Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.3

    CRITICAL
    CVE-2024-47073

    DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into business trends. In affected versions a the lack of signature verification of jwt tokens allows attackers to forge jwts which then all... Read more

    Affected Products : dataease
    • Published: Nov. 07, 2024
    • Modified: Feb. 20, 2025
  • 8.8

    HIGH
    CVE-2024-45794

    devtron is an open source tool integration platform for Kubernetes. In affected versions an authenticated user (with minimum permission) could utilize and exploit SQL Injection to allow the execution of malicious SQL queries via CreateUser API (/orchestra... Read more

    Affected Products : devtron
    • Published: Nov. 07, 2024
    • Modified: Nov. 08, 2024
  • 7.5

    HIGH
    CVE-2024-10967

    A vulnerability was found in code-projects E-Health Care System 1.0. It has been classified as critical. Affected is an unknown function of the file /Doctor/delete_user_appointment_request.php. The manipulation of the argument id leads to sql injection. I... Read more

    Affected Products : e-health_care_system
    • Published: Nov. 07, 2024
    • Modified: Nov. 26, 2024
  • 8.8

    HIGH
    CVE-2024-10966

    A vulnerability, which was classified as critical, has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected by this issue is some unknown functionality of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable leads to os command in... Read more

    Affected Products : x18_firmware x18
    • Published: Nov. 07, 2024
    • Modified: Dec. 16, 2024
  • 7.5

    HIGH
    CVE-2020-11926

    An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Clients can authenticate themselves to the device using a username and password. These credentials can be obtained through an unauthenticated web request, e.g., for a JavaScript f... Read more

    Affected Products :
    • Published: Nov. 07, 2024
    • Modified: Nov. 08, 2024
  • 8.8

    HIGH
    CVE-2020-11921

    An issue was discovered in Lush 2 through 2020-02-25. Due to the lack of Bluetooth traffic encryption, it is possible to hijack an ongoing Bluetooth connection between the Lush 2 and a mobile phone. This allows an attacker to gain full control over the de... Read more

    Affected Products :
    • Published: Nov. 07, 2024
    • Modified: Nov. 08, 2024
  • 8.0

    HIGH
    CVE-2020-11919

    An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. There is no CSRF protection.... Read more

    • Published: Nov. 07, 2024
    • Modified: Apr. 24, 2025
  • 5.4

    MEDIUM
    CVE-2020-11918

    An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. When a backup file is created through the web interface, information on all users, including passwords, can be found in cleartext in the backup file. An attacker capable of accessing the w... Read more

    • Published: Nov. 07, 2024
    • Modified: Apr. 24, 2025
  • 4.3

    MEDIUM
    CVE-2020-11917

    An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. It uses a default SSID value, which makes it easier for remote attackers to discover the physical locations of many Siime Eye devices, violating the privacy of users who do not wish to dis... Read more

    • Published: Nov. 07, 2024
    • Modified: Apr. 24, 2025
  • 6.3

    MEDIUM
    CVE-2020-11916

    An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. The password for the root user is hashed using an old and deprecated hashing technique. Because of this deprecated hashing, the success probability of an attacker in an offline cracking at... Read more

    • Published: Nov. 07, 2024
    • Modified: Apr. 24, 2025
  • 8.4

    HIGH
    CVE-2019-20459

    An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. With the SNMPv1 public community, all values can be read, and with the epson community, all the changeable values can be written/updated, as demonstrated by permanently disabling... Read more

    Affected Products :
    • Published: Nov. 07, 2024
    • Modified: Nov. 08, 2024
  • 8.8

    HIGH
    CVE-2019-20458

    An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. By default, the device comes (and functions) without a password. The user is at no point prompted to set up a password on the device (leaving a number of devices without a passwo... Read more

    Affected Products :
    • Published: Nov. 07, 2024
    • Modified: Nov. 08, 2024
  • 9.1

    CRITICAL
    CVE-2019-20457

    An issue was discovered on Brother MFC-J491DW C1806180757 devices. The printer's web-interface password hash can be retrieved without authentication, because the response header of any failed login attempt returns an incomplete authorization cookie. The v... Read more

    Affected Products :
    • Published: Nov. 07, 2024
    • Modified: Nov. 08, 2024
  • 6.4

    MEDIUM
    CVE-2024-48954

    An issue was discovered in Logpoint before 7.5.0. Unvalidated input during the EventHub Collector setup by an authenticated user leads to Remote Code execution.... Read more

    Affected Products : siem
    • Published: Nov. 07, 2024
    • Modified: Apr. 30, 2025
  • 7.5

    HIGH
    CVE-2024-48953

    An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users to register their own authentication plugins in Logpoi... Read more

    Affected Products : siem
    • Published: Nov. 07, 2024
    • Modified: Apr. 30, 2025
  • 6.4

    MEDIUM
    CVE-2024-48952

    An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints without authentication. This static key vulnerability enables attackers to create custom JWT secret keys for una... Read more

    Affected Products : soar
    • Published: Nov. 07, 2024
    • Modified: Apr. 30, 2025
  • 7.5

    HIGH
    CVE-2024-48951

    An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoint's API Token leading to authentication bypass.... Read more

    Affected Products : siem
    • Published: Nov. 07, 2024
    • Modified: Apr. 30, 2025
  • 7.5

    HIGH
    CVE-2024-48950

    An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing unauthenticated attackers to bypass CSRF protections and authentication.... Read more

    Affected Products : siem
    • Published: Nov. 07, 2024
    • Modified: Apr. 18, 2025
  • 7.7

    HIGH
    CVE-2024-40715

    A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform authentication bypass. Attackers must be able to perform Man-in-the-Middle (MITM) attack to exploit this vulnerability.... Read more

    • Published: Nov. 07, 2024
    • Modified: Jul. 11, 2025
  • 6.5

    MEDIUM
    CVE-2024-10965

    A vulnerability classified as problematic was found in emqx neuron up to 2.10.0. Affected by this vulnerability is an unknown functionality of the file /api/v2/schema of the component JSON File Handler. The manipulation leads to information disclosure. Th... Read more

    Affected Products : neuron
    • Published: Nov. 07, 2024
    • Modified: Nov. 23, 2024
Showing 20 of 293620 Results