Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.4

    HIGH
    CVE-2007-2439

    Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to cause a denial of service (device hang) and read data from a COM or LPT device via a DOS device name with an arbitrary extension.... Read more

    Affected Products : resin resin
    • Published: May. 16, 2007
    • Modified: Apr. 09, 2025
  • 9.4

    HIGH
    CVE-2007-3192

    admin/setup.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to read and modify configuration settings via a direct request.... Read more

    • Published: Jun. 12, 2007
    • Modified: Apr. 09, 2025
  • 9.4

    HIGH
    CVE-2014-2634

    Unspecified vulnerability in the server in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to bypass intended access restrictions, and modify data or cause a denial of service, via unknown vectors.... Read more

    Affected Products : service_manager
    • Published: Aug. 23, 2014
    • Modified: Apr. 12, 2025
  • 9.4

    HIGH
    CVE-2014-8384

    The InFocus IN3128HD projector with firmware 0.26 does not restrict access to cgi-bin/webctrl.cgi.elf, which allows remote attackers to modify the DHCP server and device IP configuration, reboot the device, change the device name, and have other unspecifi... Read more

    Affected Products : in3128hd_firmware in3128hd
    • Published: May. 18, 2015
    • Modified: Apr. 12, 2025
  • 9.4

    HIGH
    CVE-2018-14916

    LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.... Read more

    Affected Products : lgate-902_firmware lgate-902
    • Published: Jun. 28, 2019
    • Modified: Nov. 21, 2024
  • 9.4

    HIGH
    CVE-2019-13625

    NSA Ghidra before 9.0.1 allows XXE when a project is opened or restored, or a tool is imported, as demonstrated by a project.prp file.... Read more

    Affected Products : ghidra
    • Published: Jul. 17, 2019
    • Modified: Nov. 21, 2024
  • 9.4

    CRITICAL
    CVE-2019-16383

    MOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 allows an unauthenticated attacker to gain unauthorized access to the database. Depending on the database engine being used (MySQL, Micr... Read more

    Affected Products : moveit_transfer
    • Published: Sep. 24, 2019
    • Modified: Nov. 21, 2024
  • 9.4

    HIGH
    CVE-2019-14082

    Potential buffer over-read due to lack of bound check of memory offset passed in WLAN firmware in Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Inf... Read more

    • Published: Mar. 05, 2020
    • Modified: Nov. 21, 2024
  • 9.4

    HIGH
    CVE-2020-3652

    Possible buffer over-read issue in windows x86 wlan driver function while processing beacon or request frame due to lack of check of length of variable received. in Snapdragon Compute, Snapdragon Connectivity in MSM8998, QCA6390, SC7180, SC8180X, SDM850... Read more

    • Published: Apr. 16, 2020
    • Modified: Nov. 21, 2024
  • 9.4

    CRITICAL
    CVE-2019-20695

    Certain NETGEAR devices are affected by disclosure of sensitive information. This affects SRK60 before 2.3.5.106, SRR60 before 2.3.5.106, and SRS60 before 2.3.5.106.... Read more

    • Published: Apr. 16, 2020
    • Modified: Nov. 21, 2024
  • 9.4

    CRITICAL
    CVE-2020-10286

    the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted access to sensible files, encryption, or issue orders that disrupt robot opera... Read more

    • Published: Jul. 15, 2020
    • Modified: Nov. 21, 2024
  • 9.4

    HIGH
    CVE-2020-0283

    There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-163008257... Read more

    Affected Products : android
    • Published: Oct. 14, 2020
    • Modified: Nov. 21, 2024
  • 9.4

    HIGH
    CVE-2020-0339

    There is a possible out of bounds read due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-162980705... Read more

    Affected Products : android
    • Published: Oct. 14, 2020
    • Modified: Nov. 21, 2024
  • 9.4

    HIGH
    CVE-2020-0371

    There is a possible out of bounds read due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-163008256... Read more

    Affected Products : android
    • Published: Oct. 14, 2020
    • Modified: Nov. 21, 2024
  • 9.4

    HIGH
    CVE-2020-0376

    There is a possible out of bounds read due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-163003156... Read more

    Affected Products : android
    • Published: Oct. 14, 2020
    • Modified: Nov. 21, 2024
  • 9.4

    CRITICAL
    CVE-2024-13871

    A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (firmware version 1.3.11.490). This flaw allows an unauthenticated, network-adjacent attacker to execute arbitrary commands on the device, ... Read more

    Affected Products : box_firmware box
    • Published: Mar. 12, 2025
    • Modified: Jul. 30, 2025
    • Vuln Type: Injection
  • 9.4

    CRITICAL
    CVE-2024-25511

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/address_public_new.aspx.... Read more

    Affected Products : ruvaroa
    • Published: May. 07, 2024
    • Modified: Apr. 16, 2025
  • 9.4

    CRITICAL
    CVE-2024-34947

    Quanxun Huiju Network Technology (Beijing) Co.,Ltd IK-Q3000 3.7.10 x64 Build202401261655 was discovered to be vulnerable to an ICMP redirect attack.... Read more

    Affected Products :
    • Published: May. 20, 2024
    • Modified: Mar. 25, 2025
  • 9.4

    CRITICAL
    CVE-2024-0336

    Improper Access Control vulnerability in EMTA Grup PDKS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PDKS: before 20240603.  NOTE: The vendor was contacted early about this disclosure but did not respond in a... Read more

    Affected Products :
    • Published: Jun. 03, 2024
    • Modified: Nov. 21, 2024
  • 9.4

    CRITICAL
    CVE-2024-36059

    Directory Traversal vulnerability in Kalkitech ASE ASE61850 IEDSmart upto and including version 2.3.5 allows attackers to read/write arbitrary files via the IEC61850 File Transfer protocol.... Read more

    Affected Products :
    • Published: Jun. 27, 2024
    • Modified: Nov. 21, 2024
Showing 20 of 293331 Results