Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.9

    MEDIUM
    CVE-2023-38009

    IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the middle techniques due to the lack of certificate pinning.... Read more

    • Published: Jan. 26, 2025
    • Modified: Aug. 18, 2025
    • Vuln Type: Information Disclosure
  • 6.2

    MEDIUM
    CVE-2024-31906

    IBM Automation Decision Services 23.0.2 allows web pages to be stored locally which can be read by another user on the system.... Read more

    Affected Products : automation_decision_services
    • Published: Jan. 26, 2025
    • Modified: Aug. 14, 2025
    • Vuln Type: Information Disclosure
  • 5.5

    MEDIUM
    CVE-2024-13505

    The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ays_sections[5][questions][8][title]’ parameter in all versions up to, and including, 5.1.3.3 due to insufficient input sanitization and output escaping. This make... Read more

    Affected Products : survey_maker
    • Published: Jan. 26, 2025
    • Modified: Feb. 04, 2025
    • Vuln Type: Cross-Site Scripting
  • 6.1

    MEDIUM
    CVE-2024-12334

    The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via any parameter in all versions up to, and including, 2.4 due to insufficient input sanitization and output escaping. This ma... Read more

    Affected Products : wc_affiliate
    • Published: Jan. 26, 2025
    • Modified: Feb. 04, 2025
    • Vuln Type: Cross-Site Scripting
  • 8.8

    HIGH
    CVE-2024-11936

    The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'backup_options' and 'restore_options' function in all versions up to, and including, 3.16.0... Read more

    Affected Products : zox_news
    • Published: Jan. 26, 2025
    • Modified: Feb. 04, 2025
    • Vuln Type: Authorization
  • 8.8

    HIGH
    CVE-2024-11641

    The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.2. This is due to missing or incorrect nonce validation on the 'save' function. This makes it possible for... Read more

    • Published: Jan. 26, 2025
    • Modified: Feb. 04, 2025
    • Vuln Type: Cross-Site Request Forgery
  • 7.1

    HIGH
    CVE-2024-46881

    Develocity (formerly Gradle Enterprise) before 2024.1.8 has Incorrect Access Control. Project-level access control configuration was introduced in Enterprise Config schema version 8. Migration functionality from schema version 8 to versions 9 and 10 (in a... Read more

    Affected Products : enterprise
    • Published: Jan. 26, 2025
    • Modified: Jan. 26, 2025
    • Vuln Type: Authorization
  • 7.5

    HIGH
    CVE-2024-11090

    The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.13 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extra... Read more

    • Published: Jan. 26, 2025
    • Modified: Feb. 04, 2025
    • Vuln Type: Information Disclosure
  • 8.1

    HIGH
    CVE-2024-10705

    The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.5 via the 'mpg_download_file_by_link' function. This makes it possible for authenticated attackers, with e... Read more

    Affected Products : multiple_page_generator
    • Published: Jan. 26, 2025
    • Modified: Feb. 04, 2025
    • Vuln Type: Server-Side Request Forgery
  • 8.3

    HIGH
    CVE-2025-24858

    Develocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access to a Develocity server to obtain the hashed password of the system user. The hash algorithm used by Develocity was chosen according to best practices for pas... Read more

    Affected Products : enterprise
    • Published: Jan. 26, 2025
    • Modified: Jan. 26, 2025
    • Vuln Type: Information Disclosure
  • 6.1

    MEDIUM
    CVE-2024-10636

    The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, a... Read more

    Affected Products :
    • Published: Jan. 26, 2025
    • Modified: Jan. 26, 2025
    • Vuln Type: Cross-Site Scripting
  • 7.3

    HIGH
    CVE-2024-10633

    The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (Agency)... Read more

    Affected Products :
    • Published: Jan. 26, 2025
    • Modified: Jan. 26, 2025
    • Vuln Type: Authentication
  • 7.5

    HIGH
    CVE-2024-10628

    The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (... Read more

    Affected Products : quiz_maker
    • Published: Jan. 26, 2025
    • Modified: Jun. 05, 2025
    • Vuln Type: Injection
  • 7.2

    HIGH
    CVE-2024-10574

    The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ays_save_google_credentials' function in all versions up to, and including, 8.8.0 (Business),... Read more

    Affected Products :
    • Published: Jan. 26, 2025
    • Modified: Jan. 26, 2025
    • Vuln Type: Authorization
  • 8.1

    HIGH
    CVE-2022-49043

    xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free.... Read more

    Affected Products : libxml2
    • Published: Jan. 26, 2025
    • Modified: Jan. 26, 2025
    • Vuln Type: Memory Corruption
  • 8.5

    HIGH
    CVE-2025-0543

    Local privilege escalation in G DATA Security Client due to incorrect assignment of privileges to directories. This vulnerability allows a local, unprivileged attacker to escalate privileges on affected installations by placing an arbitrary executable in ... Read more

    Affected Products :
    • Published: Jan. 25, 2025
    • Modified: Jan. 25, 2025
    • Vuln Type: Authorization
  • 7.8

    HIGH
    CVE-2025-0542

    Local privilege escalation due to incorrect assignment of privileges of temporary files in the update mechanism of G DATA Management Server. This vulnerability allows a local, unprivileged attacker to escalate privileges on affected installations by placi... Read more

    Affected Products :
    • Published: Jan. 25, 2025
    • Modified: Jan. 25, 2025
  • 5.3

    MEDIUM
    CVE-2024-35150

    IBM Maximo Application Suite 8.10.12, 8.11.0, 9.0.1, and 9.1.0 - Monitor Component does not neutralize output that is written to logs, which could allow an attacker to inject false log entries.... Read more

    Affected Products : maximo_application_suite
    • Published: Jan. 25, 2025
    • Modified: Jul. 08, 2025
    • Vuln Type: Information Disclosure
  • 8.8

    HIGH
    CVE-2024-35148

    IBM Maximo Application Suite 8.10.10, 8.11.7, and 9.0 - Monitor Component is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-... Read more

    Affected Products : maximo_application_suite
    • Published: Jan. 25, 2025
    • Modified: Jul. 08, 2025
    • Vuln Type: Injection
  • 6.1

    MEDIUM
    CVE-2024-35145

    IBM Maximo Application Suite 9.0.0 - Monitor Component is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadi... Read more

    Affected Products : maximo_application_suite
    • Published: Jan. 25, 2025
    • Modified: Jul. 08, 2025
    • Vuln Type: Cross-Site Scripting
Showing 20 of 291219 Results