Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2023-6271

    The Backup Migration WordPress plugin before 1.3.6 stores in-progress backups information in easy to find, publicly-accessible files, which may allow attackers monitoring those to leak sensitive information from the site's backups.... Read more

    Affected Products : backup_migration
    • Published: Jan. 01, 2024
    • Modified: Jun. 11, 2025
  • 7.5

    HIGH
    CVE-2023-6029

    The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are documents from the plugin, allowing unauthenticated users to delete arbitrary posts, as well as add and delete... Read more

    Affected Products : eazydocs
    • Published: Jan. 15, 2024
    • Modified: Jun. 11, 2025
  • 4.8

    MEDIUM
    CVE-2023-5943

    The Wp-Adv-Quiz WordPress plugin before 1.0.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.... Read more

    Affected Products : wp-adv-quiz
    • Published: Jan. 29, 2024
    • Modified: Jun. 11, 2025
  • 8.8

    HIGH
    CVE-2023-5235

    The Ovic Responsive WPBakery WordPress plugin before 1.2.9 does not limit which options can be updated via some of its AJAX actions, which may allow attackers with a subscriber+ account to update blog options, such as 'users_can_register' and 'default_rol... Read more

    Affected Products : ovic_responsive_wpbakery
    • Published: Jan. 08, 2024
    • Modified: Jun. 11, 2025
  • 6.5

    MEDIUM
    CVE-2023-5006

    The WP Discord Invite WordPress plugin before 2.5.1 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to perform actions on their behalf by tricking a logged in administrator to submit a crafted request.... Read more

    Affected Products : wp_discord_invite
    • Published: Jan. 17, 2024
    • Modified: Jun. 11, 2025
  • 7.5

    HIGH
    CVE-2023-52325

    A local file inclusion vulnerability in one of Trend Micro Apex Central's widgets could allow a remote attacker to execute arbitrary code on affected installations. Please note: this vulnerability must be used in conjunction with another one to exploit... Read more

    Affected Products : apex_central
    • Published: Jan. 23, 2024
    • Modified: Jun. 11, 2025
  • 7.5

    HIGH
    CVE-2023-52111

    Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.... Read more

    Affected Products : emui harmonyos
    • Published: Jan. 16, 2024
    • Modified: Jun. 11, 2025
  • 7.5

    HIGH
    CVE-2023-52102

    Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.... Read more

    Affected Products : emui harmonyos
    • Published: Jan. 16, 2024
    • Modified: Jun. 11, 2025
  • 7.5

    HIGH
    CVE-2023-52098

    Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerability will affect availability.... Read more

    Affected Products : emui harmonyos
    • Published: Jan. 16, 2024
    • Modified: Jun. 11, 2025
  • 9.8

    CRITICAL
    CVE-2023-52026

    TOTOlink EX1800T V9.1.0cu.2112_B20220316 was discovered to contain a remote command execution (RCE) vulnerability via the telnet_enabled parameter of the setTelnetCfg interface... Read more

    Affected Products : ex1800t_firmware ex1800t
    • Published: Jan. 12, 2024
    • Modified: Jun. 11, 2025
  • 6.5

    MEDIUM
    CVE-2023-51702

    Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in metadata without any ... Read more

    Affected Products : airflow airflow_cncf_kubernetes
    • Published: Jan. 24, 2024
    • Modified: Jun. 11, 2025
  • 6.5

    MEDIUM
    CVE-2023-50944

    Apache Airflow, versions before 2.8.1, have a vulnerability that allows an authenticated user to access the source code of a DAG to which they don't have access. This vulnerability is considered low since it requires an authenticated user to exploit it. U... Read more

    Affected Products : airflow
    • Published: Jan. 24, 2024
    • Modified: Jun. 11, 2025
  • 4.8

    MEDIUM
    CVE-2023-4925

    The Easy Forms for Mailchimp WordPress plugin through 6.8.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed... Read more

    Affected Products : easy_forms_for_mailchimp
    • Published: Jan. 15, 2024
    • Modified: Jun. 11, 2025
  • 7.2

    HIGH
    CVE-2023-4797

    The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server.... Read more

    Affected Products : newsletters
    • Published: Jan. 16, 2024
    • Modified: Jun. 11, 2025
  • 9.8

    CRITICAL
    CVE-2023-4472

    Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled to a predictable seed, which could lead to an unauthenticated account takeover of any user on the application.... Read more

    Affected Products : opinio
    • Published: Feb. 01, 2024
    • Modified: Jun. 11, 2025
  • 3.1

    LOW
    CVE-2023-49619

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer. This issue affects Apache Answer: through 1.2.0. Under normal circumstances, a user can only bookmark a question once, and will o... Read more

    Affected Products : answer
    • Published: Jan. 10, 2024
    • Modified: Jun. 11, 2025
  • 8.8

    HIGH
    CVE-2023-49257

    An authenticated user is able to upload an arbitrary CGI-compatible file using the certificate upload utility and execute it with the root user privileges.... Read more

    Affected Products : h8951-4g-esp_firmware h8951-4g-esp
    • Published: Jan. 12, 2024
    • Modified: Jun. 11, 2025
  • 9.8

    CRITICAL
    CVE-2023-48793

    Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature.... Read more

    Affected Products : manageengine_adaudit_plus
    • Published: Feb. 02, 2024
    • Modified: Jun. 11, 2025
  • 9.8

    CRITICAL
    CVE-2023-48792

    Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option.... Read more

    Affected Products : manageengine_adaudit_plus
    • Published: Feb. 02, 2024
    • Modified: Jun. 11, 2025
  • 5.4

    MEDIUM
    CVE-2023-48127

    An issue in myGAKUYA mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more

    Affected Products : line
    • Published: Jan. 26, 2024
    • Modified: Jun. 11, 2025
Showing 20 of 293350 Results