Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.3

    MEDIUM
    CVE-2023-37005

    Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial Context Setup Failure` message missing a required `MME_UE_S1AP_ID` field to repeatedly... Read more

    Affected Products : open5gs
    • Published: Jan. 22, 2025
    • Modified: Apr. 22, 2025
  • 5.3

    MEDIUM
    CVE-2023-37004

    Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial Context Setup Response` message missing a required `MME_UE_S1AP_ID` field to repeatedl... Read more

    Affected Products : open5gs
    • Published: Jan. 22, 2025
    • Modified: Apr. 22, 2025
  • 5.3

    MEDIUM
    CVE-2023-37003

    Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `E-RAB Setup Response` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash th... Read more

    Affected Products : open5gs
    • Published: Jan. 22, 2025
    • Modified: Apr. 22, 2025
  • 5.3

    MEDIUM
    CVE-2023-37002

    Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `E-RAB Modification Indication` message missing a required `MME_UE_S1AP_ID` field to repeatedly... Read more

    Affected Products : open5gs
    • Published: Jan. 22, 2025
    • Modified: Apr. 22, 2025
  • 8.9

    HIGH
    CVE-2023-36998

    The NextEPC MME <= 1.0.1 (fixed in commit a8492c9c5bc0a66c6999cb5a263545b32a4109df) contains a stack-based buffer overflow vulnerability in the Emergency Number List decoding method. An attacker may send a NAS message containing an oversized Emergency Num... Read more

    Affected Products :
    • Published: Jan. 22, 2025
    • Modified: Feb. 06, 2025
  • 7.5

    HIGH
    CVE-2025-0395

    When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page siz... Read more

    Affected Products : glibc
    • Published: Jan. 22, 2025
    • Modified: Apr. 30, 2025
  • 7.3

    HIGH
    CVE-2024-13499

    The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via gamipress_do_shortcode() function in all versions up to, and including, 7.2.1. This... Read more

    Affected Products : gamipress
    • Published: Jan. 22, 2025
    • Modified: Jan. 24, 2025
  • 7.5

    HIGH
    CVE-2024-13496

    The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.3.1 due to insufficient esca... Read more

    Affected Products : gamipress
    • Published: Jan. 22, 2025
    • Modified: Mar. 24, 2025
  • 7.3

    HIGH
    CVE-2024-13495

    The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via the gamipress_ajax_get_logs() function in all versions up to, and including, 7.2.1.... Read more

    Affected Products : gamipress
    • Published: Jan. 22, 2025
    • Modified: Jan. 24, 2025
  • 4.3

    MEDIUM
    CVE-2024-13447

    The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hotel_booking_load_order_user AJAX action in all versions up to, and including, 2.1.6. This makes it possible for authenticated... Read more

    Affected Products : wp_hotel_booking
    • Published: Jan. 22, 2025
    • Modified: Jan. 24, 2025
  • 6.1

    MEDIUM
    CVE-2022-23439

    A externally controlled reference to a resource in another sphere in Fortinet FortiManager before version 7.4.3, FortiMail before version 7.0.3, FortiAnalyzer before version 7.4.3, FortiVoice version 7.0.0, 7.0.1 and before 6.4.8, FortiProxy before versio... Read more

    • Published: Jan. 22, 2025
    • Modified: Feb. 12, 2025
  • 7.2

    HIGH
    CVE-2025-0429

    The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the $form['post_content'] variable through the wpaicg_export_ai_forms() functi... Read more

    Affected Products : aipower
    • Published: Jan. 22, 2025
    • Modified: Jan. 24, 2025
  • 7.2

    HIGH
    CVE-2025-0428

    The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the $form['post_content'] variable through the wpaicg_export_prompts function.... Read more

    Affected Products : aipower
    • Published: Jan. 22, 2025
    • Modified: Jan. 24, 2025
  • 8.8

    HIGH
    CVE-2024-13361

    The AI Power: Complete AI Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpaicg_save_image_media function in all versions up to, and including, 1.8.96. This makes it possible for authenticated attac... Read more

    Affected Products : aipower
    • Published: Jan. 22, 2025
    • Modified: Jan. 24, 2025
  • 5.4

    MEDIUM
    CVE-2024-13360

    The AI Power: Complete AI Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.8.96 via the wpaicg_troubleshoot_add_vector(). This makes it possible for authenticated attackers, with subscriber-lev... Read more

    Affected Products : aipower
    • Published: Jan. 22, 2025
    • Modified: Jan. 24, 2025
  • 6.1

    MEDIUM
    CVE-2024-13319

    The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.6.5. This makes it possible for unauthenticated attack... Read more

    Affected Products : themify_builder builder
    • Published: Jan. 22, 2025
    • Modified: Jan. 24, 2025
  • 6.1

    MEDIUM
    CVE-2024-13406

    The XML for Google Merchant Center plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'feed_id' parameter in all versions up to, and including, 3.0.11 due to insufficient input sanitization and output escaping. This makes it poss... Read more

    Affected Products : xml_for_google_merchant_center
    • Published: Jan. 22, 2025
    • Modified: Jan. 24, 2025
  • 9.8

    CRITICAL
    CVE-2024-12857

    The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not properly verifying a user's identity prior to logging them in as that user. This makes it possible for unaut... Read more

    Affected Products : adforest
    • Published: Jan. 22, 2025
    • Modified: Jan. 24, 2025
  • 6.4

    MEDIUM
    CVE-2024-12117

    The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the Button block in all versions up to, and including, 3.13.11 due to insufficient input sanitization and output e... Read more

    Affected Products : stackable
    • Published: Jan. 22, 2025
    • Modified: Jan. 24, 2025
  • 6.6

    MEDIUM
    CVE-2025-23237

    Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. If a user logs in to CLI of the affected product, an arbitrary OS command may be executed.... Read more

    Affected Products :
    • Published: Jan. 22, 2025
    • Modified: Jan. 22, 2025
Showing 20 of 291123 Results