Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.5

    CVSS31
    CVE-2024-47459

    Substance3D - Sampler versions 4.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS) condition. An attacker could exploit this vulnerability to crash the application, resulting i... Read more

    Affected Products : substance_3d_sampler
    • Published: Oct. 17, 2024
    • Modified: Oct. 17, 2024
  • 6.3

    CVSS31
    CVE-2024-10070

    A vulnerability classified as critical has been found in ESAFENET CDG 5. This affects the function actionPolicyPush of the file /com/esafenet/policy/action/PolicyPushControlAction.java. The manipulation of the argument policyId leads to sql injection. It ... Read more

    Affected Products : cdg
    • Published: Oct. 17, 2024
    • Modified: Oct. 17, 2024
  • 6.3

    CVSS31
    CVE-2024-10069

    A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. Affected by this issue is the function actionPassMainApplication of the file /com/esafenet/servlet/client/MailDecryptApplicationService.java. The manipulation of the argument id l... Read more

    Affected Products : cdg
    • Published: Oct. 17, 2024
    • Modified: Oct. 17, 2024
  • 5.4

    CVSS31
    CVE-2024-46606

    A cross-site scripting (XSS) vulnerability in the component /admin.php?page=photo of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.... Read more

    Affected Products : piwigo
    • Published: Oct. 16, 2024
    • Modified: Oct. 17, 2024
  • 7.2

    CVSS31
    CVE-2024-6333

    Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.... Read more

    Affected Products :
    • Published: Oct. 17, 2024
    • Modified: Oct. 17, 2024
  • 8.6

    CVSS31
    CVE-2024-49315

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CodeFlock FREE DOWNLOAD MANAGER allows Path Traversal.This issue affects FREE DOWNLOAD MANAGER: from n/a through 1.0.0.... Read more

    Affected Products :
    • Published: Oct. 17, 2024
    • Modified: Oct. 17, 2024
  • 5.6

    CVSS31
    CVE-2005-10003

    A vulnerability classified as critical has been found in mikexstudios Xcomic up to 0.8.2. This affects an unknown part. The manipulation of the argument cmd leads to os command injection. It is possible to initiate the attack remotely. The complexity of a... Read more

    Affected Products :
    • Published: Oct. 17, 2024
    • Modified: Oct. 17, 2024
  • 5.3

    CVSS31
    CVE-2024-49580

    In JetBrains Ktor before 3.0.0 improper caching in HttpCache Plugin could lead to response information disclosure... Read more

    Affected Products : ktor
    • Published: Oct. 17, 2024
    • Modified: Oct. 17, 2024
  • 8.1

    CVSS31
    CVE-2024-49579

    In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests... Read more

    Affected Products : youtrack
    • Published: Oct. 17, 2024
    • Modified: Oct. 17, 2024
  • 7.1

    CVSS31
    CVE-2024-48048

    Cross-Site Request Forgery (CSRF) vulnerability in WSIFY – Sales can fly Wsify Widget allows Stored XSS.This issue affects Wsify Widget: from n/a through 1.0.... Read more

    Affected Products :
    • Published: Oct. 17, 2024
    • Modified: Oct. 17, 2024
  • 5.9

    CVSS31
    CVE-2024-48046

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Supsystic Contact Form by Supsystic allows Stored XSS.This issue affects Contact Form by Supsystic: from n/a through 1.7.28.... Read more

    Affected Products : contact_form
    • Published: Oct. 17, 2024
    • Modified: Oct. 17, 2024
  • 5.4

    CVSS31
    CVE-2024-48037

    Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Contact Form Widget allows Cross Site Request Forgery.This issue affects Contact Form Widget: from n/a through 1.4.2.... Read more

    Affected Products :
    • Published: Oct. 17, 2024
    • Modified: Oct. 17, 2024
  • 6.5

    CVSS31
    CVE-2024-48036

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SKT Themes SKT Blocks – Gutenberg based Page Builder allows Stored XSS.This issue affects SKT Blocks – Gutenberg based Page Builder: from n/a thro... Read more

    Affected Products : skt_blocks
    • Published: Oct. 17, 2024
    • Modified: Oct. 17, 2024
  • 7.1

    CVSS31
    CVE-2024-48032

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sumit Surai Featured Posts with Multiple Custom Groups (FPMCG) allows Reflected XSS.This issue affects Featured Posts with Multiple Custom Groups ... Read more

    Affected Products :
    • Published: Oct. 17, 2024
    • Modified: Oct. 17, 2024
  • 6.5

    CVSS31
    CVE-2024-48031

    Cross-Site Request Forgery (CSRF) vulnerability in Sumit Surai Featured Posts with Multiple Custom Groups (FPMCG) allows Cross Site Request Forgery.This issue affects Featured Posts with Multiple Custom Groups (FPMCG): from n/a through 4.0.... Read more

    Affected Products :
    • Published: Oct. 17, 2024
    • Modified: Oct. 17, 2024
  • 6.5

    CVSS31
    CVE-2024-48025

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DOGROW.NET Simple Baseball Scoreboard allows Stored XSS.This issue affects Simple Baseball Scoreboard: from n/a through 1.3.... Read more

    Affected Products :
    • Published: Oct. 17, 2024
    • Modified: Oct. 17, 2024
  • 7.1

    CVSS31
    CVE-2024-48023

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in RestaurantConnect, Inc Restaurant Reservations Widget allows Reflected XSS.This issue affects Restaurant Reservations Widget: from n/a through 1.0... Read more

    Affected Products :
    • Published: Oct. 17, 2024
    • Modified: Oct. 17, 2024
  • 6.5

    CVSS31
    CVE-2024-48022

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SysBasics Shortcode For Elementor Templates allows Stored XSS.This issue affects Shortcode For Elementor Templates: from n/a through 1.0.0.... Read more

    Affected Products :
    • Published: Oct. 17, 2024
    • Modified: Oct. 17, 2024
  • 7.1

    CVSS31
    CVE-2024-48021

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on allows Reflected XSS.This issue affects Contact Form 7 – PayPal & Stripe Add-on: from n/a t... Read more

    Affected Products : paypal_\&_stripe_add-on
    • Published: Oct. 17, 2024
    • Modified: Oct. 17, 2024
  • 0.0

    NONE
    CVE-2023-6728

    Nokia SR OS bof.cfg file encryption is vulnerable to a brute force attack. This weakness allows an attacker in possession of the encrypted file to decrypt the bof.cfg file and obtain the BOF configuration content.... Read more

    Affected Products :
    • Published: Oct. 17, 2024
    • Modified: Oct. 17, 2024
Showing 20 of 294 Results