Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.3

    HIGH
    CVE-2016-10692

    haxeshim haxe shim to deal with coexisting versions. haxeshim downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker contr... Read more

    Affected Products : haxeshim
    • EPSS Score: %1.64
    • Published: Jun. 04, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2016-10694

    alto-saxophone is a module to install and launch Chromedriver for Mac, Linux or Windows. alto-saxophone versions below 2.25.1 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code executio... Read more

    Affected Products : alto-saxophone
    • EPSS Score: %0.77
    • Published: Jun. 04, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2016-10695

    The npm-test-sqlite3-trunk module provides asynchronous, non-blocking SQLite3 bindings. npm-test-sqlite3-trunk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swa... Read more

    Affected Products : npm-test-sqlite3-trunk
    • EPSS Score: %0.77
    • Published: Jun. 04, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2018-5850

    In the function csr_update_fils_params_rso(), insufficient validation on a key length can result in an integer underflow leading to a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kerne... Read more

    Affected Products : android
    • EPSS Score: %0.05
    • Published: Jun. 06, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2023-33030

    Memory corruption in HLOS while running playready use-case.... Read more

    • EPSS Score: %0.06
    • Published: Jan. 02, 2024
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2024-23786

    Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary script on the web browser of the user who is access... Read more

    • EPSS Score: %2.54
    • Published: Feb. 14, 2024
    • Modified: Mar. 18, 2025
  • 9.3

    CRITICAL
    CVE-2024-25625

    Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. A potential security vulnerability has been discovered in `pimcore/admin-ui-classic-bundle` prior to version 1.3.4. The vulnerability involves a Host Header Injection in the `invitationLink... Read more

    Affected Products : admin_classic_bundle
    • Published: Feb. 19, 2024
    • Modified: Apr. 01, 2025
  • 9.3

    HIGH
    CVE-2021-26914

    NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in MvcUtil valueStringToObject.... Read more

    Affected Products : netmotion_mobility
    • EPSS Score: %64.44
    • Published: Feb. 08, 2021
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2022-46823

    A vulnerability has been identified in Mendix SAML (Mendix 8 compatible) (All versions >= V2.3.0 < V2.3.4), Mendix SAML (Mendix 9 compatible, New Track) (All versions >= V3.3.0 < V3.3.9), Mendix SAML (Mendix 9 compatible, Upgrade Track) (All versions >= V... Read more

    Affected Products : saml
    • EPSS Score: %0.46
    • Published: Jan. 10, 2023
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2017-2856

    An exploitable buffer overflow vulnerability exists in the DDNS client used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. On devices with DDNS enabled, an attacker who is able to intercept HTTP connections will be able to fully... Read more

    Affected Products : c1_firmware c1
    • EPSS Score: %0.42
    • Published: Sep. 17, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2018-17208

    Linksys Velop 1.1.2.187020 devices allow unauthenticated command injection, providing an attacker with full root access, via cgi-bin/zbtest.cgi or cgi-bin/zbtest2.cgi (scripts that can be discovered with binwalk on the firmware, but are not visible in the... Read more

    Affected Products : velop_firmware velop
    • EPSS Score: %16.69
    • Published: Sep. 19, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2018-13140

    Druide Antidote through 9.5.1 on Windows and Linux allows remote code execution through the update mechanism by leveraging use of HTTP to download installation packages.... Read more

    Affected Products : linux_kernel windows antidote_9 antidote
    • EPSS Score: %5.06
    • Published: Sep. 24, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2018-9077

    For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the share : name parameter. As a result, arbitrary co... Read more

    • EPSS Score: %1.87
    • Published: Sep. 28, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2021-42833

    A Use of Hardcoded Credentials vulnerability exists in AquaView versions 1.60, 7.x, and 8.x that could allow an authenticated local attacker to manipulate users and system settings.... Read more

    Affected Products : aquaview
    • EPSS Score: %0.04
    • Published: Feb. 07, 2022
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2018-9491

    In AMediaCodecCryptoInfo_new of NdkMediaCodec.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to remote code execution in external apps with no additional execution privileges needed. User interaction is needed for... Read more

    Affected Products : android
    • EPSS Score: %0.33
    • Published: Oct. 02, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2018-9497

    In impeg2_fmt_conv_yuv420p_to_yuv420sp_uv_av8 of impeg2_format_conv.s there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed ... Read more

    Affected Products : android
    • EPSS Score: %0.41
    • Published: Oct. 02, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2017-0796

    A elevation of privilege vulnerability in the MediaTek auxadc driver. Product: Android. Versions: Android kernel. Android ID: A-62458865. References: M-ALPS03353884, M-ALPS03353886, M-ALPS03353887.... Read more

    Affected Products : android
    • EPSS Score: %0.04
    • Published: Sep. 08, 2017
    • Modified: Apr. 20, 2025
  • 9.3

    HIGH
    CVE-2017-0800

    A elevation of privilege vulnerability in the MediaTek teei. Product: Android. Versions: Android kernel. Android ID: A-37683975. References: M-ALPS03302988.... Read more

    Affected Products : android
    • EPSS Score: %0.09
    • Published: Sep. 08, 2017
    • Modified: Apr. 20, 2025
  • 9.3

    HIGH
    CVE-2017-14262

    On Samsung NVR devices, remote attackers can read the MD5 password hash of the 'admin' account via certain szUserName JSON data to cgi-bin/main-cgi, and login to the device with that hash in the szUserPasswd parameter.... Read more

    • EPSS Score: %21.02
    • Published: Sep. 11, 2017
    • Modified: Apr. 20, 2025
  • 9.3

    HIGH
    CVE-2017-10855

    Untrusted search path vulnerability in FENCE-Explorer for Windows V8.4.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more

    • EPSS Score: %0.14
    • Published: Sep. 15, 2017
    • Modified: Apr. 20, 2025
Showing 20 of 292495 Results