Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.8

    HIGH
    CVE-2024-25442

    An issue in the HuginBase::PanoramaMemento::loadPTScript function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via parsing a crafted image.... Read more

    Affected Products : hugin
    • Published: Feb. 09, 2024
    • Modified: Jun. 12, 2025
  • 8.8

    HIGH
    CVE-2024-25417

    flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_translation.php.... Read more

    Affected Products : flusity
    • Published: Feb. 11, 2024
    • Modified: Jun. 12, 2025
  • 8.8

    HIGH
    CVE-2024-25308

    Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'name' parameter at School/teacher_login.php.... Read more

    Affected Products : simple_school_management_system
    • Published: Feb. 09, 2024
    • Modified: Jun. 12, 2025
  • 9.8

    CRITICAL
    CVE-2024-25191

    php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.... Read more

    Affected Products : php-jwt
    • Published: Feb. 08, 2024
    • Modified: Jun. 12, 2025
  • 9.8

    CRITICAL
    CVE-2024-24333

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc parameter in the setWiFiAclRules function.... Read more

    Affected Products : a3300r_firmware a3300r
    • Published: Jan. 30, 2024
    • Modified: Jun. 12, 2025
  • 9.8

    CRITICAL
    CVE-2024-24329

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setPortForwardRules function.... Read more

    Affected Products : a3300r_firmware a3300r
    • Published: Jan. 30, 2024
    • Modified: Jun. 12, 2025
  • 7.5

    HIGH
    CVE-2024-24263

    Lotos WebServer v0.1.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the response_append_status_line function at /lotos/src/response.c.... Read more

    Affected Products : lotos_webserver
    • Published: Feb. 05, 2024
    • Modified: Jun. 12, 2025
  • 7.5

    HIGH
    CVE-2024-24161

    MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not filtered.... Read more

    Affected Products : mrcms
    • Published: Feb. 02, 2024
    • Modified: Jun. 12, 2025
  • 5.4

    MEDIUM
    CVE-2024-24062

    springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/role.... Read more

    Affected Products : springboot-manager
    • Published: Feb. 01, 2024
    • Modified: Jun. 12, 2025
  • 5.4

    MEDIUM
    CVE-2024-24060

    springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/user.... Read more

    Affected Products : springboot-manager
    • Published: Feb. 01, 2024
    • Modified: Jun. 12, 2025
  • 9.8

    CRITICAL
    CVE-2024-24029

    JFinalCMS 5.0.0 is vulnerable to SQL injection via /admin/content/data.... Read more

    Affected Products : jfinalcms
    • Published: Feb. 02, 2024
    • Modified: Jun. 12, 2025
  • 9.8

    CRITICAL
    CVE-2024-24025

    An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: upload(). An attacker can pass in specially crafted filename parameter to perform arbitrary File download.... Read more

    Affected Products : novel-plus
    • Published: Feb. 08, 2024
    • Modified: Jun. 12, 2025
  • 9.8

    CRITICAL
    CVE-2024-24013

    A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /novel/pay/list... Read more

    Affected Products : novel-plus
    • Published: Feb. 06, 2024
    • Modified: Jun. 12, 2025
  • 9.8

    CRITICAL
    CVE-2024-24000

    jshERP v3.3 is vulnerable to Arbitrary File Upload. The jshERP-boot/systemConfig/upload interface does not check the uploaded file type, and the biz parameter can be spliced into the upload path, resulting in arbitrary file uploads with controllable paths... Read more

    Affected Products : jsherp
    • Published: Feb. 06, 2024
    • Modified: Jun. 12, 2025
  • 4.3

    MEDIUM
    CVE-2023-5858

    Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)... Read more

    Affected Products : fedora debian_linux chrome edge_chromium
    • Published: Nov. 01, 2023
    • Modified: Jun. 12, 2025
  • 6.1

    MEDIUM
    CVE-2023-5758

    When opening a page in reader mode, the redirect URL could have caused attacker-controlled script to execute in a reflected Cross-Site Scripting (XSS) attack. This vulnerability affects Firefox for iOS < 119.... Read more

    Affected Products : firefox
    • Published: Oct. 25, 2023
    • Modified: Jun. 12, 2025
  • 7.5

    HIGH
    CVE-2023-46215

    Insertion of Sensitive Information into Log File vulnerability in Apache Airflow Celery provider, Apache Airflow. Sensitive information logged as clear text when rediss, amqp, rpc protocols are used as Celery result backend Note: the vulnerability is abo... Read more

    Affected Products : airflow airflow_celery_provider
    • Published: Oct. 28, 2023
    • Modified: Jun. 12, 2025
  • 9.8

    CRITICAL
    CVE-2023-45498

    VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability.... Read more

    Affected Products : vinchin_backup_and_recovery
    • Published: Oct. 27, 2023
    • Modified: Jun. 12, 2025
  • 9.9

    CRITICAL
    CVE-2023-45163

    The 1E-Exchange-CommandLinePing instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the input parameter, which allows for a specially crafted input to perform arbitrary code execution with SYSTEM pe... Read more

    Affected Products : platform
    • Published: Nov. 06, 2023
    • Modified: Jun. 12, 2025
  • 9.9

    CRITICAL
    CVE-2023-45161

    The 1E-Exchange-URLResponseTime instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the URL parameter, which allows for a specially crafted input to perform arbitrary code execution with SYSTEM perm... Read more

    Affected Products : platform
    • Published: Nov. 06, 2023
    • Modified: Jun. 12, 2025
Showing 20 of 293298 Results