Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.3

    HIGH
    CVE-2009-1639

    Stack-based buffer overflow in Nucleus Data Recovery Kernel Recovery for Novell 4.03 allows user-assisted attackers to execute arbitrary code via a crafted .NKNT file.... Read more

    Affected Products : kernel_recovery
    • Published: May. 15, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2009-1644

    Stack-based buffer overflow in Sorinara Streaming Audio Player 0.9 allows remote attackers to execute arbitrary code via a crafted .pla file.... Read more

    Affected Products : streaming_audio_player
    • Published: May. 15, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2009-1666

    Multiple unspecified vulnerabilities in CycloMedia CycloScopeLite 2.50.3.0 allow remote attackers to execute arbitrary code via the ReturnConnection method in (1) CM_ADOConnection.dll, (2) CM_AddressInfoDBC.dll, and (3) CM_RecordingLocationDBC.dll, relate... Read more

    Affected Products : cycloscopelite
    • Published: May. 18, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2018-14923

    A vulnerability in uniview EZPlayer 1.0.6 could allow an attacker to execute arbitrary code on a targeted system via video playback.... Read more

    Affected Products : ezplayer
    • Published: Aug. 03, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2010-3041

    Multiple buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitra... Read more

    • Published: Feb. 02, 2011
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2010-3134

    Untrusted search path vulnerability in Google Earth 5.1.3535.3218 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse quserex.dll that is located in the same folder as a .kmz fi... Read more

    Affected Products : earth
    • Published: Aug. 26, 2010
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2010-3143

    Untrusted search path vulnerability in Microsoft Windows Contacts allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wab32res.dll that is located in the same folder as a .conta... Read more

    Affected Products : windows windows_11_23h2
    • Published: Aug. 27, 2010
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2009-3484

    Stack-based buffer overflow in Core FTP 2.1 build 1612 allows user-assisted remote attackers to execute arbitrary code via a long hostname in an FTP server entry in a site backup file. NOTE: some of these details are obtained from third party information... Read more

    Affected Products : core_ftp
    • Published: Sep. 30, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2019-1636

    A vulnerability in the Cisco Webex Teams client, formerly Cisco Spark, could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application URI that is defined in Windows oper... Read more

    Affected Products : webex_teams
    • Published: Jan. 23, 2019
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2010-4182

    Untrusted search path vulnerability in the Data Access Objects (DAO) library (dao360.dll) in Microsoft Windows XP Professional SP3, Windows Server 2003 R2 Enterprise Edition SP3, Windows Vista Business SP1, and Windows 7 Professional allows local users, a... Read more

    • Published: Nov. 04, 2010
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2019-14684

    A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14687... Read more

    Affected Products : password_manager
    • Published: Aug. 20, 2019
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2020-25214

    In the client in Overwolf 0.149.2.30, a channel can be accessed or influenced by an actor that is not an endpoint.... Read more

    Affected Products : overwolf
    • Published: Oct. 16, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2015-7914

    Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 allows remote attackers to bypass authentication by leveraging knowledge of a password hash without knowledge of the associated password.... Read more

    Affected Products : moduweb_vision
    • Published: Feb. 06, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-3865

    The Synaptics touchscreen driver in Android before 2016-09-05 on Nexus 5X and 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 28799389.... Read more

    Affected Products : android
    • Published: Sep. 11, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-3916

    camera/src/camera_metadata.c in the Camera service in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 307417... Read more

    Affected Products : android
    • Published: Oct. 10, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-3928

    The MediaTek video driver in Android before 2016-10-05 allows attackers to gain privileges via a crafted application, aka Android internal bug 30019362 and MediaTek internal bug ALPS02829384.... Read more

    Affected Products : android
    • Published: Oct. 10, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-3939

    drivers/video/msm/mdss/mdss_debug.c in the Qualcomm video driver in Android before 2016-10-05 on Nexus 5X, Nexus 6, Nexus 6P, and Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 30874196 and Qual... Read more

    Affected Products : android
    • Published: Oct. 10, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2019-1772

    A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected softwa... Read more

    • Published: May. 15, 2019
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2020-27277

    Delta Electronics DOPSoft Version 4.0.8.21 and prior has a null pointer dereference issue while processing project files, which may allow an attacker to execute arbitrary code.... Read more

    Affected Products : cncsoft-b dopsoft
    • Published: Jan. 11, 2021
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2017-2253

    Untrusted search path vulnerability in Installer of Yahoo! Toolbar (for Internet explorer) v8.0.0.6 and earlier, with its timestamp prior to June 13, 2017, 18:18:55 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more

    Affected Products : toolbar
    • Published: Jul. 17, 2017
    • Modified: Apr. 20, 2025
Showing 20 of 292813 Results