Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.3

    HIGH
    CVE-2020-0267

    In WindowManager, there is a possible launch of an unexpected app due to a confused deputy. This could lead to local escalation of privilege due to launching a malicious app instead of the one the user intended, with no additional execution privileges nee... Read more

    Affected Products : android
    • Published: Sep. 17, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2020-0387

    In manifest files of the SmartSpace package, there is a possible tapjacking vector due to a missing permission check. This could lead to local escalation of privilege and account hijacking with no additional execution privileges needed. User interaction i... Read more

    Affected Products : android
    • Published: Sep. 17, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2020-9590

    Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more

    • Published: Jun. 26, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2016-6193

    Buffer overflow in the Wi-Fi driver in Huawei P8 smartphones with software before GRA-CL00C92B363 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application, a different vulnerability than CVE-2016-6192.... Read more

    Affected Products : p8_smartphone_firmware
    • Published: Aug. 02, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2021-44480

    Wokka Lokka Q50 devices through 2021-11-30 allow remote attackers (who know the SIM phone number and password) to listen to a device's surroundings via a callback in an SMS command, as demonstrated by the 123456 and 523681 default passwords.... Read more

    • Published: Dec. 01, 2021
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2016-6729

    An elevation of privilege vulnerability in the Qualcomm bootloader in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility o... Read more

    Affected Products : android
    • Published: Nov. 25, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    CRITICAL
    CVE-2018-4006

    An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the writeConfig functionality. A non-root user is able to write a file anywhere on the system. A user with local access can use this vulnerability to raise... Read more

    Affected Products : shimo_vpn
    • Published: Apr. 17, 2019
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2016-10433

    In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9635M, MDM9640, MDM9645, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415,... Read more

    • Published: Apr. 18, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2016-10562

    iedriver is an NPM wrapper for Selenium IEDriver. iedriver versions below 3.0.0 download binary resources over HTTP, which leaves the module vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested ... Read more

    Affected Products : iedriver
    • Published: May. 31, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2021-34083

    Google-it is a Node.js package which allows its users to send search queries to Google and receive the results in a JSON format. When using the 'Open in browser' option in versions up to 1.6.2, google-it will unsafely concat the result's link retrieved fr... Read more

    Affected Products : google-it
    • Published: Jun. 02, 2022
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2022-24532

    HEVC Video Extensions Remote Code Execution Vulnerability... Read more

    Affected Products : hevc_video_extensions
    • Published: Apr. 15, 2022
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2008-4471

    Directory traversal vulnerability in the CExpressViewerControl class in the DWF Viewer ActiveX control (AdView.dll 9.0.0.96), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers to overwrite arbitrary files via ... Read more

    • Published: Oct. 07, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2018-17896

    Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credentials which may allow an attacker gain unauthorized access to the maintenance functions and obtain or modify infor... Read more

    • Published: Oct. 12, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2021-37566

    MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. (Affected Chipsets MT7603E, MT7610, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 2.0.2; Out-of-bound... Read more

    • Published: Dec. 26, 2021
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2019-4071

    IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 157063.... Read more

    • Published: May. 09, 2019
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2021-41274

    solidus_auth_devise provides authentication services for the Solidus webstore framework, using the Devise gem. In affected versions solidus_auth_devise is subject to a CSRF vulnerability that allows user account takeover. All applications using any versio... Read more

    Affected Products : solidus_auth_devise
    • Published: Nov. 17, 2021
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2020-13537

    An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on the vector chosen, an attacker can either add code to a script or replace a binary.By default MXViewService... Read more

    Affected Products : mxview
    • Published: Nov. 05, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2023-33072

    Memory corruption in Core while processing control functions.... Read more

    • Published: Feb. 06, 2024
    • Modified: Aug. 11, 2025
  • 9.3

    HIGH
    CVE-2008-5002

    Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilkat Crypt ActiveX Component allows remote attackers to create and overwrite arbitrary files via the WriteFile method. NOTE: this could b... Read more

    Affected Products : chilkat_crypt_activex_control
    • Published: Nov. 10, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2020-4721

    IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute a... Read more

    Affected Products : i2_analysts_notebook
    • Published: Oct. 29, 2020
    • Modified: Nov. 21, 2024
Showing 20 of 293555 Results