Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.8

    HIGH
    CVE-2019-20458

    An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. By default, the device comes (and functions) without a password. The user is at no point prompted to set up a password on the device (leaving a number of devices without a passwo... Read more

    Affected Products :
    • Published: Nov. 07, 2024
    • Modified: Nov. 08, 2024
  • 9.1

    CRITICAL
    CVE-2019-20457

    An issue was discovered on Brother MFC-J491DW C1806180757 devices. The printer's web-interface password hash can be retrieved without authentication, because the response header of any failed login attempt returns an incomplete authorization cookie. The v... Read more

    Affected Products :
    • Published: Nov. 07, 2024
    • Modified: Nov. 08, 2024
  • 6.4

    MEDIUM
    CVE-2024-48954

    An issue was discovered in Logpoint before 7.5.0. Unvalidated input during the EventHub Collector setup by an authenticated user leads to Remote Code execution.... Read more

    Affected Products : siem
    • Published: Nov. 07, 2024
    • Modified: Apr. 30, 2025
  • 7.5

    HIGH
    CVE-2024-48953

    An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users to register their own authentication plugins in Logpoi... Read more

    Affected Products : siem
    • Published: Nov. 07, 2024
    • Modified: Apr. 30, 2025
  • 6.4

    MEDIUM
    CVE-2024-48952

    An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints without authentication. This static key vulnerability enables attackers to create custom JWT secret keys for una... Read more

    Affected Products : soar
    • Published: Nov. 07, 2024
    • Modified: Apr. 30, 2025
  • 7.5

    HIGH
    CVE-2024-48951

    An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoint's API Token leading to authentication bypass.... Read more

    Affected Products : siem
    • Published: Nov. 07, 2024
    • Modified: Apr. 30, 2025
  • 7.5

    HIGH
    CVE-2024-48950

    An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing unauthenticated attackers to bypass CSRF protections and authentication.... Read more

    Affected Products : siem
    • Published: Nov. 07, 2024
    • Modified: Apr. 18, 2025
  • 7.7

    HIGH
    CVE-2024-40715

    A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform authentication bypass. Attackers must be able to perform Man-in-the-Middle (MITM) attack to exploit this vulnerability.... Read more

    • Published: Nov. 07, 2024
    • Modified: Jul. 11, 2025
  • 6.5

    MEDIUM
    CVE-2024-10965

    A vulnerability classified as problematic was found in emqx neuron up to 2.10.0. Affected by this vulnerability is an unknown functionality of the file /api/v2/schema of the component JSON File Handler. The manipulation leads to information disclosure. Th... Read more

    Affected Products : neuron
    • Published: Nov. 07, 2024
    • Modified: Nov. 23, 2024
  • 9.8

    CRITICAL
    CVE-2024-10964

    A vulnerability classified as critical has been found in emqx neuron up to 2.10.0. Affected is the function handle_add_plugin in the library cmd.library of the file plugins/restful/plugin_handle.c. The manipulation leads to buffer overflow. It is possible... Read more

    Affected Products : neuron
    • Published: Nov. 07, 2024
    • Modified: Nov. 26, 2024
  • 4.8

    MEDIUM
    CVE-2024-8378

    The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_upload, but not for example for code that uses wp_handle_sideload which is often used to upload attachments via raw POST data.... Read more

    Affected Products : safe_svg
    • Published: Nov. 07, 2024
    • Modified: May. 17, 2025
  • 7.4

    HIGH
    CVE-2024-10963

    A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attackers to trick the system by pretending to be a trusted hostname, gaining unauthorized access. This issue pose... Read more

    • Published: Nov. 07, 2024
    • Modified: Feb. 06, 2025
  • 7.5

    HIGH
    CVE-2024-10668

    There exists an auth bypass in Google Quickshare where an attacker can upload an unknown file type to a victim. The root cause of the vulnerability lies in the fact that when a Payload Transfer frame of type FILE is sent to Quick Share, the file that is c... Read more

    Affected Products : windows nearby quick_share
    • Published: Nov. 07, 2024
    • Modified: Jul. 23, 2025
  • 4.3

    MEDIUM
    CVE-2024-9926

    The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form... Read more

    Affected Products : jetpack
    • Published: Nov. 07, 2024
    • Modified: May. 28, 2025
  • 7.5

    HIGH
    CVE-2024-43440

    A flaw was found in moodle. A local file may include risks when restoring block backups.... Read more

    Affected Products : moodle
    • Published: Nov. 07, 2024
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2024-43438

    A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users returned by the report.... Read more

    Affected Products : moodle
    • Published: Nov. 07, 2024
    • Modified: Aug. 05, 2025
  • 7.2

    HIGH
    CVE-2024-43436

    A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators.... Read more

    Affected Products : moodle
    • Published: Nov. 07, 2024
    • Modified: Aug. 05, 2025
  • 8.1

    HIGH
    CVE-2024-43434

    The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.... Read more

    Affected Products : moodle
    • Published: Nov. 07, 2024
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2024-43431

    A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access.... Read more

    Affected Products : moodle
    • Published: Nov. 07, 2024
    • Modified: May. 01, 2025
  • 7.7

    HIGH
    CVE-2024-43428

    To address a cache poisoning risk in Moodle, additional validation for local storage was required.... Read more

    Affected Products : moodle
    • Published: Nov. 07, 2024
    • Modified: May. 01, 2025
Showing 20 of 293609 Results