Latest CVE Feed
-
9.3
HIGHCVE-2020-14026
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the Export Of Contacts feature in Ozeki NG SMS Gateway through 4.17.6 via a value that is mishandled in a CSV export.... Read more
Affected Products : ozeki_ng_sms_gateway- Published: Sep. 22, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2010-1179
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a large integer in the numcolors attribute of a recolorinfo element in a VML file, possibly a re... Read more
- Published: Mar. 29, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2016-6182
The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C00 before CHM-TL00HC00B564 allows attackers to cause a denial of service (system crash) or gain privileges ... Read more
- Published: Sep. 07, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-0858
Race condition in Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a crafted request.... Read more
- Published: Jan. 15, 2016
- Modified: Apr. 12, 2025
-
9.3
CRITICALCVE-2018-2623
Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: User Interface). The supported version that is affected is Prior to 8.7.13. Easily exploitable vulnerability allows unauthenticated attac... Read more
- Published: Jan. 18, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-43664
totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component process forceugpo.... Read more
- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-1926
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected sof... Read more
- Published: Aug. 07, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-1928
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected sof... Read more
- Published: Aug. 07, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-6736
An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of ... Read more
Affected Products : android- Published: Nov. 25, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-10297
In TrustZone in all Android releases from CAF using the Linux kernel, a Time-of-Check Time-of-Use Race Condition vulnerability could potentially exist.... Read more
Affected Products : android- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-10435
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9625, MDM9635M, MDM9640, MDM9645, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450,... Read more
Affected Products : sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware msm8909w_firmware mdm9206_firmware mdm9635m_firmware mdm9640_firmware mdm9645_firmware mdm9625_firmware +42 more products- Published: Apr. 18, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-11457
A vulnerability has been identified in SINUMERIK 828D V4.7 (All versions < V4.7 SP6 HF1), SINUMERIK 840D sl V4.7 (All versions < V4.7 SP6 HF5), SINUMERIK 840D sl V4.8 (All versions < V4.8 SP3). The integrated web server on port 4842/tcp of the affected pr... Read more
- Published: Dec. 12, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-26912
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in SupportRpcServlet.... Read more
Affected Products : netmotion_mobility- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10591
Prince is a Node API for executing XML/HTML to PDF renderer PrinceXML via prince(1) CLI. prince downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the r... Read more
Affected Products : prince- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10643
jstestdriver is a wrapper for Google's jstestdriver. jstestdriver downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attack... Read more
Affected Products : jstestdriver- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-21817
NVIDIA Omniverse Launcher contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can get user to browse malicious site, to acquire access tokens allowing them to access resources in other sec... Read more
- Published: Feb. 02, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-2132
It is possible to overlay the VPN dialog by a malicious application. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Andr... Read more
Affected Products : android- Published: Aug. 20, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-33256
A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse shell could be obtained if a privile... Read more
Affected Products : manageengine_adselfservice_plus- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-35082
Improper integrity check can lead to race condition between tasks PDCP and RRC? right after a valid RRC security mode command packet has been received in Snapdragon Industrial IOT... Read more
- Published: Jun. 14, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-22710
A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could cause remote code execution when malicious CGF (C... Read more
Affected Products : interactive_graphical_scada_system- Published: Mar. 11, 2021
- Modified: Nov. 21, 2024