Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.5

    MEDIUM
    CVE-2024-8286

    The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting visit logs via CSRF attacks... Read more

    Affected Products : gdpr_cookie_consent
    • Published: May. 15, 2025
    • Modified: Jun. 12, 2025
    • Vuln Type: Cross-Site Request Forgery
  • 4.8

    MEDIUM
    CVE-2024-8284

    The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed... Read more

    Affected Products : download_manager
    • Published: May. 15, 2025
    • Modified: Jun. 12, 2025
    • Vuln Type: Cross-Site Scripting
  • 4.3

    MEDIUM
    CVE-2024-8245

    The GamiPress WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more

    Affected Products : gamipress gamipress_-_reset_user
    • Published: May. 15, 2025
    • Modified: Jun. 12, 2025
    • Vuln Type: Cross-Site Request Forgery
  • 4.8

    MEDIUM
    CVE-2024-11266

    The Geocache Stat Bar Widget WordPress plugin through 0.911 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is ... Read more

    Affected Products : geocache_stat_bar_widget
    • Published: May. 15, 2025
    • Modified: Jun. 12, 2025
    • Vuln Type: Cross-Site Scripting
  • 6.5

    MEDIUM
    CVE-2024-25451

    Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_DataBuffer::ReallocateBuffer() function.... Read more

    Affected Products : bento4
    • Published: Feb. 09, 2024
    • Modified: Jun. 12, 2025
  • 7.8

    HIGH
    CVE-2024-25446

    An issue in the HuginBase::PTools::setDestImage function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via parsing a crafted image.... Read more

    Affected Products : hugin
    • Published: Feb. 09, 2024
    • Modified: Jun. 12, 2025
  • 7.8

    HIGH
    CVE-2024-25442

    An issue in the HuginBase::PanoramaMemento::loadPTScript function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via parsing a crafted image.... Read more

    Affected Products : hugin
    • Published: Feb. 09, 2024
    • Modified: Jun. 12, 2025
  • 8.8

    HIGH
    CVE-2024-25417

    flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_translation.php.... Read more

    Affected Products : flusity
    • Published: Feb. 11, 2024
    • Modified: Jun. 12, 2025
  • 8.8

    HIGH
    CVE-2024-25308

    Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'name' parameter at School/teacher_login.php.... Read more

    Affected Products : simple_school_management_system
    • Published: Feb. 09, 2024
    • Modified: Jun. 12, 2025
  • 9.8

    CRITICAL
    CVE-2024-25191

    php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.... Read more

    Affected Products : php-jwt
    • Published: Feb. 08, 2024
    • Modified: Jun. 12, 2025
  • 9.8

    CRITICAL
    CVE-2024-24333

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc parameter in the setWiFiAclRules function.... Read more

    Affected Products : a3300r_firmware a3300r
    • Published: Jan. 30, 2024
    • Modified: Jun. 12, 2025
  • 9.8

    CRITICAL
    CVE-2024-24329

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setPortForwardRules function.... Read more

    Affected Products : a3300r_firmware a3300r
    • Published: Jan. 30, 2024
    • Modified: Jun. 12, 2025
  • 7.5

    HIGH
    CVE-2024-24263

    Lotos WebServer v0.1.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the response_append_status_line function at /lotos/src/response.c.... Read more

    Affected Products : lotos_webserver
    • Published: Feb. 05, 2024
    • Modified: Jun. 12, 2025
  • 7.5

    HIGH
    CVE-2024-24161

    MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not filtered.... Read more

    Affected Products : mrcms
    • Published: Feb. 02, 2024
    • Modified: Jun. 12, 2025
  • 5.4

    MEDIUM
    CVE-2024-24062

    springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/role.... Read more

    Affected Products : springboot-manager
    • Published: Feb. 01, 2024
    • Modified: Jun. 12, 2025
  • 5.4

    MEDIUM
    CVE-2024-24060

    springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/user.... Read more

    Affected Products : springboot-manager
    • Published: Feb. 01, 2024
    • Modified: Jun. 12, 2025
  • 9.8

    CRITICAL
    CVE-2024-24029

    JFinalCMS 5.0.0 is vulnerable to SQL injection via /admin/content/data.... Read more

    Affected Products : jfinalcms
    • Published: Feb. 02, 2024
    • Modified: Jun. 12, 2025
  • 9.8

    CRITICAL
    CVE-2024-24025

    An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: upload(). An attacker can pass in specially crafted filename parameter to perform arbitrary File download.... Read more

    Affected Products : novel-plus
    • Published: Feb. 08, 2024
    • Modified: Jun. 12, 2025
  • 9.8

    CRITICAL
    CVE-2024-24013

    A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /novel/pay/list... Read more

    Affected Products : novel-plus
    • Published: Feb. 06, 2024
    • Modified: Jun. 12, 2025
  • 9.8

    CRITICAL
    CVE-2024-24000

    jshERP v3.3 is vulnerable to Arbitrary File Upload. The jshERP-boot/systemConfig/upload interface does not check the uploaded file type, and the biz parameter can be spliced into the upload path, resulting in arbitrary file uploads with controllable paths... Read more

    Affected Products : jsherp
    • Published: Feb. 06, 2024
    • Modified: Jun. 12, 2025
Showing 20 of 293284 Results