Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.8

    HIGH
    CVE-2024-45331

    A incorrect privilege assignment in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15, FortiManager versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6... Read more

    • Published: Jan. 16, 2025
    • Modified: Feb. 03, 2025
    • Vuln Type: Authorization
  • 6.5

    MEDIUM
    CVE-2024-12226

    In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes script pod log in clear-text. This was identified in Version 2 however it was determined that this could also be achieved in Version 1 a... Read more

    Affected Products :
    • Published: Jan. 16, 2025
    • Modified: Jan. 16, 2025
    • Vuln Type: Information Disclosure
  • 6.4

    MEDIUM
    CVE-2024-11452

    The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'business_categories' shortcode in all versions up to, and including, 3.3.8 due to insufficient input sanitization and output escap... Read more

    Affected Products :
    • Published: Jan. 16, 2025
    • Modified: Jan. 16, 2025
    • Vuln Type: Cross-Site Scripting
  • 4.3

    MEDIUM
    CVE-2024-10789

    The WP User Profile Avatar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the wpupa_user_admin() function. This makes it possible for un... Read more

    Affected Products :
    • Published: Jan. 16, 2025
    • Modified: Jan. 16, 2025
    • Vuln Type: Cross-Site Request Forgery
  • 9.8

    CRITICAL
    CVE-2025-22916

    RE11S v1.11 was discovered to contain a stack overflow via the pppUserName parameter in the formPPPoESetup function.... Read more

    Affected Products : re11s_firmware re11s
    • Published: Jan. 16, 2025
    • Modified: Apr. 09, 2025
    • Vuln Type: Memory Corruption
  • 9.8

    CRITICAL
    CVE-2025-22913

    RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formStaDrvSetup function.... Read more

    Affected Products : re11s_firmware re11s
    • Published: Jan. 16, 2025
    • Modified: Apr. 09, 2025
    • Vuln Type: Memory Corruption
  • 9.8

    CRITICAL
    CVE-2025-22912

    RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.... Read more

    Affected Products : re11s_firmware re11s
    • Published: Jan. 16, 2025
    • Modified: Apr. 09, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-22907

    RE11S v1.11 was discovered to contain a stack overflow via the selSSID parameter in the formWlSiteSurvey function.... Read more

    Affected Products : re11s_firmware re11s
    • Published: Jan. 16, 2025
    • Modified: Apr. 09, 2025
    • Vuln Type: Memory Corruption
  • 9.8

    CRITICAL
    CVE-2025-22906

    RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN.... Read more

    Affected Products : re11s_firmware re11s
    • Published: Jan. 16, 2025
    • Modified: Apr. 09, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-22905

    RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp.... Read more

    Affected Products : re11s_firmware re11s
    • Published: Jan. 16, 2025
    • Modified: Apr. 09, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-22904

    RE11S v1.11 was discovered to contain a stack overflow via the pptpUserName parameter in the setWAN function.... Read more

    Affected Products : re11s_firmware re11s
    • Published: Jan. 16, 2025
    • Modified: Apr. 09, 2025
    • Vuln Type: Memory Corruption
  • 8.8

    HIGH
    CVE-2025-0457

    The airPASS from NetVision Information has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands.... Read more

    Affected Products : airpass
    • Published: Jan. 16, 2025
    • Modified: Jan. 16, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-0456

    The airPASS from NetVision Information has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access the specific administrative functionality to retrieve * all accounts and passwords.... Read more

    Affected Products : airpass
    • Published: Jan. 16, 2025
    • Modified: Jan. 16, 2025
    • Vuln Type: Authentication
  • 9.8

    CRITICAL
    CVE-2025-0455

    The airPASS from NetVision Information has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.... Read more

    Affected Products : airpass
    • Published: Jan. 16, 2025
    • Modified: Jan. 16, 2025
    • Vuln Type: Injection
  • 6.1

    MEDIUM
    CVE-2025-0170

    The DWT - Directory & Listing WordPress Theme is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping on the 'sort_by' and 'token' parameters. This makes it possibl... Read more

    Affected Products : dwt_listing
    • Published: Jan. 16, 2025
    • Modified: Jan. 16, 2025
    • Vuln Type: Cross-Site Scripting
  • 5.4

    MEDIUM
    CVE-2024-10970

    The The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.43. This is due to the software allowing users to execute an action that does not properly val... Read more

    • Published: Jan. 16, 2025
    • Modified: Aug. 08, 2025
    • Vuln Type: Misconfiguration
  • 4.3

    MEDIUM
    CVE-2025-0476

    Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, which allows an attacker to crash the mobile app for any user who opened a channel containing the specially crafted attachment... Read more

    Affected Products : mattermost_server mattermost
    • Published: Jan. 16, 2025
    • Modified: Jan. 16, 2025
    • Vuln Type: Denial of Service
  • 7.1

    HIGH
    CVE-2025-22976

    SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a local attacker to execute arbitrary code via not filtering the content correctly at the "checkOrder.php" shopId module.... Read more

    Affected Products :
    • Published: Jan. 15, 2025
    • Modified: Feb. 03, 2025
    • Vuln Type: Injection
  • 8.1

    HIGH
    CVE-2025-22964

    DDSN Interactive cm3 Acora CMS version 10.1.1 has an unauthenticated time-based blind SQL Injection vulnerability caused by insufficient input sanitization and validation in the "table" parameter. This flaw allows attackers to inject malicious SQL queries... Read more

    Affected Products :
    • Published: Jan. 15, 2025
    • Modified: Feb. 03, 2025
    • Vuln Type: Injection
  • 6.1

    MEDIUM
    CVE-2025-0215

    The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the showdata and initiate_restore parameters in all versions up to, and including, 1.24.12 due to insufficient input sanitization and ou... Read more

    Affected Products :
    • Published: Jan. 15, 2025
    • Modified: Jan. 15, 2025
    • Vuln Type: Cross-Site Scripting
Showing 20 of 291222 Results