Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2011-2963

    TCPUploadServer.exe in Progea Movicon 11.2 before Build 1084 does not require authentication for critical functions, which allows remote attackers to obtain sensitive information, delete files, execute arbitrary programs, or cause a denial of service (cra... Read more

    Affected Products : movicon
    • EPSS Score: %9.93
    • Published: Jul. 29, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2008-5404

    Insecure method vulnerability in the FlexCell.Grid ActiveX control in FlexCell.ocx 5.7.0.1 in FlexCell Grid ActiveX Component allows remote attackers to create and overwrite arbitrary files via the HttpDownloadFile method. NOTE: this could be leveraged f... Read more

    Affected Products : flexcell_grid_control
    • EPSS Score: %3.42
    • Published: Dec. 10, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2011-3136

    Unspecified vulnerability in the Management Console in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.9 has unknown impact and attack vectors, aka APAR I... Read more

    • EPSS Score: %0.47
    • Published: Aug. 12, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2008-0012

    Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to the product's configuration, a different vulnerability than CVE-200... Read more

    Affected Products : serverprotect serverprotect
    • EPSS Score: %14.80
    • Published: Nov. 17, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2011-3420

    Multiple unspecified vulnerabilities in Google Chrome before 14.0.835.157 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.... Read more

    • EPSS Score: %0.57
    • Published: Sep. 12, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2011-3494

    WinSig.exe in eSignal 10.6.2425 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a long StyleTemplate element in a QUO, SUM or POR file, which triggers a stack-based buffer overflow, or (... Read more

    Affected Products : esignal
    • EPSS Score: %72.44
    • Published: Sep. 16, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2011-3498

    Heap-based buffer overflow in Progea Movicon / PowerHMI 11.2.1085 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long request.... Read more

    Affected Products : movicon movicon_powerhmi
    • EPSS Score: %64.48
    • Published: Sep. 16, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2011-4214

    OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to bypass authentication and obtain administrator privileges via a crafted oozimsrememberme cookie.... Read more

    Affected Products : aims
    • EPSS Score: %1.53
    • Published: Nov. 01, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2008-6703

    Stack-based buffer overflow in the IPureServer::_Recieve function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to execute arbitrary code via a compressed 0x39 packet, which is decompressed by the NET_Compressor::Decomp... Read more

    Affected Products : s.t.a.l.k.e.r.\
    • EPSS Score: %17.20
    • Published: Apr. 10, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2011-4548

    Multiple unspecified vulnerabilities in Google Chrome before 16.0.912.44 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.... Read more

    • EPSS Score: %0.35
    • Published: Nov. 24, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2008-1242

    The control panel on the Belkin F5D7230-4 router with firmware 9.01.10 maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a previously authenticated us... Read more

    Affected Products : f5d7230-4
    • EPSS Score: %4.23
    • Published: Mar. 10, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2011-4752

    SmarterTools SmarterStats 6.2.4100 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving frmCustomReport.aspx and certain other files... Read more

    Affected Products : smarterstats
    • EPSS Score: %1.75
    • Published: Dec. 16, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2011-4762

    Parallels Plesk Small Business Panel 10.2.0 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving smb/app/top-categories-data/ and ce... Read more

    • EPSS Score: %1.75
    • Published: Dec. 16, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2011-5323

    GE Healthcare Centricity PACS-IW 3.7.3.7, 3.7.3.8, and possibly other versions has a password of A11enda1e for the sa SQL server user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or ... Read more

    Affected Products : centricity_pacs-iw
    • EPSS Score: %0.57
    • Published: Aug. 04, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2012-0245

    Multiple stack-based buffer overflows in RobNetScanHost.exe in ABB Robot Communications Runtime before 5.14.02, as used in ABB Interlink Module, IRC5 OPC Server, PC SDK, PickMaster 3 and 5, RobView 5, RobotStudio, WebWare SDK, and WebWare Server, allow re... Read more

    • EPSS Score: %27.46
    • Published: Mar. 09, 2012
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-7282

    The management web interface on the Nisuta NS-WIR150NE router with firmware 5.07.41 and Nisuta NS-WIR300N router with firmware 5.07.36_NIS01 allows remote attackers to bypass authentication via a "Cookie: :language=en" HTTP header.... Read more

    • EPSS Score: %5.00
    • Published: Jan. 10, 2014
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2014-6434

    gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary commands via a the (1) a1 or (2) a2 parameter in a restart action.... Read more

    Affected Products : gopro_hero_firmware gopro_hero
    • EPSS Score: %3.36
    • Published: Oct. 07, 2014
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2003-1507

    Planet Technology WGSD-1020 and WSW-2401 Ethernet switches use a default "superuser" account with the "planet" password, which allows remote attackers to gain administrative access.... Read more

    Affected Products : wgsd-1020 wsw-2401
    • EPSS Score: %0.84
    • Published: Dec. 31, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2014-6626

    Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not properly restrict access to unspecified administrative functions, which allows remote attackers to bypass authentication and execute administrative actions via unknown vectors.... Read more

    Affected Products : clearpass
    • EPSS Score: %3.95
    • Published: Nov. 19, 2014
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2003-1525

    Unspecified vulnerability in My Photo Gallery 3.5, and possibly earlier versions, has unknown impact and attack vectors.... Read more

    Affected Products : my_photo_gallery
    • EPSS Score: %0.33
    • Published: Dec. 31, 2003
    • Modified: Apr. 03, 2025
Showing 20 of 290954 Results