Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.3

    CRITICAL
    CVE-2020-35798

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.84, R6900P before 1.3.2.124, R7000 before 1.0.11.100, R7000P before 1.3.2.124, R7800 before 1.0.2.74, R785... Read more

    • Published: Dec. 30, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2020-6238

    SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyformsweb, leading to Missing XML Validation. This affects confidentiality and availability (partially) of SAP Commerce.... Read more

    Affected Products : commerce_cloud commerce
    • Published: Apr. 14, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2018-7922

    Huawei ALP-L09 smart phones with versions earlier than ALP-L09 8.0.0.150(C432) have an insufficient input validation vulnerability due to lack of parameter check. An attacker tricks the user who has root privilege to install a crafted application, the app... Read more

    Affected Products : alp-l09_firmware alp-l09
    • Published: Sep. 12, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2022-31588

    The zippies/testplatform repository through 2016-07-19 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more

    Affected Products : testplatform
    • Published: Jul. 11, 2022
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2007-5279

    Heap-based buffer overflow in ConeXware PowerArchiver before 10.20.21 might allow remote attackers to execute arbitrary code via a long filename in a BlackHole archive.... Read more

    Affected Products : powerarchiver powerarchiver
    • Published: Oct. 09, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2018-8936

    The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips allow Platform Security Processor (PSP) privilege escalation.... Read more

    • Published: Mar. 22, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2018-9490

    In CollectValuesOrEntriesImpl of elements.cc, there is possible remote code execution due to type confusion. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Pro... Read more

    Affected Products : android
    • Published: Oct. 02, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2018-9521

    In parseMPEGCCData of NuPlayer2CCDecoder.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is... Read more

    Affected Products : android
    • Published: Nov. 14, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2018-9577

    In impd_parametric_drc_parse_gain_set_params of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is nee... Read more

    Affected Products : android
    • Published: Dec. 07, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2010-4723

    Smarty before 3.0.0, when security is enabled, does not prevent access to the (1) dynamic and (2) private object members of an assigned object, which has unspecified impact and remote attack vectors.... Read more

    Affected Products : smarty
    • Published: Feb. 03, 2011
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2013-3027

    Integer overflow in the DWA9W ActiveX control in iNotes in IBM Domino 9.0 before IF3 allows remote attackers to execute arbitrary code via a crafted web page, aka SPR PTHN97XHFW.... Read more

    Affected Products : lotus_domino
    • Published: Aug. 09, 2013
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2008-4321

    Buffer overflow in FlashGet (formerly JetCar) FTP 1.9 allows remote FTP servers to execute arbitrary code via a long response to the PWD command.... Read more

    Affected Products : flashget_ftp
    • Published: Sep. 29, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2020-13259

    A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to ins... Read more

    Affected Products : secflow-1v_firmware secflow-1v
    • Published: Sep. 16, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2020-5760

    Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to an OS command injection vulnerability. Unauthenticated remote attackers can execute arbitrary commands as root by crafting a special configuration file and sending a crafted SIP... Read more

    • Published: Jul. 29, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2018-9083

    In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via some other vulnerability.... Read more

    • Published: Nov. 27, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2017-0604

    An elevation of privilege vulnerability in the kernel Qualcomm power driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent ... Read more

    Affected Products : android
    • Published: May. 12, 2017
    • Modified: Apr. 20, 2025
  • 9.3

    HIGH
    CVE-2017-0675

    A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34779227.... Read more

    Affected Products : android
    • Published: Jul. 06, 2017
    • Modified: Apr. 20, 2025
  • 9.3

    HIGH
    CVE-2017-0684

    A elevation of privilege vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35421151.... Read more

    Affected Products : android
    • Published: Jul. 06, 2017
    • Modified: Apr. 20, 2025
  • 9.3

    HIGH
    CVE-2007-0020

    Heap-based buffer overflow in the SFTP protocol handler for Panic Transmit (Transmit.app) up to 3.5.5 allows remote attackers to execute arbitrary code via a long ftps:// URL.... Read more

    Affected Products : panic_transmit
    • Published: Jan. 24, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2018-13806

    A vulnerability has been identified in SIEMENS TD Keypad Designer (All versions). A DLL hijacking vulnerability exists in all versions of SIEMENS TD Keypad Designer which could allow an attacker to execute code with the permission of the user running TD D... Read more

    Affected Products : td_keypad_designer
    • Published: Sep. 12, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 292796 Results