Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.3

    CRITICAL
    CVE-2024-45367

    The web server for ONS-S8 - Spectra Aggregation Switch includes an incomplete authentication process, which can lead to an attacker authenticating without a password.... Read more

    Affected Products :
    • Published: Oct. 03, 2024
    • Modified: Oct. 04, 2024
  • 9.3

    CRITICAL
    CVE-2022-27660

    A denial of service vulnerability exists in the confctl_set_guest_wlan functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to denial of service. An attacker can send packets to trigger this vulnerability.... Read more

    • Published: Aug. 05, 2022
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2018-1000006

    GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically Electron apps running on Windows 10, 7 or 2008 that register custom protocol handlers can be tricked in arb... Read more

    • Published: Jan. 24, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2011-5158

    Multiple untrusted search path vulnerabilities in the DMTGUI2.EXE and DvInesLogFileViewer.Exe components in DATEV Grundpaket Basis CD23.20 allow local users to gain privileges via a Trojan horse (1) DVBSKNLANG101.dll or (2) DvZediTermSrvInfo004.dll file i... Read more

    Affected Products : grundpaket_basis
    • Published: Sep. 07, 2012
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2020-0449

    In btm_sec_disconnected of btm_sec.cc, there is a possible memory corruption due to a use after free. This could lead to remote code execution in the Bluetooth server with no additional execution privileges needed. User interaction is needed for exploitat... Read more

    Affected Products : android
    • Published: Nov. 10, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2024-48974

    The ventilator does not perform proper file integrity checks when adopting firmware updates. This makes it possible for an attacker to force unauthorized changes to the device's configuration settings and/or compromise device functionality by pushing a co... Read more

    Affected Products :
    • Published: Nov. 14, 2024
    • Modified: Nov. 15, 2024
  • 9.3

    HIGH
    CVE-2012-0224

    Untrusted search path vulnerability in 7-Technologies (7T) AQUIS 1.5 and earlier allows local users to gain privileges via a Trojan horse DLL in the current working directory, a different vulnerability than CVE-2012-0223.... Read more

    Affected Products : aquis
    • Published: Feb. 21, 2012
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2013-0113

    Nuance PDF Reader 7.0 and PDF Viewer Plus 7.1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document.... Read more

    Affected Products : pdf_reader pdf_reader_plus
    • Published: Feb. 24, 2013
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2017-8142

    The Trusted Execution Environment (TEE) module driver of Mate 9 and Mate 9 Pro smart phones with software versions earlier than MHA-AL00BC00B221 and versions earlier than LON-AL00BC00B221 has a use after free (UAF) vulnerability. An attacker tricks a user... Read more

    • Published: Nov. 22, 2017
    • Modified: Apr. 20, 2025
  • 9.3

    HIGH
    CVE-2014-9869

    drivers/media/platform/msm/camera_v2/isp/msm_isp_stats_util.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not validate certain index values, which allows attackers to gain privileges via a crafted applicati... Read more

    Affected Products : android
    • Published: Aug. 06, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    CRITICAL
    CVE-2022-31512

    The Atom02/flask-mvc repository through 2020-09-14 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more

    Affected Products : flask-mvc
    • Published: Jul. 11, 2022
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2009-0134

    Insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control in EasyGrid.ocx 1.0.0.1 in AAA EasyGrid ActiveX 3.51 allows remote attackers to create and overwrite arbitrary files via the (1) DoSaveFile or (2) DoSaveHtmlFile method. NOTE: vector... Read more

    Affected Products : easy_grid_control
    • Published: Jan. 16, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    CRITICAL
    CVE-2024-24986

    Improper access control in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more

    • Published: Aug. 14, 2024
    • Modified: Sep. 06, 2024
  • 9.3

    CRITICAL
    CVE-2022-31577

    The longmaoteamtf/audio_aligner_app repository through 2020-01-10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more

    Affected Products : audio_aligner_app
    • Published: Jul. 11, 2022
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2020-35798

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.84, R6900P before 1.3.2.124, R7000 before 1.0.11.100, R7000P before 1.3.2.124, R7800 before 1.0.2.74, R785... Read more

    • Published: Dec. 30, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2020-6238

    SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyformsweb, leading to Missing XML Validation. This affects confidentiality and availability (partially) of SAP Commerce.... Read more

    Affected Products : commerce_cloud commerce
    • Published: Apr. 14, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2018-7922

    Huawei ALP-L09 smart phones with versions earlier than ALP-L09 8.0.0.150(C432) have an insufficient input validation vulnerability due to lack of parameter check. An attacker tricks the user who has root privilege to install a crafted application, the app... Read more

    Affected Products : alp-l09_firmware alp-l09
    • Published: Sep. 12, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2022-31588

    The zippies/testplatform repository through 2016-07-19 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more

    Affected Products : testplatform
    • Published: Jul. 11, 2022
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2007-5279

    Heap-based buffer overflow in ConeXware PowerArchiver before 10.20.21 might allow remote attackers to execute arbitrary code via a long filename in a BlackHole archive.... Read more

    Affected Products : powerarchiver powerarchiver
    • Published: Oct. 09, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2018-8936

    The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips allow Platform Security Processor (PSP) privilege escalation.... Read more

    • Published: Mar. 22, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 293280 Results