Latest CVE Feed
-
9.3
HIGHCVE-2022-26337
Trend Micro Password Manager (Consumer) installer version 5.0.0.1262 and below is vulnerable to an Uncontrolled Search Path Element vulnerability that could allow an attacker to use a specially crafted file to exploit the vulnerability and escalate local ... Read more
Affected Products : password_manager- EPSS Score: %0.17
- Published: Mar. 08, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2022-25218
The use of the RSA algorithm without OAEP, or any other padding scheme, in telnetd_startup, allows an unauthenticated attacker on the local area network to achieve a significant degree of control over the "plaintext" to which an arbitrary blob of cipherte... Read more
Affected Products : k2_firmware k3_firmware k3c_firmware k2g_firmware k2p_firmware k2 k3 k3c k2g k2p- EPSS Score: %1.16
- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2023-21671
Memory Corruption in Core during syscall for Sectools Fuse comparison feature.... Read more
Affected Products : qca6391_firmware wcd9380_firmware wcd9385_firmware wsa8830_firmware wsa8835_firmware qcm6490_firmware qcs6490_firmware qsm8350_firmware sd888_firmware sm7315_firmware +40 more products- EPSS Score: %0.06
- Published: Nov. 07, 2023
- Modified: Aug. 11, 2025
-
9.3
HIGHCVE-2016-10432
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 410/12, SD 425, SD 430, SD 450, SD 617, SD 625, SD 650/52, SD 820, and SD 820A, TOCTOU vulnerabilities may occur while sanitizing users... Read more
Affected Products : sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware sd_410_firmware sd_412_firmware sd_425_firmware sd_430_firmware sd_650_firmware sd_652_firmware +12 more products- EPSS Score: %0.17
- Published: Apr. 18, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-1000167
OISF suricata-update version 1.0.0a1 contains an Insecure Deserialization vulnerability in the insecure yaml.load-Function as used in the following files: config.py:136, config.py:142, sources.py:99 and sources.py:131. The "list-sources"-command is affect... Read more
- EPSS Score: %1.51
- Published: Apr. 18, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-8974
Centers for Disease Control and Prevention MicrobeTRACE 0.1.11 allows remote attackers to execute arbitrary code, related to code injection via a crafted CSV file with an initial 'Source<script type="text/javascript" src=' line. Fix released on 2018-03-28... Read more
Affected Products : microbetrace- EPSS Score: %1.69
- Published: Apr. 26, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-8115
A remote code execution vulnerability exists when the Windows Host Compute Service Shim (hcsshim) library fails to properly validate input while importing a container image, aka "Windows Host Compute Service Shim Remote Code Execution Vulnerability." This... Read more
Affected Products : windows_host_compute_service_shim- EPSS Score: %7.04
- Published: May. 02, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-8872
In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, system calls read directly from memory addresses within the control program area without any verification. Manipulating this data could allow attacker data to be copied anywh... Read more
- EPSS Score: %0.80
- Published: May. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2023-49079
Misskey is an open source, decentralized social media platform. Misskey's missing signature validation allows arbitrary users to impersonate any remote user. This issue has been patched in version 2023.11.1-beta.1.... Read more
Affected Products : misskey- EPSS Score: %0.14
- Published: Nov. 29, 2023
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-0306
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device comp... Read more
- EPSS Score: %0.24
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0505
An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of th... Read more
Affected Products : android- EPSS Score: %3.78
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-10558
aerospike is an Aerospike add-on module for Node.js. aerospike versions below 2.4.2 download binary resources over HTTP, which leaves the module vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the reques... Read more
Affected Products : aerospike- EPSS Score: %0.77
- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10559
selenium-download downloads the latest versions of the selenium standalone server and the chromedriver. selenium-download before 2.0.7 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote cod... Read more
Affected Products : selenium-download- EPSS Score: %0.77
- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10593
ibapi is an Interactive Brokers API addon for NodeJS. ibapi downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. Before 2.5.6, it may be possible to cause remote code execution (RCE) by swapping out the requested binary with a... Read more
Affected Products : ibapi- EPSS Score: %1.54
- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10601
webdrvr is a npm wrapper for Selenium Webdriver including Chromedriver / IEDriver / IOSDriver / Ghostdriver. webdrvr downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) ... Read more
Affected Products : webdrvr- EPSS Score: %0.55
- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10627
scala-bin is a binary wrapper for Scala. scala-bin downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled b... Read more
Affected Products : scala-bin- EPSS Score: %0.77
- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10674
limbus-buildgen is a "build anywhere" build system. limbus-buildgen versions below 0.1.1 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested... Read more
Affected Products : limbus-buildgen- EPSS Score: %0.77
- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-16003
windows-build-tools is a module for installing C++ Build Tools for Windows using npm. windows-build-tools versions below 1.0.0 download resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE... Read more
Affected Products : windows-build-tools- EPSS Score: %0.74
- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10567
product-monitor is a HTML/JavaScript template for monitoring a product by encouraging product developers to gather all the information about the status of a product, including live monitoring, statistics, endpoints, and test results into one place. produc... Read more
Affected Products : product-monitor- EPSS Score: %0.77
- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10569
embedza is a module to create HTML snippets/embeds from URLs using info from oEmbed, Open Graph, meta tags. embedza versions below 1.2.4 download JavaScript resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remot... Read more
Affected Products : embedza- EPSS Score: %0.77
- Published: May. 31, 2018
- Modified: Nov. 21, 2024