Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.1

    CRITICAL
    CVE-2024-35143

    IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain una... Read more

    • Published: Aug. 04, 2024
    • Modified: Sep. 11, 2024
  • 6.1

    MEDIUM
    CVE-2024-7204

    Ai3 QbiBot does not properly filter user input, allowing unauthenticated remote attackers to insert JavaScript code into the chat box. Once the recipient views the message, they will be subject to a Stored XSS attack.... Read more

    Affected Products : qbibot
    • Published: Aug. 02, 2024
    • Modified: Sep. 11, 2024
  • 6.5

    MEDIUM
    CVE-2024-7323

    Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input. A remote attacker with regular privilege can exploit this vulnerability to download arbitrary files from the remote se... Read more

    Affected Products : easyflow_.net
    • Published: Aug. 02, 2024
    • Modified: Sep. 11, 2024
  • 9.8

    CRITICAL
    CVE-2024-7461

    A vulnerability was found in ForIP Tecnologia Administração PABX 1.x. It has been rated as critical. Affected by this issue is some unknown functionality of the file /authMonitCallcenter of the component monitcallcenter. The manipulation of the argument u... Read more

    Affected Products : administracao_pabx
    • Published: Aug. 05, 2024
    • Modified: Sep. 11, 2024
  • 5.9

    MEDIUM
    CVE-2024-27267

    The Object Request Broker (ORB) in IBM SDK, Java Technology Edition 7.1.0.0 through 7.1.5.18 and 8.0.0.0 through 8.0.8.26 is vulnerable to remote denial of service, caused by a race condition in the management of ORB listener threads. IBM X-Force ID: 28... Read more

    Affected Products : java_sdk
    • Published: Aug. 14, 2024
    • Modified: Sep. 11, 2024
  • 6.5

    MEDIUM
    CVE-2024-21904

    A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed t... Read more

    Affected Products : quts_hero qts
    • Published: Sep. 06, 2024
    • Modified: Sep. 11, 2024
  • 5.9

    MEDIUM
    CVE-2023-50315

    IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitive information. ... Read more

    Affected Products : websphere_application_server
    • Published: Aug. 14, 2024
    • Modified: Sep. 11, 2024
  • 6.6

    MEDIUM
    CVE-2024-21903

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability ... Read more

    Affected Products : quts_hero qts
    • Published: Sep. 06, 2024
    • Modified: Sep. 11, 2024
  • 8.8

    HIGH
    CVE-2024-21898

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the fol... Read more

    Affected Products : quts_hero qts
    • Published: Sep. 06, 2024
    • Modified: Sep. 11, 2024
  • 8.9

    HIGH
    CVE-2024-21897

    A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability... Read more

    Affected Products : quts_hero qts
    • Published: Sep. 06, 2024
    • Modified: Sep. 11, 2024
  • 6.5

    MEDIUM
    CVE-2023-51368

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to launch a denial-of-service (DoS) attack via a network. We have already fixed the vulnerabili... Read more

    Affected Products : quts_hero qts
    • Published: Sep. 06, 2024
    • Modified: Sep. 11, 2024
  • 8.7

    HIGH
    CVE-2023-51366

    A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed t... Read more

    Affected Products : quts_hero qts
    • Published: Sep. 06, 2024
    • Modified: Sep. 11, 2024
  • 4.8

    MEDIUM
    CVE-2023-50366

    A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. We have already fixed the vuln... Read more

    Affected Products : quts_hero qts
    • Published: Sep. 06, 2024
    • Modified: Sep. 11, 2024
  • 8.8

    HIGH
    CVE-2023-51367

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute code via a network. We have already fixed the vulnerability in the... Read more

    Affected Products : quts_hero qts
    • Published: Sep. 06, 2024
    • Modified: Sep. 11, 2024
  • 7.5

    HIGH
    CVE-2024-39818

    Protection mechanism failure for some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct information disclosure via network access.... Read more

    • Published: Aug. 14, 2024
    • Modified: Sep. 11, 2024
  • 5.4

    MEDIUM
    CVE-2024-43381

    reNgine is an automated reconnaissance framework for web applications. Versions 2.1.2 and prior are susceptible to Stored Cross-Site Scripting (XSS) attacks. This vulnerability occurs when scanning a domain, and if the target domain's DNS record contains ... Read more

    Affected Products : rengine
    • Published: Aug. 16, 2024
    • Modified: Sep. 11, 2024
  • 8.2

    HIGH
    CVE-2024-7868

    In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault attempting to read from an invalid address.... Read more

    Affected Products : xpdf
    • Published: Aug. 15, 2024
    • Modified: Sep. 11, 2024
  • 8.8

    HIGH
    CVE-2024-43275

    Cross-Site Request Forgery (CSRF) vulnerability in xyzscripts.Com Insert PHP Code Snippet.This issue affects Insert PHP Code Snippet: from n/a through 1.3.6.... Read more

    Affected Products : insert_php_code_snippet
    • Published: Aug. 15, 2024
    • Modified: Sep. 11, 2024
  • 9.8

    CRITICAL
    CVE-2024-44893

    An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET request.... Read more

    Affected Products :
    • Published: Sep. 10, 2024
    • Modified: Sep. 10, 2024
  • 5.7

    MEDIUM
    CVE-2024-44072

    OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends a specially crafted request to the affected product from the product's specific management page, an ar... Read more

    Affected Products :
    • Published: Sep. 10, 2024
    • Modified: Sep. 10, 2024
Showing 20 of 292731 Results