Latest CVE Feed
-
9.3
CRITICALCVE-2025-34117
A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior to August 2014 due to the presence of an undocumented backdoor listener on UDP port 53413. Exact version boundaries remain undocumented.... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Authentication
-
9.3
CRITICALCVE-2025-34101
An unauthenticated command injection vulnerability exists in Serviio Media Server versions 1.4 through 1.8 on Windows, in the /rest/action API endpoint exposed by the console component (default port 23423). The checkStreamUrl method accepts a VIDEO parame... Read more
Affected Products :- Published: Jul. 10, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-34102
A remote code execution vulnerability exists in CryptoLog (PHP version, discontinued since 2009) due to a chained exploitation of SQL injection and command injection vulnerabilities. An unauthenticated attacker can gain shell access as the web server user... Read more
Affected Products :- Published: Jul. 10, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-34095
An OS command injection vulnerability exists in Mako Server versions 2.5 and 2.6, specifically within the tutorial interface provided by the examples/save.lsp endpoint. An unauthenticated attacker can send a crafted PUT request containing arbitrary Lua os... Read more
Affected Products :- Published: Jul. 10, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Injection
-
9.3
HIGHCVE-2016-2492
The MediaTek power-management driver in Android before 2016-06-01 on Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 28085410.... Read more
- Published: Jun. 13, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2018-7923
Huawei ALP-L09 smart phones with versions earlier than ALP-L09 8.0.0.150(C432) have an insufficient input validation vulnerability due to lack of parameter check. An attacker tricks the user who has root privilege to install a crafted application, the app... Read more
- Published: Sep. 12, 2018
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2023-50254
Deepin Linux's default document reader `deepin-reader` software suffers from a serious vulnerability in versions prior to 6.0.7 due to a design flaw that leads to remote command execution via crafted docx document. This is a file overwrite vulnerability. ... Read more
- Published: Dec. 22, 2023
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2006-6749
Buffer overflow in the parse_expression function in parse_config in OpenSER 1.1.0 allows attackers to have an unknown impact via a long str parameter.... Read more
Affected Products : openser- Published: Dec. 27, 2006
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2006-5574
Unspecified vulnerability in the Brazilian Portuguese Grammar Checker in Microsoft Office 2003 and the Multilingual Interface for Office 2003, Project 2003, and Visio 2003 allows user-assisted remote attackers to execute arbitrary code via crafted text th... Read more
- Published: Dec. 31, 2006
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-0766
Stack-based buffer overflow in Remotesoft .NET Explorer 2.0.1 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long line in a .cpp file.... Read more
Affected Products : .net_explorer- Published: Feb. 06, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2006-7064
Cross-site scripting (XSS) vulnerability in forum/admin.php for Invision Power Board (IPB) 2.1.6 and earlier allows remote attackers to inject arbitrary web script or HTML as the administrator via the phpinfo parameter.... Read more
Affected Products : invision_power_board- Published: Feb. 24, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-2192
Buffer overflow in Photofiltre Studio 8.1.1 allows user-assisted remote attackers to execute arbitrary code via a crafted .tif file.... Read more
Affected Products : photofiltre_studio- Published: Apr. 24, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-2648
Stack-based buffer overflow in the Clever Database Comparer 2.2 ActiveX control (comparerax.ocx) allows remote attackers to execute arbitrary code via a long argument to the ConnectToDatabase function.... Read more
Affected Products : clever_database_comparer- Published: May. 14, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-2758
Multiple buffer overflows in WinImage 8.0.8000 allow user-assisted remote attackers to execute arbitrary code via a FAT image that contains long directory names in a deeply nested directory structure, which triggers (1) a stack-based buffer overflow durin... Read more
Affected Products : winimage- Published: May. 18, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-2847
Multiple cross-site scripting (XSS) vulnerabilities in hlstats.php in HLstats 1.35, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) authusername or (2) authpassword parameter, different vectors than CVE-2007... Read more
Affected Products : hlstats- Published: May. 24, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-2981
Buffer overflow in a certain ActiveX control in LEAD Technologies LEADTOOLS Raster OCR Document Object Library (ltrdc14e.dll) 14.5.0.44 allows remote attackers to execute arbitrary code via a long DictionaryFileName property.... Read more
Affected Products : leadtools_raster_ocr_document_object_library- Published: Jun. 01, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-3071
Buffer overflow in the GetWebStoreURL function in a certain ActiveX control in eSellerateControl365.dll 3.6.5.0 in eSellerate SDK allows user-assisted remote attackers to execute arbitrary code via a long first argument.... Read more
Affected Products : esellerate_sdk- Published: Jun. 06, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-3150
Google Desktop allows user-assisted remote attackers to execute arbitrary programs via a man-in-the-middle attack that injects JavaScript, a www.google.com search IFRAME, and a META HTTP-EQUIV="refresh" that targets a www.google.com search for a local .ex... Read more
Affected Products : desktop- Published: Jun. 11, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-3376
Buffer overflow in Apple Safari 3.0.2 on Windows XP SP2 allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long value in the title HTML tag, which triggers the overflow when the user adds t... Read more
- Published: Jun. 25, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-3489
Cross-site request forgery (CSRF) vulnerability in pop/WizU.html in the management interface in Check Point VPN-1 Edge X Embedded NGX 7.0.33x on the Check Point VPN-1 UTM Edge allows remote attackers to perform privileged actions as administrators, as dem... Read more
Affected Products : vpn-1_utm_edge- Published: Jun. 29, 2007
- Modified: Apr. 09, 2025