Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.4

    HIGH
    CVE-2019-15926

    An issue was discovered in the Linux kernel before 5.2.3. Out of bounds access exists in the functions ath6kl_wmi_pstream_timeout_event_rx and ath6kl_wmi_cac_event_rx in the file drivers/net/wireless/ath/ath6kl/wmi.c.... Read more

    Affected Products : linux_kernel ubuntu_linux debian_linux
    • Published: Sep. 04, 2019
    • Modified: Nov. 21, 2024
  • 9.4

    HIGH
    CVE-2021-1297

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to conduct directory traversal attacks and overwrite certain files ... Read more

    • Published: Feb. 04, 2021
    • Modified: Nov. 21, 2024
  • 9.4

    CRITICAL
    CVE-2012-10039

    ZEN Load Balancer versions 2.0 and 3.0-rc1 contain a command injection vulnerability in content2-2.cgi. The filelog parameter is passed directly into a backtick-delimited exec() call without sanitation. An authenticated attacker can inject arbitrary shell... Read more

    Affected Products :
    • Published: Aug. 11, 2025
    • Modified: Aug. 11, 2025
    • Vuln Type: Injection
  • 9.4

    CRITICAL
    CVE-2024-13872

    Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart daemons and detection rules on the devices. Updates can be remotely triggered through the /set_temp_token A... Read more

    Affected Products : box_firmware box
    • Published: Mar. 12, 2025
    • Modified: Jul. 30, 2025
    • Vuln Type: Misconfiguration
  • 9.4

    CRITICAL
    CVE-2024-1874

    In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply ... Read more

    Affected Products : fedora php
    • Published: Apr. 29, 2024
    • Modified: Jun. 18, 2025
  • 9.4

    HIGH
    CVE-2020-14875

    Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.1.1 - 12.1.3 and 12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker... Read more

    Affected Products : marketing
    • Published: Oct. 21, 2020
    • Modified: Nov. 21, 2024
  • 9.4

    HIGH
    CVE-2010-3671

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 is open to a session fixation attack which allows remote attackers to hijack a victim's session.... Read more

    Affected Products : typo3
    • Published: Nov. 05, 2019
    • Modified: Nov. 21, 2024
  • 9.4

    HIGH
    CVE-2010-3599

    Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect integrity and availability via unknown vectors related to Import Server. NOTE: the previous information... Read more

    Affected Products : fusion_middleware
    • Published: Jan. 19, 2011
    • Modified: Apr. 11, 2025
  • 9.4

    CRITICAL
    CVE-2024-1624

    An OS Command Injection vulnerability affecting documentation server on 3DEXPERIENCE from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x, SIMULIA Abaqus from Release 2022 through Release 2024, SIMULIA Isight from Release 2022 through Rele... Read more

    Affected Products : 3dexperience
    • Published: Mar. 01, 2024
    • Modified: Nov. 21, 2024
  • 9.4

    HIGH
    CVE-2008-5518

    Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allow remote attackers to upload files to arbitrary directories via directory traversal sequences in the (1) ... Read more

    Affected Products : windows geronimo
    • Published: Apr. 17, 2009
    • Modified: Apr. 09, 2025
  • 9.4

    HIGH
    CVE-2020-11285

    Buffer over-read while unpacking the RTCP packet we may read extra byte if wrong length is provided in RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdr... Read more

    • Published: May. 07, 2021
    • Modified: Nov. 21, 2024
  • 9.4

    HIGH
    CVE-2020-11276

    Possible buffer over read while processing P2P IE and NOA attribute of beacon and probe response frames due to improper validation of P2P IE and NOA attribute lengths in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Ele... Read more

    • Published: Feb. 22, 2021
    • Modified: Nov. 21, 2024
  • 9.4

    HIGH
    CVE-2020-11247

    Out of bound memory read while unpacking data due to lack of offset length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Mus... Read more

    • Published: Apr. 07, 2021
    • Modified: Nov. 21, 2024
  • 9.4

    HIGH
    CVE-2005-4332

    Cisco Clean Access 3.5.5 and earlier on the Secure Smart Manager allows remote attackers to bypass authentication and cause a denial of service or upload files via direct requests to obsolete JSP files including (1) admin/uploadclient.jsp, (2) apply_firmw... Read more

    • Published: Dec. 17, 2005
    • Modified: Apr. 03, 2025
  • 9.4

    CRITICAL
    CVE-2020-10265

    Universal Robots Robot Controllers Version CB2 SW Version 1.4 upwards, CB3 SW Version 3.0 and upwards, e-series SW Version 5.0 and upwards expose a service called DashBoard server at port 29999 that allows for control over core robot functions like starti... Read more

    Affected Products : ur_software ur10 ur3 ur5 ur10e ur3e ur5e
    • Published: Apr. 06, 2020
    • Modified: Nov. 21, 2024
  • 9.4

    HIGH
    CVE-2005-4156

    Unspecified vulnerability in Mambo 4.5 (1.0.0) through 4.5 (1.0.9), with magic_quotes_gpc disabled, allows remote attackers to read arbitrary files and possibly cause a denial of service via a query string that ends with a NULL character.... Read more

    Affected Products : mambo_open_source_4.5
    • Published: Dec. 11, 2005
    • Modified: Apr. 03, 2025
  • 9.4

    HIGH
    CVE-2020-11126

    Possible out of bound read while WLAN frame parsing due to lack of check for body and header length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industri... Read more

    • Published: Jun. 09, 2021
    • Modified: Nov. 21, 2024
  • 9.4

    CRITICAL
    CVE-2024-0964

    A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API request.... Read more

    Affected Products : gradio
    • Published: Feb. 05, 2024
    • Modified: Nov. 21, 2024
  • 9.4

    HIGH
    CVE-2002-2268

    Buffer overflow in Webster HTTP Server allows remote attackers to execute arbitrary code via a long URL.... Read more

    Affected Products : webster_http_server
    • Published: Dec. 31, 2002
    • Modified: Apr. 03, 2025
  • 9.4

    CRITICAL
    CVE-2019-6665

    On BIG-IP ASM 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, BIG-IQ 6.0.0 and 5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, an attacker with access to the device communication between the BIG-IP ASM Central Policy Builder ... Read more

    • Published: Nov. 27, 2019
    • Modified: Nov. 21, 2024
Showing 20 of 292803 Results