
    CVE-2024-6766

    The shortcodes-ultimate-pro WordPress plugin before 7.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to... Read more

    Affected Products : shortcodes_ultimate
    • Published: Aug. 06, 2024
    • Modified: Jun. 13, 2025
  • 9.8

    CRITICAL
    CVE-2021-20588

    Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and ... Read more

    • Published: Feb. 19, 2021
    • Modified: Jun. 13, 2025
  • 9.8

    CRITICAL
    CVE-2021-20587

    Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions ... Read more

    • Published: Feb. 19, 2021
    • Modified: Jun. 13, 2025
  • 7.3

    HIGH
    CVE-2024-40560

    Tmall_demo before v2024.07.03 was discovered to contain a SQL injection vulnerability.... Read more

    Affected Products : tmall_demo
    • Published: Jul. 15, 2024
    • Modified: Jun. 13, 2025
  • 5.3

    MEDIUM
    CVE-2024-40555

    Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload vulnerability.... Read more

    Affected Products : tmall_demo
    • Published: Jul. 15, 2024
    • Modified: Jun. 13, 2025
  • 6.8

    MEDIUM
    CVE-2024-4977

    The Index WP MySQL For Speed WordPress plugin before 1.4.18 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more

    Affected Products : mysql index_wp_mysql_for_speed
    • Published: Jul. 13, 2024
    • Modified: Jun. 13, 2025
  • 4.4

    MEDIUM
    CVE-2024-30799

    An issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of service via the Breach Return Point function.... Read more

    Affected Products : px4_drone_autopilot
    • Published: Apr. 22, 2024
    • Modified: Jun. 12, 2025
  • 6.6

    MEDIUM
    CVE-2024-29460

    An issue in PX4 Autopilot v.1.14.0 allows an attacker to manipulate the flight path allowing for crashes of the drone via the home point location of the mission_block.cpp component.... Read more

    Affected Products : px4_drone_autopilot
    • Published: Apr. 10, 2024
    • Modified: Jun. 12, 2025
  • 4.2

    MEDIUM
    CVE-2024-2260

    A session fixation vulnerability exists in the zenml-io/zenml application, where JWT tokens used for user authentication are not invalidated upon logout. This flaw allows an attacker to bypass authentication mechanisms by reusing a victim's JWT token.... Read more

    Affected Products : zenml
    • Published: Apr. 16, 2024
    • Modified: Jun. 12, 2025
  • 8.8

    HIGH
    CVE-2024-31759

    An issue in sanluan PublicCMS v.4.0.202302.e allows an attacker to escalate privileges via the change password function.... Read more

    Affected Products : publiccms
    • Published: Apr. 16, 2024
    • Modified: Jun. 12, 2025
  • 4.8

    MEDIUM
    CVE-2024-2996

    A vulnerability was found in Bdtask Multi-Store Inventory Management System up to 20240320. It has been classified as problematic. Affected is an unknown function of the component Page Title Handler. The manipulation leads to cross site scripting. It is p... Read more

    • Published: Mar. 27, 2024
    • Modified: Jun. 12, 2025
  • 5.4

    MEDIUM
    CVE-2024-2997

    A vulnerability was found in Bdtask Multi-Store Inventory Management System up to 20240320. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument Category Name/Model Name/Brand Na... Read more

    • Published: Mar. 27, 2024
    • Modified: Jun. 12, 2025
  • 5.4

    MEDIUM
    CVE-2024-2998

    A vulnerability was found in Bdtask Multi-Store Inventory Management System up to 20240320. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Store Update Page. The manipulation of the argument Store N... Read more

    • Published: Mar. 27, 2024
    • Modified: Jun. 12, 2025
  • 8.8

    HIGH
    CVE-2024-3013

    A vulnerability was found in FLIR AX8 up to 1.46.16. It has been rated as critical. This issue affects some unknown processing of the file /tools/test_login.php?action=register of the component User Registration. The manipulation leads to improper authori... Read more

    Affected Products : flir_ax8_firmware flir_ax8
    • Published: Mar. 28, 2024
    • Modified: Jun. 12, 2025
  • 6.9

    MEDIUM
    CVE-2025-31128

    gifplayer is a customizable jquery plugin to play and stop animated gifs. gifplayer contains a cross-site scripting (XSS) vulnerability. This vulnerability is fixed in 0.3.7.... Read more

    Affected Products :
    • Published: Mar. 31, 2025
    • Modified: Jun. 12, 2025
    • Vuln Type: Cross-Site Scripting
  • 7.2

    HIGH
    CVE-2025-25426

    yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface.... Read more

    Affected Products : yshopmall
    • Published: Mar. 04, 2025
    • Modified: Jun. 12, 2025
    • Vuln Type: Injection
  • 6.5

    MEDIUM
    CVE-2025-1799

    A vulnerability, which was classified as critical, was found in Zorlan SkyCaiji 2.9. This affects the function previewAction of the file vendor/skycaiji/app/admin/controller/Tool.php. The manipulation of the argument data leads to server-side request forg... Read more

    Affected Products : skycaiji
    • Published: Mar. 01, 2025
    • Modified: Jun. 12, 2025
    • Vuln Type: Server-Side Request Forgery
Showing 20 of 293507 Results