Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.8

    HIGH
    CVE-2024-7672

    A maliciously crafted DWF file, when parsed in dwfcore.dll through Autodesk Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrar... Read more

    • Published: Sep. 30, 2024
    • Modified: Aug. 26, 2025
  • 4.9

    MEDIUM
    CVE-2024-38360

    Discourse is an open source platform for community discussion. In affected versions by creating replacement words with an almost unlimited number of characters, a moderator can reduce the availability of a Discourse instance. This issue has been addressed... Read more

    Affected Products : discourse
    • Published: Jul. 15, 2024
    • Modified: Aug. 26, 2025
  • 8.8

    HIGH
    CVE-2024-6714

    An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege.... Read more

    • Published: Jul. 23, 2024
    • Modified: Aug. 26, 2025
  • 4.3

    MEDIUM
    CVE-2024-55893

    TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Addit... Read more

    Affected Products : typo3
    • Published: Jan. 14, 2025
    • Modified: Aug. 26, 2025
    • Vuln Type: Cross-Site Request Forgery
  • 6.7

    MEDIUM
    CVE-2024-24912

    A local privilege escalation vulnerability has been identified in Harmony Endpoint Security Client for Windows versions E88.10 and below. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the targ... Read more

    Affected Products : windows harmony_endpoint
    • Published: May. 01, 2024
    • Modified: Aug. 26, 2025
  • 6.1

    MEDIUM
    CVE-2024-55892

    TYPO3 is a free and open source Content Management Framework. Applications that use `TYPO3\CMS\Core\Http\Uri` to parse externally provided URLs (e.g., via a query parameter) and validate the host of the parsed URL may be vulnerable to open redirect or SSR... Read more

    Affected Products : typo3
    • Published: Jan. 14, 2025
    • Modified: Aug. 26, 2025
    • Vuln Type: Server-Side Request Forgery
  • 7.5

    HIGH
    CVE-2024-32979

    Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. It was discovered that due to improper handling and escaping of user-provided query para... Read more

    Affected Products : nautobot
    • Published: May. 01, 2024
    • Modified: Aug. 26, 2025
  • 5.3

    MEDIUM
    CVE-2024-55891

    TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has been logged as plaintext in case the password hashing mechanism used for the password was incorrect. Users are advised to update to TYP... Read more

    Affected Products : typo3
    • Published: Jan. 14, 2025
    • Modified: Aug. 26, 2025
    • Vuln Type: Misconfiguration
  • 6.1

    MEDIUM
    CVE-2025-27506

    NocoDB is software for building databases as spreadsheets. The API endpoint related to the password reset function is vulnerable to Reflected Cross-Site-Scripting. The endpoint /api/v1/db/auth/password/reset/:tokenId is vulnerable to Reflected Cross-Site-... Read more

    Affected Products : nocodb nocodb
    • Published: Mar. 06, 2025
    • Modified: Aug. 26, 2025
    • Vuln Type: Cross-Site Scripting
  • 4.2

    MEDIUM
    CVE-2024-32963

    Navidrome is an open source web-based music collection server and streamer. In affected versions of Navidrome are subject to a parameter tampering vulnerability where an attacker has the ability to manipulate parameter values in the HTTP requests. The att... Read more

    Affected Products : navidrome
    • Published: May. 01, 2024
    • Modified: Aug. 26, 2025
  • 7.6

    HIGH
    CVE-2023-49781

    NocoDB is software for building databases as spreadsheets. Prior to 0.202.9, a stored cross-site scripting vulnerability exists within the Formula virtual cell comments functionality. The nc-gui/components/virtual-cell/Formula.vue displays a v-html tag wi... Read more

    Affected Products : nocodb nocodb
    • Published: May. 14, 2024
    • Modified: Aug. 26, 2025
  • 5.7

    MEDIUM
    CVE-2023-50717

    NocoDB is software for building databases as spreadsheets. Starting in verson 0.202.6 and prior to version 0.202.10, an attacker can upload a html file with malicious content. If user tries to open that file in browser malicious scripts can be executed le... Read more

    Affected Products : nocodb nocodb
    • Published: May. 14, 2024
    • Modified: Aug. 26, 2025
  • 6.5

    MEDIUM
    CVE-2023-50718

    NocoDB is software for building databases as spreadsheets. Prior to version 0.202.10, an authenticated attacker with create access could conduct a SQL Injection attack on MySQL DB using unescaped `table_name`. This vulnerability may result in leakage of s... Read more

    Affected Products : nocodb nocodb
    • Published: May. 14, 2024
    • Modified: Aug. 26, 2025
  • 9.1

    CRITICAL
    CVE-2022-2339

    With this SSRF vulnerability, an attacker can reach internal addresses to make a request as the server and read it's contents. This attack can lead to leak of sensitive information.... Read more

    Affected Products : nocodb nocodb
    • EPSS Score: %0.72
    • Published: Jul. 07, 2022
    • Modified: Aug. 26, 2025
  • 6.5

    MEDIUM
    CVE-2023-5104

    Improper Input Validation in GitHub repository nocodb/nocodb prior to 0.96.0.... Read more

    Affected Products : nocodb nocodb
    • EPSS Score: %0.62
    • Published: Sep. 21, 2023
    • Modified: Aug. 26, 2025
  • 7.3

    HIGH
    CVE-2022-3423

    Allocation of Resources Without Limits or Throttling in GitHub repository nocodb/nocodb prior to 0.92.0. ... Read more

    Affected Products : nocodb nocodb
    • EPSS Score: %1.40
    • Published: Oct. 07, 2022
    • Modified: Aug. 26, 2025
  • 6.5

    MEDIUM
    CVE-2023-43794

    Nocodb is an open source Airtable alternative. Affected versions of nocodb contain a SQL injection vulnerability, that allows an authenticated attacker with creator access to query the underlying database. By supplying a specially crafted payload to the g... Read more

    Affected Products : nocodb nocodb
    • EPSS Score: %0.22
    • Published: Oct. 17, 2023
    • Modified: Aug. 26, 2025
  • 8.0

    HIGH
    CVE-2022-22121

    In NocoDB, versions 0.81.0 through 0.83.8 are affected by CSV Injection vulnerability (Formula Injection). A low privileged attacker can create a new table to inject payloads in the table rows. When an administrator accesses the User Management endpoint a... Read more

    Affected Products : nocodb nocodb
    • EPSS Score: %0.43
    • Published: Jan. 10, 2022
    • Modified: Aug. 26, 2025
  • 9.1

    CRITICAL
    CVE-2022-2062

    Generation of Error Message Containing Sensitive Information in GitHub repository nocodb/nocodb prior to 0.91.7+.... Read more

    Affected Products : nocodb nocodb
    • EPSS Score: %1.15
    • Published: Jun. 13, 2022
    • Modified: Aug. 26, 2025
  • 9.1

    CRITICAL
    CVE-2022-2064

    Insufficient Session Expiration in GitHub repository nocodb/nocodb prior to 0.91.7+.... Read more

    Affected Products : nocodb nocodb
    • EPSS Score: %0.30
    • Published: Jun. 13, 2022
    • Modified: Aug. 26, 2025
Showing 20 of 291890 Results