Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.8

    HIGH
    CVE-2025-7425

    A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID ... Read more

    • Published: Jul. 10, 2025
    • Modified: Sep. 04, 2025
    • Vuln Type: Memory Corruption
  • 9.0

    CRITICAL
    CVE-2024-3596

    RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Au... Read more

    • Published: Jul. 09, 2024
    • Modified: Sep. 04, 2025
  • 7.5

    HIGH
    CVE-2024-27919

    Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 and 1.29.1, theEnvoy HTTP/2 protocol stack is vulnerable to the flood of CONTINUATION frames. Envoy's HTTP/2 codec does not reset a request when header map limits have been ex... Read more

    Affected Products : envoy
    • Published: Apr. 04, 2024
    • Modified: Sep. 04, 2025
  • 7.5

    HIGH
    CVE-2024-30255

    Envoy is a cloud-native, open source edge and service proxy. The HTTP/2 protocol stack in Envoy versions prior to 1.29.3, 1.28.2, 1.27.4, and 1.26.8 are vulnerable to CPU exhaustion due to flood of CONTINUATION frames. Envoy's HTTP/2 codec allows the clie... Read more

    Affected Products : envoy
    • Published: Apr. 04, 2024
    • Modified: Sep. 04, 2025
  • 7.5

    HIGH
    CVE-2024-32475

    Envoy is a cloud-native, open source edge and service proxy. When an upstream TLS cluster is used with `auto_sni` enabled, a request containing a `host`/`:authority` header longer than 255 characters triggers an abnormal termination of Envoy process. Envo... Read more

    Affected Products : envoy
    • Published: Apr. 18, 2024
    • Modified: Sep. 04, 2025
  • 9.8

    CRITICAL
    CVE-2024-32017

    RIOT is a real-time multi-threading operating system that supports a range of devices that are typically 8-bit, 16-bit and 32-bit microcontrollers. The size check in the `gcoap_dns_server_proxy_get()` function contains a small typo that may lead to a buff... Read more

    Affected Products : riot riot
    • Published: May. 01, 2024
    • Modified: Sep. 04, 2025
  • 9.0

    CRITICAL
    CVE-2024-34346

    Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. The Deno sandbox may be unexpectedly weakened by allowing file read/write access to privileged files in various locations on Unix and Windows platforms. For example, reading `... Read more

    Affected Products : deno
    • Published: May. 07, 2024
    • Modified: Sep. 04, 2025
  • 7.8

    HIGH
    CVE-2021-39810

    In verifyDefaults of CardEmulationManager.java, there is a possible way to set a third party app as the default contactless payment app without user consent due to a missing permission check. This could lead to local escalation of privilege with no additi... Read more

    Affected Products : android
    • Published: Oct. 30, 2023
    • Modified: Sep. 04, 2025
  • 6.1

    MEDIUM
    CVE-2024-37161

    MeterSphere is an open source continuous testing platform. Prior to version 1.10.1-lts, the system's step editor stores cross-site scripting vulnerabilities. Version 1.10.1-lts fixes this issue.... Read more

    Affected Products : metersphere
    • Published: Jun. 11, 2024
    • Modified: Sep. 04, 2025
  • 6.1

    MEDIUM
    CVE-2024-37304

    NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While the platform properly filters out JavaScript from standard links, it does not adequa... Read more

    Affected Products : nugetgallery
    • Published: Jun. 12, 2024
    • Modified: Sep. 04, 2025
  • 5.3

    MEDIUM
    CVE-2024-37309

    CrateDB is a distributed SQL database. A high-risk vulnerability has been identified in versions prior to 5.7.2 where the TLS endpoint (port 4200) permits client-initiated renegotiation. In this scenario, an attacker can exploit this feature to repeatedly... Read more

    Affected Products : cratedb
    • Published: Jun. 13, 2024
    • Modified: Sep. 04, 2025
  • 6.5

    MEDIUM
    CVE-2024-31228

    Redis is an open source, in-memory database that persists on disk. Authenticated users can trigger a denial-of-service by using specially crafted, long string match patterns on supported commands such as `KEYS`, `SCAN`, `PSUBSCRIBE`, `FUNCTION LIST`, `COM... Read more

    Affected Products : redis
    • Published: Oct. 07, 2024
    • Modified: Sep. 04, 2025
  • 8.8

    HIGH
    CVE-2024-31449

    Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack buffer overflow in the bit library, which may potentially lead to remote code execution. The problem exists ... Read more

    Affected Products : redis
    • Published: Oct. 07, 2024
    • Modified: Sep. 04, 2025
  • 7.8

    HIGH
    CVE-2024-24916

    Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution with the installer's privileges (admin).... Read more

    Affected Products : windows smartconsole
    • Published: Jun. 19, 2025
    • Modified: Sep. 04, 2025
    • Vuln Type: Misconfiguration
  • 7.8

    HIGH
    CVE-2024-39755

    A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially crafted PKG file can lead to execute priviledged operation. An attacker can make an unauthenticated HTTP request to trigger this vulnerab... Read more

    Affected Products : anka_build_cloud
    • Published: Oct. 03, 2024
    • Modified: Sep. 04, 2025
  • 9.8

    CRITICAL
    CVE-2024-41433

    PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component expression.ExplainExpressionList. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. NOTE: PingCAP maintains that the actual reprodu... Read more

    Affected Products : tidb
    • Published: Sep. 03, 2024
    • Modified: Sep. 04, 2025
  • 4.3

    MEDIUM
    CVE-2024-41434

    PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows attackers to cause a Denial of Service (DoS) via a crafted input to the 'RemoveUnnecessaryFirstRow', it will check the expression between '... Read more

    Affected Products : tidb
    • Published: Sep. 03, 2024
    • Modified: Sep. 04, 2025
  • 9.8

    CRITICAL
    CVE-2025-9752

    A security vulnerability has been detected in D-Link DIR-852 1.00CN B09. Impacted is the function soapcgi_main of the file soap.cgi of the component SOAP Service. Such manipulation of the argument service leads to os command injection. The attack can be l... Read more

    Affected Products : dir-852_firmware dir-852
    • Published: Sep. 01, 2025
    • Modified: Sep. 04, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-9749

    A vulnerability was identified in HKritesh009 Grocery List Management Web App up to f491b681eb70d465f445c9a721415c965190f83b. This affects an unknown part of the file /src/update.php. The manipulation of the argument ID leads to sql injection. It is possi... Read more

    Affected Products : grocery_list_management_web
    • Published: Aug. 31, 2025
    • Modified: Sep. 04, 2025
    • Vuln Type: Injection
  • 5.4

    MEDIUM
    CVE-2025-9754

    A flaw has been found in Campcodes Online Hospital Management System 1.0. The impacted element is an unknown function of the file /edit-profile.php of the component Edit Profile Page. Executing manipulation of the argument Username can lead to cross site ... Read more

    Affected Products : online_hospital_management_system
    • Published: Sep. 01, 2025
    • Modified: Sep. 04, 2025
    • Vuln Type: Cross-Site Scripting
Showing 20 of 293192 Results