Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.8

    HIGH
    CVE-2024-43465

    Microsoft Excel Elevation of Privilege Vulnerability... Read more

    • Published: Sep. 10, 2024
    • Modified: Sep. 13, 2024
  • 6.5

    MEDIUM
    CVE-2024-7420

    The Insert PHP Code Snippet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.6. This is due to missing or incorrect nonce validation in the /admin/snippets.php file. This makes it possible for unau... Read more

    Affected Products : insert_php_code_snippet
    • Published: Aug. 15, 2024
    • Modified: Sep. 13, 2024
  • 7.5

    HIGH
    CVE-2024-43466

    Microsoft SharePoint Server Denial of Service Vulnerability... Read more

    Affected Products : sharepoint_server
    • Published: Sep. 10, 2024
    • Modified: Sep. 13, 2024
  • 7.3

    HIGH
    CVE-2024-43475

    Microsoft Windows Admin Center Information Disclosure Vulnerability... Read more

    • Published: Sep. 10, 2024
    • Modified: Sep. 13, 2024
  • 6.4

    MEDIUM
    CVE-2024-7144

    The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'slide_id' parameters in all versions up to, and including, 2.6.20 due to insufficient input sanitization and output escaping. This makes it possible for au... Read more

    Affected Products : jetelements
    • Published: Aug. 16, 2024
    • Modified: Sep. 13, 2024
  • 8.8

    HIGH
    CVE-2024-7145

    The JetElements plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.6.20 via the 'progress_type' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to incl... Read more

    Affected Products : jetelements
    • Published: Aug. 16, 2024
    • Modified: Sep. 13, 2024
  • 7.6

    HIGH
    CVE-2024-43476

    Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability... Read more

    Affected Products : dynamics_365
    • Published: Sep. 10, 2024
    • Modified: Sep. 13, 2024
  • 8.5

    HIGH
    CVE-2024-43479

    Microsoft Power Automate Desktop Remote Code Execution Vulnerability... Read more

    • Published: Sep. 10, 2024
    • Modified: Sep. 13, 2024
  • 4.3

    MEDIUM
    CVE-2023-3408

    The Bricks theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.1. This is due to missing or incorrect nonce validation on the 'save_settings' function. This makes it possible for unauthenticated attackers ... Read more

    Affected Products : bricks
    • Published: Aug. 17, 2024
    • Modified: Sep. 13, 2024
  • 8.8

    HIGH
    CVE-2024-8639

    Use after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more

    Affected Products : android chrome edge_chromium
    • Published: Sep. 11, 2024
    • Modified: Sep. 13, 2024
  • 8.8

    HIGH
    CVE-2024-8638

    Type Confusion in V8 in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)... Read more

    Affected Products : chrome edge_chromium
    • Published: Sep. 11, 2024
    • Modified: Sep. 13, 2024
  • 8.8

    HIGH
    CVE-2024-8637

    Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more

    Affected Products : android chrome edge_chromium
    • Published: Sep. 11, 2024
    • Modified: Sep. 13, 2024
  • 8.8

    HIGH
    CVE-2024-8636

    Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more

    Affected Products : chrome edge_chromium
    • Published: Sep. 11, 2024
    • Modified: Sep. 13, 2024
  • 5.4

    MEDIUM
    CVE-2023-3409

    The Bricks theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.1. This is due to missing or incorrect nonce validation on the 'reset_settings' function. This makes it possible for unauthenticated attackers... Read more

    Affected Products : bricks
    • Published: Aug. 17, 2024
    • Modified: Sep. 13, 2024
  • 6.5

    MEDIUM
    CVE-2024-43335

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CyberChimps Responsive Blocks – WordPress Gutenberg Blocks allows Stored XSS.This issue affects Responsive Blocks – WordPress Gutenberg Blocks: fr... Read more

    Affected Products : responsive_blocks
    • Published: Aug. 18, 2024
    • Modified: Sep. 13, 2024
  • 6.5

    MEDIUM
    CVE-2024-43342

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BdThemes Ultimate Store Kit Elementor Addons allows Stored XSS.This issue affects Ultimate Store Kit Elementor Addons: from n/a through 1.6.4.... Read more

    Affected Products : ultimate_store_kit
    • Published: Aug. 18, 2024
    • Modified: Sep. 13, 2024
  • 7.5

    HIGH
    CVE-2024-8751

    A vulnerability in the MSC800 allows an unauthenticated attacker to modify the product’s IP address over Sopas ET. This can lead to Denial of Service. Users are recommended to upgrade both MSC800 and MSC800 LFT to version V4.26 and S2.93.20 respectively... Read more

    Affected Products :
    • Published: Sep. 12, 2024
    • Modified: Sep. 13, 2024
  • 4.7

    MEDIUM
    CVE-2023-52897

    In the Linux kernel, the following vulnerability has been resolved: btrfs: qgroup: do not warn on record without old_roots populated [BUG] There are some reports from the mailing list that since v6.1 kernel, the WARN_ON() inside btrfs_qgroup_account_ext... Read more

    Affected Products : linux_kernel
    • Published: Aug. 21, 2024
    • Modified: Sep. 13, 2024
  • 4.7

    MEDIUM
    CVE-2023-52898

    In the Linux kernel, the following vulnerability has been resolved: xhci: Fix null pointer dereference when host dies Make sure xhci_free_dev() and xhci_kill_endpoint_urbs() do not race and cause null pointer dereference when host suddenly dies. Usb co... Read more

    Affected Products : linux_kernel
    • Published: Aug. 21, 2024
    • Modified: Sep. 13, 2024
  • 5.5

    MEDIUM
    CVE-2023-52899

    In the Linux kernel, the following vulnerability has been resolved: Add exception protection processing for vd in axi_chan_handle_err function Since there is no protection for vd, a kernel panic will be triggered here in exceptional cases. You can refe... Read more

    Affected Products : linux_kernel
    • Published: Aug. 21, 2024
    • Modified: Sep. 13, 2024
Showing 20 of 292775 Results