Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2024-45790

    This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack against legit... Read more

    Affected Products : aim-star
    • Published: Sep. 11, 2024
    • Modified: Sep. 18, 2024
  • 7.5

    HIGH
    CVE-2024-42485

    Filament Excel enables excel export for Filament admin resources. The export download route `/filament-excel/{path}` allowed downloading any file without login when the webserver allows `../` in the URL. Patched with Version v2.3.3.... Read more

    Affected Products : filament_excel
    • Published: Aug. 12, 2024
    • Modified: Sep. 18, 2024
  • 6.1

    MEDIUM
    CVE-2024-8144

    A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functionality of the file /index.php/admin of the component Logo Handler. The manipulation leads to cross site scripting. The attack can be l... Read more

    Affected Products : classcms classcms
    • Published: Aug. 25, 2024
    • Modified: Sep. 18, 2024
  • 6.5

    MEDIUM
    CVE-2024-38270

    An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel GS1900-10HP firmware version V2.80(AAZI.0)C0. This vulnerability could allow a LAN-base... Read more

    • Published: Sep. 10, 2024
    • Modified: Sep. 18, 2024
  • 8.7

    HIGH
    CVE-2024-45787

    This vulnerability exists in Reedos aiM-Star version 2.0.1 due to transmission of sensitive information in plain text in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter through API reque... Read more

    Affected Products : aim-star
    • Published: Sep. 11, 2024
    • Modified: Sep. 18, 2024
  • 5.3

    MEDIUM
    CVE-2024-7727

    The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions called via the 'h5vp_ajax_handler' ajax action in all versions up to, and ... Read more

    Affected Products : html5_video_player
    • Published: Sep. 11, 2024
    • Modified: Sep. 18, 2024
  • 9.8

    CRITICAL
    CVE-2024-8517

    SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending a crafted multipart file upload HTTP request.... Read more

    Affected Products : spip
    • Published: Sep. 06, 2024
    • Modified: Sep. 18, 2024
  • 4.3

    MEDIUM
    CVE-2024-7721

    The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_password' function in all versions up to, and including, 2.5.34. This makes i... Read more

    Affected Products : html5_video_player
    • Published: Sep. 11, 2024
    • Modified: Sep. 18, 2024
  • 8.8

    HIGH
    CVE-2024-45041

    External Secrets Operator is a Kubernetes operator that integrates external secret management systems. The external-secrets has a deployment called default-external-secrets-cert-controller, which is bound with a same-name ClusterRole. This ClusterRole has... Read more

    Affected Products : external_secrets_operator
    • Published: Sep. 09, 2024
    • Modified: Sep. 18, 2024
  • 9.8

    CRITICAL
    CVE-2024-8611

    A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file ssms.php. The manipulation of the argument customer leads to sql injection. The attack... Read more

    Affected Products : tailoring_management_system
    • Published: Sep. 09, 2024
    • Modified: Sep. 18, 2024
  • 7.1

    HIGH
    CVE-2024-43327

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Boone Gorges Invite Anyone allows Reflected XSS.This issue affects Invite Anyone: from n/a through 1.4.7.... Read more

    Affected Products : invite_anyone
    • Published: Aug. 18, 2024
    • Modified: Sep. 18, 2024
  • 5.9

    MEDIUM
    CVE-2024-43967

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Stark Digital WP Testimonial Widget allows Stored XSS.This issue affects WP Testimonial Widget: from n/a through 3.1.... Read more

    Affected Products : wp_testimonial_widget
    • Published: Aug. 26, 2024
    • Modified: Sep. 18, 2024
  • 8.8

    HIGH
    CVE-2024-39641

    Cross-Site Request Forgery (CSRF) vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.6.8.2.... Read more

    Affected Products : learnpress
    • Published: Aug. 26, 2024
    • Modified: Sep. 18, 2024
  • 8.8

    HIGH
    CVE-2024-39645

    Cross-Site Request Forgery (CSRF) vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2.... Read more

    Affected Products : tutor_lms
    • Published: Aug. 26, 2024
    • Modified: Sep. 18, 2024
  • 8.8

    HIGH
    CVE-2024-39657

    Cross-Site Request Forgery (CSRF) vulnerability in Sender Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce.This issue affects Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce: from n/a through 2.6.18.... Read more

    Affected Products : sender
    • Published: Aug. 26, 2024
    • Modified: Sep. 18, 2024
  • 8.8

    HIGH
    CVE-2024-43116

    Cross-Site Request Forgery (CSRF) vulnerability in 10up Simple Local Avatars.This issue affects Simple Local Avatars: from n/a through 2.7.10.... Read more

    Affected Products : simple_local_avatars
    • Published: Aug. 26, 2024
    • Modified: Sep. 18, 2024
  • 8.8

    HIGH
    CVE-2024-43117

    Cross-Site Request Forgery (CSRF) vulnerability in WPMU DEV Hummingbird.This issue affects Hummingbird: from n/a through 3.9.1.... Read more

    Affected Products : hummingbird hummingbird
    • Published: Aug. 26, 2024
    • Modified: Sep. 18, 2024
  • 7.5

    HIGH
    CVE-2024-43230

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Shared Files – File Upload Form Shared Files.This issue affects Shared Files: from n/a through 1.7.28.... Read more

    Affected Products : shared_files
    • Published: Aug. 26, 2024
    • Modified: Sep. 18, 2024
  • 8.8

    HIGH
    CVE-2023-37233

    Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.... Read more

    Affected Products : spectrum
    • Published: Sep. 10, 2024
    • Modified: Sep. 18, 2024
  • 9.8

    CRITICAL
    CVE-2023-37234

    Loftware Spectrum through 4.6 has unprotected JMX Registry.... Read more

    Affected Products : spectrum
    • Published: Sep. 10, 2024
    • Modified: Sep. 18, 2024
Showing 20 of 290985 Results