Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.8

    HIGH
    CVE-2024-5915

    A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges.... Read more

    Affected Products : globalprotect
    • Published: Aug. 14, 2024
    • Modified: Aug. 20, 2024
  • 9.8

    CRITICAL
    CVE-2024-5914

    A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container.... Read more

    Affected Products : cortex_xsoar_commonscripts
    • Published: Aug. 14, 2024
    • Modified: Aug. 20, 2024
  • 9.8

    CRITICAL
    CVE-2024-43399

    Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Before 4.0.7, there is a flaw in the Static Libraries analysis section. Specifically, during the extr... Read more

    Affected Products : mobile_security_framework
    • Published: Aug. 19, 2024
    • Modified: Aug. 20, 2024
  • 9.8

    CRITICAL
    CVE-2024-7922

    A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 a... Read more

    • Published: Aug. 19, 2024
    • Modified: Aug. 20, 2024
  • 9.1

    CRITICAL
    CVE-2024-38891

    An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Sniffing Network Traffic attack due to the cleartext transmission of sensitive information.... Read more

    Affected Products : caterease
    • Published: Aug. 02, 2024
    • Modified: Aug. 20, 2024
  • 8.8

    HIGH
    CVE-2024-42633

    A Command Injection vulnerability exists in the do_upgrade_post function of the httpd binary in Linksys E1500 v1.0.06.001. As a result, an authenticated attacker can execute OS commands with root privileges.... Read more

    Affected Products : e1500_firmware e1500
    • Published: Aug. 19, 2024
    • Modified: Aug. 20, 2024
  • 9.8

    CRITICAL
    CVE-2024-38887

    An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand control over the operating system from the database due to the execution of commands with unnecessary priv... Read more

    Affected Products : caterease
    • Published: Aug. 02, 2024
    • Modified: Aug. 20, 2024
  • 7.5

    HIGH
    CVE-2024-6348

    Predictable seed generation in the security access mechanism of UDS in the Blind Spot Protection Sensor ECU in Nissan Altima (2022) allows attackers to predict the requested seeds and bypass security controls via repeated ECU resets and seed requests.... Read more

    • Published: Aug. 19, 2024
    • Modified: Aug. 20, 2024
  • 7.8

    HIGH
    CVE-2024-32927

    In sendDeviceState_1_6 of RadioExt.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more

    Affected Products : android
    • Published: Aug. 19, 2024
    • Modified: Aug. 20, 2024
  • 7.5

    HIGH
    CVE-2024-42657

    An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of encryption during login process... Read more

    • Published: Aug. 19, 2024
    • Modified: Aug. 20, 2024
  • 9.8

    CRITICAL
    CVE-2024-42658

    An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's parameter... Read more

    • Published: Aug. 19, 2024
    • Modified: Aug. 20, 2024
  • 9.0

    CRITICAL
    CVE-2024-43400

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible for a user without Script or Programming rights to craft a URL pointing to a page with arbitrary JavaScript. This requires social engin... Read more

    Affected Products : xwiki
    • Published: Aug. 19, 2024
    • Modified: Aug. 20, 2024
  • 9.0

    CRITICAL
    CVE-2024-43401

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can trick a user with elevated rights to edit a content with a malicious payload using a WYSIWYG editor. The u... Read more

    Affected Products : xwiki
    • Published: Aug. 19, 2024
    • Modified: Aug. 20, 2024
  • 7.5

    HIGH
    CVE-2024-7924

    A vulnerability was found in ZZCMS 2023. It has been declared as critical. This vulnerability affects unknown code of the file /I/list.php. The manipulation of the argument skin leads to path traversal. The attack can be initiated remotely. The exploit ha... Read more

    Affected Products : zzcms
    • Published: Aug. 19, 2024
    • Modified: Aug. 20, 2024
  • 7.5

    HIGH
    CVE-2024-7925

    A vulnerability was found in ZZCMS 2023. It has been rated as problematic. This issue affects some unknown processing of the file 3/E_bak5.1/upload/eginfo.php. The manipulation of the argument phome with the input ShowPHPInfo leads to information disclosu... Read more

    Affected Products : zzcms
    • Published: Aug. 19, 2024
    • Modified: Aug. 20, 2024
  • 5.1

    MEDIUM
    CVE-2024-7453

    A vulnerability was found in FastAdmin 1.5.0.20240328. It has been declared as problematic. This vulnerability affects unknown code of the file /[admins_url].php/general/attachment/edit/ids/4?dialog=1 of the component Attachment Management Section. The ma... Read more

    Affected Products : fastadmin
    • Published: Aug. 04, 2024
    • Modified: Aug. 20, 2024
  • 7.5

    HIGH
    CVE-2024-6918

    CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause a crash of the Accutech Manager when receiving a specially crafted request over port 2536/TCP.... Read more

    Affected Products : accutech_manager
    • Published: Aug. 20, 2024
    • Modified: Aug. 20, 2024
  • 9.8

    CRITICAL
    CVE-2024-43311

    Improper Privilege Management vulnerability in Geek Code Lab Login As Users allows Privilege Escalation.This issue affects Login As Users: from n/a through 1.4.2.... Read more

    Affected Products :
    • Published: Aug. 19, 2024
    • Modified: Aug. 20, 2024
  • 6.1

    MEDIUM
    CVE-2024-7850

    The BP Profile Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.7.5. This is due to missing or incorrect nonce validation on the bps_ajax_field_selector(), bps_ajax_template_options(), and bps... Read more

    Affected Products :
    • Published: Aug. 20, 2024
    • Modified: Aug. 20, 2024
  • 7.5

    HIGH
    CVE-2024-43345

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PluginOps Landing Page Builder allows PHP Local File Inclusion.This issue affects Landing Page Builder: from n/a through 1.5.2.0.... Read more

    Affected Products : landing_page_builder
    • Published: Aug. 19, 2024
    • Modified: Aug. 20, 2024
Showing 20 of 291526 Results