Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2025-0463

    A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0. It has been classified as critical. Affected is an unknown function of the file /crm/weixinmp/index.php?userid=123&module=Users&usid=1&action=UsersAjax&minip... Read more

    Affected Products : lingdang_crm
    • Published: Jan. 14, 2025
    • Modified: Aug. 28, 2025
    • Vuln Type: Authentication
  • 8.8

    HIGH
    CVE-2025-8123

    A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been classified as critical. Affected is an unknown function of the file /system/dept/edit. The manipulation of the argument ancestors leads to sql injection. It is possible to launch the a... Read more

    Affected Products : deer-wms-2
    • Published: Jul. 24, 2025
    • Modified: Aug. 28, 2025
    • Vuln Type: Injection
  • 8.8

    HIGH
    CVE-2025-8124

    A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /system/role/authUser/unallocatedList. The manipulation of the argument params[dataScope] l... Read more

    Affected Products : deer-wms-2
    • Published: Jul. 25, 2025
    • Modified: Aug. 28, 2025
    • Vuln Type: Injection
  • 8.8

    HIGH
    CVE-2025-8126

    A vulnerability classified as critical has been found in deerwms deer-wms-2 up to 3.3. This affects an unknown part of the file /system/user/export. The manipulation of the argument params[dataScope] leads to sql injection. It is possible to initiate the ... Read more

    Affected Products : deer-wms-2
    • Published: Jul. 25, 2025
    • Modified: Aug. 28, 2025
    • Vuln Type: Injection
  • 5.4

    MEDIUM
    CVE-2023-4957

    A vulnerability of authentication bypass has been found on a Zebra Technologies ZTC ZT410-203dpi ZPL printer. This vulnerability allows an attacker that is in the same network as the printer, to change the username and password for the Web Page by sending... Read more

    Affected Products : zt410_firmware zt410
    • EPSS Score: %0.00
    • Published: Oct. 11, 2023
    • Modified: Aug. 28, 2025
  • 10.0

    CRITICAL
    CVE-2025-34158

    Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres.... Read more

    Affected Products : media_server
    • Published: Aug. 21, 2025
    • Modified: Aug. 28, 2025
    • Vuln Type: Information Disclosure
  • 9.8

    CRITICAL
    CVE-2025-8125

    A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been rated as critical. Affected by this issue is some unknown functionality of the file /system/role/authUser/allocatedList. The manipulation of the argument params[dataScope] leads to sql... Read more

    Affected Products : deer-wms-2
    • Published: Jul. 25, 2025
    • Modified: Aug. 28, 2025
    • Vuln Type: Injection
  • 5.5

    MEDIUM
    CVE-2023-41234

    NULL pointer dereference in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable denial of service via local access.... Read more

    Affected Products : windows power_gadget
    • Published: May. 16, 2024
    • Modified: Aug. 28, 2025
  • 8.8

    HIGH
    CVE-2023-42773

    Improper neutralization in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more

    Affected Products : windows power_gadget
    • Published: May. 16, 2024
    • Modified: Aug. 28, 2025
  • 8.8

    HIGH
    CVE-2023-45217

    Improper access control in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more

    Affected Products : windows power_gadget
    • Published: May. 16, 2024
    • Modified: Aug. 28, 2025
  • 7.8

    HIGH
    CVE-2023-45221

    Improper buffer restrictions in Intel(R) Media SDK all versions may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more

    Affected Products : media_sdk
    • Published: May. 16, 2024
    • Modified: Aug. 28, 2025
  • 5.5

    MEDIUM
    CVE-2023-45315

    Improper initialization in some Intel(R) Power Gadget software for Windwos all versions may allow an authenticated user to potentially enable denial of service via local access.... Read more

    Affected Products : windows power_gadget
    • Published: May. 16, 2024
    • Modified: Aug. 28, 2025
  • 7.8

    HIGH
    CVE-2023-45320

    Uncontrolled search path element in some Intel(R) VTune(TM) Profiler software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more

    Affected Products : vtune_profiler
    • Published: May. 16, 2024
    • Modified: Aug. 28, 2025
  • 7.8

    HIGH
    CVE-2023-45736

    Insecure inherited permissions in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more

    Affected Products : windows power_gadget
    • Published: May. 16, 2024
    • Modified: Aug. 28, 2025
  • 5.5

    MEDIUM
    CVE-2023-45846

    Incomplete cleanup in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable denial of service via local access.... Read more

    Affected Products : macos power_gadget
    • Published: May. 16, 2024
    • Modified: Aug. 28, 2025
  • 8.8

    HIGH
    CVE-2023-46689

    Improper neutralization in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more

    Affected Products : macos power_gadget
    • Published: May. 16, 2024
    • Modified: Aug. 28, 2025
  • 7.9

    HIGH
    CVE-2023-46691

    Use after free in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more

    Affected Products : windows power_gadget
    • Published: May. 16, 2024
    • Modified: Aug. 28, 2025
  • 8.6

    HIGH
    CVE-2024-9497

    DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress 4 SDK installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.... Read more

    Affected Products :
    • Published: Jan. 24, 2025
    • Modified: Aug. 27, 2025
    • Vuln Type: Misconfiguration
  • 5.3

    MEDIUM
    CVE-2024-9411

    A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument dict_value leads to cross site scripting. It is possibl... Read more

    Affected Products : ofcms
    • Published: Oct. 01, 2024
    • Modified: Aug. 27, 2025
  • 7.5

    HIGH
    CVE-2024-9037

    A vulnerability classified as critical has been found in Codezips Internal Marks Calculation 1.0. Affected is an unknown function of the file index.php. The manipulation of the argument tid leads to sql injection. It is possible to launch the attack remot... Read more

    Affected Products : internal_marks_calculation
    • Published: Sep. 20, 2024
    • Modified: Aug. 27, 2025
Showing 20 of 292319 Results