Latest CVE Feed
-
9.6
CRITICALCVE-2016-3610
Unspecified vulnerability in Oracle Java SE 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Libraries, a different vulnerability than CVE-2016-3598.... Read more
- EPSS Score: %7.07
- Published: Jul. 21, 2016
- Modified: Apr. 12, 2025
-
9.6
CRITICALCVE-2017-12369
A "Cisco WebEx Network Recording Player Out-of-Bounds Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user with a... Read more
Affected Products : webex_meetings- EPSS Score: %2.15
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2020-6457
Use after free in speech recognizer in Google Chrome prior to 81.0.4044.113 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.... Read more
- EPSS Score: %1.07
- Published: May. 21, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2018-17462
Incorrect refcounting in AppCache in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform a sandbox escape via a crafted HTML page.... Read more
- EPSS Score: %1.39
- Published: Nov. 14, 2018
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-21106
Use after free in autofill in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.... Read more
- EPSS Score: %4.04
- Published: Jan. 08, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-22234
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12.8, and all versions starting from 14.0 before 14.0.4. A specially crafted design image allowed attackers ... Read more
Affected Products : gitlab- EPSS Score: %0.17
- Published: Aug. 05, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-4949
Use after free in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: May. 15, 2024
- Modified: Dec. 19, 2024
-
9.6
CRITICALCVE-2024-23476
The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve the Remote Code Execution. ... Read more
Affected Products : access_rights_manager- EPSS Score: %1.94
- Published: Feb. 15, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-40867
A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in iOS 18.1 and iPadOS 18.1. A remote attacker may be able to break out of Web Content sandbox.... Read more
- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
9.6
CRITICALCVE-2019-8617
An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 12.3. A sandboxed process may be able to circumvent sandbox restrictions.... Read more
Affected Products : iphone_os- EPSS Score: %0.50
- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2019-8562
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows. A sandboxed process may be able to circumvent sandbox restrictions.... Read more
- EPSS Score: %0.48
- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-27513
Remote desktop takeover via phishing ... Read more
Affected Products : gateway application_delivery_controller_firmware application_delivery_controller- EPSS Score: %0.29
- Published: Nov. 08, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-23479
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve a Remote Code Execution. ... Read more
Affected Products : access_rights_manager- EPSS Score: %1.30
- Published: Feb. 15, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-16045
Use after Free in Payments in Google Chrome on Android prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.... Read more
- EPSS Score: %0.50
- Published: Jan. 14, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2015-5211
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script ext... Read more
- EPSS Score: %1.91
- Published: May. 25, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2021-21110
Use after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.... Read more
- EPSS Score: %23.07
- Published: Jan. 08, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2017-12371
A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a use... Read more
Affected Products : webex_meetings- EPSS Score: %2.15
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2016-5580
Unspecified vulnerability in the Secure Global Desktop component in Oracle Virtualization 4.7 and 5.2 allows remote authenticated users to affect confidentiality and availability via vectors through Web Services.... Read more
Affected Products : secure_global_desktop- EPSS Score: %0.50
- Published: Oct. 25, 2016
- Modified: Apr. 12, 2025
-
9.6
CRITICALCVE-2017-10089
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: ImageIO). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple p... Read more
- EPSS Score: %0.36
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2017-10090
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated attac... Read more
- EPSS Score: %0.42
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025