Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.3

    HIGH
    CVE-2007-5820

    Directory traversal vulnerability in index.php in Ax Developer CMS (AxDCMS) 0.1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter.... Read more

    Affected Products : ax_developer_cms
    • EPSS Score: %2.18
    • Published: Nov. 05, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2007-6009

    Multiple buffer overflows in ACD products allow user-assisted remote attackers to execute arbitrary code via a long section string in a (1) XBM or (2) XPM file to (a) ID_X.apl or (b) IDE_ACDStd.apl. NOTE: the PSP and LHA vectors are already covered by CV... Read more

    • EPSS Score: %5.57
    • Published: Nov. 15, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2007-6008

    Heap-based buffer overflow in emlsr.dll before 2.0.0.4 in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK allows remote attackers to execute arbitrary code via a long Content-Type header line in an EML file. NOTE: the provenance of this... Read more

    • EPSS Score: %3.63
    • Published: Nov. 15, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2007-4344

    Multiple input validation errors in ACD ACDSee Photo Manager 9.0 build 108, Pro Photo Manager 8.1 build 99, and Photo Editor 4.0 build 195 allow user-assisted remote attackers to execute arbitrary code via a long section string in (1) a PSP image to the I... Read more

    • EPSS Score: %10.35
    • Published: Nov. 15, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2007-6088

    PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBBViet 02.03.07 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.... Read more

    Affected Products : phpbbviet
    • EPSS Score: %2.41
    • Published: Nov. 22, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2007-6086

    Directory traversal vulnerability in index.php in VigileCMS 1.4 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the module parameter.... Read more

    Affected Products : vigilecms
    • EPSS Score: %2.38
    • Published: Nov. 22, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2007-6189

    A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remote attackers to execute arbitrary code via a long argument to the InitX method that begins with a "%%" sequence, which is misinterprete... Read more

    Affected Products : online_anti-virus_scanner
    • EPSS Score: %13.20
    • Published: Nov. 30, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2007-6436

    Stack-based buffer overflow in JSGCI.DLL in JustSystems Ichitaro 2005, 2006, and 2007 allows user-assisted remote attackers to execute arbitrary code via a crafted document, as actively exploited in December 2007 by the Tarodrop.F trojan. NOTE: some of t... Read more

    Affected Products : ichitaro ichitaro
    • EPSS Score: %5.82
    • Published: Dec. 18, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2007-6555

    PHP remote file inclusion vulnerability in modules/mod_pxt_latest.php in the mosDirectory (com_directory) 2.3.2 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path] parameter.... Read more

    Affected Products : mosdirectory
    • EPSS Score: %2.79
    • Published: Dec. 28, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-0379

    Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SelectedSession method, whic... Read more

    Affected Products : crystal_reports_xi
    • EPSS Score: %14.00
    • Published: Jan. 22, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-0392

    Multiple buffer overflows in Microsoft Visual Basic Enterprise Edition 6.0 SP6 allow user-assisted remote attackers to execute arbitrary code via a .dsr file with a long (1) ConnectionName or (2) CommandName line.... Read more

    Affected Products : visual_basic
    • EPSS Score: %53.06
    • Published: Jan. 23, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-0493

    fpx.dll 3.9.8.0 in the FlashPix plugin for IrfanView 4.10 allows remote attackers to execute arbitrary code via a crafted FlashPix (.FPX) file, which triggers heap corruption. NOTE: some of these details are obtained from third party information.... Read more

    Affected Products : irfanview
    • EPSS Score: %7.61
    • Published: Jan. 30, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-0715

    Buffer overflow in ACDSee Photo Manager 8.1, 9.0, and 10.0 allows user-assisted remote attackers to execute arbitrary code via a malformed XBM file. NOTE: this might be the same as CVE-2007-6009.... Read more

    Affected Products : photo_manager
    • EPSS Score: %3.92
    • Published: Feb. 12, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-0531

    Heap-based buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SIP firmware might allow remote SIP servers to execute arbitrary code via a crafted challenge/response message.... Read more

    • EPSS Score: %1.53
    • Published: Feb. 15, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-1116

    Insecure method vulnerability in the Web Scan Object ActiveX control (OL2005.dll) in Rising Antivirus Online Scanner allows remote attackers to force the download and execution of arbitrary code by setting the BaseURL property and invoking the UpdateEngin... Read more

    Affected Products : rising_web_scan_object
    • EPSS Score: %6.93
    • Published: Mar. 03, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2007-6253

    Multiple buffer overflows in Adobe Form Designer 5.0 and Form Client 5.0 allow remote attackers to execute arbitrary code via unknown vectors in the (1) Adobe File Dialog Button (FileDlg.dll) and the (2) Adobe Copy to Server Object (SvrCopy.dll) ActiveX c... Read more

    Affected Products : form_client form_designer
    • EPSS Score: %36.11
    • Published: Mar. 12, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-1465

    SQL injection vulnerability in the Detodas Restaurante (com_restaurante) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php, a different product than CVE-2008-... Read more

    Affected Products : joomla\! mambo com_restaurante
    • EPSS Score: %0.45
    • Published: Mar. 24, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-1092

    Buffer overflow in msjet40.dll before 4.0.9505.0 in Microsoft Jet Database Engine allows remote attackers to execute arbitrary code via a crafted Word file, as exploited in the wild in March 2008. NOTE: as of 20080513, Microsoft has stated that this is t... Read more

    • EPSS Score: %63.02
    • Published: Mar. 25, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-0312

    Stack-based buffer overflow in the AutoFix Support Tool ActiveX control 2.7.0.1 in SYMADATA.DLL in multiple Symantec Norton products, including Norton 360 1.0, AntiVirus 2006 through 2008, Internet Security 2006 through 2008, and System Works 2006 through... Read more

    • EPSS Score: %23.04
    • Published: Apr. 08, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-1860

    Static code injection vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to inject arbitrary PHP code into includes/Config.php via the default parameter.... Read more

    Affected Products : lokicms
    • EPSS Score: %4.65
    • Published: Apr. 17, 2008
    • Modified: Apr. 09, 2025
Showing 20 of 291384 Results