Latest CVE Feed
-
10.0
HIGHCVE-2017-1000214
GitPHP by xiphux is vulnerable to OS Command Injections... Read more
Affected Products : gitphp- EPSS Score: %7.22
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2007-1486
PHP remote file inclusion vulnerability in template.class.php in Carbonize Lazarus Guestbook before 1.7.3 allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to admin.php, probably due to a dynamic variable evalua... Read more
Affected Products : lazarus_guestbook- EPSS Score: %2.08
- Published: Mar. 16, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-1568
Stack-based buffer overflow in DaanSystems NewsReactor 20070220.21 allows remote attackers to execute arbitrary code via a yEnc (yEncode) encoded article with a long filename.... Read more
Affected Products : newsreactor- EPSS Score: %12.70
- Published: Mar. 21, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2003-1346
D-Link wireless access point DWL-900AP+ 2.2, 2.3 and possibly 2.5 allows remote attackers to set factory default settings by upgrading the firmware using AirPlus Access Point Manager.... Read more
Affected Products : dwl-900ap\+- EPSS Score: %0.58
- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2008-0568
Unspecified vulnerability in the IP-authentication feature in the Secure Site 5.x-1.0 and 4.7.x-1.0 module for Drupal allows remote attackers to gain the privileges of a user who has authenticated from behind the same proxy server as the attacker.... Read more
Affected Products : secure_site_module- EPSS Score: %0.85
- Published: Feb. 05, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2011-2555
Cisco TelePresence Recording Server 1.7.2.x before 1.7.2.1 has a default password for the root administrator account, which makes it easier for remote attackers to modify the configuration via an SSH session, aka Bug ID CSCtr76182.... Read more
Affected Products : telepresence_recording_server_software- EPSS Score: %1.14
- Published: Aug. 29, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2020-7805
An issue was discovered on KT Slim egg IML500 (R7283, R8112, R8424) and IML520 (R8112, R8368, R8411) wifi device. This issue is a command injection allowing attackers to execute arbitrary OS commands.... Read more
- EPSS Score: %5.27
- Published: May. 07, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-15425
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mod_security.php. The ... Read more
Affected Products : webpanel- EPSS Score: %1.98
- Published: Jul. 28, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2011-1566
Directory traversal vulnerability in dc.exe 9.00.00.11059 and earlier in 7-Technologies Interactive Graphical SCADA System (IGSS) allows remote attackers to execute arbitrary programs via ..\ (dot dot backslash) sequences in opcodes (1) 0xa and (2) 0x17 t... Read more
Affected Products : igss- EPSS Score: %77.66
- Published: Apr. 05, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2008-2888
Multiple PHP remote file inclusion vulnerabilities in MiGCMS 2.0.5, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[application][app_root] parameter to (1) collection.class.php and (2) conten... Read more
Affected Products : migcms- EPSS Score: %2.25
- Published: Jun. 27, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2002-0525
Format string vulnerabilities in (1) inews or (2) rnews for INN 2.2.3 and earlier allow local users and remote malicious NNTP servers to gain privileges via format string specifiers in NTTP responses.... Read more
Affected Products : inn- EPSS Score: %4.36
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0449
Buffer overflow in webpsvc.exe for Talentsoft Web+ 5.0 and earlier allows remote attackers to execute arbitrary code via a long argument to webplus.exe program, which triggers the overflow in webpsvc.exe.... Read more
Affected Products : web\+_server- EPSS Score: %13.01
- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0491
admin.php in AlGuest 1.0 guestbook checks for the existence of the admin cookie to authenticate the AlGuest administrator, which allows remote attackers to bypass the authentication and gain privileges by setting the admin cookie to an arbitrary value.... Read more
Affected Products : alguest- EPSS Score: %0.55
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1573
Buffer overflow in smtpscan.dll for Trend Micro InterScan VirusWall 3.51 for Windows NT has allows remote attackers to execute arbitrary code via a certain configuration parameter.... Read more
Affected Products : interscan_viruswall- EPSS Score: %1.95
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2020-15490
An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple buffer overflow vulnerabilities exist in CGI scripts, leading to remote code execution with root privileges. (The set of affected scripts is similar to CVE-2020-12266.)... Read more
- EPSS Score: %3.84
- Published: Jul. 01, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2008-4509
Unrestricted file upload vulnerability in processFiles.php in FOSS Gallery Admin and FOSS Gallery Public 1.0 beta allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to... Read more
Affected Products : foss_gallery- EPSS Score: %14.68
- Published: Oct. 09, 2008
- Modified: Apr. 09, 2025
-
10.0
CRITICALCVE-2019-18580
Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by sending a crafted RMI request to execute arbitrary... Read more
Affected Products : emc_storage_monitoring_and_reporting- EPSS Score: %11.84
- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2014-0598
Directory traversal vulnerability in iPrint in Novell Open Enterprise Server (OES) 11 SP1 before Maintenance Update 9151 on Linux has unspecified impact and remote attack vectors.... Read more
- EPSS Score: %0.73
- Published: Jun. 18, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2007-1917
Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Detail... Read more
Affected Products : linux_kernel aix solaris macos hp-ux windows_server tru64 os_400 reliant_unix rfc_library +1 more products- EPSS Score: %9.37
- Published: Apr. 10, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-1955
Multiple stack-based buffer overflows in the SignKorea SKCrypAX ActiveX control module 5.4.1.2 allow remote attackers to execute arbitrary code via a long string in unspecified arguments to the (1) DownloadCert, (2) DecryptFileByKey, and (3) EncryptFileBy... Read more
Affected Products : skcommax_activex_control- EPSS Score: %5.45
- Published: Apr. 11, 2007
- Modified: Apr. 09, 2025