Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.3

    HIGH
    CVE-2010-3101

    Directory traversal vulnerability in FTPx Corp FTP Explorer 10.5.19.1 for Windows, and probably earlier versions, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename.... Read more

    Affected Products : ftp_explorer
    • EPSS Score: %0.18
    • Published: Aug. 21, 2010
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2018-7923

    Huawei ALP-L09 smart phones with versions earlier than ALP-L09 8.0.0.150(C432) have an insufficient input validation vulnerability due to lack of parameter check. An attacker tricks the user who has root privilege to install a crafted application, the app... Read more

    Affected Products : alp-l09_firmware alp-l09
    • EPSS Score: %0.12
    • Published: Sep. 12, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2023-50254

    Deepin Linux's default document reader `deepin-reader` software suffers from a serious vulnerability in versions prior to 6.0.7 due to a design flaw that leads to remote command execution via crafted docx document. This is a file overwrite vulnerability. ... Read more

    Affected Products : deepin_reader deepin-compressor
    • EPSS Score: %8.85
    • Published: Dec. 22, 2023
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2009-0491

    Stack-based buffer overflow in Elecard MPEG Player 5.5 build 15884.081218 allows remote attackers to execute arbitrary code via a M3U file containing a long URL.... Read more

    Affected Products : elecard_mpeg_player
    • EPSS Score: %7.33
    • Published: Feb. 10, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-1999-0704

    Buffer overflow in Berkeley automounter daemon (amd) logging facility provided in the Linux am-utils package and others.... Read more

    Affected Products : freebsd linux bsd_os
    • EPSS Score: %4.18
    • Published: Sep. 16, 1999
    • Modified: Apr. 03, 2025
  • 9.3

    HIGH
    CVE-2003-1336

    Buffer overflow in mIRC before 6.11 allows remote attackers to execute arbitrary code via a long irc:// URL.... Read more

    Affected Products : mirc
    • EPSS Score: %66.55
    • Published: Dec. 31, 2003
    • Modified: Apr. 03, 2025
  • 9.3

    HIGH
    CVE-2006-6261

    Buffer overflow in Quintessential Player 4.50.1.82 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) M3u or (2) M3u-8 file; or a (3) crafted PLS file with a long value in the (a)... Read more

    • EPSS Score: %6.16
    • Published: Dec. 04, 2006
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2006-6282

    members.php in Vikingboard 0.1.2 allows remote attackers to trigger a forced SQL error via an invalid s parameter, a different vector than CVE-2006-4709. NOTE: might only be an exposure if display_errors is enabled, but due to lack of details, even this ... Read more

    Affected Products : vikingboard
    • EPSS Score: %0.82
    • Published: Dec. 04, 2006
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2006-6749

    Buffer overflow in the parse_expression function in parse_config in OpenSER 1.1.0 allows attackers to have an unknown impact via a long str parameter.... Read more

    Affected Products : openser
    • EPSS Score: %0.92
    • Published: Dec. 27, 2006
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2006-6884

    Buffer overflow in the WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 Build 6667 allows remote attackers to execute arbitrary code via a long argument to the CreateNewFolderFromName method, a diffe... Read more

    Affected Products : winzip
    • EPSS Score: %9.45
    • Published: Dec. 31, 2006
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2006-5574

    Unspecified vulnerability in the Brazilian Portuguese Grammar Checker in Microsoft Office 2003 and the Multilingual Interface for Office 2003, Project 2003, and Visio 2003 allows user-assisted remote attackers to execute arbitrary code via crafted text th... Read more

    • EPSS Score: %39.16
    • Published: Dec. 31, 2006
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2007-0766

    Stack-based buffer overflow in Remotesoft .NET Explorer 2.0.1 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long line in a .cpp file.... Read more

    Affected Products : .net_explorer
    • EPSS Score: %6.31
    • Published: Feb. 06, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2007-0913

    Unspecified vulnerability in Microsoft Powerpoint allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as exploited by Trojan.PPDropper.G. NOTE: as of 20070213, it is not clear whether this is the same issue as CVE-... Read more

    Affected Products : powerpoint
    • EPSS Score: %37.96
    • Published: Feb. 14, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2007-1037

    Stack-based buffer overflow in News File Grabber 4.1.0.1 and earlier allows remote attackers to execute arbitrary code via a .nzb file with a long subject field. NOTE: the provenance of this information is unknown; the details are obtained solely from th... Read more

    Affected Products : news_file_grabber
    • EPSS Score: %8.61
    • Published: Feb. 21, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2006-7061

    Scriptsez.net E-Dating System stores data files with predictable names under the web document root with insufficient access control, which allows remote attackers to read private messages and leverage them for cross-site scripting (XSS) attacks.... Read more

    Affected Products : e-dating_system
    • EPSS Score: %0.60
    • Published: Feb. 24, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2006-7064

    Cross-site scripting (XSS) vulnerability in forum/admin.php for Invision Power Board (IPB) 2.1.6 and earlier allows remote attackers to inject arbitrary web script or HTML as the administrator via the phpinfo parameter.... Read more

    Affected Products : invision_power_board
    • EPSS Score: %0.57
    • Published: Feb. 24, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2007-1197

    Multiple unspecified vulnerabilities in Epiware before 4.7.5 have unknown impact and attack vectors, possibly related to cross-site scripting (XSS) and other unspecified issues.... Read more

    Affected Products : epiware
    • EPSS Score: %0.34
    • Published: Mar. 02, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2007-1534

    DFSR.exe in Windows Meeting Space in Microsoft Windows Vista remains available for remote connections on TCP port 5722 for 2 minutes after Windows Meeting Space is closed, which allows remote attackers to have an unknown impact by connecting to this port ... Read more

    Affected Products : windows_vista
    • EPSS Score: %38.74
    • Published: Mar. 20, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2007-1725

    SQL injection vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to execute arbitrary SQL commands via the filename of an uploaded file to the avatar function, as demonstrated by setting admin privileges.... Read more

    Affected Products : icebb
    • EPSS Score: %0.66
    • Published: Mar. 28, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2007-1820

    Nortel Networks CallPilot and Meridian Mail voicemail systems, when a mailbox has auto logon enabled, allow remote attackers to retrieve or remove messages, or reconfigure the mailbox, by spoofing Calling Number Identification (CNID, aka Caller ID).... Read more

    Affected Products : callpilot meridian_mail
    • EPSS Score: %1.14
    • Published: Apr. 02, 2007
    • Modified: Apr. 09, 2025
Showing 20 of 291395 Results